Scheduling

Task scheduling

Task scheduling is a system management feature that allows you to automate routine jobs to run once or on a recurring basis.

Time zones and seasonal time changes

Tasks are scheduled in Coordinated Universal Time (UTC). Because UTC remains constant year-round, scheduled tasks do not automatically adjust for local variations such as summer time or Daylight Saving Time. For example, a task scheduled for 2:00 a.m. during standard time runs at 3:00 a.m. during summer time.

Automatically scheduled tasks

The system automatically schedules these tasks:

  • A one-time task to download and install the latest VDB, at initial setup.

  • A weekly task to download the latest available, starting at initial setup.

  • A daily task to updated certificate revocation lists (CRL), when you configure user or audit log certificates.

Schedule a task

Before you begin

Before you schedule a task:

Follow these steps to schedule a one-time or recurring task.

Procedure


Step 1

Choose System (system gear icon) > Tools > Scheduling and click Add Task.

Step 2

Choose a Job Type and configure the task-specific parameters. Refer to Scheduled task types for the specific options and restrictions for each task.

Step 3

Specify the schedule details: once or recurring, start time, and frequency.

Step 4

Enter a name for the task, and optionally, a comment and email addresses for status notifications.

You can see comments when you view task details in the calendar.

Step 5

Click Save.


Your task is scheduled and will run at the time you configured.

Guidelines and prerequisites for scheduled tasks

This section provides user role requirements and best practices for scheduling tasks in general. Refer to Scheduled task types for task-specific guidelines and prerequisites.

When to run tasks

Follow these best practices when scheduling tasks:

  • Automatically scheduled tasks: Review automatically scheduled tasks to make sure they run at the right time for your environment.

  • Traffic inspection and flow: Schedule tasks that might interrupt traffic during maintenance windows.

Scheduling task sequences

Some outcomes require that you schedule multiple tasks in sequence. Leave enough time so that each task can finish before the next begins.

Table 1. Outcomes requiring multiple scheduled tasks

Outcome

Tasks

VDB update

  1. Download Latest Update

  2. Install Latest Update

Scheduled task types

This section describes the available scheduled task types, as well as guidelines and requirements for each task.

Backup

Purpose: Back up managed devices.

Options:

  • Backup Type: Device

Guidelines and limitations:

  • Supported devices: Some devices, such as devices in the public cloud, cannot be backed up.

  • Simultaneous backups: Back up no more than 20 devices per task. Do not schedule multiple backup tasks for the same time; start with 30 minutes between backups.

  • Bandwidth: If you are transferring backup files, consider scheduling backups during periods of low network use.

Download CRL

Purpose: Download certificate revocation list (CRL) updates. The system automatically schedules daily CRL updates when you configure user or audit log certificates in the system configuration. Use the scheduler to change the update interval or run a one-time update. Disabling the configurations removes the task.

Download latest update

Purpose: Download the latest VDB update. Initial setup schedules a weekly download of the latest applicable updates.


Note


Use System (system gear icon) > Product Upgrades to upgrade software. Scheduled software upgrades are not supported, although the web interface allows configuration.


Options:

  • Update Items: Choose Vulnerability Database.

Guidelines and limitations:

  • Required task order: To update the VDB, download then install. Download must finish before install begins.

  • Bandwidth: Consider scheduling downloads during periods of low network use.

Push latest update


Note


Use System (system gear icon) > Product Upgrades to upgrade software. Scheduled software upgrades are not supported, although the web interface allows configuration.


Install latest update

Purpose: Install a VDB update.


Note


Use System (system gear icon) > Product Upgrades to upgrade software. Scheduled software upgrades are not supported, although the web interface allows configuration.


Options:

  • Update Items: Choose Vulnerability Database.

  • Device: Choose the Cloud-Delivered Firewall Management Center.

Guidelines and limitations:

  • Required task order: To update the VDB, download then install. Download must finish before install begins.

  • Do not perform tasks related to mapped vulnerabilities while the VDB is updating. Even if the Message Center shows no progress for several minutes or indicates that the update has failed, do not restart the update. Instead, contact Cisco TAC.

  • Deploy during a maintenance window to implement changes: Snort typically restarts during the first deployment after VDB update. Restarting the Snort process briefly interrupts traffic flow and inspection on all devices, including devices configured for high availability or clustering.

Queue Intrusion Policy Apply

Purpose: Deploy intrusion policy changes from the Cloud-Delivered Firewall Management Center to managed devices.

Options:

  • Intrusion Policy: The policy you want to deploy.

  • Device: The device where you want to deploy the policy.

Guidelines and limitations:

Update URL Filtering Database

Purpose: Obtain the latest URL filtering data from Cisco. By default, when you enable URL filtering, automatic updates are enabled. However, if you need to control exactly when these updates occur, use the scheduler.

Guidelines and limitations:

  • Licenses: URL Filtering

  • Prerequisite configurations: You must enable URL filtering to schedule this task. Disable automatic updates on Integration > Other Integrations > Cloud Services.

  • Update size, duration, and bandwidth: Daily updates are typically small. With longer intervals, expect larger downloads and additional time for the changes to propagate, and consider scheduling during periods of low network use.