Cisco Cisco Firepower Management Center 2000 Fehlerbehebungsanleitung

Seite von 4
Automatic Download Update Failure on a
FireSIGHT Management Center
Document ID: 118791
Contributed by Nazmul Rajib, Cisco Engineering.
Jan 06, 2016
Contents
Introduction
Possible Reasons for Failure
Impact
Verification
     Verify the DNS Settings
     Verify the Connection
Troubleshooting
Related Documents
Introduction
You can update a Cisco FireSIGHT Management Center manually or automatically. In order to perform an
automatic software update, you can create a schedule task on your Management Center to run at a future time.
In some cases, a scheduled task to update a FireSIGHT Management Center with latest software release may
fail. This document discusses this issue and provides recommendation.
Possible Reasons for Failure
A FireSIGHT Management Center may fail to download an update file from the Cisco Download Update
Infrastructure, when one of the following occurs in your network:
Security policy of your company blocks DNS traffic.
• 
Configuration outside of your Management Center impacts download. For example, a firewall rule
may allow only one IP address for 
support.sourcefire.com
.
• 
Caution
: Cisco utilizes round robin DNS for load balancing, fault-tolerance, and uptime. Therefore, the IP
Addresses of DNS servers may change.
Impact
If You Use the Following Method...
Action Item
System default configuration for automatic download
No action required
Download the update files manually and upload it to FireSIGHT Management
Center
No action required
Firewall rules to filter access to the Cisco managed Download Update Infrastructure Follow the solution
Failures are partially mitigated by the three retries and the next scheduled run. Repeated failures are
likely an indication of an external factor such as firewalls or an outage with the Infrastructure.
• 
As the round robin DNS is on the domain name, you need to take steps to ensure that there is no
•