<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How often does IPS update on Firepower devices in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-often-does-ips-update-on-firepower-devices/m-p/5343755#M1123347</link>
    <description>&lt;P&gt;In an FMC-managed FTD deployment, the IPS updates (SRU and LSP for Snort2 and Snort 3 respectively) are downloaded from Cisco by the FMC. They are deployed to the managed FTDs only when deployed (the update can be setup to automatically deploy if desired). Only the FMC management interface requires https (TLS) access to Cisco's repositories. It then sends the updates to the managed devices (when deploying) via the sftunnel management connection (FMC management interface to FTD management interface via TLS over tcp/8305).&lt;/P&gt;</description>
    <pubDate>Fri, 31 Oct 2025 17:32:54 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2025-10-31T17:32:54Z</dc:date>
    <item>
      <title>How often does IPS update on Firepower devices</title>
      <link>https://community.cisco.com/t5/network-security/how-often-does-ips-update-on-firepower-devices/m-p/5242691#M1118531</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;On Firepower firewalls, how often does the IPS update?&lt;/P&gt;&lt;P&gt;I can see timers for the "security intelligence" feeds, default 2 hours, but nothing for the intrusion side, I can see some settings under system &amp;gt; content updates, is this it? if so, it looks like you have to push a policy to the FTD for it to get the latest updates? can this not be automatic?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="carltownshend_0-1735817875183.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/236876i2AD0E41C66199C0B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="carltownshend_0-1735817875183.png" alt="carltownshend_0-1735817875183.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jan 2025 11:39:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-often-does-ips-update-on-firepower-devices/m-p/5242691#M1118531</guid>
      <dc:creator>carl.townshend</dc:creator>
      <dc:date>2025-01-02T11:39:28Z</dc:date>
    </item>
    <item>
      <title>Re: How often does IPS update on Firepower devices</title>
      <link>https://community.cisco.com/t5/network-security/how-often-does-ips-update-on-firepower-devices/m-p/5242732#M1118533</link>
      <description>&lt;P&gt;As shown in the screenshot, there is an option to deploy policy after the recurring rule update discovers and downloads new IPS rule sets (Snort Rule Updates (SRUs) for Snort 2 and Local Security Policies (LSPs) for Snort 3 intrusion policies) from cisco.com. That will sync your managed devices' rule sets with those available from Cisco. Rule sets are typically updated by Cisco a couple of times per month.&lt;/P&gt;
&lt;P&gt;You also have the option of automatically tuning your IPS policies by using Firepower recommendations which further fine tune your IPS policy based on observed traffic / hosts on your network. That is done via a combination of a setting within the IPS policy and an (optional) recurring job that your setup in the FMC scheduling section.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jan 2025 13:58:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-often-does-ips-update-on-firepower-devices/m-p/5242732#M1118533</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-01-02T13:58:55Z</dc:date>
    </item>
    <item>
      <title>Re: How often does IPS update on Firepower devices</title>
      <link>https://community.cisco.com/t5/network-security/how-often-does-ips-update-on-firepower-devices/m-p/5242736#M1118536</link>
      <description>&lt;P&gt;Yep, under &lt;STRONG&gt;System &amp;gt; Content Updates &amp;gt; Rule Updates&lt;/STRONG&gt;, you can set up &lt;STRONG&gt;Recurring Rule Update Imports&lt;/STRONG&gt; (e.g., daily). For it to be fully automatic, check "Deploy updated policies after rule update completes." Without that, you'll need to manually push the policy to apply the updates. Security Intelligence updates are separate (default every 2 hours).&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jan 2025 14:11:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-often-does-ips-update-on-firepower-devices/m-p/5242736#M1118536</guid>
      <dc:creator>PacketWhisperer</dc:creator>
      <dc:date>2025-01-02T14:11:42Z</dc:date>
    </item>
    <item>
      <title>Re: How often does IPS update on Firepower devices</title>
      <link>https://community.cisco.com/t5/network-security/how-often-does-ips-update-on-firepower-devices/m-p/5242775#M1118539</link>
      <description>&lt;P&gt;Hi, thanks for the info, are you saying the above setting will push the latest IPS updates out daily? I thought with this being a security device it would pretty much be an automatic setting, on Checkpoint for example, the daily update happens at midnight by default, why is this switched off by default and has to be enabled?&lt;/P&gt;&lt;P&gt;What would the recommendation be?&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jan 2025 15:15:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-often-does-ips-update-on-firepower-devices/m-p/5242775#M1118539</guid>
      <dc:creator>carl.townshend</dc:creator>
      <dc:date>2025-01-02T15:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: How often does IPS update on Firepower devices</title>
      <link>https://community.cisco.com/t5/network-security/how-often-does-ips-update-on-firepower-devices/m-p/5242779#M1118540</link>
      <description>&lt;P&gt;Cisco does not publish IPS rule updates daily. You can see the published updates in the software.cisco.com site for FMC here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://software.cisco.com/download/home/286259687/type/286321931/release/LSP" target="_blank"&gt;https://software.cisco.com/download/home/286259687/type/286321931/release/LSP&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;For instance, there were 10 updates published in October 2024, 7 each in November and December.&lt;/P&gt;
&lt;P&gt;Every vendor bundles their software differently. Cisco Talos has determined that is it most effective to stream SI updates throughout the day, with a 2 hour feed update being the default for FMC and FDM. Snort rules are less frequent - several times monthly as I noted. So if you check for them daily, you will always have the latest ones.&lt;/P&gt;
