Download Print this page

Cisco Firepower Management Center 1000 Getting Started Manual page 37

Advertisement

Cisco Firepower Management Center 1000, 2500, and 4500 Getting Started Guide
Step 9
Click Save.
Configure Recurring Intrusion Rule Updates
As new vulnerabilities become known, the Cisco Talos Intelligence Group (Talos) releases intrusion rule
updates that you can import onto your FMC, and then implement by deploying the changed configuration to
your managed devices. These updates affect intrusion rules, preprocessor rules, and the policies that use the
rules. Intrusion rule updates are cumulative, and Cisco recommends you always import the latest update.
Before you begin
Make sure the FMC can access the internet.
Procedure
Step 1
Choose System > Updates > Rule Updates.
Step 2
Check the Enable Recurring Rule Update Imports from the Support Site checkbox.
Step 3
Choose values to determine Import Frequency.
Step 4
Check the Deploy updated policies to targeted devices after rule update completes checkbox.
Step 5
Click Save.
Schedule VDB Downloads and Updates
The Cisco vulnerability database (VDB) is a database of known vulnerabilities to which hosts may be
susceptible, as well as fingerprints for operating systems, clients, and applications. The system uses the VDB
to help determine whether a particular host increases your risk of compromise.
Use these instructions to schedule regular automatic downloads and installations of the latest VDB update.
The Cisco Talos Intelligence Group (Talos) issues periodic VDB updates no more than once daily. We strongly
recommend you always maintain the latest VDB update on your FMC.
When automating VDB updates, you must automate two separate steps:
• Downloading the VDB update.
• Installing the VDB update.
Allow enough time between tasks for the process to complete. For example, if you schedule a task to install
an update and the update has not fully downloaded, the installation task will not succeed. However, if the
scheduled installation task repeats daily, it will install the downloaded VDB update when the task runs the
next day.
Cisco Firepower Management Center 1000, 2500, and 4500 Getting Started Guide
Configure Recurring Intrusion Rule Updates
37

Advertisement

loading