New features in SNS 3.4.1

IPsec VPN

In cases where a VPN links two sites, and the internal network of one site overlaps the other site's internal network, local traffic on each site must not go through the encrypted tunnel. This operating mode was not supported in previous versions of SNS.

It can be enabled using CLI commands:

CONFIG IPSEC UPDATE slot=<1-10> BypassLocalTraffic=1
CONFIG IPSEC ACTIVATE

Stormshield Network Real-Time Monitor

Protection of private data

In the interests of compliance with the European General Data Protection Regulation (GDPR), private data found in logs (e.g., user, machine name, source IP address, etc.) will no longer be displayed systematically in SNRTM's screens. By default, only the super administrator (admin account) will be able to view such data. Other administrators will only be allowed to enable access to private data after they have received an individual and temporary code for access to private data.