Cisco Cisco Firepower Management Center 4000

Page of 1844
 
42-16
FireSIGHT System User Guide
 
Chapter 42      Enhancing Network Discovery 
  Using Custom Fingerprinting
If a fingerprint is inactive, you can modify all elements of the fingerprint and resubmit it to the Defense 
Center. This includes all properties you specified when creating the fingerprint, such as fingerprint type, 
target IP addresses and ports, vulnerability mappings, and so on. When you edit an inactive fingerprint 
and submit it, it is resubmitted to the system and, if it is a client fingerprint, you must resend traffic to 
the appliance before activating it. Note that you can select only a single vulnerability mapping for an 
inactive fingerprint. After you activate the fingerprint, you can map additional operating systems and 
versions to its vulnerabilities list.
If a fingerprint is active, you can modify the fingerprint name, description, custom operating system 
display, and map additional vulnerabilities to it. 
For more information, see the following sections:
  •
  •
Editing an Inactive Fingerprint
License: 
FireSIGHT
If a fingerprint is inactive, you can modify its properties and resubmit it to the system. This includes 
making changes such as the type of fingerprint to use, the target system to fingerprint, and so on. 
To edit inactive fingerprints:
Access: 
Admin/Discovery Admin
Step 1
Select 
Policies 
Network Discovery
, then click 
Custom Operating Systems
.
The Custom Fingerprint page appears.
Step 2
Click the edit icon (
) next to the fingerprint you want to edit.
The Edit Custom Fingerprint page appears.
Step 3
Make changes to the fingerprint as necessary:
  •
If you are modifying a client fingerprint, see 
 for more information 
about the options you can configure.
  •
If you are modifying a server fingerprint, see 
information about the options you can configure.
Step 4
Click 
Save
 to resubmit the fingerprint.
Note
If you modified a client fingerprint, remember to send traffic from the host to the appliance 
gathering the fingerprint.
Editing an Active Fingerprint
License: 
FireSIGHT
When a fingerprint is active, you can change its name, description, and display label. In addition, you 
can manage vulnerability mappings, including adding and deleting vulnerability mappings.