SNS version 4.8.16 LTSB bug fixes
System
Network - Interfaces
Support reference TAC-950
Additional controls have been added when an interface that is used in the configuration is modified to switch from a DHCP configuration to a static address system.
IPsec VPN
Support reference TAC-582
VTIs using the system name <ipsec0> can no longer be created through the CLI console in order to prevent name conflicts.
High availability (HA)
Support reference TAC-1463
Configuration tokens, which describe timeouts when the status of an interface changes during HA quality calculations, now function properly.
Support references TAC-1448 - TAC-1450
The configuration tokens <HAResyncBatchSize> and <HaResyncBatchDelay> can now be added through the command setconf in the configuration of a global IPsec VPN policy (Global/VPN/XX).
Support reference TAC-572
When the administrator password is changed after the HA cluster is created, the passive firewall now no longer raises an alert regarding the password.
Support reference TAC-1099
HA synchronization tasks are no longer wrongly enabled during the firmware update. This regression appeared in SNS version 4.8.0.
Configuration - Renaming objects
Support reference TAC-987
When objects in nested groups are renamed, they are no longer wrongly deleted from these groups.
Router objects
Support reference TAC-1338
When an SD-WAN configuration has:
- A router object that was configured with a nominal gateway and a backup gateway,
- Both interfaces supporting these gateways, which have DHCP-assigned addresses.
The interface that supports the active gateway is now correctly updated when the gateway switches, and the intrusion prevention engine no longer restarts in loop.
Automatic updates - Active Update
Support reference TAC-1400
An exclusion in the external proxy configuration no longer prevents the automatic update mechanism from functioning.
Report database
Support reference TAC-373 - TAC-1248
The CLI/Serverd command REPORT RESET report=all now correctly releases the space allocated to the database.
URL classification - Extended Web Control (EWC)
Support reference TAC-1601
The EWC URL classification solution now uses only the ewc.stormshieldcs.eu server as its classification source. Manual requests can be made once again from the web administration interface.
Monitoring
Support references TAC-5 - TAC-1185
A message indicating that a physical component has recovered an "operational" status ("CPU health status recovered" messages) is now generated only if a downgrade message was sent earlier for the component in question.
Hardware
SN910 model firewalls
Support reference TAC-990
Updating certain SN910 model firewalls from a version strictly lower than SNS 4.7.0 to an SNS 4.8.16 version no longer causes the firewall to malfunction (amnesiac state), as was the case with intermediate SNS versions.
Intrusion prevention engine
TCP protocol
Support reference TAC-1315
When a TCP acknowledgment that contains data arrives late, it no longer causes the block alarm "Wrong TCP sequence number (ACK out of windows 2)" (tcpudp:16 alarm) to appear, but instead "Wrong TCP sequence number on ACK with data" (tcpudp:785 alarm), which does not block packets by default.
Web administration interface
IPsec VPN
Support reference TAC-1494
The positions of IPsec rules are now correctly calculated when a display filter is applied. Their order is no longer misaligned when a rule is deleted.
High availability (HA)
Support reference TAC-1164
The HA configuration wizard no longer suggests parent VLAN interfaces as the main or secondary link, as such a configuration does not function.