New features and enhancements in SNS 5.1.1 EA
IPsec VPN
Compatibility of Virtual IPsec Interfaces (VTI) with third-party vendors
Virtual IPsec interfaces (VTIs) are now compatible with third-party vendors Fortinet, Palo Alto Networks, Checkpoint, SonicWall, CISCO, Microsoft Azure VPN Gateway and Amazon Web Services VPN Gateway. The advantages are as follows:
- IPsec compatibility with other vendors is no longer limited only to policy-based tunnels.
- It is no longer necessary to specify remote networks in the IPsec policy,
- The IPsec policy is independent of the IP addresses of the traffic endpoints and the flows supported,
- The selection of flows to be encrypted in the tunnel is much more flexible and precise,
- Only one tunnel, and therefore only one phase 2 negotiation, is required, regardless of the number of networks connected.
Learn more about configuring VTI interfaces.
IMPORTANT
If your firewalls are managed by SMC, you must first update the SMC server to version 3.9 and then update your firewalls to version 5.1.0. Indeed, a server in version lower than SMC 3.9 will not be able to deploy a VTI-based configuration on firewalls in version 5.1.0 or higher.
IPsec tunnels with EAP-TLS authentication
Introduced in SNS version 5.1.0, the EAP-TLS method enables multi-factor authentication (MFA) to be implemented on native clients of different operating systems (Microsoft Windows, macOS, iOS, Android) for the creation of IPsec tunnels (IKEv2) with an SNS firewall. It is no longer necessary to use a specific IPsec VPN client on user workstations to benefit from enhanced authentication.
Learn more about configuring a tunnel with EAP-TLS authentication.
IPsec tunnels with multiple certificate authentication
This authentication method, based on RFC 4739, allows the implementation of multi-factor authentication in Restricted Broadcast mode. The mobile peer is then authenticated by presenting two certificates:
- The one on their workstation, protected, for example, by the machine's TPM,
- Their user certificate, stored on a smartcard, for example.
Note that an IPsec VPN client that also supports this method is required.
Learn more about configuring a tunnel with multi-certificate authentication.
Changes to the IPsec VPN module in the web administration interface
- The Encryption Policy – Tunnels tab is now divided into three sub-tabs to distinguish:
- Route-based tunnels, established through virtual IPsec interfaces (VTI). You can configure them with a backup VTI interface and a backup remote gateway to provide redundancy.
- Policy-based tunnels,
- Tunnels linked to mobile clients.
- These tunnels are defined using three new configuration wizards.
- Peers are now divided into three types:
- Static gateways: gateways with a fixed and known IP address,
- Dynamic gateways: gateways whose IP address may vary,
- Mobile clients.
- IPsec tunnel monitoring also distinguishes between the three types of tunnels.
Authentication – Identity provider support via OpenID Connect (OIDC)
OIDC support, introduced in SNS 5.0 for Microsoft Entra ID, is expanded to be compatible with other identity providers: Keycloak, ADFS, Thales Safenet, InWebo Trustbuilder and Wallix Trustelem.
Integrating your SNS firewall with these third-party solutions enables harmonized management of your users’ identities and privileges by creating per user group policies. By relying on the authentication mechanisms of these solutions, you ensure the identity of users or administrators connected locally or through a VPN.
Note that OIDC authentication requires the use of NTP servers to synchronize firewall time. An alarm is triggered when this is not the case.
Captive portal
The captive portal authentication page can now show the following:
- The authentication form (LDAP),
- A button for authentication via OpenID Connect (OIDC),
- A button for authentication by certificate (SSL).
These elements are displayed using the CLI/Serverd CONFIG AUTH INTERFACE ADVANCED command, using the configuration tokens LoginFormEnabled=0|1, SSLButtonEnabled=0|1, OIDCButtonEnabled=0|1 and is conditional on the activation of the linked authentication methods. Therefore:
- The authentication form is displayed on the authentication page in all cases unless the LoginFormEnabled token is set to 0,
- The OIDC authentication button is displayed if the OIDC method is enabled on the firewall and if the OIDCButtonEnabled token is set to 1,
- The SSL authentication button is displayed if the SSL method is enabled on the firewall and if the SSLButtonEnabled token is set to 1.
Automatic update of custom web services and IP address categories
Custom web services and IP address categories allow you to tailor your protection by creating security policies based on your situation or legislation. By placing these web services in blocking rules, you create custom indicator of compromise (IOC) lists based on IP addresses or domain names.
These objects can now be updated automatically in the Active Update module. A new grid allows you to define the third-party distribution points hosting updates for these web services.
Learn more about automatically updating custom web services and IP address categories.
Filter policy-based routing and static routing
Filter policy-based routing (PBR) priority over static routing can be enabled or disabled using the CLI/Serverd CONFIG SECURITYINSPECTION COMMON STATEFUL PBROverrideStatic=0|1 command.
Learn more about the CONFIG SECURITYINSPECTION COMMON STATEFUL command.
SSL VPN
The openvpn_client.zip archive generated by the firewall for Stormshield VPN SSL clients now includes connection/disconnection scripts for Linux and macOS clients.
Prohibiting a downgrade to an earlier SNS version
An option in the Maintenance > Advanced configuration module allows the super administrator (admin account) to prohibit the installation of an earlier version of SNS firmware on the firewall.
Elastic Virtual Appliances (EVA)
UEFI BIOS
From version SNS 5.1, EVA virtual firewalls use a UEFI BIOS.
cloud-init support
From version SNS 5.1, EVA virtual firewalls support the cloud-init configuration tool.
