<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Intelligence Custom DNS feeds in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/security-intelligence-custom-dns-feeds/m-p/3685140#M1005365</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I think firepower will continue using the old feed until it recognizes a new feed.&lt;BR /&gt;Tested this on my unit and when I removed the feed from hosting server, it's still blocking the same entry.&lt;BR /&gt;&lt;BR /&gt;From FMC documentation.&lt;BR /&gt;"If the system downloads a corrupt feed or a feed with no recognizable entries, the system continues using the old feed data (unless it is the first download). However, if the system can recognize even one entry in the feed, it uses the entries it can recognize."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note: There is a slight delay after the feed is updated before devices starts to use it.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;br, Mikael&lt;/P&gt;</description>
    <pubDate>Thu, 09 Aug 2018 16:20:49 GMT</pubDate>
    <dc:creator>mikael.lahtela</dc:creator>
    <dc:date>2018-08-09T16:20:49Z</dc:date>
    <item>
      <title>Security Intelligence Custom DNS feeds</title>
      <link>https://community.cisco.com/t5/network-security/security-intelligence-custom-dns-feeds/m-p/3680382#M1005363</link>
      <description>&lt;P&gt;One of my customers is looking to configure a custom DNS feed in FMC.&amp;nbsp; He asked me the question what happens if the server hosting the crashes?&amp;nbsp; Does FMC lose this information?&amp;nbsp; Also, if they remove an entry from the feed, does it remove it from FMC?&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I have a feeling I know the answers, but wanted to double check for sure.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dan&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:51:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-intelligence-custom-dns-feeds/m-p/3680382#M1005363</guid>
      <dc:creator>Dan Eyster</dc:creator>
      <dc:date>2019-03-12T13:51:59Z</dc:date>
    </item>
    <item>
      <title>Re: Security Intelligence Custom DNS feeds</title>
      <link>https://community.cisco.com/t5/network-security/security-intelligence-custom-dns-feeds/m-p/3685140#M1005365</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I think firepower will continue using the old feed until it recognizes a new feed.&lt;BR /&gt;Tested this on my unit and when I removed the feed from hosting server, it's still blocking the same entry.&lt;BR /&gt;&lt;BR /&gt;From FMC documentation.&lt;BR /&gt;"If the system downloads a corrupt feed or a feed with no recognizable entries, the system continues using the old feed data (unless it is the first download). However, if the system can recognize even one entry in the feed, it uses the entries it can recognize."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note: There is a slight delay after the feed is updated before devices starts to use it.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;br, Mikael&lt;/P&gt;</description>
      <pubDate>Thu, 09 Aug 2018 16:20:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-intelligence-custom-dns-feeds/m-p/3685140#M1005365</guid>
      <dc:creator>mikael.lahtela</dc:creator>
      <dc:date>2018-08-09T16:20:49Z</dc:date>
    </item>
  </channel>
</rss>

