This section describes the available scheduled task types (Job
Type in the scheduler), as well as guidelines and requirements for each
task.
Backup
Purpose: Back up the Firewall Management
Center and managed devices. Initial setup schedules a
weekly configuration backup of the Firewall Management
Center, stored locally.
Options:
-
Backup Type: Device or Firewall Management
Center
-
Backup Profile: Firewall Management
Center backups require a backup profile. Refer to
Create a backup profile.
-
Retrieve to Management Center: Devices only. This option controls device backups irrespective of remote storage is enabled or not.
-
Enabled (default): If remote storage is configured, the backup files are saved to remote storage, else the device backup files
are saved to the Firewall Management
Center in /var/sf/remote-backup/.
-
Disabled: Saves device backups to the device in /var/sf/backup/.
For more information about managing backup, refer to Manage backups and remote storage.
Guidelines and limitations:
-
Supported devices: Some devices, such as devices in the public cloud, cannot be backed
up. Refer to Requirements: backup and restore configuration.
-
Prerequisite configurations: Firewall Management
Center backups require a backup profile. Refer to
Create a backup profile.
-
Simultaneous backups: Back up no more than 20 devices per task. Do not schedule
multiple backup tasks for the same time; start with 30 minutes between backups.
-
Bandwidth: If you are transferring backup files, consider scheduling backups during
periods of low network use.
Cisco recommended rules
Purpose: Generate rule state recommendations and modify intrusion policies based on network
discovery data.
Options:
Guidelines and limitations:
-
Licenses: IPS
-
Prerequisite configurations: You must have at least one custom intrusion policy with
recommendations enabled to schedule this
task.
-
Save changes before the task runs: If your intrusion policies have unsaved changes,
recommendations are not applied. Discard your changes and commit the policy to apply
recommendations.
-
Deploy during a maintenance window to implement changes: Snort may need to restart.
Restarting the Snort process briefly interrupts traffic flow and inspection on all
devices, including devices configured for high availability or clustering.
Deploy policies
Purpose: Deploy configuration changes from the Firewall Management
Center to managed devices. You may want to schedule a deploy after recommended rules, VDB updates.
Options:
Guidelines and limitations:
-
Traffic inspection and flow: When you deploy,
resource demands may result in a small number of packets dropping without
inspection. Additionally, deploying some configurations restarts the Snort process,
which interrupts traffic inspection. Whether traffic drops during this interruption
or passes without further inspection depends on how the target device handles
traffic. Refer to Snort restart traffic behavior and Configurations that restart the snort process when deployed or activated.
-
Concurrent deployments: Scheduled policy deployments do not run if a manual policy
deployment is already in progress. You cannot deploy from the web interface while a
scheduled deployment is running.
Download CRL
Purpose: Download certificate revocation list (CRL) updates. The
system automatically schedules daily CRL updates when you configure user or audit log
certificates in the system configuration. Use the scheduler to change the update interval or
run a one-time update. Disabling the configurations removes the task.
Guidelines and limitations:
Download latest update
Purpose: Download the latest VDB update. Initial setup schedules a weekly download of the latest
applicable updates.

Note
|
Use to upgrade software. Scheduled software upgrades are not supported, although the web
interface allows configuration.
|
Options:
Guidelines and limitations:
-
Required task order: To update the VDB, download then install. Download must finish
before install begins.
-
Internet access: The Firewall Management
Center must have internet access to download updates. Refer to Internet Resources Accessed.
-
Bandwidth: Consider scheduling downloads during periods of low network use.
Push latest update

Note
|
Use to upgrade software. Scheduled software upgrades are not supported, although the web
interface allows configuration.
|
Install latest update
Purpose: Install a VDB update.

Note
|
Use to upgrade software. Scheduled software upgrades are not supported, although the web
interface allows configuration.
|
Options:
Guidelines and limitations:
-
Required task order: To update the VDB, download then install. Download must finish
before install begins.
-
Do not perform tasks related to mapped vulnerabilities while the VDB is updating. Even
if the Message Center shows no progress for several minutes or indicates that the update
has failed, do not restart the update. Instead, contact Cisco TAC.
-
Deploy during a maintenance window to implement changes: Snort typically restarts
during the first deployment after VDB update. Restarting the Snort process briefly
interrupts traffic flow and inspection on all devices, including devices configured for
high availability or clustering.
Nmap scan
Purpose: Nmap scans refresh static operating system, application, and server data
previously supplied by Nmap. You can also use these scans to test for unidentified
applications and servers.
Options:
-
Nmap Remediation: The specific Nmap remediation to run.
-
Nmap Target: The scan target.
-
Domain: In a multidomain deployment, the domain whose network
map you want to augment.
Guidelines and limitations:
-
Prerequisite configurations: You must configure Nmap scanning to schedule this task.
This includes creating an Nmap instance, scan target, and remediation. Refer to Nmap scanning guidelines for additional guidelines.
-
Scan regularly: The system does not automatically update network map data replaced by
Nmap unless you delete the scan targets from the network map and allow the system to
rediscover them. Schedule regular scans to keep your network map current.
-
Bandwidth: Consider scheduling expensive scans, such as portscans, during periods of
low network use.
Report
Purpose: Schedule report generation.
Options:
-
Report Template: Use a system-provided template or create your
own to generate the report. To get reports by email, edit the report template. The
scheduler email option sends only task status and does not send the report by email.
-
If report is empty, still attach to email:
Receive reports as email attachments even when reports have no data; for example, when
no events of a certain type occurred during the report period.
Update URL filtering database
Purpose: Obtain the latest URL filtering data from Cisco. By default, when you enable URL
filtering, automatic updates are enabled. However, if you need to control exactly when these
updates occur, use the scheduler.
Guidelines and limitations:
-
Licenses: URL Filtering
-
Prerequisite configurations: You must enable URL filtering to schedule this
task. Disable automatic updates on .
-
Update size, duration, and bandwidth: Daily updates are typically small. With longer
intervals, expect larger downloads and additional time for the changes to propagate, and
consider scheduling during periods of low network
use.
-
Internet access: The Firewall Management
Center must have internet access to download updates. Refer to Internet Resources Accessed.