<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower rulee update in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3884825#M922199</link>
    <description>&lt;P&gt;1. SRU and VDB updates are generally independent of your FMC and Firepower versions.&lt;/P&gt;
&lt;P&gt;2. Malware (AMP) license is required only for File policies. They inspect files using cloud-based analysis of a SHA-256 hash of the file. (or AMP private cloud for some customers with that product). It does not affect or interact with the SRU or VDB or entitlement to those.&lt;/P&gt;
&lt;P&gt;SRU and VDB updates do require a current IPS subscription (known as "Threat" for FTD devices) to be entitled to download them (although there's not any technical enforcement of that requirement).&lt;/P&gt;</description>
    <pubDate>Thu, 04 Jul 2019 14:19:27 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2019-07-04T14:19:27Z</dc:date>
    <item>
      <title>Firepower rulee update</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3356446#M922179</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have cisco 5516x with firepower.&lt;/P&gt;
&lt;P&gt;My firepower install at FMC version 5.4.1.&lt;/P&gt;
&lt;P&gt;Below my question.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. what is the best practice to update the rule ( System &amp;gt; Update &amp;gt; Rule Updates&amp;nbsp; ) by weekly basis or monthly ?&lt;/P&gt;
&lt;P&gt;2. Any impact during the rule update?&lt;/P&gt;
&lt;P&gt;3. how rollback in case any issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:34:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3356446#M922179</guid>
      <dc:creator>sahrizal123</dc:creator>
      <dc:date>2020-02-21T15:34:18Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower rulee update</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3356482#M922180</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Its recommended to update the rules weekly basis as they are released to make sure you are covered by latest security update.&lt;/P&gt;
&lt;P&gt;There is no direct impact during the update. Once the update is downloaded, its stored in FMC but not yet applied on sensor/FTD unless you have selected to deploy policy also with auto update.&lt;/P&gt;
&lt;P&gt;Once you deploy the policy again, new updates are installed along with the deployment.&lt;/P&gt;
&lt;P&gt;You can track the changes as well. Check an old forum update (related)&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportforums.cisco.com/t5/firesight-system-3d-system/firesight-rule-update/td-p/2777508" target="_blank"&gt;https://supportforums.cisco.com/t5/firesight-system-3d-system/firesight-rule-update/td-p/2777508&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But there is not official/easy way of rollback. But in case its absolutely required, you can reach out to TAC and it can be done although not recommended.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope it helps,&lt;/P&gt;
&lt;P&gt;Yogesh&lt;/P&gt;</description>
      <pubDate>Wed, 28 Mar 2018 09:00:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3356482#M922180</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2018-03-28T09:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower rulee update</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3356601#M922181</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/130037"&gt;@sahrizal123&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;
&lt;P&gt;My firepower install at FMC version 5.4.1.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;You should really upgrade your Firepower software. Your version is quite old and there are many bug fixes and new features in the 3 major and many minor releases since 5.4.x.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Mar 2018 12:15:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3356601#M922181</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-03-28T12:15:14Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower rulee update</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3357176#M922182</link>
      <description>Thank you Yogesh, noted will update weekly basis.</description>
      <pubDate>Thu, 29 Mar 2018 03:22:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3357176#M922182</guid>
      <dc:creator>sahrizal123</dc:creator>
      <dc:date>2018-03-29T03:22:28Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower rulee update</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3357177#M922183</link>
      <description>Thank you Marvin, we will upgrade after updated the Rule.&lt;BR /&gt;Now pending maintenance window.</description>
      <pubDate>Thu, 29 Mar 2018 03:23:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3357177#M922183</guid>
      <dc:creator>sahrizal123</dc:creator>
      <dc:date>2018-03-29T03:23:18Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower rulee update</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3357186#M922184</link>
      <description>Hi Marvin,&lt;BR /&gt;What is the different between manage device and defence centre.&lt;BR /&gt;As my understanding defence centre is FMC.&lt;BR /&gt;I have read somewhere that FMC and manage device only need one version older.</description>
      <pubDate>Thu, 29 Mar 2018 03:49:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3357186#M922184</guid>
      <dc:creator>sahrizal123</dc:creator>
      <dc:date>2018-03-29T03:49:39Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower rulee update</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3357190#M922185</link>
