SNS version 5.1.1 EA bug fixes
System
Authentication - Captive portal
When using an authentication rule that references multiple methods, the password entered in the captive portal is no longer displayed in the URL built by the captive portal.
Filtering and NAT
Support reference TAC-1004
Creating a filter rule using a machine reputation value less than zero is now denied.
Supervision via SNMP – SSL VPN
SNMP MIBs now only show established SSL VPN tunnels.
High availability (HA)
Support reference TAC-1260
The storage of SSH keys used by HA has been modified to prevent these keys from becoming out of sync during a firewall configuration restore.
Support reference TAC-572
When the administrator password is changed after the HA cluster is created, the passive firewall now no longer raises an alert regarding the password.
VLAN and High Availability (HA)
Support reference TAC-1164
It is no longer possible to create a VLAN on a dedicated HA interface, or to use an interface with a VLAN as an interface for HA when creating a cluster. These configurations prevented the proper operation of the ICMP protocol through the firewall.
Deploying a configuration from Stormshield Management Center (SMC)
Support reference TAC-1217
Optimizations have been made to reduce the time taken by the SNS firewall to deploy and validate a configuration from an SMC server.
Restoring a configuration
Support reference TAC-1363
Restoring a configuration with more interfaces than the configuration to be replaced no longer causes false alerts in the compatibility tests.
Proxies
During a complete download for which the server sends more bytes than specified in the Content-Length field, for example by adding "\r\n" characters at the end of the request, the firewall no longer erroneously generates additional logs considering it to be a new request.
Filtering and NAT
Support reference TAC-1290
The error messages displayed when a filter policy fails to reload have been updated to provide a clearer understanding of the cause of the failure. Example: case of a group with too many objects.
Storage
Support reference TAC-1167
The presence of a defective SD/microSD card no longer prevents the firewall from restarting.
IPsec VPN
Updating the IPsec policy no longer erroneously removes the value assigned to the Traffic Flow Confidentiality (TFC) parameter if it was present before the update.
Support reference TAC-1197
The corrupt ESP packet counter has been corrected and now shows a correct value.
AES-GCM now replaces AES-256-CBC as the default encryption suite used in the PQCTransition IPsec profile.
Support reference TAC-1464
In a mobile IPsec configuration with certificate-based authentication, when the DN field of the user certificate contains non-ASCII characters—such as accented characters—these characters are no longer incorrectly replaced with question marks when the certificate details are displayed in logs or in the output of swanctl command-line commands.
Network - Interfaces
Support reference TAC-380
When a firewall interface is inoperative, it remains reachable via a gateway if its IP address is present in the routing table. This behavior can now be configured using the KeepDownIFAddresses token in the [Config] section of the ConfigFiles/network configuration file. Specify a value of 1 to keep this behavior or 0 to stop the inoperable interface responding.
Support reference TAC-950
Additional controls have been added when an interface used in a filter rule is changed from DHCP configuration to fixed addressing.
Logs
Support reference TAC-1413
Memory leaks have been fixed in the log management mechanism during a connection/disconnection to a syslog server.
Logs – SNMP protocol
Support reference TAC-1131
You can enable SNMP protocol verbose mode again. This regression appeared in SNS version 4.7.0.
Configuration – Renaming an object
Support reference TAC-987
Renaming an object in nested groups no longer removes it from these groups.
GRE Tunnels – Maximum Segment Size (MSS) Value
Support reference TAC-1214
The MSS value of TCP packets passing through a GRE tunnel is now correct.
SSL VPN - RADIUS authentication
Authentication of an SSL VPN client in RADIUS and TOTP mode allows an empty password again. This regression appeared in SNS version 5.0.0.
Support reference TAC-1065
The groups of a user from a RADIUS server are now correctly retrieved when this user connects via the SSL VPN.
Monitoring
Support reference TAC-1051
The content parameter of the CLI/Serverd REPORT GET LASTHOUR | DAY | LAST7DAYS | LAST30DAYS command is correctly taken into account again. This regression appeared in SNS version 4.3.0.
