<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SNORT3 benefits? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/snort3-benefits/m-p/4994353#M1107803</link>
    <description>&lt;P&gt;There are few features which require Snort3, e.g.:&lt;/P&gt;&lt;P&gt;- TLS 1.3 decryption&lt;BR /&gt;- EVE&lt;BR /&gt;- Elephant flow detection/remediation&lt;BR /&gt;- Port scan detection/prevention&lt;BR /&gt;- Rule Groups&lt;/P&gt;&lt;P&gt;Among them Rule Groups can really be helpful to tune Intrusion Policy.&lt;/P&gt;&lt;P&gt;HTTP/2 probably requires Snort3 too, but I'm not sure. If QUIC will ever be supported, it will be supported in Snort3 only. So, Cisco doesn't really give us a choice, long-term. On the other hand, Snort3 stability can still be a problem. Hopefully other members who use it will comment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Jan 2024 13:59:47 GMT</pubDate>
    <dc:creator>tvotna</dc:creator>
    <dc:date>2024-01-11T13:59:47Z</dc:date>
    <item>
      <title>SNORT3 benefits?</title>
      <link>https://community.cisco.com/t5/network-security/snort3-benefits/m-p/4994274#M1107795</link>
      <description>&lt;P&gt;hi out there - we are just upgrading our FTD's from 6.6.x to .7.0.0 to 7.2.5 - and there we get the option to also upgrade the SNORT engine from SNORT2 to SNORT3 - but besides of the commercial crab stating we get the most powerfull engine then - what benefits do we get - besides of getting rid of that annoying error from a upgraded ftd of "snort engine waiting for data".&lt;/P&gt;&lt;P&gt;Has anyone noticed some benefits or better inspection - less cpu consumption or what?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2024 11:38:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snort3-benefits/m-p/4994274#M1107795</guid>
      <dc:creator>tiwang</dc:creator>
      <dc:date>2024-01-11T11:38:41Z</dc:date>
    </item>
    <item>
      <title>Re: SNORT3 benefits?</title>
      <link>https://community.cisco.com/t5/network-security/snort3-benefits/m-p/4994315#M1107799</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; - FYI :&amp;nbsp;&lt;A href="https://www.snort.org/snort3" target="_blank"&gt;https://www.snort.org/snort3&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2024 13:01:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snort3-benefits/m-p/4994315#M1107799</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2024-01-11T13:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: SNORT3 benefits?</title>
      <link>https://community.cisco.com/t5/network-security/snort3-benefits/m-p/4994327#M1107801</link>
      <description>&lt;P&gt;yes i also noticed that - just that table there - &lt;A href="https://blog.snort.org/2020/08/snort-3-2-differences.html" target="_blank"&gt;https://blog.snort.org/2020/08/snort-3-2-differences.html&lt;/A&gt; - looks like it has been some desperately looking for some positive difference to write there - like:&lt;BR /&gt;default config - snort2: complex, needs tuning snort3: simplified, effective&lt;/P&gt;&lt;P&gt;how do you measure "effective" ?&lt;/P&gt;&lt;P&gt;or&amp;nbsp;&lt;/P&gt;&lt;P&gt;stream TCP: snort2: complex implementation snort3: new and improved implementation&lt;/P&gt;&lt;P&gt;and so - you know - lots of statements which are hard to measure on - like a lot of sales crab...&lt;/P&gt;&lt;P&gt;so therefor my question - has some in real life production env seen some benefits which can be measured?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2024 13:24:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snort3-benefits/m-p/4994327#M1107801</guid>
      <dc:creator>tiwang</dc:creator>
      <dc:date>2024-01-11T13:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: SNORT3 benefits?</title>
      <link>https://community.cisco.com/t5/network-security/snort3-benefits/m-p/4994353#M1107803</link>
      <description>&lt;P&gt;There are few features which require Snort3, e.g.:&lt;/P&gt;&lt;P&gt;- TLS 1.3 decryption&lt;BR /&gt;- EVE&lt;BR /&gt;- Elephant flow detection/remediation&lt;BR /&gt;- Port scan detection/prevention&lt;BR /&gt;- Rule Groups&lt;/P&gt;&lt;P&gt;Among them Rule Groups can really be helpful to tune Intrusion Policy.&lt;/P&gt;&lt;P&gt;HTTP/2 probably requires Snort3 too, but I'm not sure. If QUIC will ever be supported, it will be supported in Snort3 only. So, Cisco doesn't really give us a choice, long-term. On the other hand, Snort3 stability can still be a problem. Hopefully other members who use it will comment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2024 13:59:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snort3-benefits/m-p/4994353#M1107803</guid>
      <dc:creator>tvotna</dc:creator>
      <dc:date>2024-01-11T13:59:47Z</dc:date>
    </item>
  </channel>
</rss>

