Cisco iconCiscoSep 30, 2026 ~7 min source read

When security moves at machine speed, campus networks can’t afford to stop

Cisco outlines an operating model that reduces exposure immediately and preserves uptime while making controlled software updates, using Live Protect for temporary runtime shields and xFSU to minimize upgrade disruption.

When security moves at machine speed, campus networks can’t afford to stop

Share this story

Send the public story page.

Useful takeaways from this story.

Live Protect provides validated, temporary runtime shields that reduce exposure to specific vulnerabilities without requiring an immediate reboot or full upgrade.

Both approaches require platform, release, and policy eligibility checks and are not universal replacements for permanent fixes.

Campus networks now carry higher-stakes traffic—clinical devices, industrial robots, point-of-sale systems, research workloads, and persistent AI agents. Attackers increasingly use AI-assisted tools to find and weaponize vulnerabilities faster than traditional, human-paced operational models can respond. The result: security teams need faster containment techniques that don't take the network offline.

Practical workflow for Live Protect

  • Start with an advisory that identifies exposure and the fixed software path.
  • Use a validated Live Protect shield when the platform, release, policy, and mode are supported.
  • Monitor the shield to see whether matching events occur before enforcement.
  • Enforce the shield to block or mitigate the exploit path in real time.
  • Disable or retire the shield after the permanent software fix is applied.
  • Immediate exposure reduction without forcing emergency upgrades or reboots.
  • A reversible, targeted control for specific vulnerability conditions.

Extended Fast Software Upgrade addresses the operational costs and availability risks of full software image upgrades—particularly for access-layer switches that lack redundant forwarding paths per endpoint.

  • It separates control plane and data plane operations during the upgrade.
  • The control plane restarts on the new software while the data plane continues forwarding using previously programmed hardware state.
  • The data plane is then updated in a short, targeted window and resumes forwarding using preserved forwarding state.
  • On switch stacks, the process is staggered across members and uses stateful switchover to preserve continuity.
  • Operators must run eligibility checks and meet platform and software prerequisites.
  • Security and networking teams gain a staged operating model: detect and advise, temporarily shield, monitor and enforce, then perform a controlled permanent upgrade.
  • Upgrades become more predictable and repeatable, reducing reliance on risky, overnight "heroic" change windows.
  • Infrastructure becomes both a dependent system to patch and an active protection point where targeted mitigations can run in production.
  • Inventory devices and map which platforms and releases are eligible for Live Protect and xFSU.
  • Integrate advisory monitoring with procedures to request and apply Live Protect shields when available.
  • Validate prerequisites and run eligibility checks before planning xFSU upgrades.
  • Schedule permanent software maintenance upgrades after temporary mitigation, and retire shields once the update is applied.

Live Protect and xFSU aim to reduce exposure and maintain connectivity while giving teams a controlled path to permanent remediation. Both are operational tools that require specific platform support and careful planning, but together they change how campus networks respond to faster, AI-accelerated threats.

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app