SNS version 4.8.17 LTSB bug fixes

System

SSL VPN - RADIUS authentication

Support reference TAC-1065

The groups of a user from a RADIUS server are now correctly retrieved when this user connects via the SSL VPN.

IPsec VPN

Support reference TAC-1539

Memory leak issues have been fixed in the IPsec VPN engine.

Support reference TAC-1464

In a mobile IPsec configuration with certificate authentication, when the DN field of the user certificate contains non-ASCII characters such as accented characters, these characters are no longer erroneously replaced by question marks when the certificate characteristics are displayed in logs or swanctl online command returns.

High availability (HA)

Support reference TAC-1260

The storage of the SSH keys used by HA has been modified to avoid desynchronization of these keys when restoring firewall configuration.

High availability (HA) - IPsec VPN

Support reference TAC-1466

Now, if a toggle occurs when:

  • IPsec VPN tunnels are active,

  • there was no synchronization,

phase 2 of the tunnels are deleted so that the tunnels will be closed.

Filtering and NAT

Support reference TAC-1290

The error messages reported when a filter policy failed to load have been modified to better understand the cause of this failure. Example: case of a group with too many objects.

Logs

Support reference TAC-1413

Memory leaks have been fixed in the log management mechanism during Syslog server connect/disconnect.

Logs – SNMP protocol

Support reference TAC-1131

You can enable SNMP protocol verbose mode again. This regression appeared in SNS version 4.7.0.

DNS cache mechanism

Support reference TAC-1272

Improvements have been made to the DNS cache mechanism so that it no longer exceeds the limits authorized for the firewall and causes an unexpected stop in sending DNS requests.

Monitoring

Support reference TAC-440

The maximum value of the acceptable CPU temperature is now read only once when the supervision engine is started.

Starting the firewall

Support reference TAC-1469

User permission set-up operation feedback is now no longer redirected to the dmesg file, but to the /var/tmp/boot.result file, so that the firewall start-up phase is no longer unnecessarily slowed down.

Intrusion prevention engine

Authentication

Support reference TAC-1491

Memory leaks have been fixed in user management using the explicit proxy.

Web administration interface

Monitoring

Support reference TAC-1579

Now, in Supervision > System > History, the User Space and Usages curves are no longer inverted.

URL/SSL filtering

Support reference TAC-1347

In the Filtering/NAT screen, delays of several seconds could occur when the displayed filter policy contains many rules using URL/SSL filtering. This issue has been fixed.