<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS auto-update vs manual download in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-auto-update-vs-manual-download/m-p/1476181#M67151</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Corey;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; You're certainly welcome - always a pleasure to assist!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 25 Jun 2010 15:03:52 GMT</pubDate>
    <dc:creator>Scott Fringer</dc:creator>
    <dc:date>2010-06-25T15:03:52Z</dc:date>
    <item>
      <title>IPS auto-update vs manual download</title>
      <link>https://community.cisco.com/t5/network-security/ips-auto-update-vs-manual-download/m-p/1476172#M67142</link>
      <description>&lt;P&gt;Is there a delay in what's available via auto-update and updates that are available for manual download through cisco.com?&amp;nbsp; I noticed today that S498 became available yesterday, but my IPS module in my ASA hasn't downloaded it automatically yet.&amp;nbsp; When I do a #sh statistics host, I have a recent download attempt that says "Success: No installable auto update package found on server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just wondering if there is a delay between manual and auto updates or if I need to be concerned that my auto-udpates aren't working properly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:02:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-auto-update-vs-manual-download/m-p/1476172#M67142</guid>
      <dc:creator>corey</dc:creator>
      <dc:date>2019-03-10T12:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: IPS auto-update vs manual download</title>
      <link>https://community.cisco.com/t5/network-security/ips-auto-update-vs-manual-download/m-p/1476173#M67143</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There should not be a delay on the availability of the update on the website.&amp;nbsp; When your sensor is scheduled to check may be later than the time it was posted and cause a potential delay.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jun 2010 19:06:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-auto-update-vs-manual-download/m-p/1476173#M67143</guid>
      <dc:creator>Scott Fringer</dc:creator>
      <dc:date>2010-06-23T19:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: IPS auto-update vs manual download</title>
      <link>https://community.cisco.com/t5/network-security/ips-auto-update-vs-manual-download/m-p/1476174#M67144</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe it's checked today - last directory read attempt was today, but I guess the last download attempt was yesterday.&amp;nbsp; What's the difference?&amp;nbsp; And if it is indeed not working, what's the best way to troubleshoot my issue.&amp;nbsp; Here's the pertinent info from my sh statistics host:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Auto Update Statistics&lt;BR /&gt;&amp;nbsp;&amp;nbsp; lastDirectoryReadAttempt = 18:24:12 UTC Wed Jun 23 2010&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; =&amp;nbsp;&amp;nbsp; Read directory: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://198.133.219.25//cgi-bin/front.x/ida/locator/locator.pl"&gt;https://198.133.219.25//cgi-bin/front.x/ida/locator/locator.pl&lt;/A&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; =&amp;nbsp;&amp;nbsp; Success: No installable auto update package found on server&lt;BR /&gt;&amp;nbsp;&amp;nbsp; lastDownloadAttempt = 19:44:09 UTC Tue Jun 22 2010&lt;BR /&gt;&amp;nbsp;&amp;nbsp; lastInstallAttempt = 19:45:05 UTC Tue Jun 22 2010&lt;BR /&gt;&amp;nbsp;&amp;nbsp; nextAttempt = 19:24:00 UTC Wed Jun 23 2010&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jun 2010 19:10:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-auto-update-vs-manual-download/m-p/1476174#M67144</guid>
      <dc:creator>corey</dc:creator>
      <dc:date>2010-06-23T19:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: IPS auto-update vs manual download</title>
      <link>https://community.cisco.com/t5/network-security/ips-auto-update-vs-manual-download/m-p/1476175#M67145</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The "lastDirectoryReadAttempt" is when the last check occurred (should match your scheduled timing).&amp;nbsp; If the status is that there is no available update, that is as far as the process goes.&amp;nbsp; If an update is available, the sensor should attempt to download.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The "lastDownloadAttempt" will indicate the last time an update download was found and the download was attempted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The "lastInstallAttempt" will indicate the last time an update was downloaded and install initiated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It does look like it checked at a point today and did not find an available update.&amp;nbsp; That your outputs are UTC, I cannot correlate when the check today was run in relation to the publishing of the latest update.&amp;nbsp; It may be that there is a cache engine between your sensor and Cisco, and it is indicating that there is nothing available.&amp;nbsp; I would give the process another 24 hours to update.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jun 2010 20:48:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-auto-update-vs-manual-download/m-p/1476175#M67145</guid>
