SNS version 5.0.7 bug fixes

System

SSL VPN - RADIUS authentication

Support reference TAC-1065

The groups of a user from a RADIUS server are now correctly retrieved when this user connects via the SSL VPN.

High availability (HA)

Support reference TAC-1260

The storage of SSH keys used by HA has been modified to prevent these keys from becoming out of sync during a firewall configuration restore.

Configuration – Renaming an object

Support reference TAC-987

Renaming an object in nested groups no longer removes it from these groups.

IPsec VPN

AES-GCM now replaces AES-256-CBC as the default encryption suite used in the PQCTransition IPsec profile.

Support reference TAC-1464

In a mobile IPsec configuration with certificate-based authentication, when the DN field of the user certificate contains non-ASCII characters—such as accented characters—these characters are no longer incorrectly replaced with question marks when the certificate details are displayed in logs or in the output of swanctl command-line commands.

Filtering and NAT

Support reference TAC-1290

The error messages reported when a filter policy failed to load have been modified to better understand the cause of this failure. Example: case of a group with too many objects.

Logs

Support reference TAC-1413

Memory leaks have been fixed in the log management mechanism during a connection/disconnection to a syslog server.

Monitoring

Support reference TAC-440

The maximum value of the acceptable CPU temperature is now read only once when the supervision engine is started. As this value is fixed, its reading performed regularly was inappropriate and could lead to unexpected restarts of the firewall.

DNS cache mechanism

Support reference TAC-1272

Improvements have been made to the DNS cache mechanism in order to no longer exceed the limits authorized for the firewall and to no longer cause an unexpected stoppage of the sending of DNS requests.

Starting the firewall

Support reference TAC-1469

User permission set-up operations are now no longer redirected to the dmesg file, but to the /var/tmp/boot.result file, so that the firewall start-up phase is no longer unnecessarily slowed down.

Intrusion prevention engine

Authentication

Support reference TAC-1491

Memory leaks have been fixed in user management using the explicit proxy.