Updates

Content updates

Content updates keep your deployment current with changing security and contextual information. The system uses this information to evaluate network activity and respond to changes in the threat landscape. Automatic content updates are often enabled by initial configuration or when you enable the related feature.

Types of content updates

Firewall Management Center uses these types of content updates:

Product upgrades

This guide does not include procedures for upgrading the system software or firewall chassis. Instead, refer to the companion upgrade guide: https://cisco.com/go/ftd-fmc-upgrade-76.

Guidelines for content updates

These guidelines apply to all content updates. Refer to the topics for each update type for update-specific guidance.

User roles

Admin

Domains

Global, except for custom Snort 2 rule import

Internet access

Firewall Management Center must be able to access the internet to download content updates. Refer to Communication Ports and Internet Access.

Release information

Read any release notes or advisory text that accompanies a content update. This information describes compatibility, prerequisites, new capabilities, behavior changes, and warnings.

When to perform content updates

Follow these guidelines when performing and scheduling content updates:

  • Scheduled updates: Review scheduled updates to make sure they run at the right time for your environment.

  • Bandwidth: Perform updates that require large amounts of bandwidth during periods of low network use.

  • Traffic inspection and flow: Perform updates that might interrupt traffic during maintenance windows.

Content updates are scheduled in Coordinated Universal Time (UTC), which remains constant year-round. Scheduled updates do not adjust automatically for local time changes, such as daylight saving time or summer time. For example, an update scheduled for 2:00 a.m. during standard time runs at 3:00 a.m. after the local clock moves forward.

Vulnerability database (VDB) updates

The VDB is a database of known vulnerabilities to which hosts may be susceptible, as well as fingerprints for operating systems, clients, and applications. The system uses the VDB to help determine whether a particular host increases your risk of compromise.

VDB versions

We periodically release VDB updates. Each update replaces the previous version.

Starting with VDB 357, you can install an earlier VDB as far back as the baseline VDB for Firewall Management Center.

VDB update duration

The time required to update the VDB and its associated mappings on the Firewall Management Center depends on the number of hosts in your network map. Allow approximately one minute for every 1000 hosts.

Scheduled VDB updates

Initial configuration automatically downloads and installs the latest VDB as a one-time operation and creates a weekly task to download future updates. Review the schedule and adjust as needed. To update the VDB and deploy configurations automatically, create separate tasks. For more information, refer to Scheduling.

Deployment after VDB updates

Deploy configuration changes after a VDB update for updated application detectors and operating system fingerprints to take effect. Updated vulnerability information takes effect without deploy.


Caution


The first deploy after a VDB update usually restarts Snort because updated application detectors and operating system fingerprints require a restart. Restarting Snort briefly interrupts traffic flow and inspection on all devices, including those configured for high availability or scalability. Interface configurations determine whether traffic drops or passes without inspection during the interruption. When you deploy without restarting Snort, resource demands may result in a small number of packets dropping without inspection.


VDB release information

For VDB 343 and later, Cisco Secure Firewall Application Detectors provides searchable application detector information. The release notes describe changes in each VDB release.

VDB lite

Manually update the VDB

Perform an on-demand update to keep the VDB current or to install an older VDB.

Before you begin

If the Firewall Management Center cannot access the internet or you are installing an older VDB, download the VDB manually from https://www.cisco.com/go/firepower-software. Select or search for your model—or choose any model because all Firewall Management Centers use the same VDB—and then open the Coverage and Content Updates page.

Starting with VDB 357, you can install any VDB as far back as the baseline VDB for the Firewall Management Center.

Procedure


Step 1

Choose System (system gear icon) > Content Updates > VDB Updates.

Step 2

Choose how you want to get the VDB onto the Firewall Management Center.

  • Direct download: Click Download Updates.

  • Manual upload: Click Upload Update, click Choose File, select the VDB, and click Upload.

Step 3

Install the VDB.

