<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FireSight DC Updates in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firesight-dc-updates/m-p/2905575#M1030678</link>
    <description>&lt;P&gt;Device:FirePower 7115 running version 6.0.1 (no malware license)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;In Host Attributes you can edit the operating system if the discovery gets it wrong. There are versions of OS that are not listed eg. newer versions of Juniper etc. What software update, updates that information?&lt;/P&gt;
&lt;P&gt;In the past there was SEU, Rules, GeoDB and VDB. Is there still SEU? What exactly is updated when you update VDB &amp;amp; SEU?&lt;/P&gt;
&lt;P&gt;I'm guessing VDB are the signatures for malware but if I don't have malware license what does it do? Can I still use it?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 13:01:34 GMT</pubDate>
    <dc:creator>ottleydamian</dc:creator>
    <dc:date>2019-03-12T13:01:34Z</dc:date>
    <item>
      <title>FireSight DC Updates</title>
      <link>https://community.cisco.com/t5/network-security/firesight-dc-updates/m-p/2905575#M1030678</link>
      <description>&lt;P&gt;Device:FirePower 7115 running version 6.0.1 (no malware license)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;In Host Attributes you can edit the operating system if the discovery gets it wrong. There are versions of OS that are not listed eg. newer versions of Juniper etc. What software update, updates that information?&lt;/P&gt;
&lt;P&gt;In the past there was SEU, Rules, GeoDB and VDB. Is there still SEU? What exactly is updated when you update VDB &amp;amp; SEU?&lt;/P&gt;
&lt;P&gt;I'm guessing VDB are the signatures for malware but if I don't have malware license what does it do? Can I still use it?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:01:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-dc-updates/m-p/2905575#M1030678</guid>
      <dc:creator>ottleydamian</dc:creator>
      <dc:date>2019-03-12T13:01:34Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/firesight-dc-updates/m-p/2905576#M1030679</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;VDB updates are not for malware. They are for vulnerability database and application fingerprints where you can do application based filtering.&amp;nbsp; You need protection+control license for that.&lt;/P&gt;
&lt;P&gt;SEU and rules updates still come and they are specifically for IPS and snort rules.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If new OS is not there or no info for any vendor, custom OS fingerprinting can be configured.&lt;/P&gt;
&lt;P&gt;Rate if helps.&lt;/P&gt;
&lt;P&gt;Yogesh&lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2016 06:18:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-dc-updates/m-p/2905576#M1030679</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2016-05-26T06:18:32Z</dc:date>
    </item>
    <item>
      <title>What I am saying is when you</title>
      <link>https://community.cisco.com/t5/network-security/firesight-dc-updates/m-p/2905577#M1030680</link>
      <description>&lt;P&gt;What I am saying is when you try to configure for an OS that didn't fingerprint, there is no option to setup some specific OSes. eg I am doing a manual OS for Juniper that was fingerprinted as MS. If I do a custom then I don't believe I will get vulnerabilities (CVEs) in Host Attributes.&lt;/P&gt;
&lt;P&gt;Vendor: Juniper Networks&lt;/P&gt;
&lt;P&gt;Product: ScreenOS&lt;/P&gt;
&lt;P&gt;Major: 6&lt;/P&gt;
&lt;P&gt;Minor: only 0 and 1 &lt;STRONG&gt;no 3&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Both are also Revision and Build is out of date&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;-----------------------------------&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Vendor: Cisco&lt;/P&gt;
&lt;P&gt;Product IOS Software: only up 12 &lt;STRONG&gt;not 15 etc, etc&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;So which update, updates those?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;----------------------------------&lt;/P&gt;
&lt;P&gt;Under Updates in version&amp;nbsp; 6.0.1 there is only Tabs for:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Product Updates&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Rule Updates&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Geolocation Updates&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Where is SEU updated?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2016 13:34:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-dc-updates/m-p/2905577#M1030680</guid>
      <dc:creator>ottleydamian</dc:creator>
      <dc:date>2016-05-26T13:34:25Z</dc:date>
    </item>
  </channel>
</rss>

