SNS version 4.8.17 LTSB bug fixes
System
SSL VPN - RADIUS authentication
Support reference TAC-1065
The groups of a user from a RADIUS server are now correctly retrieved when this user connects via the SSL VPN.
IPsec VPN
Support reference TAC-1539
Memory leak issues have been fixed in the IPsec VPN engine.
Support reference TAC-1464
In a mobile IPsec configuration with certificate authentication, when the DN field of the user certificate contains non-ASCII characters such as accented characters, these characters are no longer erroneously replaced by question marks when the certificate characteristics are displayed in logs or swanctl online command returns.
High availability (HA)
Support reference TAC-1260
The storage of the SSH keys used by HA has been modified to avoid desynchronization of these keys when restoring firewall configuration.
High availability (HA) - IPsec VPN
Support reference TAC-1466
Now, if a toggle occurs when:
-
IPsec VPN tunnels are active,
-
there was no synchronization,
phase 2 of the tunnels are deleted so that the tunnels will be closed.
Filtering and NAT
Support reference TAC-1290
The error messages reported when a filter policy failed to load have been modified to better understand the cause of this failure. Example: case of a group with too many objects.
Logs
Support reference TAC-1413
Memory leaks have been fixed in the log management mechanism during Syslog server connect/disconnect.
Logs – SNMP protocol
Support reference TAC-1131
You can enable SNMP protocol verbose mode again. This regression appeared in SNS version 4.7.0.
DNS cache mechanism
Support reference TAC-1272
Improvements have been made to the DNS cache mechanism so that it no longer exceeds the limits authorized for the firewall and causes an unexpected stop in sending DNS requests.
Monitoring
Support reference TAC-440
The maximum value of the acceptable CPU temperature is now read only once when the supervision engine is started.
Starting the firewall
Support reference TAC-1469
User permission set-up operation feedback is now no longer redirected to the dmesg file, but to the /var/tmp/boot.result file, so that the firewall start-up phase is no longer unnecessarily slowed down.
Intrusion prevention engine
Authentication
Support reference TAC-1491
Memory leaks have been fixed in user management using the explicit proxy.
Web administration interface
Monitoring
Support reference TAC-1579
Now, in Supervision > System > History, the User Space and Usages curves are no longer inverted.
URL/SSL filtering
Support reference TAC-1347
In the Filtering/NAT screen, delays of several seconds could occur when the displayed filter policy contains many rules using URL/SSL filtering. This issue has been fixed.