Scheduling

Task scheduling

Task scheduling is a system management feature that allows you to automate routine jobs to run once or on a recurring basis.

Time zones and seasonal time changes

Tasks are scheduled in Coordinated Universal Time (UTC). Because UTC remains constant year-round, scheduled tasks do not automatically adjust for local variations such as summer time or Daylight Saving Time. For example, a task scheduled for 2:00 a.m. during standard time runs at 3:00 a.m. during summer time.

Automatically scheduled tasks

The system automatically schedules these tasks:

  • Download and install the latest vulnerability database (VDB): once, after initial setup.

  • Download VDB updates: weekly, starting at initial setup.

  • Locally stored configuration-only backup of the Firewall Management Center: weekly, starting at initial setup.

  • Certificate revocation list (CRL) updates: daily, when you configure user or audit log certificates.

Schedule a task

Use this procedure to schedule a one-time or recurring task.

Before you begin

Before you schedule a task:

Procedure


Step 1

Choose System (system gear icon) > Tools > Scheduling.

Step 2

Click Add Task.

Step 3

Choose a Job Type.

Step 4

Specify whether the task runs Once or Recurring. Set the schedule details: start date, time, and frequency.

Step 5

Enter a name for the task.

Step 6

Configure the parameters for your task. Refer to Scheduled task types.

Step 7

(Optional) Enter a Comment.

You can see comments when you view task details in the calendar.

Step 8

(Optional) Enter email addresses in the Email Status To: field to get task status messages.

Step 9

Click Save.


Your task is scheduled and will run at the time you configured.

Guidelines and prerequisites for scheduled tasks

Prerequisites

Follow these prerequisites when scheduling tasks:
  • User role: Admin or Maintenance

  • Licenses: You must have the required license for the scheduled task. For example, to download URL filtering data you need a URL Filtering license. To schedule intrusion policy tasks, you need an IPS license.

  • Internet access: Firewall Management Center must have internet access to download updates. See Internet Resources Accessed.

  • Additional per-task prerequisites: Each task may have unique prerequisites. For example, scheduling reports requires a report template, scheduling an Nmap scan requires you set up Nmap scanning, and so on. Refer to Scheduled task types.

When to run tasks

Follow these best practices when scheduling tasks:

  • Review automatically scheduled tasks to make sure they run at the right time for your environment.

  • Schedule tasks that require large amounts of bandwidth during periods of low network use. For example, downloading data or performing expensive Nmap scans (such as portscans).

  • Schedule tasks that might interrupt traffic, such as deploying policies or installing VDB updates, during maintenance windows.

  • Leave enough time between dependent tasks. For example, if you schedule a VDB download and install, ensure the download is finished before starting the install.

Scheduled task types

This section describes the available scheduled task types, as well as guidelines and requirements for each task.

Backup

Purpose: Back up the Firewall Management Center and managed devices.

Options:

  • Backup Type: Device or Firewall Management Center

  • Backup Profile: Firewall Management Center backups require a backup profile. Refer to Create a backup profile.

  • Retrieve to Management Center: Devices only. When you have not configured remote storage, this option controls where device backups are saved.

    • Enabled (default): Saves device backups to the Firewall Management Center in /var/sf/remote-backup/.

    • Disabled: Saves device backups to the device in /var/sf/backup/.

    If you configured remote storage, backup files are saved remotely and this option has no effect. For more information, refer to Manage backups and remote storage.

Guidelines and restrictions:

  • Supported devices: Some devices, such as devices in the public cloud, cannot be backed up. Refer to Requirements: backup and restore configuration.

  • Simultaneous backups: Back up no more than 20 devices per task. Do not schedule multiple backup tasks for the same time; start with 30 minutes between backups.

Cisco Recommended Rules

Purpose: Automatically generate rule state recommendations and modify intrusion policies based on network discovery data.

Options:

  • Policies: The intrusion policies where you want to generate recommendations.

Guidelines and restrictions:

  • Prerequisites: You must have at least one custom intrusion policy with recommendations enabled to schedule this task.

  • Save changes before the task runs: If your intrusion policies have unsaved changes, recommendations are not applied. Discard your changes and commit the policy to apply recommendations.

  • Deploy to implement changes: Modified rule states take effect the next time you deploy the intrusion policy.

Deploy Policies

Purpose: Deploy configuration changes from the Firewall Management Center to managed devices.

Options:

  • Device: The device where you want to deploy the policies.

