Our Cisco Firepower Management Centre (FMC) 2000 appliances (Cisco Part Number: FS2000-K9) running 6.1.0.3 (Patch 57) software have a scheduled job configured to keep Geolocation Updates up to date. The job is scheduled to run weekly on Mondays at 6am.
However, the problem we have discovered is that when the scheduled job runs the latest Geolocation update is not downloaded and installed.
From the investigation conducted so far, we suspect that this is due to a issue whereby the Firepower Management Centre appliance is reporting that the "Latest" version of Geolocation Update is the same as the "Current" version as shown in screenshot extract attached where both "Current" and "Latest" versions of Geolocation Update are reported as "2017-12-04-002" (4th December 2017).
This incorrect info is also being reported at the CLI - as shown in log extract below captured from the FMC appliance today:
Jan 08 2018 08:30:15 XXXXXXFSA01 , new version 2017-12-04-002
Jan 08 2018 08:30:15 XXXXXXFSA01 SF-IMS[20524]: [25035] SFDataCorrelator:GeoLocation [INFO] current version 2017-12-04-002
The latest Geolocation released by Cisco is actually update "2018-01-02-002" which Cisco released on 2nd January 2018.
- Note: This problem with failure to update to the latest Geolocation update version only occurs with scheduled Geolocation updates - i.e. One-Time Geolocation Updates run manually download and installed fine with the result of bringing the FMC appliances are brought up to date with the latest version of Geolocation update released by Cisco - which is our current workaround to the problem.