How Are Deep Inspection Signature Updates Managed by NSM?
NSM Deep Inspection
There are two processes involved in DI signature updates:
Sig-pack
NetScreen devices with DI enabled download a sig-pack (binary file) directly from either a NetScreen update site or a user-defined central server. This update is performed at defined intervals, or when manually triggered by the user. NSM can configure the source URL and download intervals on the devices it manages. In addition, there is a feature in NSM (Devices | Update Attack Database) that can be used to trigger an update on one device, a select group of devices, or all devices.
Signature Update
To effectively configure DI policies, NSM also receives a copy of the attack database. The signature update file (ASCII/NML file) can be downloaded at any time from a user-defined URL, or manually loaded from a file. This signature update file is also used to provide a description of the DI alerts in NSM's Log Viewer.