SNS 3.11.28 LTSB bug fixes

System

Filter - NAT

The use of the comparison mathematical operator "different from" ( icon or "!=") in a filter rule no longer results in the wrong address range being generated for the rule in question.

Support references 85357 - 85376

In filter rules that use a set of network objects, one of which is linked to a disabled DHCP-configured interface, restarting the firewall will no longer wrongly enable the "(1) Block all" filter rule. This regression appeared in SNS version 3.11.26 LTSB.

Proxies

Support references 85041 - 85048 - 85260 - 85286 - 85314

Proxies no longer freeze when an SSL decryption rule encounters certificates with the following characteristics:

  • Certificates with a blank Subject field,
  • Certificates signed by a certification authority that the proxy has not recognized as trusted (e.g., self-signed CAs).

And the action associated with the SSL protocol analysis of Unknown certificates is set to Delegate to user.