UnixGuy wrote: » @FillAwful: see I use Palo Alto IDS/IPS, and I don't really write Snort rule...it's just a GUI. So you use Snort open source? I'm going to use Cisco FirePower soon-ish, not sure if it's a best practice to write Snort rules.?