SMC 3.9.2 fixes

Active Update server

Active Update server certificate format

The certificate that SMC generated for Active Update was not compatible with SNS in versions 5.1.x and higher.

SMC version 3.9.2 provides a certificate that is compatible by default with all versions of SNS.

The certificate is automatically updated when version 3.9.2 is installed, except when a custom certificate is used.

WARNING
If you are using the SMC Active Update server with the default certificate, refer to the Recommendations section before updating SMC to version 3.9.2.

Authorities and certificates

Support reference 86360

Retrieving information about SNS firewall certificates

If you have opted to declare the certificates used by firewalls in SMC by entering their subjects and senders in the System > IPsec VPN tab in firewall properties, SMC now runs commands to retrieve certificate information gradually every day at midnight.

Previously, SMC would run commands simultaneously on all relevant firewalls, which could cause overloading and downgrade server performance.

Filter and NAT rules

Support reference 86366

Importing rules

Filter and NAT rules can now be imported on SMC from a CSV file containing up to 16,000 rules.

If an issue occurs while deploying a large quantity of rules on SNS firewalls, refer to the Stormshield knowledge base.

VPN topologies

Support reference 86361

Deploying VPN topologies on SNS firewalls with DR mode enabled

VPN topologies can now be deployed across firewalls on which Diffusion Restreinte mode has been enabled, and which are in version 5.x.

SMC public API

Support reference 86238

The "vpnLocalAddress" and "publicIpAddress" fields are now correctly fetched by route API calls:

  • GET /papi/v1/vpn/topologies/{uuid}

  • GET /papi/v1/vpn/topologies