  1. Next to the VDB update you want to install, click either the Install icon (for a newer VDB) or the Rollback icon (for an older VDB).

  2. Choose the Firewall Management Center.

  3. Click Install.

Monitor update progress in the Message Center. Do not use mapped-vulnerability features while the VDB is updating. If the Message Center shows no progress for several minutes or reports that the update failed, do not restart it. Contact Cisco TAC.

Step 4

Verify update success.

The current version is displayed on the VDB update page and on Help (help icon) > About.


The system uses the new vulnerability information. However, you must deploy before updated application detectors and operating system fingerprints can take effect.

What to do next

  • Deploy configuration changes.

  • If configurations reference vulnerabilities, application detectors, or fingerprints that are no longer available, review those configurations to confirm that they handle traffic as expected. A scheduled VDB update can undo a rollback. To retain the older VDB, change the scheduled task or delete any newer VDB packages.

Geolocation database (GeoDB) updates

The geolocation database (GeoDB) maps IP addresses to geographic locations so that you can view and filter traffic by location.

GeoDB versions

We periodically release GeoDB updates. Each update replaces the previous version.

Scheduled GeoDB updates

Initial configuration schedules weekly updates to keep geolocation information accurate. Review the schedule and adjust it as needed. Refer to Schedule GeoDB updates.

Deployment after GeoDB updates

The Firewall Management Center automatically updates the GeoDB on managed devices, so deploy is usually unnecessary. If an update adds a new country, which is rare, deploy configuration changes as soon as possible. This allows the new country to count as part of its continent. For example, if an update adds Country to Continent, rules that filter based on "Continent" do not match traffic through Country until you deploy.

Deprecated IP package

We no longer provide the geolocation IP package, which contained contextual data associated with routable IP addresses. This saves disk space and does not affect geolocation rules or traffic handling in any way. Any contextual data is now stale, and upgrading to most later versions deletes the IP package. Options to download the IP package or view contextual data have no effect, and are removed in later versions.

Schedule GeoDB updates

Schedule recurring GeoDB updates to keep the installed geolocation information current.

Initial configuration creates a weekly schedule for GeoDB updates. Review the schedule and adjust the start time as needed.


Note


The IP Package Download option available in some versions has no effect. We no longer provide an IP package. In later versions, this option is removed.


Procedure


Step 1

Choose System (system gear icon) > Content Updates > Geolocation Updates.

Step 2

Configure recurring GeoDB updates.

  1. Under Recurring Geolocation Updates, check Enable Recurring Weekly Updates from the Support Site.

  2. Specify the Update Start Time.

Step 3

Click Save.


Manually update the GeoDB

Perform an on-demand update to keep the GeoDB current.

Before you begin

If the Firewall Management Center cannot access the internet, download the GeoDB manually from https://www.cisco.com/go/firepower-software. Select or search for your model—or choose any model because all Firewall Management Centers use the same GeoDB—and then open the Coverage and Content Updates page.


Note


The IP Package Download option available in some versions has no effect. We no longer provide an IP package. In later versions, this option is removed.


Procedure


Step 1

Choose System (system gear icon) > Content Updates > Geolocation Updates.

Step 2

Under One-Time Geolocation Update, choose how you want to get the GeoDB onto the Firewall Management Center.

  • Direct download: Choose Download and install geolocation update from the Support Site.

  • Manual upload: Choose Upload and install geolocation update, click Choose File, and select the GeoDB.

Step 3

Click Import.

Monitor update progress in the Message Center.

Step 4

Verify update success.

The current version is displayed on the GeoDB update page and on Help (help icon) > About.


The system uses the new geolocation information. However, you must deploy before new countries can take effect. Until you deploy, the new country does not count as part of its continent. For example, if an update adds Country to Continent, rules that filter based on "Continent" do not match traffic through Country until you deploy.

What to do next

If the update adds a new country, deploy configuration changes.

