Exploration of Snort 3 Features and Integration with VPP Platform

Mrityunjay Kumar via Snort-users <[email protected]> Thu, 23 Jan 2025 07:34:20 +0000
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <PN3P287MB2313E31F5E489CD941C8BA72A9E02@PN3P287MB2313.INDP287.PROD.OUTLOOK.COM>
--===============8019511154921324976==
Content-Language: en-US
Content-Type: multipart/alternative;
	boundary="_000_PN3P287MB2313E31F5E489CD941C8BA72A9E02PN3P287MB2313INDP_"

--_000_PN3P287MB2313E31F5E489CD941C8BA72A9E02PN3P287MB2313INDP_
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable

Dear Snort Team,
I hope this email finds you well.
We are currently exploring Snort 3 and its potential as a Next-Generation F=
irewall (NGFW) for integration with our product. Our platform is based on V=
PP (Vector Packet Processing), and we have completed basic testing with the=
 Snort 3 DAQ leveraging VPP's zero-copy functionality. Additionally, we hav=
e performed fine-tuning and engineering to optimize performance.
We believe Snort 3 could be a strong candidate for our NGFW solution if it =
supports the following features:

  1.  L4 and L7 Firewall
  2.  VPN (IPsec)
  3.  Web Filtering
  4.  SSL Inspection (Certificate and Deep Inspection)
While we have achieved basic testing, one of the challenges we are facing i=
s adding and managing rules effectively. We are particularly interested in =
understanding:

  *   The best practices for creating and managing rules within Snort 3, es=
pecially for L7 inspection.
  *   How Snort 3 handles SSL Inspection (certificate-based and deep inspec=
tion).
  *   Whether Snort 3 has native support or integrations for features like =
antivirus, web filtering, application control, and VPN.
  *   Guidance on implementing DNAT/VIP functionality and static routing wi=
thin a Snort 3 deployment.
  *   Any recommendations or documentation for using Snort 3 as part of an =
NGFW setup.
We believe Snort 3 has the potential to meet our requirements, and with the=
 right support and configuration, we are eager to integrate it into our pro=
duct.
Looking forward to your detailed guidance and recommendations on the above =
points.
Thank you for your support and for developing such a robust security platfo=
rm.
Best Regards,
Mrityunjay
"Confidentiality Warning: This message and any attachments are intended onl=
y for the use of the intended recipient(s). =

are confidential and may be privileged. If you are not the intended recipie=
nt. you are hereby notified that any =

review. re-transmission. conversion to hard copy. copying. circulation or o=
ther use of this message and any attachments is =

strictly prohibited. If you are not the intended recipient. please notify t=
he sender immediately by return email. =

and delete this message and any attachments from your system.

Virus Warning: Although the company has taken reasonable precautions to ens=
ure no viruses are present in this email. =

The company cannot accept responsibility for any loss or damage arising fro=
m the use of this email or attachment."