Support reference TAC-440
The maximum value of the acceptable CPU temperature is now read only once when the supervision engine is started. As this value is fixed, its reading performed regularly was inappropriate and could lead to unexpected restarts of the firewall.
BIRD dynamic routing
Support reference TAC-1394
Activation of dynamic routing traces is now retained when migrating from BIRD v1 to BIRD v2.
Automatic updates - Active Update
Support reference TAC-1400
An exclusion in the external proxy configuration no longer prevents the automatic update mechanism from working.
Starting the firewall
Support reference TAC-1469
User permission set-up operations are now no longer redirected to the dmesg file, but to the /var/tmp/boot.result file, so that the firewall start-up phase is no longer unnecessarily slowed down.
DNS cache mechanism
Support reference TAC-1272
Improvements have been made to the DNS cache mechanism in order to no longer exceed the limits authorized for the firewall and to no longer cause an unexpected stoppage of the sending of DNS requests.
Hardware
SN910 model firewalls
Support reference TAC-990
Updating certain SN910 model firewalls from a version strictly lower than SNS 4.7.0 to a SNS 5.1.0 version no longer makes this firewall dysfunctional (amnesiac state) as was the case for intermediate SNS versions.
Intrusion prevention engine
TCP Protocol
Support reference TAC-1315
When a TCP acknowledgment containing data arrives late, it no longer causes the lifting of the blocking alarm “Wrong TCP sequence number (ACK out of windows 2)” (tcpudp:16 alarm), but that of the alarm, non-blocking by default, “Incorrect TCP sequence number on ACK with data” (tcpudp:785 alarm).
The number of acknowledgments issued by the firewall during certain TCP connections has been limited to prevent potential packet exchange loops.
Querying the host table
Support reference TAC-1141
Improvements have been made to the mechanism for querying information about machines listed in the host table, in order to prevent packet loss on a heavily loaded firewall. The command sfctl -s host -vv now replaces the command sfctl -s host -v.
HTTP Protocol
Support reference TAC-887
The 3 cases that trigger the "HTTP Protocol Overflow" alarm (alarm http:55) now generate 3 separate pieces of additional information to facilitate troubleshooting. These 3 cases are as follows:
- An overflow in the body of the message that retains the same complement,
- An overflow in the “info body” field, which has been replaced by the additional “reply info body” field,
- An overflow in any other field that has been replaced by the “other field” complement.
Authentication
Support reference TAC-1491
Memory leaks have been fixed in user management using the explicit proxy.
Web administration interface
Implicit rules
Saving the configuration following a change in the status of an implicit rule no longer causes the warning message to be displayed erroneously: “Without explicit filter rules, administration tools that use port 1300 will not be able to access your firewall. Save anyway?”
Protocols
Support references -1184 - TAC-1361
Accidentally deleting certain tokens from a protocol's configuration file no longer prevents the protocol's configuration page from loading in the web-based administration interface.
Objects
Support reference TAC-1136
As sorting by the Type and Value columns is not currently available, the sort icon has been removed from those columns.
TPM
Support reference TAC-1352
After initializing the TPM, the Protect with TPM option is directly visible in the Certificates and PKIs module without having to change the configuration module to make it appear.
Users
Support reference TAC-1438
The details of a user from an external Microsoft Active Directory type LDAP directory are displayed correctly again. This regression appeared in SNS version 5.0.2.
Audit logs
Support reference TAC-973
The Access corresponding security rule action, which can be accessed by right-clicking on a log line, now works correctly when the name of the filter rule is greater than or equal to 36 characters.
Dashboard
Support reference TAC-1460
The link to access the license details from the dashboard is functional again.
URL/SSL filtering
Support reference TAC-1347
In the Filtering/NAT screen, delays of several seconds could occur when the displayed filter policy contained many rules using URL/SSL filtering. This issue has been fixed.