SNS version 5.0.6 bug fixes
System
High availability (HA)
Support reference TAC-1099
HA synchronization tasks are no longer wrongly enabled during a firewall firmware update. This regression appeared in SNS version 4.8.0.
Support references TAC-1448 - TAC-1450
The configuration tokens <HAResyncBatchSize> and <HaResyncBatchDelay> can now be added through the command setconf in the configuration of a global IPsec VPN policy (Global/VPN/XX).
Support reference TAC-1463
Configuration tokens, which describe timeouts when the status of an interface changes during HA quality calculations, now function properly.
Logs - SNMP
Support reference TAC-1131
SNMP verbose mode can once again be enabled. This regression appeared in SNS version 4.7.0.
Network - Interfaces
Support reference TAC-950
Additional controls have been added when an interface that is used in the configuration is modified to switch from a DHCP configuration to a static address system.
Router objects
Support reference TAC-1338
When an SD-WAN configuration has:
- A router object that was configured with a nominal gateway and a backup gateway,
- Both interfaces supporting these gateways, which have DHCP-assigned addresses.
The interface that supports the active gateway is now correctly updated when the gateway switches, and the intrusion prevention engine no longer restarts in loop.
Automatic updates - Active Update
Support reference TAC-1400
An exclusion in the external proxy configuration no longer prevents the automatic update mechanism from functioning.
Hardware
SN910 model firewalls
Support reference TAC-990
Updating certain SN910 model firewalls from a version strictly lower than SNS 4.7.0 to an SNS 5.1.0 version no longer causes the firewall to malfunction (amnesiac state), as was the case with intermediate SNS versions.
Intrusion prevention engine
TCP protocol
Support reference TAC-1315
When a TCP acknowledgment that contains data arrives late, it no longer generates the block alarm "Wrong TCP sequence number (ACK out of windows 2)" (tcpudp:16 alarm), but instead "Wrong TCP sequence number on ACK with data" (tcpudp:785 alarm), which does not block packets by default.
Web administration interface
IPsec VPN - Peers tab
Support reference TAC-1471
When the global/local policy is changed using the selector found in the Peers tab in the IPsec VPN module, the peers associated with the selected policy are now correctly shown.
Support reference TAC-1494
The positions of IPsec rules are now correctly calculated when a display filter is applied. Their order is no longer misaligned when a rule is deleted.
High availability (HA)
Support reference TAC-1164
The HA configuration wizard no longer suggests parent VLAN interfaces as the main or secondary link, as such a configuration does not function.