<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="7920" language="fr" source="https://portal.flane.ch/swisscom/fr/xml-course/cisco-ssfrules" lastchanged="2026-02-17T12:46:24+01:00" parent="https://portal.flane.ch/swisscom/fr/xml-courses"><title>Securing Cisco Networks with Snort Rule Writing Best Practices</title><productcode>SSFRULES</productcode><vendorcode>CI</vendorcode><vendorname>Cisco</vendorname><fullproductcode>CI-SSFRULES</fullproductcode><version>2.1</version><objective>&lt;p&gt;After taking this course, you should be able to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Describe the Snort rule development process&lt;/li&gt;&lt;li&gt;Describe the Snort basic rule syntax and usage&lt;/li&gt;&lt;li&gt;Describe how traffic is processed by Snort&lt;/li&gt;&lt;li&gt;Describe several advanced rule options used by Snort&lt;/li&gt;&lt;li&gt;Describe OpenAppID features and functionality&lt;/li&gt;&lt;li&gt;Describe how to monitor the performance of Snort and how to tune rules&lt;/li&gt;&lt;/ul&gt;</objective><essentials>&lt;p&gt;To fully benefit from this course, you should have:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Basic understanding of networking and network protocols&lt;/li&gt;&lt;li&gt;Basic knowledge of Linux command-line utilities&lt;/li&gt;&lt;li&gt;Basic knowledge of text editing utilities commonly found in Linux&lt;/li&gt;&lt;li&gt;Basic knowledge of network security concepts&lt;/li&gt;&lt;li&gt;Basic knowledge of a Snort-based IDS/IPS system&lt;/li&gt;&lt;/ul&gt;</essentials><audience>&lt;p&gt;This course is for technical professionals to gain skills in writing rules for Snort-based intrusion detection systems (IDS) and intrusion prevention systems (IPS). The primary audience includes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Security administrators&lt;/li&gt;&lt;li&gt;Security consultants&lt;/li&gt;&lt;li&gt;Network administrators&lt;/li&gt;&lt;li&gt;System engineers&lt;/li&gt;&lt;li&gt;Technical support personnel using open source IDS and IPS&lt;/li&gt;&lt;li&gt;Channel partners and resellers&lt;/li&gt;&lt;/ul&gt;</audience><outline>&lt;ul&gt;
&lt;li&gt;Introduction to Snort Rule Development&lt;/li&gt;&lt;li&gt;Snort Rule Syntax and Usage&lt;/li&gt;&lt;li&gt;Traffic Flow Through Snort Rules&lt;/li&gt;&lt;li&gt;Advanced Rule Options&lt;/li&gt;&lt;li&gt;OpenAppID Detection&lt;/li&gt;&lt;li&gt;Tuning Snort&lt;/li&gt;&lt;/ul&gt;</outline><objective_plain>After taking this course, you should be able to:


- Describe the Snort rule development process
- Describe the Snort basic rule syntax and usage
- Describe how traffic is processed by Snort
- Describe several advanced rule options used by Snort
- Describe OpenAppID features and functionality
- Describe how to monitor the performance of Snort and how to tune rules</objective_plain><essentials_plain>To fully benefit from this course, you should have:


- Basic understanding of networking and network protocols
- Basic knowledge of Linux command-line utilities
- Basic knowledge of text editing utilities commonly found in Linux
- Basic knowledge of network security concepts
- Basic knowledge of a Snort-based IDS/IPS system</essentials_plain><audience_plain>This course is for technical professionals to gain skills in writing rules for Snort-based intrusion detection systems (IDS) and intrusion prevention systems (IPS). The primary audience includes:


