SNS version 5.0.7 bug fixes
System
SSL VPN - RADIUS authentication
Support reference TAC-1065
The groups of a user from a RADIUS server are now correctly retrieved when this user connects via the SSL VPN.
High availability (HA)
Support reference TAC-1260
The storage of SSH keys used by HA has been modified to prevent these keys from becoming out of sync during a firewall configuration restore.
Configuration – Renaming an object
Support reference TAC-987
Renaming an object in nested groups no longer removes it from these groups.
IPsec VPN
AES-GCM now replaces AES-256-CBC as the default encryption suite used in the PQCTransition IPsec profile.
Support reference TAC-1464
In a mobile IPsec configuration with certificate-based authentication, when the DN field of the user certificate contains non-ASCII characters—such as accented characters—these characters are no longer incorrectly replaced with question marks when the certificate details are displayed in logs or in the output of swanctl command-line commands.
Filtering and NAT
Support reference TAC-1290
The error messages reported when a filter policy failed to load have been modified to better understand the cause of this failure. Example: case of a group with too many objects.
Logs
Support reference TAC-1413
Memory leaks have been fixed in the log management mechanism during a connection/disconnection to a syslog server.
Monitoring
Support reference TAC-440
The maximum value of the acceptable CPU temperature is now read only once when the supervision engine is started. As this value is fixed, its reading performed regularly was inappropriate and could lead to unexpected restarts of the firewall.
DNS cache mechanism
Support reference TAC-1272
Improvements have been made to the DNS cache mechanism in order to no longer exceed the limits authorized for the firewall and to no longer cause an unexpected stoppage of the sending of DNS requests.
Starting the firewall
Support reference TAC-1469
User permission set-up operations are now no longer redirected to the dmesg file, but to the /var/tmp/boot.result file, so that the firewall start-up phase is no longer unnecessarily slowed down.
Intrusion prevention engine
Authentication
Support reference TAC-1491
Memory leaks have been fixed in user management using the explicit proxy.