Intrusion rules
|
Download intrusion rules (SRU/LSP).
|
Active peer downloads, syncs to standby.
|
est.sco.cisco.com
updates-talos.sco.cisco.com
updates-dyn-talos.sco.cisco.com
updates.ironport.com
Cisco regional cloud: About Cisco Regional
Cloud
|
Security intelligence
|
Download security intelligence feeds.
|
Active peer downloads, syncs to standby.
|
intelligence.sourcefire.com
|
URL filtering
|
Download URL category and reputation data.
Manually query (look up) URL category and reputation data.
Query for uncategorized URLs.
|
Active peer downloads, syncs to standby.
|
URLs:
-
est.sco.cisco.com
-
*.talos.cisco.com
-
updates-talos.sco.cisco.com
-
updates-dyn-talos.sco.cisco.com
-
updates.ironport.com
-
Cisco regional cloud: About Cisco Regional
Cloud
IPv4 blocks:
-
146.112.62.0/24
-
146.112.63.0/24
-
146.112.255.0/24
-
146.112.59.0/24
IPv6 blocks:
-
2a04:e4c7:ffff::/48
-
2a04:e4c7:fffe::/48
|
Malware Defense
|
Secure Malware Analytics
Cloud lookups.
|
Both peers perform lookups.
|
Required Server Addresses for
Proper Cisco Secure Endpoint & Malware Analytics
Operations
|
Download signature updates for file preclassification and local
malware analysis.
|
Active peer downloads, syncs to standby.
|
updates.vrt.sourcefire.com
amp.updates.vrt.sourcefire.com
|
Query for dynamic analysis results.
|
Both peers query for dynamic analysis reports.
|
fmc.api.threatgrid.com
fmc.api.threatgrid.eu
|
Secure Endpoint
|
Receive malware events detected by Secure Endpoint from the cloud.
Display malware events detected by the system in Secure Endpoint.
Use centralized file Block and Allow lists created in Secure Endpoint to override dispositions from the cloud.
|
Both peers receive events.
You must also configure the cloud connection on both peers
(configuration is not synced).
|
Required Server Addresses for
Proper Cisco Secure Endpoint & Malware Analytics
Operations
|
Event enrichment
|
Download Talos taxonomy.
Query Talos for event enrichment.
|
Both peers communicate.
|
URLs:
IPv4 blocks:
-
146.112.62.0/24
-
146.112.63.0/24
-
146.112.255.0/24
-
146.112.59.0/24
IPv6 blocks:
-
2a04:e4c7:ffff::/48
-
2a04:e4c7:fffe::/48
|
Vulnerability database
|
Download VDB updates.
|
Active peer downloads, syncs to standby.
|
support.sourcefire.com
|
Geolocation database
|
Download GeoDB updates.
|
Active peer downloads, syncs to standby.
|
support.sourcefire.com
|