Cisco Cisco Firepower Management Center 4000
5-9
FireSIGHT System User Guide
Chapter 5 Managing Reusable Objects
Working with Security Intelligence Lists and Feeds
To configure a Security Intelligence feed:
Access:
Admin/Intrusion Admin
Step 1
On the object manager’s Security Intelligence page, click
Add Security Intelligence
.
The Security Intelligence pop-up window appears.
Step 2
Type a
Name
for the feed. You can use any printable standard ASCII characters except curly braces (
{}
).
Step 3
From the
Type
drop-down list, specify that you want to configure a
Feed
.
The pop-up window updates with new options.
Step 4
Specify a
Feed URL
and optionally, an
MD5 URL
.
Step 5
Select an
Update Frequency
.
You can select from various intervals from two hours to one week. You can also disable feed updates.
Step 6
Click
Save
.
The Security Intelligence feed object is created. Unless you disabled feed updates, the Defense Center
attempts to download and verify the feed. You can now use the feed object in access control policies.
attempts to download and verify the feed. You can now use the feed object in access control policies.
Manually Updating Security Intelligence Feeds
License:
Protection
Supported Devices:
Series 3, Virtual, X-Series, ASA FirePOWER
Supported Defense Centers:
Any except DC500
Manually updating Security Intelligence feeds updates all feeds, including the Intelligence Feed.
To update all Security Intelligence feeds:
Access:
Admin/Access Admin/Network Admin
Step 1
On the object manager’s Security Intelligence page, click
Update Feeds
.
Step 2
Confirm that you want to update all feeds.
A confirmation dialog appears, warning you that it can take several minutes for the update to take effect.
Step 3
Click
OK
.
After the Defense Center downloads and verifies the feed updates, it communicates any changes to its
managed devices. Your deployment begins filtering traffic using the updated feeds.
managed devices. Your deployment begins filtering traffic using the updated feeds.
Working with Custom Security Intelligence Lists
License:
Protection
Supported Devices:
Series 3, Virtual, X-Series, ASA FirePOWER
Supported Defense Centers:
Any except DC500