cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2057
Views
10
Helpful
9
Replies

FMC connecting to amazon

Hello, 

 

I have a client reporting that the FMC is connecting the last couple of days to some IP ( i.e. 34.246.67.169)  through https and maybe it is downloading. It is strange because it is something new and the bandwidth is consumed, foe ten or so minutes.

He tracked the IP to Amazon Europe. 

 

I would like to ask if there is any communication between the FMC and Amazon. 

How could I track this connection that concerns only the FMC?

 

Regards, 

Konstantinos

2 Accepted Solutions

Accepted Solutions

balaji.bandi
Hall of Fame
Hall of Fame

FMC download updates from Cisco update server, need to check is this hosted on Amazon

As per my knowledge the IP belong to **.brightcloud.com)  this is for webroot updates i guess.

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

View solution in original post

Marvin Rhoads
Hall of Fame
Hall of Fame

As @balaji.bandi noted, the Amazon address is one location where the Brightcloud server (database.brightcloud.com - source for FMC's URL updates) is hosted.

We can see this in the following screen taken from Cisco Umbrella Investigate:

Umbrella Lookup.PNG

View solution in original post

9 Replies 9

balaji.bandi
Hall of Fame
Hall of Fame

FMC download updates from Cisco update server, need to check is this hosted on Amazon

As per my knowledge the IP belong to **.brightcloud.com)  this is for webroot updates i guess.

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hello Balaji, 

 

Yes, I agree that this traffic could be updates from Cisco, but why they take up all the bandwidth?

 

I saw too about brightcloud, but how could I check if cisco is hosted in amazon?

 

Also, this is the DR where the IPS does not work yet.

 

Regards, 

Konstantinos

Marvin Rhoads
Hall of Fame
Hall of Fame

As @balaji.bandi noted, the Amazon address is one location where the Brightcloud server (database.brightcloud.com - source for FMC's URL updates) is hosted.

We can see this in the following screen taken from Cisco Umbrella Investigate:

Umbrella Lookup.PNG

Hello Marvin, 

 

Ok so the FMC tries to download updates for its URL database. 

Why do you think it consumes all the bandwidth?

 

Regards, 

Konstantinos

what kind of bandwidth consumption we are talking ? its general incremental updates it will pull from that servers.

 

until you have initiated other software upgrades.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

It is taking up all the line. 

Well it must be a provider issue, as it seems. There were problems so it timed out, that's why it kept retrying to download. 

 

Thank you for your help

 

Regards, 

Konstantinos

Hope you sorted the issue with provider by now. (on the side note  more interested all line speed ? what speed it is ?)

 

if this is resolved marked as resolved so others can refer this as solution.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hello, 

 

It was about 14 Mbps

 

Regards, 

Konstantinos

14MBps is small amount for internet in this era, if that is the case you an shedule for non-peak hours to get updates.(this is not recommended, since you miss real time any zero attack scenarios)

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card