Points of attention for an update from the latest version 4.8 LTSB

IMPORTANT
If you are planning to upgrade a firewall from the latest version 4.8 LTSB to version 5.1 EA, we recommend that you read this section carefully.

NOTE
A complete list of automatic behavior changes related to the update of your SNS firewall to version 5.1 EA from the latest available version, 4.8 LTSB, can be found in the Behavior Changes section of these Release Notes.

Upgrade path from version 4.8 LTSB

It is strongly recommended that you update your firewall from latest available version of SNS 4.8 LTSB. Before updating to SNS 5.1, also ensure that no configuration settings trigger a warning message indicating that a feature you are using is deprecated.

Changes introduced in version 5.1.0

Requirements for the update

The update to version 5.1 of the following configurations is refused:

  • Configuration using the SPNEGO authentication method, as this method is no longer supported.
  • Configuration using monitoring via SNMP v1, as this version of the SNMP protocol is no longer supported.
  • Configuration with a VLAN whose parent interface is an HA interface, as this configuration is not supported.
  • Configuration using custom interface names prefixed by <all_> or <internals_>.
  • Configuration using per-interface routing; this configuration is no longer supported.

IMPORTANT
If your firewalls are managed by SMC, you must first update the SMC server to version 3.9 and then update your firewalls to version 5.1.0. Indeed, a server in version lower than SMC 3.9 will not be able to deploy a VTI-based configuration on firewalls in version 5.1.0 or higher.

Deprecated Features in Version 5.1

  • Define a default method and action in the authentication policy.
  • Multi-user authentication and cookie authentication. Please replace it with the TS Agent method.
  • The legacy STRING format OIDs from the STORMSHIELD-ROUTE-MIB—namely snsRouteUsagePrct, snsRoutePacketLossPrct, and snsRouteUnreachPrct—are still present in this MIB, but the values they return are marked as deprecated.
    More information on updating the STORMSHIELD-ROUTE-MIB.
  • The explicit HTTP proxy and WPAD features are deprecated and should no longer be used in production.
    Warning messages are displayed when these features are used in a configuration updated to version 5.0.6 (dashboard, filter rules, access to .pac file).

SNMP monitoring

Please read the Behavior Changes section of these Release Notes carefully before updating to SNS 5.1 a firewall that is monitored via SNMP.

BIRD dynamic routing – OSPF protocol – IPsec virtual interfaces (VTI)

Please read the Behavior Changes section of these Release Notes carefully before updating to SNS 5.1 a configuration using IPsec virtual interfaces involved in OSPF dynamic routing.

URL classification - Extended Web Control (EWC)

The EWC URL classification solution now uses only the server ewc.stormshieldcs.eu as the classification source. Manual requests from the web-based administration interface are once more functional.

Automatic backups

When the automatic backup module is configured to use a certificate that is signed with the obsolete SHA1 algorithm, the certificate will be rejected and the automatic backup will be suspended without sending data for security reasons. An error message prompts the administrator to generate a new customized certificate that is signed using a secure algorithm.

EVAs (Elastic Virtual Appliances)

EVA firewalls in factory configuration are now equipped with a 4 GB /data partition, compared to 2 GB in previous SNS versions. This change does not apply to EVAs that were installed in an earlier version and updated to SNS version 5. We recommend reinstalling these virtual machines directly with SNS version 5.
Please note that 2 GB of memory is required to use the antivirus software.