cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1533
Views
0
Helpful
1
Replies

CSM 4.17 GeoIP Update

patoberli
VIP Alumni
VIP Alumni

Hello All

 

CSMs GeoIP Database wasn't updated since last year:

https://software.cisco.com/download/home/286321073/type/284963388/release/2018.12.26

Also when checking under Tools -> IP Intelligence Settings there is no update since a while.

 

The manual states they are updated monthly:

https://www.cisco.com/c/en/us/td/docs/security/security_management/cisco_security_manager/security_manager/417/user/guide/CSMUserGuide/syspage.html#33764

GeoIP Maxmind Database Update Settings 
MaxMind GeoLite City update packages are updated monthly on Cisco.com. Use the GeoIP Maxmind Database Update Settings to download an update package automatically from Cisco.com and to configure scheduled updates.

In any case, my problem is that the CSM generated Reports for top hits are not anymore showing from which countries the hits/attacks were from, because the database is older than 90 days (can those 90 days be somewhere customized?). 

 

Also the automatic scheduler to update them has probably never worked since I use a 4.x version. Yes, I have accepted all certificates, EULAs and so on. Disabled and enabled the updates and nothing. 

 

Thanks

Patrick

1 Reply 1

patoberli
VIP Alumni
VIP Alumni
Found the reason and it doesn't make me happy...
Release notes 4.19 state:
GeoIP Lookup Service has upgraded their database to GeoIP2, and Cisco Security Manager 4.19 is yet to be upgraded. Hence, the auto update of GeoIP and the default GeoIP packages will only have the database of December 2018.
Source: https://www.cisco.com/c/en/us/td/docs/security/security_management/cisco_security_manager/security_manager/419/release/notes/csmrn419.html
Review Cisco Networking for a $25 gift card