      <description>Hi Yogesh,&lt;BR /&gt;Should we upgrade VDB version on weekly basis too ?&lt;BR /&gt;Any impact after upgrade VDB version ?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Below is current software :&lt;BR /&gt;&lt;BR /&gt;Model 	Virtual Defense Center 64bit&lt;BR /&gt;Serial Number 	None&lt;BR /&gt;Software Version 	5.4.1 (build 59)&lt;BR /&gt;OS 	Sourcefire Linux OS 5.4.0 (build126)&lt;BR /&gt;Snort Version 	2.9.7 GRE (Build 178)&lt;BR /&gt;Rule Update Version 	2016-12-01-001-vrt&lt;BR /&gt;Rulepack Version 	1812&lt;BR /&gt;Module Pack Version 	2083&lt;BR /&gt;Geolocation Update Version 	None&lt;BR /&gt;VDB Version 	build 211 ( 2014-07-18 02:21:53 )</description>
      <pubDate>Thu, 29 Mar 2018 03:59:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3357190#M922185</guid>
      <dc:creator>sahrizal123</dc:creator>
      <dc:date>2018-03-29T03:59:43Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower rulee update</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3357225#M922186</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You are correct about the naming convention.&lt;/P&gt;
&lt;P&gt;FMC is defence center and managed device could be your SFR module or hardware SFR box also called sensor.&lt;/P&gt;
&lt;P&gt;I would really suggest to update the VDB as well as current VDB is 294.&lt;/P&gt;
&lt;P&gt;VDB is for application awareness and yes as SRU (snort rules) update, you should update the VDB as well.&lt;/P&gt;
&lt;P&gt;Everything else remains same for VDB as well where you need to apply the access control policy first to push the new VDB changes to managed device&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope it helps,&lt;/P&gt;
&lt;P&gt;Yogesh&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 05:58:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3357225#M922186</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2018-03-29T05:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower rulee update</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3357237#M922187</link>
      <description>Hi Yogesh,&lt;BR /&gt;&lt;BR /&gt;Thank you.&lt;BR /&gt;Is this correct ?&lt;BR /&gt;Software Version 	5.4.1 (build 59)  &amp;lt;---  FMC&lt;BR /&gt;OS 	Sourcefire Linux OS 5.4.0 (build126)  &amp;lt;--- Manage device</description>
      <pubDate>Thu, 29 Mar 2018 06:17:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3357237#M922187</guid>
      <dc:creator>sahrizal123</dc:creator>
      <dc:date>2018-03-29T06:17:41Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower rulee update</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3357320#M922188</link>
      <description>&lt;P&gt;Hi Sahrizal,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, that would be correct.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 08:56:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3357320#M922188</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2018-03-29T08:56:08Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower rulee update</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3357389#M922189</link>
      <description>&lt;P&gt;Cisco has a good explanation of the naming as it has changed across the releases since they acquired Sourcefire back in 2013. You can find it here:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/compatibility/firepower-compatibility.html#reference_9C7ED89DF14645BDA166E80F7BDA5FB7" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/compatibility/firepower-compatibility.html#reference_9C7ED89DF14645BDA166E80F7BDA5FB7&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As of release 6.2, Firepower Management Center cannot manage devices running anything prior to 6.1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FMC 6.1 could manage both 5.x and 6.x devices.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2019 14:13:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3357389#M922189</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-07-04T14:13:44Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower rulee update</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3359343#M922190</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;
&lt;P&gt;If we upgrade from 5.4.1 to 6.2.2 , it will not effect the ASA traffic right ? ( currently set to monitor-only )&lt;/P&gt;
&lt;P&gt;It require atleast 4 hour to upgrade to 6.2.2 ?&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Apr 2018 01:20:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3359343#M922190</guid>
      <dc:creator>sahrizal123</dc:creator>
      <dc:date>2018-04-03T01:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower rulee update</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3359505#M922191</link>
      <description>&lt;P&gt;If your ASA Firepower service module is at 5.4.1 and being used in monitor-only mode, then an upgrade (or even uninstall) will not affect traffic through the ASA.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It it would be easier to de-register it from FMC, upgrade FMC to the current 6.2.3 release (that will take several hours by itself) and then re-image the module to 6.2.3, re-register it and re-deploy the policies.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Apr 2018 08:27:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3359505#M922191</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-04-03T08:27:53Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower rulee update</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3359524#M922192</link>
