05-28-2014 04:15 AM
Im still having issues with auto upgrading for anti virus and anti spam. The feature keys are within date and do not expire until next year.
Aware Cisco had issues with updating via their end and this has been resolved but I still need to perform forced updates for anti spam and anti virus.
Automatic updates is enabled.
CISCO - has this been resolved completely?
Security Services - Service Updates
Update Server (images): | Dynamic (Cisco IronPort Update Server) |
---|---|
Update Server (list): | Dynamic (Cisco IronPort Update Server) |
Automatic Updates: | Enabled |
Update Interval: | 5m |
Interface: | |
HTTP Proxy Server: | Not Enabled |
HTTPS Proxy Server: | Not Enabled |
05-28-2014 07:58 PM
What version of AsyncOS are you running? This would be on your ESA appliances, correct? Also - have you tried using the downloads-static URLs? This may help to resolve any firewall/routing issues that may be affecting local sites...
https://ironport.custhelp.com/app/answers/detail/a_id/994/kw/static
As of June 28th, 2013: downloads-static.ironport.com will have IPv4 address 208.90.58.105
Cisco offers static servers for those sites that have strict firewall requirements.
Hostnames, IPs, and Ports involved (Please Note that all the information below are needed in the firewalls, if you configure the update and upgrade using static method):
downloads-static.ironport.com: 208.90.58.105 on port 80
update-manifests.ironport.com: 208.90.58.5 on port 443
updates-static.ironport.com: 208.90.58.25 on port 80
Changing the Upgrade and Update Settings on AsyncOS:
1. Start on the Service Updates page of the Security Services page.
2. Click Edit Update Settings....
3. In the 'Update Servers (images)' section select Local Update Servers.
4. For 'Base Url (all services except McAfee Anti-Virus definitions and IronPort AsyncOS upgrades)' enter: http://downloads-static.ironport.com. Set "Port' to 80. Authentication settings should be left blank.
5. For 'Host (McAfee Anti-Virus definitions, PXE Engine updates, IronPort AsyncOS upgrades)' enter: updates-static.ironport.com.
6. Leave the section labeled 'Update Servers (list)' set to IronPort Update Servers.
7. Fill in Proxy Servers settings if appropriate.
8. Click Submit.
9. Click Commit Changes.
10. Confirm by clicking Commit Changes again.
Testing
You can test if the upgrades are working by going to the System Upgrade page and clicking on Available Upgrades. If the list of available versions displays, then your setup is complete. To verify updates are working, you can use the CLI command 'tail' to look at the appropriate log for errors. For Sophos updates, monitor the antivirus log. For McAfee, watch the updater_logs. For CASE updates used by IPAS and VOF, look at the antispam log. The system will also send alerts when updates fail.
I hope this helps!
-Robert
(*If you have received the answer to your original question, and found this helpful/correct - please mark the question as answered, and be sure to leave a rating to reflect!)
03-21-2018 06:18 AM
Following this thread, is there a static download URL for Intelligent-Multiscan engine? I know it goes out to cloudmark for updates using CDN and configuring that on a firewall makes it quite difficult.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide