Scheduling

Task scheduling

Task scheduling is a system management feature that allows you to automate routine jobs to run once or on a recurring basis.

Time zones and seasonal time changes

Tasks are scheduled in Coordinated Universal Time (UTC). Because UTC remains constant year-round, scheduled tasks do not automatically adjust for local variations such as summer time or Daylight Saving Time. For example, a task scheduled for 2:00 a.m. during standard time runs at 3:00 a.m. during summer time.

Automatically scheduled tasks

The system automatically schedules these tasks:

  • Download and install the latest vulnerability database (VDB): once, after initial setup.

  • Download patches, maintenance releases, and VDB updates: weekly, starting at initial setup.

  • Locally stored configuration-only backup of the Firewall Management Center: weekly, starting at initial setup.

  • Certificate revocation list (CRL) updates: daily, when you configure user or audit log certificates.

Schedule a task

Use this procedure to schedule a one-time or recurring task.

Before you begin

Before you schedule a task:

Procedure


Step 1

Choose System (system gear icon) > Tools > Scheduling.

Step 2

Click Add Task.

Step 3

Choose a Job Type.

Step 4

Specify whether the task runs Once or Recurring. Set the schedule details: start date, time, and frequency.

Step 5

Enter a name for the task.

Step 6

Configure the parameters for your task. Refer to Scheduled task types.

Step 7

(Optional) Enter a Comment.

You can see comments when you view task details in the calendar.

Step 8

(Optional) Enter email addresses in the Email Status To: field to get task status messages.

Step 9

Click Save.


Your task is scheduled and will run at the time you configured.

Guidelines and prerequisites for scheduled tasks

Prerequisites

Follow these prerequisites when scheduling tasks:
  • User role: Admin or Maintenance

  • Licenses: You must have the required license for the scheduled task. For example, to download URL filtering data you need a URL Filtering license. To schedule intrusion policy tasks, you need an IPS license.

  • Internet access: Firewall Management Center must have internet access to download updates. See Internet Resources Accessed.

  • Additional per-task prerequisites: Each task may have unique prerequisites. For example, scheduling reports requires a report template, scheduling an Nmap scan requires you set up Nmap scanning, and so on. Refer to Scheduled task types.

When to run tasks

Follow these best practices when scheduling tasks:

  • Review automatically scheduled tasks to make sure they run at the right time for your environment.

  • Schedule tasks that require large amounts of bandwidth during periods of low network use. For example, downloading software or data, pushing updates to managed devices, or performing expensive Nmap scans (such as portscans).

  • Schedule tasks that might interrupt traffic, such as deploying policies or installing VDB updates, during maintenance windows.

  • Leave enough time between dependent tasks. For example, if you schedule a download, then a push, and then an install, ensure the download is finished before starting the push. And, ensure the push is finished before starting the install.

Scheduled task types

This section describes the available scheduled task types, as well as guidelines and requirements for each task.

Backup

Purpose: Back up the Firewall Management Center and managed devices.

Options:

  • Backup Type: Device or Firewall Management Center

  • Backup Profile: Firewall Management Center backups require a backup profile. Refer to Create a backup profile.

  • Retrieve to Management Center: Devices only. When you have not configured remote storage, this option controls where device backups are saved.

    • Enabled (default): Saves device backups to the Firewall Management Center in /var/sf/remote-backup/.

    • Disabled: Saves device backups to the device in /var/sf/backup/.

    If you configured remote storage, backup files are saved remotely and this option has no effect. For more information, refer to Manage backups and remote storage.

Guidelines and restrictions:

  • Supported devices: Some devices, such as devices in the public cloud, cannot be backed up. Refer to Requirements: backup and restore configuration.

  • Simultaneous backups: Back up no more than 20 devices per task. Do not schedule multiple backup tasks for the same time; start with 30 minutes between backups.

Cisco Recommended Rules

Purpose: Automatically generate rule state recommendations and modify intrusion policies based on network discovery data.

Options:

  • Policies: The intrusion policies where you want to generate recommendations.

Guidelines and restrictions:

  • Prerequisites: You must have at least one custom intrusion policy with recommendations enabled to schedule this task.

  • Save changes before the task runs: If your intrusion policies have unsaved changes, recommendations are not applied. Discard your changes and commit the policy to apply recommendations.

  • Deploy to implement changes: Modified rule states take effect the next time you deploy the intrusion policy.

Deploy Policies

Purpose: Deploy configuration changes from the Firewall Management Center to managed devices.

