Validate Snort 3 policies

This task validates Snort 3 policies to ensure they work correctly with current and previous device versions, handling version-specific configurations and inspector settings.

To validate the Snort 3 policies, here is a list of basic information that you can make note of:

  • Current version of the Firewall Management Center can manage multiple Firewall Threat Defense versions.

  • Current version of Firewall Management Center supports network analysis policy (NAP) configurations which are not applicable to previous version of Firewall Threat Defense devices.

  • Current NAP Policy and validations will work based on the current version support.

  • Changes may include content which is not valid for previous versions of Firewall Threat Defenses.

  • Policy configuration changes are accepted if they are valid for the current version and performed using the current Snort 3 binary and NAP schema.

  • For previous version Firewall Threat Defenses, validation is performed during deployment using NAP schema and Snort 3 binary for that specific version. If there is any configuration which is not applicable for the given version, the user is informed or warned that the configuration not supported on the given version will not be deployed, while the remaining configuration will be deployed.

In this procedure, when we associate the NAP policy to an Access Control Policy and deploy it on a device, for example any inspector like rate filter configuration is applied to validate the Snort 3 policies.

Procedure


Step 1

Steps to Override NAP Policy Configuration: Under Inspectors in the Snort 3 Version of the network analysis policy, expand the required inspector for which you want to override the default setting.

The default configuration is displayed on the left column and the overridden configuration is displayed on the right column under the inspector.

  1. Under the Overridden Configuration on the right column, click Edit Inspector (Pencil) icon to make changes to any inspector like rate_filter.

    The Override Configuration pop-up appears where you can make the required edits to the rate_filter inspector. Click OK.

  2. Click Save to save the changes.

    Alternatively, you can use the Actions dropdown menu to upload the overridden configuration file.

Step 2

Click the Actions dropdown menu in the Snort 3 Version of the network analysis policy.

Step 3

Under Upload, you can click Overridden Configuration to upload the JSON file that contains the overridden configuration.

Caution

Upload only the changes that you require. You should not upload the entire configuration as it causes the overrides to remain persistent, so any subsequent changes to the default configuration from LSP updates will not be applied.

You can drag and drop a file or click to browse to the JSON file saved in your system that contains the overridden inspector configuration.

  • Merge inspector overrides: Content in the uploaded file is merged with the existing configuration if there is no common inspector. If there are common inspectors, then the content in the uploaded file (for common inspectors) takes precedence over the previous content, and it replaces the previous configuration for those inspectors.
  • Replace inspector overrides: Removes all previous overrides and replaces them with the new content in the uploaded file.
    Attention

    As choosing this option deletes all the previous overrides, make an informed decision before overriding the configuration using this option.

    If any error occurs while uploading the overridden inspectors, you see the error on the Upload Overridden Configuration File pop-up window. You can also download the file with the error, then fix the error and reupload the file.

Step 4

Steps to Associate NAP Policy to Access Control Policy: In the access control policy editor, click Advanced, then click Edit next to the Network Analysis and Intrusion Policies section.

  1. From the Default Network Analysis Policy drop-down list, select a default network analysis policy.

    If you choose a user-created policy, you can click Edit to edit the policy in a new window. You cannot edit system-provided policies.

  2. Click OK and then click Save to save the policy.

Step 5

Alternatively, in the access control policy editor, click Advanced, then click Edit next to the Network Analysis and Intrusion Policies section.

  1. Click Add Rule.

  2. Configure the rule's conditions by clicking the options you want to add.

  3. Click Network Analysis and choose the Network Analysis Policy you want to use to preprocess the traffic matching this rule.

  4. Click Add.

Step 6

Deployment: On the Firewall Management Center menu bar, click Deploy and then select Deployment.

Step 7

Identify and choose the devices on which you want to deploy configuration changes.

  • Search: Search for the device name, type, domain, group, or status in the search box.
  • Expand: Click Expand Arrow to view device-specific configuration changes to be deployed.

    By selecting the device check box, all changes for that device listed under it are pushed for deployment. Alternatively, you can use the Policy Selection to select individual policies or configurations to deploy, withholding the rest.

    Optionally, use Show or Hide Policy to selectively view or hide the associated unmodified policies.

Step 8

Click Deploy.

Step 9

If the system identifies errors or warnings in the changes to be deployed, it displays them in the Validation Messages window. To view complete details, click the arrow icon before the warnings or errors.

Note

It displays a warning that Snort 3 network analysis policy contains inspectors or attributes not valid for this Firewall Threat Defense version. Invalid settings will be skipped during deployment. Invalid inspectors are: ["rate_filter"] only for devices lower than 7.1 version.