Vulnerability database (VDB) updates
The VDB is a database of known vulnerabilities to which hosts may be susceptible, as well as fingerprints for operating systems, clients, and applications. The system uses the VDB to help determine whether a particular host increases your risk of compromise.
VDB versions
We periodically release VDB updates. Each update replaces the previous version.
Starting with VDB 357, you can install an earlier VDB as far back as the baseline VDB for Cloud-Delivered Firewall Management Center.
VDB update duration
The time required to update the VDB and its associated mappings on the Cloud-Delivered Firewall Management Center depends on the number of hosts in your network map. Allow approximately one minute for every 1000 hosts.
Scheduled VDB updates
Initial configuration automatically downloads and installs the latest VDB as a one-time operation and creates a weekly task to download future updates. Review the schedule and adjust as needed. To update the VDB and deploy configurations automatically, create separate tasks. For more information, refer to Scheduling.
Deployment after VDB updates
Deploy configuration changes after a VDB update for updated application detectors and operating system fingerprints to take effect. Updated vulnerability information takes effect without deploy.
Caution | The first deploy after a VDB update usually restarts Snort because updated application detectors and operating system fingerprints require a restart. Restarting Snort briefly interrupts traffic flow and inspection on all devices, including those configured for high availability or scalability. Interface configurations determine whether traffic drops or passes without inspection during the interruption. When you deploy without restarting Snort, resource demands may result in a small number of packets dropping without inspection. |
VDB release information
For VDB 343 and later, Cisco Secure Firewall Application Detectors provides searchable application detector information. The release notes describe changes in each VDB release.
VDB lite
For the Secure Firewall 220, the system installs a smaller VDB (also called VDB lite). This smaller VDB contains the same applications, but fewer detection patterns. Devices using the smaller VDB can miss some application identification versus devices using the full VDB.