- Security administrators
- Security consultants
- Network administrators
- System engineers
- Technical support personnel using open source IDS and IPS
- Channel partners and resellers</audience_plain><outline_plain>- Introduction to Snort Rule Development
- Snort Rule Syntax and Usage
- Traffic Flow Through Snort Rules
- Advanced Rule Options
- OpenAppID Detection
- Tuning Snort</outline_plain><duration unit="d" days="3">3 jours</duration><pricelist><price country="PL" currency="EUR">2000.00</price><price country="CR" currency="USD">2995.00</price><price country="PA" currency="USD">2995.00</price><price country="CL" currency="USD">2995.00</price><price country="AR" currency="USD">2995.00</price><price country="CO" currency="USD">2995.00</price><price country="PE" currency="USD">2995.00</price><price country="MX" currency="USD">2995.00</price><price country="BR" currency="USD">2995.00</price><price country="P3" currency="USD">2995.00</price><price country="IT" currency="EUR">2490.00</price><price country="RU" currency="RUB">255000.00</price><price country="US" currency="USD">2800.00</price><price country="GB" currency="GBP">2410.00</price><price country="GR" currency="EUR">1575.00</price><price country="MK" currency="EUR">1575.00</price><price country="HU" currency="EUR">1575.00</price><price country="FR" currency="EUR">2670.00</price><price country="SG" currency="USD">2240.00</price><price country="IN" currency="USD">1680.00</price><price country="DE" currency="EUR">3595.00</price><price country="SE" currency="EUR">3595.00</price><price country="CH" currency="CHF">3600.00</price><price country="CA" currency="CAD">3865.00</price><price country="AT" currency="EUR">3595.00</price></pricelist><miles><milesvalue country="CL" vendorcurrency="CLC" vendorcurrencyname="Cisco Learning Credits">30.00</milesvalue><milesvalue country="MX" vendorcurrency="CLC" vendorcurrencyname="Cisco Learning Credits">30.00</milesvalue><milesvalue country="GB" vendorcurrency="CLC" vendorcurrencyname="Cisco Learning Credits">28.00</milesvalue><milesvalue country="PL" vendorcurrency="CLC" vendorcurrencyname="Cisco Learning Credits">28.00</milesvalue><milesvalue country="FR" vendorcurrency="CLC" vendorcurrencyname="Cisco Learning Credits">28.00</milesvalue><milesvalue country="S2" vendorcurrency="CLC" vendorcurrencyname="Cisco Learning Credits">28.00</milesvalue><milesvalue country="CA" vendorcurrency="CLC" vendorcurrencyname="Cisco Learning Credits">28.00</milesvalue><milesvalue country="ES" vendorcurrency="CLC" vendorcurrencyname="Cisco Learning Credits">28.00</milesvalue><milesvalue country="SG" vendorcurrency="CLC" vendorcurrencyname="Cisco Learning Credits">28.00</milesvalue><milesvalue country="BR" vendorcurrency="CLC" vendorcurrencyname="Cisco Learning Credits">28.00</milesvalue><milesvalue country="PE" vendorcurrency="CLC" vendorcurrencyname="Cisco Learning Credits">28.00</milesvalue><milesvalue country="P3" vendorcurrency="CLC" vendorcurrencyname="Cisco Learning Credits">28.00</milesvalue><milesvalue country="PA" vendorcurrency="CLC" vendorcurrencyname="Cisco Learning Credits">28.00</milesvalue><milesvalue country="AR" vendorcurrency="CLC" vendorcurrencyname="Cisco Learning Credits">28.00</milesvalue><milesvalue country="CR" vendorcurrency="CLC" vendorcurrencyname="Cisco Learning Credits">28.00</milesvalue><milesvalue country="NL" vendorcurrency="CLC" vendorcurrencyname="Cisco Learning Credits">28.00</milesvalue><milesvalue country="AE" vendorcurrency="CLC" vendorcurrencyname="Cisco Learning Credits">28.00</milesvalue><milesvalue country="US" vendorcurrency="CLC" vendorcurrencyname="Cisco Learning Credits">28.00</milesvalue><milesvalue country="CO" vendorcurrency="CLC" vendorcurrencyname="Cisco Learning Credits">28.00</milesvalue><milesvalue country="IT" vendorcurrency="CLC" vendorcurrencyname="Cisco Learning Credits">28.00</milesvalue><milesvalue country="SE" vendorcurrency="CLC" vendorcurrencyname="Cisco Learning Credits">28.00</milesvalue><milesvalue country="IL" vendorcurrency="CLC" vendorcurrencyname="Cisco Learning Credits">28.00</milesvalue><milesvalue country="EG" vendorcurrency="CLC" vendorcurrencyname="Cisco Learning Credits">28.00</milesvalue><milesvalue country="AT" vendorcurrency="CLC" vendorcurrencyname="Cisco Learning Credits">28.00</milesvalue><milesvalue country="CH" vendorcurrency="CLC" vendorcurrencyname="Cisco Learning Credits">28.00</milesvalue><milesvalue country="DE" vendorcurrency="CLC" vendorcurrencyname="Cisco Learning Credits">28.00</milesvalue></miles></course>