<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Snort3 rate filter in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/snort3-rate-filter/m-p/5302760#M1121471</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Im trying to configure rate filter in Firepower Snort3 according to this reference:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/snort3-inspectors/snort-3-inspector-reference/rate-filter-inspector.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/snort3-inspectors/snort-3-inspector-reference/rate-filter-inspector.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;For single rate filter with single GID:SIG combination it is working as expected. But I would like to configure more rate filters, or at least activate rate-filter for this three intrusion rules 135:1, 135:2, 135:3 for single IP address.&lt;/P&gt;
&lt;P&gt;In the reference is written: "&lt;SPAN&gt;You can define multiple rate-based filters on the same rule as well as on different rules." And my question is: Does anybody please know how to do this...?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 26 Jun 2025 07:54:35 GMT</pubDate>
    <dc:creator>Jiri Tyl</dc:creator>
    <dc:date>2025-06-26T07:54:35Z</dc:date>
    <item>
      <title>Snort3 rate filter</title>
      <link>https://community.cisco.com/t5/network-security/snort3-rate-filter/m-p/5302760#M1121471</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Im trying to configure rate filter in Firepower Snort3 according to this reference:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/snort3-inspectors/snort-3-inspector-reference/rate-filter-inspector.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/snort3-inspectors/snort-3-inspector-reference/rate-filter-inspector.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;For single rate filter with single GID:SIG combination it is working as expected. But I would like to configure more rate filters, or at least activate rate-filter for this three intrusion rules 135:1, 135:2, 135:3 for single IP address.&lt;/P&gt;
&lt;P&gt;In the reference is written: "&lt;SPAN&gt;You can define multiple rate-based filters on the same rule as well as on different rules." And my question is: Does anybody please know how to do this...?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 07:54:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snort3-rate-filter/m-p/5302760#M1121471</guid>
      <dc:creator>Jiri Tyl</dc:creator>
      <dc:date>2025-06-26T07:54:35Z</dc:date>
    </item>
    <item>
      <title>Re: Snort3 rate filter</title>
      <link>https://community.cisco.com/t5/network-security/snort3-rate-filter/m-p/5302765#M1121472</link>
      <description>&lt;P&gt;Sorry can you more elaborate&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You need many rate limit for same rule&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or rate limit for many rule&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 08:12:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snort3-rate-filter/m-p/5302765#M1121472</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-06-26T08:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: Snort3 rate filter</title>
      <link>https://community.cisco.com/t5/network-security/snort3-rate-filter/m-p/5302773#M1121474</link>
      <description>&lt;P&gt;Yes, I can elaborate more. I need many rate limit for same rule.&lt;/P&gt;
&lt;P&gt;Thanks Jiri&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 08:26:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snort3-rate-filter/m-p/5302773#M1121474</guid>
      <dc:creator>Jiri Tyl</dc:creator>
      <dc:date>2025-06-26T08:26:14Z</dc:date>
    </item>
    <item>
      <title>Re: Snort3 rate filter</title>
      <link>https://community.cisco.com/t5/network-security/snort3-rate-filter/m-p/5302836#M1121481</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I finally found a solution to my problem. Maybe I can save someone some time...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Data is array, there under is correct JSON syntax for multiple filter items. On top of this, you should set the corresponding action in the intrussion rule overrides (if it is not in default) for the used&amp;nbsp;GID:SIG ( for me 135:1, 135:2 and 135:3).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;{&lt;BR /&gt;"rate_filter": {&lt;BR /&gt;"type": "singleton",&lt;BR /&gt;"enabled": true,&lt;BR /&gt;"data": [&lt;BR /&gt;{&lt;BR /&gt;"apply_to": "[X.X.X.X]",&lt;BR /&gt;"count": 10,&lt;BR /&gt;"gid": 135,&lt;BR /&gt;"new_action": "block",&lt;BR /&gt;"seconds": 1,&lt;BR /&gt;"sid": 1,&lt;BR /&gt;"timeout": 30,&lt;BR /&gt;"track": "by_dst"&lt;BR /&gt;},&lt;BR /&gt;{&lt;BR /&gt;"apply_to": "[X.X.X.X]",&lt;BR /&gt;"count": 10,&lt;BR /&gt;"gid": 135,&lt;BR /&gt;"new_action": "block",&lt;BR /&gt;"seconds": 1,&lt;BR /&gt;"sid": 2,&lt;BR /&gt;"timeout": 30,&lt;BR /&gt;"track": "by_dst"&lt;BR /&gt;},&lt;BR /&gt;{&lt;BR /&gt;"apply_to": "[X.X.X.X]",&lt;BR /&gt;"count": 10,&lt;BR /&gt;"gid": 135,&lt;BR /&gt;"new_action": "block",&lt;BR /&gt;"seconds": 1,&lt;BR /&gt;"sid": 3,&lt;BR /&gt;"timeout": 30,&lt;BR /&gt;"track": "by_dst"&lt;BR /&gt;}&lt;BR /&gt;]&lt;BR /&gt;}&lt;BR /&gt;}&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 12:08:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snort3-rate-filter/m-p/5302836#M1121481</guid>
      <dc:creator>Jiri Tyl</dc:creator>
      <dc:date>2025-06-26T12:08:21Z</dc:date>
    </item>
    <item>
      <title>Re: Snort3 rate filter</title>
      <link>https://community.cisco.com/t5/network-security/snort3-rate-filter/m-p/5302987#M1121484</link>
      <description>&lt;P&gt;The code you use is not for same rule&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;GID:SIG&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I think you use SIG 1'2'3&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Anyway I think I found solution but I will more check it before answer you&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;MHM&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 14:20:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snort3-rate-filter/m-p/5302987#M1121484</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-06-26T14:20:57Z</dc:date>
    </item>
    <item>
      <title>Re: Snort3 rate filter</title>
      <link>https://community.cisco.com/t5/network-security/snort3-rate-filter/m-p/5305979#M1121627</link>
      <description>&lt;P&gt;Check this if this what you looking for&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://rayka-co.com/lesson/cisco-firepower-event-suppression/" target="_blank"&gt;https://rayka-co.com/lesson/cisco-firepower-event-suppression/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221881-configure-custom-local-snort-rules-in-sn.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-threat-defense/221881-configure-custom-local-snort-rules-in-sn.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sat, 05 Jul 2025 12:17:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/snort3-rate-filter/m-p/5305979#M1121627</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-05T12:17:19Z</dc:date>
    </item>
  </channel>
</rss>