Options:

  • Device: The device where you want to deploy the policies.

  • Skip deployment for up-to-date devices: Enabled by default to improve performance during the deployment process.

Guidelines and restrictions:

  • Traffic interruption: When you deploy, resource demands may result in a small number of packets dropping without inspection. Additionally, deploying some configurations restarts the Snort process, which interrupts traffic inspection. Whether traffic drops during this interruption or passes without further inspection depends on how the target device handles traffic. See Snort restart traffic behavior and Configurations that restart the snort process when deployed or activated.

  • Concurrent deployments: Scheduled policy deployments do not run if a manual policy deployment is already in progress. You cannot deploy from the web interface while a scheduled deployment is running.

Download CRL

The system automatically schedules daily certificate revocation list (CRL) updates with a Download CRL task when you configure user or audit log certificates in the system configuration. Use the scheduler to change the update interval or run a one-time update.

Download, Push, or Install Latest Update

Purpose:

  • Download and install VDB updates.

  • Download and install Firewall Management Center patches and maintenance releases.

  • Download, push, and install patches and maintenance releases on managed devices.

Guidelines and restrictions:

  • Supported upgrade types: Schedule maintenance updates and patches. Major upgrades are not supported.

  • Required task order: For Firewall Management Center and VDB updates, download then install. For device software upgrades, add a push between download and install. Allow enough time between dependent tasks; for example, download must complete before push or install.

  • Grouped devices: Use simple device groups to upgrade multiple devices with one scheduled task. The system upgrades the targets one at a time. In high availability or clustered deployments, devices use the normal upgrade behavior.

  • Traffic inspections and flow: For high availability or clustered devices, traffic inspection and flow are not interrupted. For standalone devices, interface configurations determine whether traffic is dropped or passed without inspection.

For more information about upgrades, including additional restrictions and recommended actions if an upgrade is unresponsive or fails, refer to the upgrade guide for your Firewall Management Center version: Secure Firewall Threat Defense upgrade guides for Firewall Management Center.

Nmap Scan

Purpose: Schedule Nmap scans to refresh static operating system, application, and server data previously supplied by Nmap, or test for unidentified applications and servers.

Options:

  • Nmap Remediation: The specific Nmap remediation to run.

  • Nmap Target: The scan target.

  • Domain: In a multidomain deployment, the domain whose network map you want to augment.

Guidelines and restrictions:

  • Prerequisite: You must configure Nmap scanning to schedule this task. This includes creating an Nmap instance, scan target, and remediation. Refer to Nmap Scanning Guidelines for additional guidelines.

  • Scan regularly: The system does not automatically update network map data replaced by Nmap unless you delete the scan targets from the network map and allow the system to rediscover them. Schedule regular scans to keep your network map current.

Report

Purpose: Schedule report generation.

Options:

  • Report Template: Use a system-provided template or create your own to generate the report. To get reports by email, edit the report template. The scheduler's email option sends only task status and does not email the report.

  • If report is empty, still attach to email: Receive reports as email attachments even when reports have no data; for example, when no events of a certain type occurred during the report period.

Update URL Filtering Database

Purpose: Obtain the latest URL filtering data from Cisco. By default, when you enable URL filtering, automatic updates are enabled. However, if you need to control exactly when these updates occur, use the scheduler.

Guidelines and restrictions:

  • Prerequisites: You must enable URL filtering to schedule this task. Disable automatic updates on Integration > Other Integrations > Cloud Services.

  • Update size and duration: Daily updates are typically small. With longer intervals, expect larger downloads and additional time for the changes to propagate.

History for scheduling

This table provides the feature history for the task scheduler.

Feature

Minimum Firewall Management Center

Minimum Firewall Threat Defense

Details

Automatic intrusion rule updates.

6.6

Any

Initial setup enables daily intrusion rule updates. We recommend you review this task and adjust if necessary. For the updated rules to take effect you must deploy configurations.

Automatic software downloads and configuration backups.

6.5

Any

Initial setup schedules weekly tasks to:

  • Download the latest available software updates for the FMC and its managed devices.

  • Perform a locally stored configuration-only backup.

We recommend you review these tasks and adjust as necessary.

Schedule remote backups of many managed devices.

6.4

Any

Schedule device backups.

New/modified screens: When configuring a recurring backup, you can now choose a Backup Type: management center vs device.

Platform restrictions: Device must support on-demand backup; see Requirements: backup and restore configuration.