[Snort-users] Subscription Rulesets vs Sourcefire product rulesets

Joel Esler (jesler) jesler at cisco.com
Thu Feb 15 11:56:47 EST 2018


The rules, themselves?  No.  The capabilities of the FirePower platform far exceed that of regular Snort (auto port detection, load balancing, etc). The SRU (for the firepower platform) and the ruleset you download from Snort.org<http://Snort.org> have the same rules in them.  But they operate completely differently/

--
Joel Esler | Talos: Manager | jesler at cisco.com<mailto:jesler at cisco.com>






On Feb 15, 2018, at 8:59 AM, Austin Clark via Snort-users <snort-users at lists.snort.org<mailto:snort-users at lists.snort.org>> wrote:


All,

Is there any fundamental difference between the Snort subscription ruleset and the ruleset my sourcefire box receives from cisco/Talos.

Austin
_______________________________________________
Snort-users mailing list
Snort-users at lists.snort.org<mailto:Snort-users at lists.snort.org>
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

Please visit http://blog.snort.org<http://blog.snort.org/> to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-users/attachments/20180215/f67ea887/attachment-0001.html>


More information about the Snort-users mailing list