Intrusion rule updates

An intrusion rule update is a cumulative package that provides new and modified intrusion and preprocessor rules, and modifies the policies that use them.

Intrusion rule update versions

As new vulnerabilities become known, the Talos Intelligence Group releases intrusion rule updates. Keep intrusion rules up to date. Each update replaces the previous version, and you can import only an update that is newer than the currently installed version.

Contents of intrusion rule updates

An intrusion rule update can contain these types of content:

  • Rules and rule states: An update can add, modify, or delete intrusion and preprocessor rules. The default state of a new rule can differ between system-provided intrusion policies. For example, a new rule can be enabled in the Security over Connectivity policy and disabled in the Connectivity over Security policy. An update can also change the default state of an existing rule.

  • Rule categories: An update can contain new rule categories. Importing the update adds all new categories.

  • Preprocessor and advanced settings: An update can change advanced settings in system-provided intrusion policies and preprocessor settings in system-provided network analysis policies. It can also change the default values of advanced preprocessing and performance options in access control policies.

  • Variables: An update can change the default values of existing variables without overriding customized values. It also adds new variables.

Policy changes from intrusion rule updates

Intrusion rule updates can affect system-provided and custom network analysis and intrusion policies, as well as the access control policies that use them. The effects depend on the policy type.

  • System-provided policies: Changes to system-provided network analysis and intrusion policies and advanced access control settings take effect after you redeploy the configuration.

  • Custom policies: Every custom network analysis and intrusion policy is based directly or indirectly on a system-provided policy. For each custom policy, you can prevent rule updates from automatically applying changes from its base policy. You can then apply the base-policy changes manually on a schedule independent of rule update imports. Updates do not override customized settings.


Caution


Importing an intrusion rule update discards all cached changes to network analysis and intrusion policies. Before you import an update, use the Rule Updates page to identify policies with cached changes and the users who made them.


Scheduled intrusion rule updates

Initial configuration creates a daily schedule for intrusion rule updates. Review the schedule and adjust the frequency as needed. Refer to Schedule intrusion rule updates.

Deployment after intrusion rule updates

Deploy configuration changes after an intrusion rule update for the update’s changes to take effect. You can configure an import to deploy automatically to affected devices. Automatic deployment is especially useful when you allow updates to modify system-provided base intrusion policies.


Caution


Although a rule update by itself does not restart Snort when you deploy, other changes you have made may. Restarting Snort briefly interrupts traffic flow and inspection on all devices, including those configured for high availability or scalability. Interface configurations determine whether traffic drops or passes without inspection during the interruption. When you deploy without restarting Snort, resource demands may result in a small number of packets dropping without inspection.


Schedule intrusion rule updates

Schedule recurring intrusion rule updates to keep the installed intrusion rules current.

Before you begin

Make sure your process for updating intrusion rules complies with your security policies.

Initial configuration creates a daily schedule for intrusion rule updates. Review the schedule and adjust the frequency as needed. You can also configure automatic deployment after each rule update. Automatic deployment can disrupt traffic inspection and flow.

Procedure


Step 1

Choose System (system gear icon) > Content Updates > Rule Updates.

Step 2

Configure recurring rule updates.

  1. Under Recurring Rule Update Imports, check Enable Recurring Rule Update Imports.

  2. Specify the Import Frequency and start time.

  3. (Optional) Check Deploy all policies to targeted devices after rule update completes.

Step 3

Click Save.


Manually update intrusion rules

Perform an on-demand update to keep intrusion rules current.

Before you begin

  • Make sure your process for updating intrusion rules complies with your security policies.

  • If the Firewall Management Center cannot access the internet, download the update manually from https://www.cisco.com/go/firepower-software. Select or search for your model—or choose any model because all Firewall Management Centers use the same update—and then open the Coverage and Content Updates page.

Procedure


Step 1

Choose System (system gear icon) > Content Updates > Rule Updates.

Step 2

Configure the one-time rule update.