Security
Support references TAC-1279 TAC-1566
Previously, the certificate authority used by default by the SSL proxy contained the serial number of the product from which it was generated. It now contains “SNS-SSLProxy-default-authority”. Note that this authority is not regenerated during the SNS version 5 update.
Route monitoring
Two CLI/Serverd commands are now available to supervise routes injected into the system kernel:
- MONITOR ROUTEGET: displays the route associated with a destination (machine object or IP address) passed as a parameter,
- MONITOR ROUTETABLE: displays the routing tables.
More information on the CLI / Serverd commands MONITOR ROUTEGET and MONITOR ROUTETABLE.
BIRD dynamic routing
OSPF Protocol
Support reference TAC-1384
The OSPF packet send and receive buffers can now be configured in the BIRD v1 and BIRD v2 configuration files.
Static routing
The CONFIG NETWORK ROUTE (IPV6) CHECK command is used to check the consistency of static routing and to display any errors and warnings concerning the configuration of static routes and default routes on the firewall.
More information on the CONFIG NETWORK ROUTE CHECK and CONFIG NETWORK ROUTE IPV6 CHECK commands.
Restoring a configuration
Any restoration of a configuration backup from an earlier version of SNS is now subject to verification, allowing you to cancel the restoration in case of uncertainty or an error.
SSL/URL filtering
You can now configure 30 SSL/URL filter profiles, compared to 10 in older versions of SNS.
SNMP monitoring
STORMSHIELD-ASQ-STATS-MIB
A description has been added to each OID of the STORMSHIELD-ASQ-STATS-MIB to provide a better understanding of its role.
STORMSHIELD-ROUTE-MIB
To improve SNMP monitoring of packet loss rate within router objects, three OIDs in INTEGER format snsRouteUsagePrctRaw, snsRoutePacketLossPrctRaw and snsRouteUnreachPrctRaw have been added to the STORMSHIELD-ROUTE-MIB.
The old OIDs in STRING format, respectively snsRouteUsagePrct, snsRoutePacketLossPrct and snsRouteUnreachPrct, are still present in this MIB but the values they return are marked as deprecated.
STORMSHIELD-SYSTEM-MONITOR-MIB, STORMSHIELD-SERVICES-MIB and STORMSHIELD-HA-MIB
To improve SNMP monitoring of SNS firewalls, three OIDs in TimeTicks format have been added:
- snsSysUptime in the STORMSHIELD-SYSTEM-MONITOR MIB,
- snsServicesSysUptime in the STORMSHIELD-SERVICES-MIB,
- snsHASysUptime in the STORMSHIELD-HA-MIB.
The old OIDs in STRING format, snsUptime, snsServicesUptime, and snsHAUptime, respectively, are still present but the values they return are marked as deprecated.
STORMSHIELD-ALARM-MIB
To allow the aggregation of several occurrences of the same alarm in a single log line, a repeat field indicating the number of occurrences has been added in the STORMSHIELD-ALARM-MIB as well as in the traps relating to this MIB.
An OID corresponding to the priority of the alarm has also been added to this MIB as well as in the traps related to this MIB.
STORMSHIELD-LICENCE-MIB
The STORMSHIELD-LICENSE-MIB now provides information on the options subscribed to and their expiry date.
STORMSHIELD-IPSEC-STATS-MIB
The STORMSHIELD-IPSEC-STATS-MIB is now used to obtain statistics concerning ESP IPsec packets replayed or rejected.
DNS servers
On a firewall reset to factory configuration ( defaultconfig ), the root DNS servers are no longer used by default for DNS requests. This behavior can be enabled or disabled using the CLI/Serverd CONFIG DNS USEROOT state=on|off command.
Learn more about the CONFIG DNS USEROOT command.
Improved user experience
Searching for objects by their IP address
In the Network Objects module, entering an IPv4 or IPv6 address in the search field searches for this address among objects of the type machine, group, network, and IP address range. You can then identify the configuration modules using the objects matching the IP address you are looking for.
The objects returned are:
- Machine objects matching the IP address entered,
- Group type objects with a member matching this IP address,
- Network and address range objects that encompass this IP address.
Routing
The routing configuration module now includes a verification console to detect and display configuration errors.
High availability (HA)
When HA verbose mode is enabled, a log entry is added to specify the reason for a cluster member’s quality being set to 0.
System events – High availability
System node name information has been added in HA-related system events.
Active partition
A warning message is displayed when the firewall’s active partition is the backup partition.
CLI/Serverd LIST command
The CLI/Serverd LIST command now returns the administrator’s full name in the form <user@domain> in the list of users connected to the firewall.
Web services
The Web Services import mechanism now supports CSV files in UTF8 format with BOM (Byte Order Mark).
Logs – Authentication
The authentication of a user belonging to more than 250 groups or for whom the length of the group name string exceeds 4096 characters triggers the writing of a line in the authentication log.
Logs - Administration
An Administration logs module has been added: it groups all firewall administration logs.
OSPF Protocol
The netstat -axp ospf system command now displays additional information about the OSPF dynamic routing protocol:
- R-BATC (Buffer All Time Counter): maximum number of memory buffers used by the receive queue,
- S-BATC (Buffer All Time Counter): maximum number of memory buffers used by the send queue,
- R-BATB (Buffer All Time Bytes): maximum size, in bytes, of memory buffers used by the receive queue,
- S-BATB (Buffer All Time Bytes): maximum size, in bytes, of memory buffers used by the send queue.