Cisco Cisco Firepower Management Center 4000

Page of 1844
 
53-18
FireSIGHT System User Guide
 
Chapter 53      Updating System Software 
  Importing Rule Updates and Local Rule Files
Using Recurring Rule Updates
License: 
Any
You can import rule updates on a daily, weekly, or monthly basis, using the Rule Updates page. If your 
FireSIGHT Systemdeployment includes two Defense Centers configured as a high availability pair, you 
only need to update rules on one of the Defense Centers. The second Defense Center receives the rule 
update as part of the regular synchronization process.
To schedule recurring rule updates:
Access: 
Admin
Step 1
Select 
System > Updates
, then select the 
Rule Updates
 tab.
The Rule Updates page appears.
Tip
You can also click 
Import Rules
 on the Rule Editor page, which you access by selecting 
Policies > Intrusion 
> Rule Editor
.
Step 2
Optionally, click 
Delete All Local Rules
, then click 
OK
 to move all user-defined rules that you have created 
or imported to the deleted folder. See 
 for more information.
Step 3
Select 
Enable Recurring Rule Update Imports
.
The page expands to display options for configuring recurring imports.
Import status messages appear beneath the 
Recurring Rule Update Imports
 section heading. Recurring 
imports are enabled when you save your settings.
Tip
To disable recurring imports, clear the 
Enable Recurring Rule Update Imports
 check box and click 
Save
.
Step 4
In the 
Import Frequency
 field, select 
Daily
Weekly
, or 
Monthly
 from the drop-down list.
Tip
You can select from a recurring task drop-down list either by clicking on your selection or by typing the 
first letter or number in the selection one or more times and pressing Enter.
Step 5
If you selected 
Weekly
 in the 
Import Frequency
 field, use the drop-down list that appears to select the day 
of the week when you want to import rule updates.
Step 6
If you selected 
Monthly
 in the 
Import Frequency
 field, use the drop-down list that appears to select the day 
of the month when you want to import rule updates.
Step 7
In the 
Import Frequency
 field, specify the time when you want to start your recurring rule update import.
Step 8
Optionally, select 
Reapply intrusion policies after the Rule Update import completes
 to automatically reapply 
intrusion policies currently applied from this appliance when the rule update import completes.
Note that you cannot apply intrusion policies to stacked devices that are running different versions of 
the FireSIGHT System (for example, if an upgrade on one of the devices fails). See 
 for more information.
Step 9
Click 
Save
 to enable recurring rule update imports using your settings.
The status message under the Recurring Rule Update Imports section heading changes to indicate that 
the rule update has not yet run.