Print Download PDF Send Feedback

Previous

Next

Deleting SNORT Protection Rules from the Multi-Domain Server

To delete SNORT protection rules from the Multi-Domain Server:

  1. Connect with SmartConsole to the Multi-Domain Server to the mds context.
  2. From the left navigation panel, click Multi Domain > Domains.
  3. Right-click on the Global Domain and select Collect to domain.
  4. From the left navigation panel, click Security Policies.
  5. Open the applicable global policy.
  6. In the top section Threat Prevention, click Policy.
  7. In the bottom section Threat Tools, click IPS Protections.
  8. From the top toolbar, click Actions > Snort Protections > Delete all Snort protections.

  9. Publish the session.
  10. Close the SmartConsole connected to the Global Domain.
  11. From the left navigation panel, click Multi Domain > Global Assignments.
  12. Reassign the Global Policy to the Local Domains.
  13. Connect with SmartConsole to the applicable Multi-Domain Server that manages the applicable Security Gateway or Security Cluster.
  14. Install the Threat Prevention Policy on the applicable Security Gateway or Security Cluster.

Action on SNORT Protection Rules

The Security Gateway enforces SNORT protection rules based on the profile which is installed on the Security Gateway. For example, if the profile installed on the Security Gateway is Optimized, by default the Security Gateway does not enforce SNORT protection rules, because their performance impact is High and the allowed performance impact defined in the Optimized profile is Medium or lower.

To override the profile settings for a specific SNORT protection:

  1. In IPS Protections, right-click a SNORT protection and select Edit.

    Note - The SNORT protection names start with Snort imported.

  2. Right-click the profile and select Edit.

  3. In the Main Action area, select Override with.

  4. From the drop-down menu, select the required action.

  5. Click OK.
  6. Click Close.
  7. Publish the session.
  8. Install the Threat Prevention Policy.

Note - The images here follow the example described above. If you are on a different profile, or want a different action, change steps 2 or 4 accordingly.