- CheckMates
- :
- Products
- :
- General Topics
- :
- Create Snort Rule File to Import to Checkpoint IPS
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Create Snort Rule File to Import to Checkpoint IPS
Hi ,
I have been provided an excel.csv file which contains snort definitions and been asked to import them into checkpoint IPS. However I see that checkpoint needs a snort rules file in order to be able to import the definitions and add them. has anybody come across a toll that will convert the csv file to a snort rules file so it can be imported . csv file attached
Thanks
Enzo
1 Reply
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I can see no snort definitions here, only a listing - a Snort rule looks like this:
<Action> <Protocol> <Source IP Address> <Source Port> <Direction>
<Destination IP Address> <Destination Port> (msg:"<Text>";
<Keyword>:"<Option>";)
But you only have a list of threats and signatures, not snort definitions/signatures itself, with the columns:
Threat ID
Threat Name
Severity
Release Date
Signature ID
Signature Name
It is not possible to convert this into snort rules...
CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
