IMPORTANT
SNS 3.x versions have reached End of Maintenance since July 1st, 2024.
We recommend that you update your SNS firewalls to a version with maintenance to guarantee the protection of your infrastructure.
SNS 3.7.34 LTSB bug fixes
System
Proxies
Support references 84517 - 84824 - 84826 - 84868 - 84877 - 84879
The analysis of a self-signed certificate without a "Subject" field in traffic that matches an SSL decryption rule will no longer cause the proxy to hang.
Support reference 84899
An issue that could cause the SSL proxy to shut down unexpectedly on a firewall managing high traffic has been fixed.
High availability
Support reference 84711
Changes have been made to enhance the stability of the active member of a high availability firewall cluster.
Support reference 84100
In a high availability configuration, when a link is lost on the active node of the cluster, the switch from the active to passive node now takes place faster. This allows the passive node to switch more quickly to an active state, therefore minimizing interruption to network traffic.
Support reference 84522
In some high availability configurations containing several hundred VLANs, requests to show the high availability status will no longer cause abnormally excessive CPU consumption.
Restoration of the SNS firewall configuration or configuration deployment via SMC
Support reference 84630
An issue preventing configurations from being restored on the SNS firewall or new configurations from being deployed on the SNS firewall via the SMC server has been fixed. This issue generated the error "Unable to move restored files to their final location".
GRE interfaces
Support reference 84625
In configurations that use GRE interfaces when non-IP packets are present, memory leak issues would sometimes cause network traffic to freeze unexpectedly, which would then require the firewall to be restarted. This issue has been fixed.
GRE tunnels
Support reference 75479
During advanced troubleshooting, packets captured via tcpdump over GRE interfaces were malformed. This issue has been fixed.
SSL VPN portal
As the signature of the Java applet used for the SSL VPN portal is close to expiry, users will see a warning message after the signature expires. This applet's signature has been renewed and the applet will be automatically updated when the firewall is updated to SNS version 3.7.34 LTSB.