  • Skip deployment for up-to-date devices: Enabled by default to improve performance during the deployment process.

Guidelines and restrictions:

  • Traffic interruption: When you deploy, resource demands may result in a small number of packets dropping without inspection. Additionally, deploying some configurations restarts the Snort process, which interrupts traffic inspection. Whether traffic drops during this interruption or passes without further inspection depends on how the target device handles traffic. See Snort restart traffic behavior and Configurations that restart the snort process when deployed or activated.

  • Concurrent deployments: Scheduled policy deployments do not run if a manual policy deployment is already in progress. You cannot deploy from the web interface while a scheduled deployment is running.

Download CRL

The system automatically schedules daily certificate revocation list (CRL) updates with a Download CRL task when you configure user or audit log certificates in the system configuration. Use the scheduler to change the update interval or run a one-time update.

Download, Push, or Install Latest Update

Purpose: Schedule and install VDB updates. You do not need to push VDB updates to devices; the push task is only for software updates (which are no longer supported in the scheduler).


Note


Use System (system gear icon) > Product Upgrades to upgrade software. Scheduled software upgrades are not supported, although the web interface allows configuration.


Nmap Scan

Purpose: Schedule Nmap scans to refresh static operating system, application, and server data previously supplied by Nmap, or test for unidentified applications and servers.

Options:

  • Nmap Remediation: The specific Nmap remediation to run.

  • Nmap Target: The scan target.

  • Domain: In a multidomain deployment, the domain whose network map you want to augment.

Guidelines and restrictions:

  • Prerequisite: You must configure Nmap scanning to schedule this task. This includes creating an Nmap instance, scan target, and remediation. Refer to Nmap Scanning Guidelines for additional guidelines.

  • Scan regularly: The system does not automatically update network map data replaced by Nmap unless you delete the scan targets from the network map and allow the system to rediscover them. Schedule regular scans to keep your network map current.

Report

Purpose: Schedule report generation.

Options:

  • Report Template: Use a system-provided template or create your own to generate the report. To get reports by email, edit the report template. The scheduler's email option sends only task status and does not email the report.

  • If report is empty, still attach to email: Receive reports as email attachments even when reports have no data; for example, when no events of a certain type occurred during the report period.

Update URL Filtering Database

Purpose: Obtain the latest URL filtering data from Cisco. By default, when you enable URL filtering, automatic updates are enabled. However, if you need to control exactly when these updates occur, use the scheduler.

Guidelines and restrictions:

  • Prerequisites: You must enable URL filtering to schedule this task. Disable automatic updates on Integration > Other Integrations > Cloud Services.

  • Update size and duration: Daily updates are typically small. With longer intervals, expect larger downloads and additional time for the changes to propagate.

History for scheduling

This table provides the feature history for the task scheduler.

Feature

Minimum Firewall Management Center

Minimum Firewall Threat Defense

Details

Deprecated: Scheduled software upgrades.

7.3.0

Any

Upgrade impact. Scheduled software upgrade tasks stop working.

The Download Latest Update, Push Latest Update, and Install Latest Update scheduled tasks are no longer supported for software updates, although the web interface allows configuration. (Exception: Version 7.3.1.2)

You can still use the Download Latest Update and Install Latest Update tasks to schedule VDB updates.

Automatic VDB downloads.

7.3.0

Any

Initial setup schedules a weekly task to download the latest available software updates, which now includes the latest VDB. We recommend you review this weekly task and adjust if necessary, as well as schedule a new weekly task to actually update the VDB. You must deploy configurations for new application detectors and operating system fingerprints to take effect.

New/modified screens: The Vulnerability Database check box is now enabled by default in the system-created Weekly Software Download scheduled task.

Automatic intrusion rule updates.

6.6

Any

Initial setup enables daily intrusion rule updates. We recommend you review this task and adjust if necessary. For the updated rules to take effect you must deploy configurations.

Automatic software downloads and configuration backups.

6.5

Any

Initial setup schedules weekly tasks to:

  • Download the latest available software updates for the FMC and its managed devices.

  • Perform a locally stored configuration-only backup.

We recommend you review these tasks and adjust as necessary.

Schedule remote backups of many managed devices.

6.4

Any

Schedule device backups.

New/modified screens: When configuring a recurring backup, you can now choose a Backup Type: management center vs device.

Platform restrictions: Device must support on-demand backup; see Requirements: backup and restore configuration.