<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic @niravgunjan  , in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054229#M1007681</link>
    <description>&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://supportforums.cisco.com/users/niravgunjan"&gt;niravgunjan&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp; ,&lt;/P&gt;
&lt;P&gt;Please see the following doc:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118631-technote-firesight-00.html#anc5&lt;/P&gt;
&lt;P&gt;The command, from the ASA enable mode, is:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;session sfr do password-reset&lt;/PRE&gt;</description>
    <pubDate>Tue, 21 Mar 2017 16:06:32 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2017-03-21T16:06:32Z</dc:date>
    <item>
      <title>VDB update to  Firepower module on ASA</title>
      <link>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054217#M1007664</link>
      <description>&lt;P&gt;Do we need to update VDB update separately on firepower module or updarting on FMC is enough?FMC version 5.4&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:18:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054217#M1007664</guid>
      <dc:creator>niravgunjan</dc:creator>
      <dc:date>2019-03-12T13:18:26Z</dc:date>
    </item>
    <item>
      <title>Hi There,</title>
      <link>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054218#M1007666</link>
      <description>&lt;P&gt;Hi There,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Yes VDB needs to be updated separately apart from FMC/module upgrade.&lt;/P&gt;
&lt;P&gt;FMC or module upgrade, upgrades the software/OS of the device. VDB is a database on which application detection/prevention works.&lt;/P&gt;
&lt;P&gt;Hope that helps.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Yogesh&lt;/P&gt;
&lt;P&gt;Rate if helps.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Feb 2017 09:54:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054218#M1007666</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2017-02-26T09:54:22Z</dc:date>
    </item>
    <item>
      <title>how can i check what is VDB</title>
      <link>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054219#M1007667</link>
      <description>&lt;P&gt;how can i check what is VDB version on Sensors which are managed by FMC?&lt;/P&gt;</description>
      <pubDate>Sun, 26 Feb 2017 15:10:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054219#M1007667</guid>
      <dc:creator>niravgunjan</dc:creator>
      <dc:date>2017-02-26T15:10:51Z</dc:date>
    </item>
    <item>
      <title>If your access Control</title>
      <link>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054220#M1007669</link>
      <description>&lt;P&gt;If your access Control Policies are up to date on all of your sensors, they will have the VDB that is installed on your FMC.&lt;/P&gt;
&lt;P&gt;The best practice is to have scheduled jobs to download and install the latest updates and re-deploy policy on a regular basis. I use weekly periodicity.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your audit log should also show you the events when the above happens (whether scheduled or manual). You can filter as shown in this example:&lt;/P&gt;
&lt;P&gt;https://&amp;lt;Your FMC address or FQDN&amp;gt;/events/?table=audit_log&amp;amp;constraints=message%3DDeployment-%2C-VDB&amp;amp;workflow=Audit%20Log&amp;amp;page=0&lt;/P&gt;
&lt;P&gt;Make sure you adjust the time window to be a couple of weeks - the default is last hour.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2017 03:34:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054220#M1007669</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-02-27T03:34:28Z</dc:date>
    </item>
    <item>
      <title>It shows VDB updated on FMC</title>
      <link>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054221#M1007671</link>
      <description>&lt;P&gt;It shows VDB updated on FMC .Does it mean redeploying policies also &amp;nbsp;installs VDB updates to sensor?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2017 08:03:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054221#M1007671</guid>
      <dc:creator>niravgunjan</dc:creator>
      <dc:date>2017-02-27T08:03:58Z</dc:date>
    </item>
    <item>
      <title>You are correct. You can</title>
      <link>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054222#M1007672</link>
      <description>&lt;P&gt;You are correct. You can check current VDB version by navigating to Help&amp;gt;About and match it with the current VDB update 279.&lt;/P&gt;
&lt;P&gt;Deploying policy will push the new update to sensors as well.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Yogesh&lt;/P&gt;
&lt;P&gt;Rate if helps.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2017 09:21:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054222#M1007672</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2017-02-27T09:21:04Z</dc:date>
    </item>
    <item>
      <title>Is there a way to directly</title>
      <link>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054223#M1007674</link>
      <description>&lt;P&gt;Is there a way to directly confirm which VDB is loaded on a sensor?&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Diego&lt;/P&gt;</description>
      <pubDate>Sun, 12 Mar 2017 22:01:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054223#M1007674</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2017-03-12T22:01:08Z</dc:date>
    </item>
    <item>
      <title>The method Yogesh and I both</title>
      <link>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054224#M1007675</link>
      <description>&lt;P&gt;The method Yogesh and I both mentioned is the supported approach.&lt;/P&gt;
&lt;P&gt;If you log into a sensor and change to expert mode you can also see the information in the ngfw.rules file.&lt;/P&gt;
