12-14-2021 01:00 AM
Query regarding Vulnerability in Apache Log4j Library Affecting Cisco Products: December 2021
As per the above critical advisory, I was looking at new Intrusion rule in the older FMC that we have (running version 6.1.0.5) and noticed that download of the new rules have been failing due to certificate issue.
“Download updates failed: Peer certificate cannot be authenticated with known CA certificates”
Is it possible to download the specific new rules manually, if so how?
If this is not possible, I’ve found that upgrading the FMC to 6.2.0 fixes the certificate issue affecting download from FMC.
In order to upgrade from 6.1.0.5 to 6.2.0, can I double check that:
We are looking to replace this ASA to FPR2140 which is managed on the newer build FMC so want to spend as little time and effort as possible.
Please advise.
Many thanks,
Solved! Go to Solution.
12-14-2021 05:14 AM
So updating to the latest Intrusion rules has worked and I can see the Log4j drop rules are in the policy.
12-14-2021 01:07 AM - edited 12-14-2021 01:13 AM
Ah, I'm guessing 'Update Intrusion Rules' is the bit I need to understand
12-14-2021 05:14 AM
So updating to the latest Intrusion rules has worked and I can see the Log4j drop rules are in the policy.
12-15-2021 03:21 PM
hey mate
How do you see the events for those "Log4j" logs?
12-17-2021 03:16 AM
hi @Heino Human
This might be of your interest:
https://blogs.cisco.com/security/protecting-against-log4j-with-secure-firewall-secure-ips
12-14-2021 07:21 AM
6.1.0.5 to 6.2.0 is a direct upgrade that is supported:
FMC 6.2.0 cannot manage an ASA Firepower service module running 6.0.1.4.
12-17-2021 03:13 AM
Thank you @Marvin Rhoads Not sure how I missed that 6.2.0 is not compatible with 6.0.1.4!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide