I've seen the thread quite a bit here bit am still struggling. For some reason the SSM module is connected behind another firewall before eventually passing the traffic off to the ASA in-which the IPS module is housed.
I'm not seeing any drops on the 'first' firewall infront of the SSM but I see a reference in the User Guide to requiring a access policy with 2 cisco ip's in.
Currently the policy only has 220.127.116.11 in it.
Are both these ips required for IPS signature updates to succeed?
Also, just to confirm that the default URL is: https://18.104.22.168//cgi-bin/front.x/ida/locator/locator.pl as at 6.1-2(E3)