  1. Under One-Time Rule Update/Rules Import, choose how to update intrusion rules.

    • Direct download: Choose Download new rule update....

    • Manual upload: Choose Rule update or text rule file..., click Choose File, and select the intrusion rule update.

  2. (Optional) Check Reapply all policies after the rule update import completes.

Step 3

Click Import.

Monitor update progress in the Message Center. Even if the Message Center shows no progress for several minutes or indicates that the update has failed, do not restart the update. Instead, contact Cisco TAC.

Step 4

Verify update success.

The current version is displayed on the rule update page and on Help (help icon) > About.


What to do next

If you did not deploy configuration changes as part of the update, deploy them now.

Guidelines for importing custom Snort 2 rules

Use these guidelines to import custom standard text rules for use in Snort 2 intrusion policies.

File and rule syntax requirements

Import rules using a rule file that meets these requirements:

  • Use a plain text file encoded in ASCII or UTF-8.

  • Use only alphanumeric characters, spaces, underscores (_), periods (.), and hyphens (-) in the file name.

  • To import a rule in the deleted state, precede it with one number sign (#). A rule preceded by two number signs (##) is not imported.

  • Do not use escape characters in rules.

  • Limit each source or destination port list to 64 characters. A longer list causes the import to fail.

For more information on writing custom rules, refer to Custom Snort 2 Intrusion Policies for Access Control and to the Snort manual at http://www.snort.org.

SID, GID, and revision number requirements

Follow these requirements for SIDs, GIDs, and revision numbers:

  • Do not specify a GID. A standard text rule receives GID 1. In a multidomain deployment, a rule imported into a subdomain instead receives a domain-specific GID from 1000 through 2000.

  • Leave the SID and revision number unspecified when importing a rule for the first time. The rule receives an available SID of 1000000 or greater and a revision number of 1.

  • If you must specify a SID for a new rule, use an unassigned value from 1000000 through 2147483647 (the 32-bit limit).

  • When importing an updated or previously deleted rule, include its assigned SID and a revision number greater than its current revision number.

To determine the current revision number, edit the imported rule. Deleting a custom rule moves it to the deleted rule category and increments its revision number. You can then import a later revision to reinstate the rule.

Import custom Snort 2 rules

Import custom standard text rules so you can enable them in Snort 2 intrusion policies.

This procedure applies only to custom standard text rules for Snort 2 intrusion policies. In a multidomain deployment, you can import rules in any domain, and can view rules imported in the current domain and ancestor domains. For Snort 3, refer to the rule-tuning topics in Custom Snort 3 Intrusion Policies for Access Control.

Before you begin

Procedure


Step 1

Choose System (system gear icon) > Content Updates > Rule Updates.

You can also click Import Rules in the intrusion rules editor (Objects > Intrusion Rules).

Step 2

(Optional) Delete all existing custom rules.

To replace all existing custom rules with the rules in the new file, click Delete All Local Rules. The deleted rules move to the deleted rule category, and their revision numbers increase.

Step 3

Import the rule file.

  1. Under One-Time Rule Update/Rules Import, choose Rule update or text rule file to upload and install.

  2. Click Choose File, select your rule file, and click Import.

You can monitor import progress in the Message Center. Even if the Message Center shows no progress for several minutes or indicates that the import has failed, do not restart the import. Instead, contact Cisco TAC.


  • Imported rules are added to the local rule category in a disabled state.

  • Imported rules receive Generator ID (GID) 1 unless imported into a subdomain, where they receive a domain-specific GID from 1000 through 2000.

  • New imported rules receive an available Snort ID (SID) of 1000000 or greater and a revision of 1. In a multidomain deployment, SIDs assigned within a domain might not be sequential when multiple users import rules concurrently.

What to do next

  • Edit Snort 2 intrusion policies and enable the rules you imported.

