Sophos XG is using an older version of Snort IPS than UTM does.
XG uses: "snort_inline: Version 2.4.3RC3-test3 (Build 26) " and latest pattern update on my XG is 5th of November while from snort.org latest rules are from 12th.
Anyway I understand that you need time to integrate and test new rules on appliance but this brings a security concern:
1. The appliance should use the latest signature IPS as possible
2. The appliance should use the latest Engine as possible
Can you explain why pattern updates take so much time?
Why you are not using the latest version of snort?
Luk
This thread was automatically locked due to age.