Verify Hotfix Applied to Cisco FirePower Threat Defender (FTD) via CLI

Installed firmware hotfix to a Cisco FirePower will not change the display base version in the FirePower Device Manager (FDM).

To verify that the hotfix is applied, it will need to be checked via the CLI which is tracked in the patch history.

Connect to the FirePower using SSH to the IP address of the firewall.

After logging in, run the following commands:

> expert
firewall# cat /etc/sf/patch_history

The hotfix is identified by the version with HK pre-pended.

reference: https://www.cisco.com/c/en/us/support/docs/security/secure-firewall-management-center/226216-clarify-the-fmc-hotfix-version-display.html


Leave a comment