cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5527
Views
1
Helpful
3
Replies

FMC VDB Update

Thomas Yarger
Level 1
Level 1

Hi All, 

 

I have a customer on a very OLD Vulnerability DB version and I'm a bit leery about updating as the customer is very sensitive to outages and demands perfection with any change/update. Are there any gotcha's or caveats I should be aware of before I update the DB? Thanks!

 

Screen Shot 2018-01-09 at 4.16.43 PM.png

 

 

 

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

You definitely want a change control window with scheduled outage.

 

A VDB update restarts Snort when deployed:

 

https://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config-guide-v61/policy_management.html

 

So you will have a few seconds on unavailability for the IPS. Depending on the architecture (fail open etc.), that may result in a brief loss of service.

 

Other than that it should be fine. You can always open a proactive TAC case to be doubly sure.

View solution in original post

3 Replies 3

Marvin Rhoads
Hall of Fame
Hall of Fame

You definitely want a change control window with scheduled outage.

 

A VDB update restarts Snort when deployed:

 

https://www.cisco.com/c/en/us/td/docs/security/firepower/610/configuration/guide/fpmc-config-guide-v61/policy_management.html

 

So you will have a few seconds on unavailability for the IPS. Depending on the architecture (fail open etc.), that may result in a brief loss of service.

 

Other than that it should be fine. You can always open a proactive TAC case to be doubly sure.

Thanks Marvin!

How did you go with this? Mission success? 

 

Any pre reqs for Snort version etc. 

 

Thanks

Adam

 

Review Cisco Networking for a $25 gift card