SMC 3.9.2 fixes
Active Update server
Active Update server certificate format
The certificate that SMC generated for Active Update was not compatible with SNS in versions 5.1.x and higher.
SMC version 3.9.2 provides a certificate that is compatible by default with all versions of SNS.
The certificate is automatically updated when version 3.9.2 is installed, except when a custom certificate is used.
WARNING
If you are using the SMC Active Update server with the default certificate, refer to the Recommendations section before updating SMC to version 3.9.2.
Authorities and certificates
Support reference 86360
Retrieving information about SNS firewall certificates
If you have opted to declare the certificates used by firewalls in SMC by entering their subjects and senders in the System > IPsec VPN tab in firewall properties, SMC now runs commands to retrieve certificate information gradually every day at midnight.
Previously, SMC would run commands simultaneously on all relevant firewalls, which could cause overloading and downgrade server performance.
Filter and NAT rules
Support reference 86366
Importing rules
Filter and NAT rules can now be imported on SMC from a CSV file containing up to 16,000 rules.
If an issue occurs while deploying a large quantity of rules on SNS firewalls, refer to the Stormshield knowledge base.
VPN topologies
Support reference 86361
Deploying VPN topologies on SNS firewalls with DR mode enabled
VPN topologies can now be deployed across firewalls on which Diffusion Restreinte mode has been enabled, and which are in version 5.x.
SMC public API
Support reference 86238
The "vpnLocalAddress" and "publicIpAddress" fields are now correctly fetched by route API calls:
-
GET /papi/v1/vpn/topologies/{uuid}
-
GET /papi/v1/vpn/topologies