    Do not enable an imported rule that uses the deprecated threshold keyword in an intrusion policy that also uses intrusion event thresholding. This combination causes policy validation to fail.

  • Deploy configuration changes.

Intrusion rule update logs

The Rule Update Log on the Rule Updates page records each intrusion rule update and custom Snort 2 rule import, including its time, user, and status. Each log also identifies the affected rules and components. Deleting a log does not delete the imported objects.

In a multidomain deployment, you can view logs for the current domain and its descendant domains. You cannot view logs from ancestor or sibling domains.

Intrusion rule update log fields

This table explains the fields in intrusion rule update logs.

Table 1. Intrusion rule update log fields

Field

Description

Action

Identifies how the import affected the object.

Default action

For a rule, the default action defined by the update is Pass, Alert, or Drop. The field is blank for other object types.

Details

Identifies the affected component or rule. For a changed rule, the field displays the GID, SID, and previous revision number in GID:SID:Rev format. The field is blank for a rule that has not changed.

Domain

The domain whose intrusion policies can use the updated rule. Intrusion policies in descendant domains can also use the rule. This field is only present in a multidomain deployment.

GID

The generator ID for a rule. For example:

  • A GID of 1 identifies a standard text rule. In a multidomain deployment, GID 1 is reserved for the Global domain.

  • A GID of 3 identifies a shared object rule.

  • A GID from 1000 through 2000 identifies a rule imported into a subdomain.

Name

The name of the imported object. For a rule, the name corresponds to the rule’s Message field. For a rule update component, the field displays the component name.

Policy

For an imported rule, the field displays All when the import succeeds and the rule can be enabled in all applicable system-provided default intrusion policies. The field is blank for other object types.

Rev

The revision number for a rule.

Rule update

The rule update file name.

SID

The Snort ID for a rule.

Time

The time and date the import began.

Type

Identifies the imported object as a rule update component, rule, or policy apply. A policy apply record indicates that the option to reapply all policies after the import was enabled.

Action values

The Action field in intrusion rule update logs uses these values.

Table 2. Action values in intrusion rule update logs

Action

Meaning

new

The rule was stored for the first time.

changed

A rule update component was modified, or a rule was imported with a higher revision number and the same GID and SID.

collision

The import was skipped because the revision conflicts with an existing component or rule.

deleted

The rule was deleted from the rule update.

enabled

A rule, preprocessor, or other feature was enabled in a system-provided default policy.

disabled

A rule was disabled in a system-provided default policy.

drop

A rule was set to Drop and Generate Events in a system-provided default policy.

error

The update or import failed.

apply

The option to reapply all policies after the import was enabled.

Searching intrusion rule update logs

A search from the detailed log view searches the entire database, not only the selected import. Use the time range to limit the results to relevant records.

History for content updates

This table provides the feature history for content updates.

Table 3. History for content updates

Feature

Minimum Firewall Management Center

Minimum Firewall Threat Defense

Details

Automatic VDB downloads.

7.3.0

Any

The initial setup on the Firewall Management Center schedules a weekly task to download the latest available software updates, which now includes the latest vulnerability database (VDB). We recommend you review this weekly task and adjust if necessary. Optionally, schedule a new weekly task to actually update the VDB and deploy configurations.

New/modified screens: The Vulnerability Database check box is now enabled by default in the system-created Weekly Software Download scheduled task.

Install any VDB.

7.3.0

Any

Starting with VDB 357, you can now install any VDB as far back as the baseline VDB for that Firewall Management Center.

After you update the VDB, deploy configuration changes. If you based configurations on vulnerabilities, application detectors, or fingerprints that are no longer available, examine those configurations to make sure you are handling traffic as expected. Also, keep in mind a scheduled task to update the VDB can undo a rollback. To avoid this, change the scheduled task or delete any newer VDB packages.

New/modified screens: On System(system gear icon) > Updates > Product Updates > Available Updates, if you upload an older VDB, a new Rollback icon appears instead of the Install icon.

