Import custom Snort 2 rules

Import custom standard text rules so you can enable them in Snort 2 intrusion policies.

This procedure applies only to custom standard text rules for Snort 2 intrusion policies. For Snort 3, refer to the rule-tuning topics in Custom Snort 3 Intrusion Policies for Access Control.

Before you begin

Procedure


Step 1

Choose Administration > Upgrades & updates > Content Updates > Rule Updates.

You can also click Import Rules in the intrusion rules editor (Policies > + Show more > Security policies > Intrusion Rules).

Step 2

(Optional) Delete all existing custom rules.

To replace all existing custom rules with the rules in the new file, click Delete All Local Rules. The deleted rules move to the deleted rule category, and their revision numbers increase.

Step 3

Import the rule file.

  1. Under One-Time Rule Update/Rules Import, choose Rule update or text rule file to upload and install.

  2. Click Choose File, select your rule file, and click Import.

You can monitor import progress in the Message Center. Even if the Message Center shows no progress for several minutes or indicates that the import has failed, do not restart the import. Instead, contact Cisco TAC.


  • Imported rules are added to the local rule category in a disabled state.

  • Imported rules receive Generator ID (GID) 1.

  • New imported rules receive an available Snort ID (SID) of 1000000 or greater and a revision of 1.

What to do next

  • Edit Snort 2 intrusion policies and enable the rules you imported.

    Do not enable an imported rule that uses the deprecated threshold keyword in an intrusion policy that also uses intrusion event thresholding. This combination causes policy validation to fail.

  • Deploy configuration changes.