Scheduled task types
Backup
Purpose: Back up managed devices.
Options:
-
Backup Type: Device
Guidelines and limitations:
-
Supported devices: Some devices, such as devices in the public cloud, cannot be backed up.
-
Simultaneous backups: Back up no more than 20 devices per task. Do not schedule multiple backup tasks for the same time; start with 30 minutes between backups.
-
Bandwidth: If you are transferring backup files, consider scheduling backups during periods of low network use.
Download CRL
Purpose: Download certificate revocation list (CRL) updates. The system automatically schedules daily CRL updates when you configure user or audit log certificates in the system configuration. Use the scheduler to change the update interval or run a one-time update. Disabling the configurations removes the task.
Download latest update
Purpose: Download the latest VDB update. Initial setup schedules a weekly download of the latest applicable updates.
Note | Use to upgrade software. Scheduled software upgrades are not supported, although the web interface allows configuration. |
Options:
-
Update Items: Choose Vulnerability Database.
Guidelines and limitations:
-
Required task order: To update the VDB, download then install. Download must finish before install begins.
-
Bandwidth: Consider scheduling downloads during periods of low network use.
Push latest update
Note | Use to upgrade software. Scheduled software upgrades are not supported, although the web interface allows configuration. |
Install latest update
Purpose: Install a VDB update.
Note | Use to upgrade software. Scheduled software upgrades are not supported, although the web interface allows configuration. |
Options:
-
Update Items: Choose Vulnerability Database.
-
Device: Choose the Cloud-Delivered Firewall Management Center.
Guidelines and limitations:
-
Required task order: To update the VDB, download then install. Download must finish before install begins.
-
Do not perform tasks related to mapped vulnerabilities while the VDB is updating. Even if the Message Center shows no progress for several minutes or indicates that the update has failed, do not restart the update. Instead, contact Cisco TAC.
-
Deploy during a maintenance window to implement changes: Snort typically restarts during the first deployment after VDB update. Restarting the Snort process briefly interrupts traffic flow and inspection on all devices, including devices configured for high availability or clustering.
Queue intrusion policy apply
Purpose: Deploy intrusion policy changes from the Cloud-Delivered Firewall Management Center to managed devices.
Options:
-
Intrusion Policy: The policy you want to deploy.
-
Device: The device where you want to deploy the policy.
Guidelines and limitations:
-
Traffic inspection and flow: When you deploy, resource demands may result in a small number of packets dropping without inspection. Additionally, deploying some configurations restarts the Snort process, which interrupts traffic inspection. Whether traffic drops during this interruption or passes without further inspection depends on how the target device handles traffic. Refer to Snort restart traffic behavior and Configurations that restart the snort process when deployed or activated.
Update URL filtering database
Purpose: Obtain the latest URL filtering data from Cisco. By default, when you enable URL filtering, automatic updates are enabled. However, if you need to control exactly when these updates occur, use the scheduler.
Guidelines and limitations:
-
Licenses: URL Filtering
-
Prerequisite configurations: You must enable URL filtering to schedule this task. Disable automatic updates on .
-
Update size, duration, and bandwidth: Daily updates are typically small. With longer intervals, expect larger downloads and additional time for the changes to propagate, and consider scheduling during periods of low network use.