&lt;P&gt;Take care not to change anything in this mode - it can brick your sensor without too much effort.&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&amp;gt; expert&lt;BR /&gt;admin@firepower:~$ cat /var/sf/detection_engines/*/ngfw.rules&lt;BR /&gt;#### ngfw.rules&lt;BR /&gt;##############################################################################&lt;BR /&gt;#&lt;BR /&gt;# AC Name : Lab Access Control&lt;BR /&gt;# Policy Exported : Fri Mar 10 04:08:34 2017 (UTC)&lt;BR /&gt;# File Written : Fri Mar 10 04:09:32 2017 (UTC)&lt;BR /&gt;#&lt;BR /&gt;# DC Version : 6.2.0&lt;BR /&gt;# SRU : 2017-03-09-002-vrt&lt;BR /&gt;# &lt;SPAN style="color: #ff0000;"&gt;VDB : 279&lt;/SPAN&gt;&lt;BR /&gt;#&lt;BR /&gt;##############################################################################&lt;BR /&gt;#&lt;BR /&gt;policy 00505687-0476-0ed3-0000-034359744830&lt;BR /&gt;revision 00000000-0000-0000-0000-000058c226c2&lt;BR /&gt;interface 123 78c50696-90ac-11e6-bb9e-9db906e7ee0d&lt;BR /&gt;zone 0 78f9cf34-90ac-11e6-bb9e-9db906e7ee0d&lt;BR /&gt;http_block /var/sf/detection_engines/da31b3fa-7a01-11e6-a59a-8e590377015b/httpBlock.html&lt;BR /&gt;http_bypass /var/sf/detection_engines/da31b3fa-7a01-11e6-a59a-8e590377015b/httpBypass.html&lt;BR /&gt;&lt;BR /&gt;iab_mode Off&lt;BR /&gt;# Start of AC rule. &lt;BR /&gt;268435461 audit any any any any any any any any (log dcforward flowend) (urlcat 76)&lt;BR /&gt;268435464 allow any any any any any any any any (log dcforward flowend) (ipspolicy 52)&lt;BR /&gt;# End of AC rule. &lt;BR /&gt;admin@firepower:~$&lt;/PRE&gt;
&lt;PRE class="prettyprint"&gt;&lt;BR /&gt;&amp;nbsp;&lt;/PRE&gt;</description>
      <pubDate>Mon, 13 Mar 2017 02:09:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054224#M1007675</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-03-13T02:09:40Z</dc:date>
    </item>
    <item>
      <title>This certainly works (and so</title>
      <link>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054225#M1007676</link>
      <description>&lt;P&gt;This certainly works (and so does "show version" from the &amp;gt; prompt) but what I had in mind was something I can do from the FMC since that is where you spend 95% of your time and also this being an enterprise management console we don't want to have to go SSHing around to a few dozen boxes!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Diego&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2017 15:32:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054225#M1007676</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2017-03-13T15:32:42Z</dc:date>
    </item>
    <item>
      <title>If you just look at the top</title>
      <link>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054226#M1007677</link>
      <description>&lt;P&gt;If you just look at the top level device management page it indicates whether all of your devices' policies are up to date. If they are, then they all have the same VDB version that's installed on the FMC.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2017 02:41:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054226#M1007677</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-03-14T02:41:53Z</dc:date>
    </item>
    <item>
      <title>Yes, I agree but it would</title>
      <link>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054227#M1007678</link>
      <description>&lt;P&gt;Yes, I agree but it would just make me feel better if they would explicitly show versions so that you don't have to infer or extrapolate that since the access policy is up to date then so are all other components.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;It's just the paranoid/ocd part of me showing a little bit.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Diego&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2017 14:05:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054227#M1007678</guid>
      <dc:creator>tato386</dc:creator>
      <dc:date>2017-03-14T14:05:17Z</dc:date>
    </item>
    <item>
      <title>I am not able to login to</title>
      <link>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054228#M1007680</link>
      <description>&lt;P&gt;I am not able to login to Firepower module in ASA-5555-x via CLI.these modules are managed by FMC.How can i reset ID paaswprd?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Mar 2017 14:53:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054228#M1007680</guid>
      <dc:creator>niravgunjan</dc:creator>
      <dc:date>2017-03-21T14:53:25Z</dc:date>
    </item>
    <item>
      <title>@niravgunjan  ,</title>
      <link>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054229#M1007681</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://supportforums.cisco.com/users/niravgunjan"&gt;niravgunjan&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp; ,&lt;/P&gt;
&lt;P&gt;Please see the following doc:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118631-technote-firesight-00.html#anc5&lt;/P&gt;
&lt;P&gt;The command, from the ASA enable mode, is:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;session sfr do password-reset&lt;/PRE&gt;</description>
      <pubDate>Tue, 21 Mar 2017 16:06:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054229#M1007681</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-03-21T16:06:32Z</dc:date>
    </item>
    <item>
      <title>Thankyou all for the response</title>
      <link>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054230#M1007682</link>
      <description>&lt;P&gt;Thankyou all for the response&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2017 10:44:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/3054230#M1007682</guid>
      <dc:creator>niravgunjan</dc:creator>
      <dc:date>2017-03-27T10:44:06Z</dc:date>
    </item>
    <item>
      <title>Re: Yes, I agree but it would</title>
      <link>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/4044723#M1067719</link>
      <description>&lt;P&gt;Hi All, Any workaround for this to see device VDB &amp;amp; SRU versions from FMC CLI?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2020 06:22:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vdb-update-to-firepower-module-on-asa/m-p/4044723#M1067719</guid>
      <dc:creator>Muhammad Abubakar</dc:creator>
      <dc:date>2020-03-12T06:22:28Z</dc:date>
    </item>
  </channel>
</rss>

