Amaranten Firewall Changes from v8.40.04 to v8.50.00

Release date: 2004-12-20 [ISO]

Version 8.50.00 contains a number of major changes, and also a number of gotcha's. The most notable changes and gotcha's are highlighted here:

 

» 

Dynamic routing introduced: OSPF and route failover. This carries with it a number of changes, such as Security/Transport equivalent interface groups, which are necessary in order for connections to be able to move from one interface to another.

 

 

» 

Single-admin Virtual System/Router support enables the creation of logical units with separate routing tables and, to some extent, rulesets, under the same administrative scope.

 

 

» 

PPTP and L2TP clients and servers.

 

 

» 

H.323 Application Layer Gateway implemented.

 

 

» 

Gotcha: Order of rule lookups changed. Policy-based routing rules are now consulted before other rulesets. As a result, destination interface filtering is now done according to the PBR table in use. Also, Proxy ARP will now obey PBR.

 

 

» 

Gotcha: The "Secure" rule flag was removed. Changes brought on by dynamic routing meant that the "Secure" rule flag, which forces traffic through a matching IPsec tunnel, had to be removed. As of v8.20.00, the (better) alternative is to simply route traffic over IPsec tunnels.

 

 

» 

Gotcha: Given that the number of PBR routing tables equal the number of Virtual Systems / Routers supported, the number of PBR tables allowed is now controlled by the license. Most licenses allow 5 routing tables, though some of the larger appliance models allow more than that by default. Support for additional Virtual Systems may be purchased as add-ons to your existing license.

 

 

» 

Gotcha: HA: Upgrading directly to v8.50.00 from versions prior to v8.40.01 will lead to loss of state synchronization.

 

 

» 

New "miniature" firewall core in distribution. The two core flavors distributed are now: a "-full" version, with all functionality in it, and the new "-mini" version, with a number of disk-space-consuming options removed.

 

 

» 

Amaranten Firewall Logger for Linux is now included in the distribution.

 

Contents of this document

Version 8.50.00 contains bug fixes to the Firewall Core and the Firewall Manager. This document outlines bug fixes as well as improvements for each component.

The upgrade procedures in this document refers to upgrades from earlier v8.0x installations.

·  Files installed by v8.50.00

·  How to upgrade earlier v8.0x firewalls to v8.50.00

·  HA upgrade procedure

·  Firewall Manager

[Changes

[Bug Fixes

[Known Problems / Bugs]

·  Firewall Core

[Changes]

[Bug Fixes]

[Known Problems / Bugs

For future reference: This document is stored in the "Docs" sub-folder of your Firewall Manager install folder.

Change logs / release notes for earlier versions of Amaranten Firewall are available in the release notes section of www.Amaranten.com/support.

 

 

 Summary of changes and bug fixes

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Firewall Manager

  Change: 

Namespace "firewall core version" logic changed

  Change: 

Network objects and services are no longer rearranged

  Change: 

Service groups may now be members of service groups

  Bug fix: 

Log analyzer would show broken ethernet headers for non-ethernet packets

  Bug fix: 

Firewalls set as DNS names could not revert back to numeric IP address

Firewall Core

  Change: 

H.323 Application Layer Gateway implemented

  Change: 

PPTP and L2TP clients and servers implemented

  Change: 

IPsec: The "Secure" rule flag was removed

  Change: 

Local user database added

  Change: 

PPP: IP addresses and remote networks may now be configured per user

  Change: 

Hosts and ranges may now be excluded from network objects

  Change: 

IPsec: Transport mode may now be selected per tunnel

  Change: 

"All-to-One" mappings for SAT rules rewriting the destination

  Change: 

Allow two windows machines to ping each other simultaneously

  Change: 

PPPoE client can now request a "preferred IP" from server

  Change: 

IPsec: The "ikesnoop" command can now filter IP addresses

  Change: 

Buffered log sending implemented

  Change: 

DHCP Server: "next server" field now configurable

  Change: 

FTP ALG: List of known and disallowed commands updated

  Change: 

IPsec: XAuth client support added

  Change: 

IPsec: Full draft-beaulieu-ike-xauth-02 support

  Change: 

DHCP Relayer and Server now support DHCPINFORM messages

  Change: 

Packets from originator is now enough to keep non-TCP states alive

  Change: 

New advanced setting: IPOPT_RTRALT

  Change: 

DHCP client will now include options 12, 60 and 61 in requests

  Change: 

"-verbose" switch added to arpsnoop console command

  Change: 

ARP section: IP addresses may now be published on multiple interfaces at once

  Change: 

Single-Admin Virtual Systems now configurable

  Change: 

The OSPF routing protocol implemented

  Change: 

Rule lookup order changed: PBR rules are now consulted first

  Change: 

Route failover via status monitoring implemented

  Change: 

"Security/Transport Equivalent" interface groups added

  Change: 

Connections over different interfaces are now always treated as separate

  Change: 

ARP related functionality will now obey PBR rules

  Change: 

New mode PBR table mode: "Only"

  Change: 

Interfaces may now be set as "members" of a PBR table

  Change: 

"ping" command enhanced to aid in routing troubleshooting

  Change: 

IPsec interfaces will now auto-add routes according to PBR table membership

  Change: 

DHCP Relayer will now obey PBR

  Bug fix: 

HTTP ALG problems with Microsoft Windows Update and some other sites

  Bug fix: 

FTP ALG problems with PBR

  Bug fix: 

Deselecting ALGs from a service would require a reboot

  Bug fix: 

Crash if DNS client was making a query during a config re-read

  Bug fix: 

Reject responses (TCP RST / ICMP unreach) would not obey PBR

  Bug fix: 

Automatic IPsec keepalives would not work with 0.0.0.0/0 as local or remote net

  Bug fix: 

IPsec: Auto-adding routes would fail intermittently

  Bug fix: 

IPsec data lifetimes higher than 4194304KB (4GB) would be misinterpreted

  Known problem: 

IPsec: Compatibility issue with MS IPsec NAT Traversal

  Bug fix: 

HA: Incorrect behavior of Route Local IPs on inactive node

  Known problem: 

HA: No state synchronization for ALGs

  Known problem: 

HA: Tunnels unreachable from inactive node

  Known problem: 

HA: No state synchronization for L2TP and PPTP

 

 Files installed by v8.50.00

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

This is a list of files that are new to the v8.50.00 release. All paths are relative to your Firewall Manager install folder.

» 

Cores/fwc-8.50.00-full.cfx
This is the v8.50.00 full firewall core. Upload it to your existing firewall, or create new boot media with it. It contains all available functionality.

» 

Cores/fwc-8.50.00-mini.cfx
This is a version of the v8.50.00 core with certain features removed. It is less than half the size of the full version. The features removed are:
- IPsec VPN
- The H.323 Application Layer Gateway
- OSPF

» 

Docs/changes-8.40.04-to-8.50.00.html
This document.

» 

FWMgr8.exe
This is the v
8.50.00 Firewall Manager. Earlier version 8