Content updates and product upgrades no longer share a page.

7.2.6

7.4.1

Any

Content updates and product upgrades no longer share a page.

  • System(system gear icon) > Content Updates is where you update intrusion rules, the VDB, and the GeoDB.

  • System(system gear icon) > Product Upgrades is where you upgrade the Firewall Management Center and all managed devices, as well as manage upgrade packages.

  • System(system gear icon) > Updates is deprecated. All Firewall Threat Defense upgrades now use the wizard.

Custom Snort 2 intrusion rule import warns when rules collide.

6.7.0

Any

The system now warns you of rule collisions when you import custom Snort 2 intrusion rules. Previously, the system would silently skip the rules that cause collisions—with the exception of Version 6.6.0.1, where a rule import with collisions would fail entirely.

On the Rule Updates page, if a rule import had collisions, a warning icon is displayed in the Status column. For more information, hover your pointer over the warning icon and read the tooltip.

Note that a collision occurs when you try to import an intrusion rule that has the same SID/revision number as an existing rule. You should always make sure that updated versions of custom rules have new revision numbers.

New/modified screens: We added a warning icon to System(system gear icon) > Updates > Rule Updates.

Automatic VDB update during initial setup.

6.6.0

Any

When you set up a new or reimaged Firewall Management Center, the system attempts to update the vulnerability database (VDB).

This is a one-time operation. If the Firewall Management Center has internet access, we recommend you schedule tasks to perform automatic recurring VDB update downloads and installations.

Automatic intrusion rule updates.

6.6.0

Any

Initial setup enables daily intrusion rule updates. We recommend you review this task and adjust if necessary. For the updated rules to take effect you must deploy configurations.

Automatic software downloads and GeoDB updates.

6.5.0

Any

When you set up a new or reimaged Firewall Management Center, the system schedules weekly patch downloads and GeoDB updates.

Signed SRU, VDB, and GeoDB updates.

6.4.0

Any

So the system can verify that you are using the correct update files, Version 6.4+ uses signed updates for intrusion rules (SRU), the vulnerability database (VDB), and the geolocation database (GeoDB). Earlier versions continue to use unsigned updates.

Unless you manually download updates, for example, in an air-gapped deployment—you should not notice any difference in functionality. If, however, you do manually download and install SRU, VDB, and GeoDB updates, make sure you download the correct package for your current version.

Signed update files begin with 'Cisco' instead of 'Sourcefire,' and terminate in .sh.REL.tar instead of .sh, as follows:

  • SRU: Cisco_Firepower_SRU-date-build-vrt.sh.REL.tar

  • VDB: Cisco_VDB_Fingerprint_Database-4.5.0-version.sh.REL.tar

  • GeoDB: Cisco_GEODB_Update-date-build.sh.REL.tar

We will provide both signed and unsigned updates until the end-of-support for versions that require unsigned updates. Do not untar signed (.tar) packages. If you accidentally upload a signed update to an older Firewall Management Center or ASA FirePOWER device, you must manually delete it. Leaving the package takes up disk space, and also may cause issues with future upgrades.

Snort restart warnings before VDB updates.

6.2.3

Any

The system now warns you VDB updates restart the Snort process. This interrupts traffic inspection and, depending on how the managed device handles traffic, possibly interrupts traffic flow. You can cancel the install until a more convenient time, such as during a maintenance window.

These warnings can appear:

  • After you download and manually install a VDB.

  • When you create a scheduled task to install the VDB.

  • When the VDB installs in the background, such as during a previously scheduled task or as part of a software upgrade.

Deprecated: Geolocation details

6.2.3

Any

We no longer provide the geolocation IP package, which contained contextual data associated with routable IP addresses. This saves disk space and does not affect geolocation rules or traffic handling in any way. Any contextual data is now stale, and upgrading to most later versions deletes the IP package. Options to download the IP package or view contextual data have no effect, and are removed in later versions.