      <dc:creator>Scott Fringer</dc:creator>
      <dc:date>2010-06-23T20:48:54Z</dc:date>
    </item>
    <item>
      <title>Re: IPS auto-update vs manual download</title>
      <link>https://community.cisco.com/t5/network-security/ips-auto-update-vs-manual-download/m-p/1476176#M67146</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I may have a larger issue.&amp;nbsp; According to IDM, my CPU has been sitting at 100% for the last few days and the Analysis Engine Status has been sitting on "Processing Transaction" the whole tim as well.&amp;nbsp; I'm wondering if it might have had an issue trying to apply it's sig update.&amp;nbsp; Is there a way to kick the process in the pants and get it moving again?&amp;nbsp; Should I reboot the module?&amp;nbsp; The sensor is still picking up events.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jun 2010 20:11:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-auto-update-vs-manual-download/m-p/1476176#M67146</guid>
      <dc:creator>corey</dc:creator>
      <dc:date>2010-06-24T20:11:30Z</dc:date>
    </item>
    <item>
      <title>Re: IPS auto-update vs manual download</title>
      <link>https://community.cisco.com/t5/network-security/ips-auto-update-vs-manual-download/m-p/1476177#M67147</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Corey;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; It sounds like you are encountering bug CSCsq53214.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsq53214"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsq53214&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; The fix is, as you asked, to reboot the module.&amp;nbsp; You should be able to confirm current signature update from the output of 'sh ver' issued on the CLI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jun 2010 10:52:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-auto-update-vs-manual-download/m-p/1476177#M67147</guid>
      <dc:creator>Scott Fringer</dc:creator>
      <dc:date>2010-06-25T10:52:02Z</dc:date>
    </item>
    <item>
      <title>Re: IPS auto-update vs manual download</title>
      <link>https://community.cisco.com/t5/network-security/ips-auto-update-vs-manual-download/m-p/1476178#M67148</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think you're right, Scott.&amp;nbsp; One final question - rebooting the module does not affect the ASA, right? (I can reboot it without affecting my users, right?)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jun 2010 14:50:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-auto-update-vs-manual-download/m-p/1476178#M67148</guid>
      <dc:creator>corey</dc:creator>
      <dc:date>2010-06-25T14:50:22Z</dc:date>
    </item>
    <item>
      <title>Re: IPS auto-update vs manual download</title>
      <link>https://community.cisco.com/t5/network-security/ips-auto-update-vs-manual-download/m-p/1476179#M67149</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Corey;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; It is possible to reboot the AIP-SSM without impacting user traffic.&amp;nbsp; There are some things to check:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- mode of operation:&lt;/P&gt;&lt;P&gt;&amp;nbsp; - fail-open will allow traffic to traverse the ASA while the AIP-SSM is rebooting&lt;/P&gt;&lt;P&gt;&amp;nbsp; - fail-close will dstop traffic from traversing the ASA while the AIP-SSM is rebooting&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- presence of failover for the ASA&lt;/P&gt;&lt;P&gt;&amp;nbsp; - if no failover configured, you should encounter no issue&lt;/P&gt;&lt;P&gt;&amp;nbsp; - if you are operating in active/standby failover, a failover will occur&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - you can overcome this by removing the service policy for IPS inspection prior to the reboot of the AIP-SSM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jun 2010 14:54:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-auto-update-vs-manual-download/m-p/1476179#M67149</guid>
      <dc:creator>Scott Fringer</dc:creator>
      <dc:date>2010-06-25T14:54:31Z</dc:date>
    </item>
    <item>
      <title>Re: IPS auto-update vs manual download</title>
      <link>https://community.cisco.com/t5/network-security/ips-auto-update-vs-manual-download/m-p/1476180#M67150</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for all your replies!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jun 2010 14:56:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-auto-update-vs-manual-download/m-p/1476180#M67150</guid>
      <dc:creator>corey</dc:creator>
      <dc:date>2010-06-25T14:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: IPS auto-update vs manual download</title>
      <link>https://community.cisco.com/t5/network-security/ips-auto-update-vs-manual-download/m-p/1476181#M67151</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Corey;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; You're certainly welcome - always a pleasure to assist!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jun 2010 15:03:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-auto-update-vs-manual-download/m-p/1476181#M67151</guid>
      <dc:creator>Scott Fringer</dc:creator>
      <dc:date>2010-06-25T15:03:52Z</dc:date>
    </item>
  </channel>
</rss>

