cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5068
Views
0
Helpful
3
Replies

FMC VDB Update

Thomas Yarger
Level 1
Level 1

Hi All, 

 

I have a customer on a very OLD Vulnerability DB version and I'm a bit leery about updating as the customer is very sensitive to outages and demands perfection with any change/update. Are there any gotcha's or caveats I should be aware of before I update the DB? Thanks!

 

Screen Shot 2018-01-09 at 4.16.43 PM.png

 

 

 

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

You definitely want a change control window with scheduled outage.

 

A VDB update restarts Snort when deployed:

 

https://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config-guide-v61/policy_management.html

 

So you will have a few seconds on unavailability for the IPS. Depending on the architecture (fail open etc.), that may result in a brief loss of service.

 

Other than that it should be fine. You can always open a proactive TAC case to be doubly sure.

View solution in original post

3 Replies 3

Marvin Rhoads
Hall of Fame
Hall of Fame

You definitely want a change control window with scheduled outage.

 

A VDB update restarts Snort when deployed:

 

https://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config-guide-v61/policy_management.html

 

So you will have a few seconds on unavailability for the IPS. Depending on the architecture (fail open etc.), that may result in a brief loss of service.

 

Other than that it should be fine. You can always open a proactive TAC case to be doubly sure.

Thanks Marvin!

How did you go with this? Mission success? 

 

Any pre reqs for Snort version etc. 

 

Thanks

Adam

 

Review Cisco Networking products for a $25 gift card