Validate Snort 3 policies
This task validates Snort 3 policies to ensure they work correctly with current and previous device versions, handling version-specific configurations and inspector settings.
To validate the Snort 3 policies, here is a list of basic information that you can make note of:
-
Current version of the Firewall Management Center can manage multiple Firewall Threat Defense versions.
-
Current version of Firewall Management Center supports network analysis policy (NAP) configurations which are not applicable to previous version of Firewall Threat Defense devices.
-
Current NAP Policy and validations will work based on the current version support.
-
Changes may include content which is not valid for previous versions of Firewall Threat Defenses.
-
Policy configuration changes are accepted if they are valid for the current version and performed using the current Snort 3 binary and NAP schema.
-
For previous version Firewall Threat Defenses, validation is performed during deployment using NAP schema and Snort 3 binary for that specific version. If there is any configuration which is not applicable for the given version, the user is informed or warned that the configuration not supported on the given version will not be deployed, while the remaining configuration will be deployed.
In this procedure, when we associate the NAP policy to an Access Control Policy and deploy it on a device, for example any inspector like rate filter configuration is applied to validate the Snort 3 policies.
Procedure
Step 1 | Steps to Override NAP Policy Configuration: Under Inspectors in the Snort 3 Version of the network analysis policy, expand the required inspector for which you want to override the default setting. The default configuration is displayed on the left column and the overridden configuration is displayed on the right column under the inspector. | ||||
Step 2 | Click the Actions dropdown menu in the Snort 3 Version of the network analysis policy. | ||||
Step 3 | Under Upload, you can click Overridden Configuration to upload the JSON file that contains the overridden configuration.
You can drag and drop a file or click to browse to the JSON file saved in your system that contains the overridden inspector configuration.
| ||||
Step 4 | Steps to Associate NAP Policy to Access Control Policy: In the access control policy editor, click Advanced, then click Edit next to the Network Analysis and Intrusion Policies section. | ||||
Step 5 | Alternatively, in the access control policy editor, click Advanced, then click Edit next to the Network Analysis and Intrusion Policies section.
| ||||
Step 6 | Deployment: On the Firewall Management Center menu bar, click Deploy and then select Deployment. | ||||
Step 7 | Identify and choose the devices on which you want to deploy configuration changes.
| ||||
Step 8 | Click Deploy. | ||||
Step 9 | If the system identifies errors or warnings in the changes to be deployed, it displays them in the Validation Messages window. To view complete details, click the arrow icon before the warnings or errors.
|