&lt;P&gt;Many customers do not want to have constant changes to IPS rules since it may be counter to their change management process. Thus, Cisco gives you the option of being anywhere on the spectrum from no updates to having updates the day they are published and further deploying the updates as soon as you get them. If they didn't provide this flexibility, some very large customers would choose not to use them. What's optimal for your use case may be the opposite for another customer.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jan 2025 15:28:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-often-does-ips-update-on-firepower-devices/m-p/5242779#M1118540</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-01-02T15:28:52Z</dc:date>
    </item>
    <item>
      <title>Re: How often does IPS update on Firepower devices</title>
      <link>https://community.cisco.com/t5/network-security/how-often-does-ips-update-on-firepower-devices/m-p/5242790#M1118541</link>
      <description>&lt;P&gt;Thanks Marvin, nice response there&lt;/P&gt;&lt;P&gt;So when we talk about IPS updates, we are talking about new signatures etc?&lt;/P&gt;&lt;P&gt;With regards to the SI updates, these are not signatures but networks and URL's right ?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jan 2025 15:59:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-often-does-ips-update-on-firepower-devices/m-p/5242790#M1118541</guid>
      <dc:creator>carl.townshend</dc:creator>
      <dc:date>2025-01-02T15:59:05Z</dc:date>
    </item>
    <item>
      <title>Re: How often does IPS update on Firepower devices</title>
      <link>https://community.cisco.com/t5/network-security/how-often-does-ips-update-on-firepower-devices/m-p/5242793#M1118542</link>
      <description>&lt;P&gt;You're welcome &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1117933"&gt;@carl.townshend&lt;/a&gt; .&lt;/P&gt;
&lt;P&gt;Yes and yes re your two latest questions.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jan 2025 16:05:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-often-does-ips-update-on-firepower-devices/m-p/5242793#M1118542</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-01-02T16:05:57Z</dc:date>
    </item>
    <item>
      <title>Re: How often does IPS update on Firepower devices</title>
      <link>https://community.cisco.com/t5/network-security/how-often-does-ips-update-on-firepower-devices/m-p/5343690#M1123343</link>
      <description>&lt;P&gt;Hello Marvin,&lt;/P&gt;
&lt;P&gt;I am still starting to understand how IPS works with FTD, one question please. In the scenario with FTD version 7.X managed with an on prem FMC, the IPS updates are downloaded by the FMC and the deployed to FTD with policy push? or they are downloaded directly to FTD? I enabled IPS in a new FTD deployment but i get an error about connectivity with updates URL. This connectivity required from the FMC or from FTD? i assume this downloads use the management interface rigth? Thanks in advance.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 31 Oct 2025 12:47:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-often-does-ips-update-on-firepower-devices/m-p/5343690#M1123343</guid>
      <dc:creator>daniel_rs</dc:creator>
      <dc:date>2025-10-31T12:47:38Z</dc:date>
    </item>
    <item>
      <title>Re: How often does IPS update on Firepower devices</title>
      <link>https://community.cisco.com/t5/network-security/how-often-does-ips-update-on-firepower-devices/m-p/5343755#M1123347</link>
      <description>&lt;P&gt;In an FMC-managed FTD deployment, the IPS updates (SRU and LSP for Snort2 and Snort 3 respectively) are downloaded from Cisco by the FMC. They are deployed to the managed FTDs only when deployed (the update can be setup to automatically deploy if desired). Only the FMC management interface requires https (TLS) access to Cisco's repositories. It then sends the updates to the managed devices (when deploying) via the sftunnel management connection (FMC management interface to FTD management interface via TLS over tcp/8305).&lt;/P&gt;</description>
      <pubDate>Fri, 31 Oct 2025 17:32:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-often-does-ips-update-on-firepower-devices/m-p/5343755#M1123347</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-10-31T17:32:54Z</dc:date>
    </item>
    <item>
      <title>Re: How often does IPS update on Firepower devices</title>
      <link>https://community.cisco.com/t5/network-security/how-often-does-ips-update-on-firepower-devices/m-p/5353621#M1123820</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi Marvin, do you have any additional info on Cisco Talos SI updates? It seems to me administrators don't have the same control on when these get applied. When we go to deploy a change we see that user "system" modified something, but the details are opaque. I've been bit with what I believe is a bad EVE fingerprint blocking legit traffic. Any idea on how we can control or see Talos SI updates? Thanks,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2025 21:38:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-often-does-ips-update-on-firepower-devices/m-p/5353621#M1123820</guid>
      <dc:creator>danielpacheco613</dc:creator>
      <dc:date>2025-12-09T21:38:35Z</dc:date>
    </item>
    <item>
      <title>Re: How often does IPS update on Firepower devices</title>
      <link>https://community.cisco.com/t5/network-security/how-often-does-ips-update-on-firepower-devices/m-p/5353917#M1123829</link>
      <description>&lt;P&gt;SI feeds are pushed to the managed devices when they arrive on FMC, there's no deployment required.&lt;/P&gt;
&lt;P&gt;The updates attributed to the system user when you do a deployment are more likely IPS rules that result from FMC having updated the SRU / LSP packages for Snort 2 / 3 respectively.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2025 15:00:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-often-does-ips-update-on-firepower-devices/m-p/5353917#M1123829</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-12-10T15:00:43Z</dc:date>
    </item>
  </channel>
</rss>

