Manually update the VDB

Perform an on-demand update to keep the VDB current or to install an older VDB.

Before you begin

If you are installing an older VDB, download it manually from https://www.cisco.com/go/firepower-software. Choose any Cloud-Delivered Firewall Management Center model, then open the Coverage and Content Updates page.

Starting with VDB 357, you can install any VDB as far back as the baseline VDB for the Cloud-Delivered Firewall Management Center.

Procedure


Step 1

Choose Administration > Upgrades & updates > Content Updates > VDB Updates.

Step 2

Choose how you want to get the VDB onto the Cloud-Delivered Firewall Management Center.

  • Direct download: Click Download Updates.

  • Manual upload: Click Upload Update, click Choose File, select the VDB, and click Upload.

Step 3

Install the VDB.

  1. Next to the VDB update you want to install, click either the Install icon (for a newer VDB) or the Rollback icon (for an older VDB).

  2. Choose the Cloud-Delivered Firewall Management Center.

  3. Click Install.

Monitor update progress in the Message Center. Do not use mapped-vulnerability features while the VDB is updating. If the Message Center shows no progress for several minutes or reports that the update failed, do not restart it. Contact Cisco TAC.

Step 4

Verify update success.

The current version is displayed on the VDB update page.


The system uses the new vulnerability information. However, you must deploy before updated application detectors and operating system fingerprints can take effect.

What to do next

  • Deploy configuration changes.

  • If configurations reference vulnerabilities, application detectors, or fingerprints that are no longer available, review those configurations to confirm that they handle traffic as expected. A scheduled VDB update can undo a rollback. To retain the older VDB, change the scheduled task or delete any newer VDB packages.