Previously, the compatibility of snort rules and UDS defined in the Manager were checked against the Network Security Platform signature set. Only the signatures that passed compilation were pushed to the Sensors to overcome signature set push failure. After you upgrade to Manager version 10.1, along with test compilation status, the Manager also uses the status of McAfee Snort Engine and Suricata Engine validation status to determine the state of the custom attack. When a signature set is pushed to the Sensor, only the custom attacks in published state are forwarded to the Sensors along with the standard signature set.
To view the compilation status for custom attacks, go to Manager → <Admin Domain Name> → Policy Types → IPS . IPS page opens. Click Custom Attacks, the Native McAfee Format tab opens. The Test Compile column displays the compilation result for the custom attacks. The status is displayed as Success for the custom attacks that pass test compilation and Failed for custom attacks that do not pass test compilation. Click Snort Format, the Validation column under McAfee Snort Engine column displays validation status from McAfee Snort Engine and the Validation column under Suricata Snort Engine column displays validation status from Suricata Snort Engine. The custom attacks failed to publish are moved to staged state and filtered out when signature set is pushed to the Sensors.
Note
The Manager compiles all active custom attacks during reboot or startup. The IPS Policies page is not available till the Manager completes the compilation operation. It takes about 7 minutes for the page to load.
The following table shows the rules for determining the state of the custom attack in Native McAfee format:
| State of the Custom Attack | McAfee Snort Engine Validation Status | Test Compile Status |
|---|---|---|
| Published | Success | Success |
| Published | Warning | Success |
| Staged | Warning | Success |
| Staged | Warning | Failed |
| Staged | Failed | Pending |
| Staged | Success | Failed |
The following table shows the rules for determining the state of the custom attack in Snort format:
| State of the Custom Attack | McAfee Snort Engine Validation Status | Test Compile Status | Suricata Engine Validation Status |
|---|---|---|---|
| Published | Success | Success | Success |
| Published | Success | Failed | Success |
| Published | Success | Success | Failed |
| Published | Failed | Pending | Success |
| Published | Warning | Success | Success |
| Published | Warning | Failed | Success |
| Staged | Warning | Success | Failed |
| Staged | Warning | Failed | Failed |
| Staged | Failed | Pending | Failed |
| Staged | Success | Failed | Failed |