Import Snort configuration files globally for all Engines

Import Snort configuration files globally to configure default settings for Snort inspection for all Engines.

Note: Engines do not receive automatic updates for Snort rule sets. When new Snort rule sets are available, you must import new Snort configuration files and refresh the policy on the Engine to start using the new Snort rule sets.

For more details about the product and how to configure features, click Help or press F1.

Steps

  1. Select Menu > System Tools > Global System Properties.
  2. Click the Global Options tab.
  3. Click Browse next to the Snort Configuration field, then select the Snort configuration file.
  4. Click OK.

Next steps

Enable Snort inspection for each Engine where you want to use Snort inspection.

Global System Properties dialog box — Global Options tab

Use this tab to configure general settings for the Secure SD-WAN Manager and Engine.

You can also use this tab to:

  • Authorize McAfee® Global Threat Intelligence™ (McAfee GTI). Only administrators with unrestricted permissions (superusers) can enable McAfee GTI.
  • Show users in the Home view.
  • Set the expiration time for one-time passwords that are generated when you save the initial configuration for an Engine.
  • Import Snort configuration files globally to configure default settings for Snort inspection for all Engines.

All settings are optional.

Option Definition
Enable McAfee Global Threat Intelligence (GTI) and McAfee Threat Intelligence Exchange (TIE) usage When selected, enables McAfee GTI usage.
Note: McAfee Threat Intelligence Exchange (TIE) is no longer supported in Engine 6.10 and higher.
Show Users in the Home View When selected, users that have been recently active are shown in the Home view.
Retrieve Information for Users Active A user is considered active if they have generated log data. Select the time period to retrieve the information. The longer the time period, the greater the performance impact.
Display Users as
  • User Names — The name of the user is shown. The information is shown as it is shown in the logs.
  • Source IP Addresses — If user name information is not available, or cannot be shown due to privacy legislation, you can show only the source IP address of the user.
Show Users From These Networks

(Only if Display Users as is Source IP Addresses

If you want to show users as source IP addresses, select the networks where your users are located.
One-Time Passwords Expire After Defines the expiration time for one-time passwords that are generated when you save the initial configuration for an Engine. If the one-time password is not used, it automatically expires after the expiration time has elapsed.

By default, one-time passwords expire after 30 days.

Snort Configuration The externally created Snort configuration .zip file that contains the Snort configuration files and rules for Snort inspection.
  • Click Browse to select a file.
  • Click None to remove a previously imported file.
  • Click Export to export the Snort configuration file.

All Engines for which Snort inspection is enabled use the global Snort configuration by default.

Settings in the Snort configuration .zip file for an individual Engine are combined with the settings in the global Snort configuration .zip file. If any configuration files in a Snort configuration .zip file for an individual Engine have the same files name and paths as configuration files in the global Snort configuration .zip file, the overlapping files in the global Snort configuration .zip file are ignored.