Amaranten Firewall Changes from v8.50.02 to v8.60.02

8.60.00 release date: 2005-09-14 [ISO]

Users upgrading from v7.0x or earlier should read changes-7.0x.xx-to-8.00.02.html first.

Version 8.60.02 contains a number of new features which are highlighted here:

 

» 

Transparent Mode support enables automatic creation of routes for hosts moving between different interfaces within the same group of transparent interfaces.

 

 

» 

Server Load Balancing (SLB) support enables distribution of traffic load across multiple servers to scale beyond the capacity of one single server, and to tolerate a server failure.

 

 

» 

Radius Accounting support enables accounting capabilities for authenticated users.

 

 

» 

RADIUS Interim Accounting support enables interim accounting updates for logged in users.

 

 

» 

GRE Session Keys support enables the possibility to identify tunnels by ID.

 

Contents of this document

Version 8.60.02 contains fixes to problems in the Firewall Core and the Firewall Manager. This document outlines problems solved as well as improvements for each component.

The upgrade procedures in this document refers to upgrades from earlier v8.0x installations.

¡¤  Files installed by v8.60.02

¡¤  How to upgrade earlier v8.0x firewalls to v8.60.02

¡¤  How to upgrade v6.0x/v7.0x firewalls to v8.0x

¡¤  HA upgrade procedure

 

For future reference: This document is stored in the "Docs" sub-folder of your Firewall Manager install folder.

Change logs / release notes for earlier versions of Amaranten Firewall are available in the release notes section of www.amaranten.com/support.

 

 

 Summary of changes and problems solved

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Firewall Manager

  Change: 

Simplified IPsec configuration

  Change: 

Dialog for adding switchroutes has been changed

  Change: 

Two new default proposal lists added

  Problem solved: 

Netobject groups can not be included when creating a new netobject group

  Problem solved: 

CRL setting for CA certificates overwritten by manager

  Problem solved: 

Real-time Logger and Remote Console may crash in Firewall Manager.

  Problem solved: 

The firewall manager crashes if a user clicks in the authentication column for a IPsec tunnel

  Problem solved: 

Firewall Manager cannot remove integrity algorithms from proposal lists

  Problem solved: 

It is not possible to add routes to the "core" interface

  Problem solved: 

IPSec/IKE Proposals are written down to configuration file in the wrong order

  Problem solved: 

Problems with switchroutes in PBR tables

  Problem solved: 

Erroneous warning displayed

  Problem solved: 

IPsec Config Mode pools in global namespace does not work

  Problem solved: 

Not possible to configure null encryption in IPsec proposals

Firewall Core

  Change: 

Transparent Mode implemented

  Change: 

Server Load Balancing implemented

  Change: 

Radius Accounting support implemented

  Change: 

Support for server-side IKE Configuration Mode

  Change: 

Misc. IPsec changes

  Change: 

Conn command modified

  Change: 

ARP timeout setting limit decreased

  Change: 

New synrelayer available

  Change: 

New "routemon" console command

  Change: 

HTTP ALG now allows compressed data

  Change: 

Packets with disallowed source Ethernet addresses are now dropped when using Transparent Mode

  Change: 

New advanced settings for forwarded ARP traffic when Transparent Mode is used

  Change: 

RADIUS Interim Accounting supported

  Change: 

GRE session keys supported

  Change: 

IPSec NAT-traversal behaviour changed

  Problem solved: 

HTTP ALG might cause the Firewall to crash in some situations

  Problem solved: 

Interfaces are taken down during reconfiguration

  Problem solved: 

IPsec: Compatibility issue with MS IPsec NAT Traversal

  Problem solved: 

HA: Shared MAC addresses are not unique on all interfaces

  Problem solved: 

Multiple entries may be added in the layer 3 cache for a host if Transparent Mode is configured

  Problem solved: 

L2TP client/server does not send a unique hostname during negotiations

  Problem solved: 

SLB monitoring problems

  Problem solved: 

Promiscuous mode is enabled by default on all interfaces

  Problem solved: 

Calling the shutdown console command does not always restart the core

  Problem solved: 

Transparent Mode feature can cause memory leakage

  Problem solved: 

ARP handling in Transparent Mode incompatible with Microsoft Network Load Balancing

  Problem solved: 

Filtered "conn" console command displays wrong number of not shown connections

  Problem solved: 

The "ping" command will ignore the interface PBR setting when the "-r " parameter is used

  Problem solved: 

Problems administrating a Firewall over netcon on a virtual router interface

  Problem solved: 

Problems terminating a L2TP session inside a virtual router

  Problem solved: 

L2TP server may stop to listen for incoming connection attempts

  Problem solved: 

The L2TP engine may use 0 as session ID, which is not allowed according to RFC 1661

  Problem solved: 

IPsec engine runs out of internal states

  Problem solved: 

IPSec Config Mode IP pool problem

  Problem solved: 

Problems with reconfiguration when using a license allowing only a few IPSec tunnels

  Problem solved: 

Certificate setting to not validate with CRL is lost after reconfiguration

  Problem solved: 

MTU problems over IPSec interfaces

  Problem solved: 

Problems sending LDAP traffic over IPSec tunnels

  Problem solved: 

IPSec keepalive does not work

  Problem solved: 

IPSec tunnels using ID-lists may fail to be re-authenticated after being taken down

  Problem solved: 

Firewall does not complain if private key file is not understood

  Problem solved: 

IPSec re-keying fails

  Problem solved: 

IPSec re-configuration problems

 

 Files installed by v8.60.02

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

This is a list of files that are new to the v8.60.02 release. All paths are relative to your Firewall Manager install folder.

» 

Cores/fwc-8.60.02-full.cfx
This is the v8.60.02 full firewall core. Upload it to your existing firewall, or create new boot media with it. It contains all available functionality.

» 

Cores/fwc-8.60.02-mini.cfx
This is a version of the v8.60.02 core with certain features removed. It is less than half the size of the full version. The features removed are:
- IPsec VPN
- The H.323 Application Layer Gateway
- OSPF

» 

Docs/changes-8.50.02-to-8.60.02.html
This document.

» 

FWMgr8.exe
This is the v8.60.02 Firewall Manager. Earlier version 8 Firewall Managers will be backed up with the extensions ".old1" and ".old2".

 

 How to upgrade earlier v8.0x firewalls to v8.60.02