--_000_PN3P287MB2313E31F5E489CD941C8BA72A9E02PN3P287MB2313INDP_
Content-Type: text/html; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii">
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;
	mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:#0563C1;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:#954F72;
	text-decoration:underline;}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Calibri",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri",sans-serif;
	mso-fareast-language:EN-US;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:1591621279;
	mso-list-template-ids:1074414358;}
@list l0:level1
	{mso-level-number-format:bullet;
	mso-level-text:\F0B7;
	mso-level-tab-stop:36.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Symbol;}
@list l0:level2
	{mso-level-number-format:bullet;
	mso-level-text:o;
	mso-level-tab-stop:72.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:"Courier New";
	mso-bidi-font-family:"Times New Roman";}
@list l0:level3
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:108.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l0:level4
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:144.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l0:level5
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:180.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l0:level6
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:216.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l0:level7
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:252.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l0:level8
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:288.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l0:level9
	{mso-level-number-format:bullet;
	mso-level-text:\F0A7;
	mso-level-tab-stop:324.0pt;
	mso-level-number-position:left;
	text-indent:-18.0pt;
	mso-ansi-font-size:10.0pt;
	font-family:Wingdings;}
@list l1
	{mso-list-id:2132085949;
	mso-list-template-ids:-673696058;}
ol
	{margin-bottom:0cm;}
ul
	{margin-bottom:0cm;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-IN" link=3D"#0563C1" vlink=3D"#954F72">
<div class=3D"WordSection1">
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><b><span style=3D"mso-fareast-language:EN-IN">Dear Snort Team,</sp=
an></b><span style=3D"mso-fareast-language:EN-IN"><o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span style=3D"mso-fareast-language:EN-IN">I hope this email finds=
 you well.<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span style=3D"mso-fareast-language:EN-IN">We are currently explor=
ing Snort 3 and its potential as a Next-Generation Firewall (NGFW) for inte=
gration with our product. Our platform
 is based on VPP (Vector Packet Processing), and we have completed basic te=
sting with the Snort 3 DAQ leveraging VPP&#8217;s zero-copy functionality. =
Additionally, we have performed fine-tuning and engineering to optimize per=
formance.<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span style=3D"mso-fareast-language:EN-IN">We believe Snort 3 coul=
d be a strong candidate for our NGFW solution if it supports the following =
features:<o:p></o:p></span></p>
<ol start=3D"1" type=3D"1">
<li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-=
alt:auto;mso-list:l1 level1 lfo1">
<b><span style=3D"mso-fareast-language:EN-IN">L4 and L7 Firewall</span></b>=
<span style=3D"mso-fareast-language:EN-IN"><o:p></o:p></span></li><li class=
=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;=
mso-list:l1 level1 lfo1">
<b><span style=3D"mso-fareast-language:EN-IN">VPN (IPsec)</span></b><span s=
tyle=3D"mso-fareast-language:EN-IN"><o:p></o:p></span></li><li class=3D"Mso=
Normal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-lis=
t:l1 level1 lfo1">
<b><span style=3D"mso-fareast-language:EN-IN">Web Filtering</span></b><span=
 style=3D"mso-fareast-language:EN-IN"><o:p></o:p></span></li><li class=3D"M=
soNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-l=
ist:l1 level1 lfo1">
<b><span style=3D"mso-fareast-language:EN-IN">SSL Inspection (Certificate a=
nd Deep Inspection)</span></b><span style=3D"mso-fareast-language:EN-IN"><o=
:p></o:p></span></li></ol>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span style=3D"mso-fareast-language:EN-IN">While we have achieved =
basic testing, one of the challenges we are facing is adding and managing r=
ules effectively. We are particularly
 interested in understanding:<o:p></o:p></span></p>
<ul type=3D"disc">
<li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-=
alt:auto;mso-list:l0 level1 lfo2">
<span style=3D"mso-fareast-language:EN-IN">The best practices for creating =
and managing rules within Snort 3, especially for L7 inspection.<o:p></o:p>=
</span></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-ma=
rgin-bottom-alt:auto;mso-list:l0 level1 lfo2">
<span style=3D"mso-fareast-language:EN-IN">How Snort 3 handles SSL Inspecti=
on (certificate-based and deep inspection).<o:p></o:p></span></li><li class=
=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;=
mso-list:l0 level1 lfo2">
<span style=3D"mso-fareast-language:EN-IN">Whether Snort 3 has native suppo=
rt or integrations for features like antivirus, web filtering, application =
control, and VPN.<o:p></o:p></span></li><li class=3D"MsoNormal" style=3D"ms=
o-margin-top-alt:auto;mso-margin-bottom-alt:auto;mso-list:l0 level1 lfo2">
<span style=3D"mso-fareast-language:EN-IN">Guidance on implementing DNAT/VI=
P functionality and static routing within a Snort 3 deployment.<o:p></o:p><=
/span></li><li class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-mar=
gin-bottom-alt:auto;mso-list:l0 level1 lfo2">
<span style=3D"mso-fareast-language:EN-IN">Any recommendations or documenta=
tion for using Snort 3 as part of an NGFW setup.<o:p></o:p></span></li></ul>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span style=3D"mso-fareast-language:EN-IN">We believe Snort 3 has =
the potential to meet our requirements, and with the right support and conf=
iguration, we are eager to integrate it
 into our product.<o:p></o:p></span></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span style=3D"mso-fareast-language:EN-IN">Looking forward to your=
 detailed guidance and recommendations on the above points.<o:p></o:p></spa=
n></p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span style=3D"mso-fareast-language:EN-IN">Thank you for your supp=
ort and for developing such a robust security platform.<o:p></o:p></span></=
p>
<p class=3D"MsoNormal" style=3D"mso-margin-top-alt:auto;mso-margin-bottom-a=
lt:auto"><span style=3D"mso-fareast-language:EN-IN">Best Regards,<o:p></o:p=
></span></p>
<p class=3D"MsoNormal">Mrityunjay<o:p></o:p></p>
</div>
<P><br><span style=3D"text-decoration: none">"<strong><span style=3D"text-d=
ecoration: underline">Confidentiality Warning</span></strong></span>: This =
message and any attachments are intended only for the use of the intended r=
ecipient(s), are confidential and may be privileged. If you are not the int=
ended recipient, you are hereby notified that any review, re-transmission, =
conversion to hard copy, copying, circulation or other use of this message =
and any attachments is strictly prohibited. If you are not the intended rec=
ipient, please notify the sender immediately by return email and delete thi=
s message and any attachments from your system.</P>
<P><strong><span style=3D"text-decoration: underline">Virus Warning:</span>=
</strong> Although the company has taken reasonable precautions to ensure n=
o viruses are present in this email. The company cannot accept responsibili=
ty for any loss or damage arising from the use of this email or attachment.=
"</P></body>
</html>

--_000_PN3P287MB2313E31F5E489CD941C8BA72A9E02PN3P287MB2313INDP_--


--===============8019511154921324976==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

--===============8019511154921324976==--