SNS version 5.0.6 bug fixes

System

High availability (HA)

Support reference TAC-1099

HA synchronization tasks are no longer wrongly enabled during a firewall firmware update. This regression appeared in SNS version 4.8.0.

Support references TAC-1448 - TAC-1450

The configuration tokens <HAResyncBatchSize> and <HaResyncBatchDelay> can now be added through the command setconf in the configuration of a global IPsec VPN policy (Global/VPN/XX).

Support reference TAC-1463

Configuration tokens, which describe timeouts when the status of an interface changes during HA quality calculations, now function properly.

Logs - SNMP

Support reference TAC-1131

SNMP verbose mode can once again be enabled. This regression appeared in SNS version 4.7.0.

Network - Interfaces

Support reference TAC-950

Additional controls have been added when an interface that is used in the configuration is modified to switch from a DHCP configuration to a static address system.

Router objects

Support reference TAC-1338

When an SD-WAN configuration has:

  • A router object that was configured with a nominal gateway and a backup gateway,
  • Both interfaces supporting these gateways, which have DHCP-assigned addresses.

The interface that supports the active gateway is now correctly updated when the gateway switches, and the intrusion prevention engine no longer restarts in loop.

Automatic updates - Active Update

Support reference TAC-1400

An exclusion in the external proxy configuration no longer prevents the automatic update mechanism from functioning.

Hardware

SN910 model firewalls

Support reference TAC-990

Updating certain SN910 model firewalls from a version strictly lower than SNS 4.7.0 to an SNS 5.1.0 version no longer causes the firewall to malfunction (amnesiac state), as was the case with intermediate SNS versions.

Intrusion prevention engine

TCP protocol

Support reference TAC-1315

When a TCP acknowledgment that contains data arrives late, it no longer generates the block alarm "Wrong TCP sequence number (ACK out of windows 2)" (tcpudp:16 alarm), but instead "Wrong TCP sequence number on ACK with data" (tcpudp:785 alarm), which does not block packets by default.

Web administration interface

IPsec VPN - Peers tab

Support reference TAC-1471

When the global/local policy is changed using the selector found in the Peers tab in the IPsec VPN module, the peers associated with the selected policy are now correctly shown.

Support reference TAC-1494

The positions of IPsec rules are now correctly calculated when a display filter is applied. Their order is no longer misaligned when a rule is deleted.

High availability (HA)

Support reference TAC-1164

The HA configuration wizard no longer suggests parent VLAN interfaces as the main or secondary link, as such a configuration does not function.