Just looking to upgrade to Snort3 & the Cisco page re adoption, lists "Intrusion Policy used before Access Control rule is determined" should be configured if you use Application or URL filtering rules. Its a global setting so can't be focused to just rules say from north/outside where we would least like to see even limited unfiltered traffic passage.
See https://secure.cisco.com/secure-firewall/v7.2/docs/snort-3-adoption#feature-comparison
Does anyone have experience with this, as the details are a bit lite. The concept is fine, apply IPS policy to traffic that has yet to be determined based on the Application or URL filters in a rule. Just wondering what others have used here ? & if it had any impact on the function of there FTD's !?
Thanks for any input.