      <description>Thank you Marvin,&lt;BR /&gt;De-register FMC, upgrade FMC and reimage module require to access server or only can be done at GUI ( i done have server access ESXi).&lt;BR /&gt;Kindly advise step to redeploy policy.</description>
      <pubDate>Tue, 03 Apr 2018 08:55:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3359524#M922192</guid>
      <dc:creator>sahrizal123</dc:creator>
      <dc:date>2018-04-03T08:55:12Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower rulee update</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3359692#M922193</link>
      <description>&lt;P&gt;You don't need console (ESXi) access to FMC to upgrade it. You do need to be able to transfer files you have downloaded from cisco.com onto a PC to the server via the web interface.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You do need console (ssh) access to the Firepower (sfr) service module to reimage it. If you upgraded it step-by-step instead you can do it all via the FMC but it will take most of an entire day (assuming it all goes well) vs. about 2 hours to reimage.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I really recommend you read the documentation on the above steps. It's all covered there - upgrading, re-imaging, registering, deploying policy etc. There are many good free presentations available on Cisco Live as well. You should understand the basics before logging into any production system and making significant changes.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Apr 2018 13:37:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3359692#M922193</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-04-03T13:37:46Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower rulee update</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3364926#M922195</link>
      <description>I set rule updates for daily during non-business hours. I have never had a problem.</description>
      <pubDate>Thu, 12 Apr 2018 13:27:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3364926#M922195</guid>
      <dc:creator>Bill CARTER</dc:creator>
      <dc:date>2018-04-12T13:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower rulee update</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3884753#M922197</link>
      <description>&lt;P&gt;I have few questions regarding the SRU &amp;amp; VDB upgrade that would be grateful if someone could help me with:&lt;/P&gt;&lt;P&gt;1- for both SRU&amp;amp; VDB upgrade, doesn't matter what version of FMC/ FIREPOWER&amp;nbsp; we are in:&amp;nbsp;&lt;/P&gt;&lt;P&gt;FMC:&lt;/P&gt;&lt;P&gt;SOFTWARE VERSION: 6.2.3&lt;/P&gt;&lt;P&gt;SNORT VERSION: 2.9.12&lt;/P&gt;&lt;P&gt;VDB VERSION: BUILD 291&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FirePOWER module: 6.2.3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2-Do I need malware license to get the weekly basis updates?&amp;nbsp;&lt;/P&gt;&lt;P&gt;3-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2019 12:33:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3884753#M922197</guid>
      <dc:creator>D@1984</dc:creator>
      <dc:date>2019-07-04T12:33:28Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower rulee update</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3884825#M922199</link>
      <description>&lt;P&gt;1. SRU and VDB updates are generally independent of your FMC and Firepower versions.&lt;/P&gt;
&lt;P&gt;2. Malware (AMP) license is required only for File policies. They inspect files using cloud-based analysis of a SHA-256 hash of the file. (or AMP private cloud for some customers with that product). It does not affect or interact with the SRU or VDB or entitlement to those.&lt;/P&gt;
&lt;P&gt;SRU and VDB updates do require a current IPS subscription (known as "Threat" for FTD devices) to be entitled to download them (although there's not any technical enforcement of that requirement).&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2019 14:19:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3884825#M922199</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-07-04T14:19:27Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower rulee update</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3884856#M922200</link>
      <description>&lt;P&gt;many thanks. How/where FMC get the updates from if I set to have weekly updates automatically?&lt;/P&gt;&lt;P&gt;Just want to make sure there is no firewall, etc in between to block the updates.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2019 15:31:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3884856#M922200</guid>
      <dc:creator>D@1984</dc:creator>
      <dc:date>2019-07-04T15:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower rulee update</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3885013#M922202</link>
      <description>&lt;P&gt;The SRU and VDB updates should be coming from support.sourcefire.com.&lt;/P&gt;
&lt;P&gt;Details and troubleshooting instructions can be found here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118791-technote-firesight-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118791-technote-firesight-00.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jul 2019 02:14:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rulee-update/m-p/3885013#M922202</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-07-05T02:14:13Z</dc:date>
    </item>
  </channel>
</rss>

