New firewall behavior

This section lists the behavioral changes associated with updating your SNS firewall to version 5.1.2 EA since the last available 4.8 LTSB release.

As SNS version 5 is a major version, it introduces new firewall behavior that may have significant impacts on configurations in a production environment. As such, you are strongly advised to carefully read the list of changes, as well as the requirements for the update to version 5,

Changes introduced in version 5.1.0

Requirements for the update

The update to version 5.1 of the following configurations is refused:

  • Configuration using the SPNEGO authentication method, as this method is no longer supported.
  • Configuration using monitoring via SNMP v1, as this version of the SNMP protocol is no longer supported.
  • Configuration with a VLAN whose parent interface is an HA interface, as this configuration is not supported.
  • Configuration using custom interface names prefixed by <all_> or <internals_>.

IMPORTANT
If your firewalls are managed by SMC, you must first update the SMC server to version 3.9 and then update your firewalls to version 5.1.0. Indeed, a server in version lower than SMC 3.9 will not be able to deploy a VTI-based configuration on firewalls in version 5.1.0 or higher.

Deprecated Features in Version 5.1

  • Define a default method and action in the authentication policy.
  • Multi-user authentication and cookie authentication. Please replace it with the TS Agent method.
  • Use of explicit HTTP proxy and WPAD.
  • The legacy STRING format OIDs from the STORMSHIELD-ROUTE-MIB—namely snsRouteUsagePrct, snsRoutePacketLossPrct, and snsRouteUnreachPrct—are still present in this MIB, but the values they return are marked as deprecated. The configuration of the SNMP monitoring tools must therefore be updated accordingly.
    More information on updating the STORMSHIELD-ROUTE-MIB.

BIRD dynamic routing – OSPF protocol – IPsec virtual interfaces (VTI)

The VTI interfaces involved in BIRD dynamic routing are not compatible by default with the VTI interfaces of older SNS versions. You must add the type nbma; directive to the BIRD configuration, OSPF section then interface sub-section, in order to be compatible through the OSPF protocol.

It is strongly recommended that you make this configuration change on all routers before updating the firewall to version SNS 5.1.

It is also strongly recommended to reference VTI interfaces by their names, rather than by their driver names, in the BIRD configuration. The driver's name has indeed been changed in SNS version 5.1.

A warning message is displayed in the dynamic routing configuration web interface when VTI interfaces for which the nbma mode is not specified are used in BIRD dynamic routing.

BIRD dynamic routing

When BIRD v1 is not used in the firewall configuration, the corresponding tab is no longer displayed in the Network > Dynamic routing module.

Authentication – TS Agent

For security reasons, the list of encryption suites proposed when establishing a TLS connection by the TS Agent has been limited to suites based on TLS v1.3.

SNMP - Obsolete encryption and hashing algorithms

Upgrading to version 5.1 of an SNMP configuration that uses the deprecated SHA128 and/or MD5 hash algorithms, or DES encryption, will result in the mandatory use of the SHA256 and AES algorithms after the update.

The configuration of the SNMP monitoring tools must therefore be updated accordingly.

Default DNS servers

From version SNS 5.1, Quad9 DNS servers are the DNS servers used by default by firewalls in factory configuration.

URL classification - Extended Web Control (EWC)

The EWC URL classification solution now uses only the server ewc.stormshieldcs.eu as the classification source.

Interface naming

An interface name can no longer consist of the name of an existing interface followed by the string <_number> in order to avoid potential naming conflicts. Example: test_1 is no longer allowed.

Changes introduced in version 5.0.7

BIRD dynamic routing – OSPF protocol – IPsec virtual interfaces (VTI)

SNS-50949 JIRA

In order to prepare a configuration update to version 5.1 or higher, the "type nbma;" directive (nbma: non-broadcast multiple access network) must be added to the configuration of the VTI interfaces involved in dynamic routing.

It is also strongly recommended to reference VTI interfaces by their names, rather than by their driver names, in the BIRD configuration.

A warning message is displayed in the dynamic routing configuration web interface when VTI interfaces for which the nbma mode is not specified are used in BIRD dynamic routing.

Changes introduced in version 5.0.6

Deprecated Features in Version 5

The explicit HTTP proxy and WPAD features are deprecated and should no longer be used in production.
Warning messages are displayed when these features are used in a configuration updated to version 5.0.6 (dashboard, filter rules, access to .pac file).

Certificates and PKI

In order to comply with best practice and to maintain compatibility with future versions of certain web browsers, server certificates no longer have the Extended Key Usage (XKU) “clientAuth” policy.

URL classification - Extended Web Control (EWC)

The EWC URL classification solution now uses only the server ewc.stormshieldcs.eu as the classification source. Manual requests from the web-based administration interface are once more functional.

Changes introduced in version 5.0.5

Obsolete features removed in version 5

Multi-user authentication (cookie-based authentication) is deprecated and will be removed in a future release. Please replace it with the TS Agent method.

Changes introduced in version 5.0.2 EA

Requirements for the update

  • Attempts to update to version 5 SSL VPN configurations that use algorithms other than AES-128-GCM, AES-192-GCM, AES-256-GCM and ChaCha20- Poly1305, or with compression enabled, are denied.
  • Attempts to update a firewall to version 5 are denied if the certificate used by the firewall has been signed with the obsolete SHA1 algorithm.
  • Firewalls cannot be updated to version 5 if the ClamAV antivirus engine is used.
  • In SNS version 5, the 3DES encryption algorithm is no longer available for IPsec configurations. Since IPsec configurations using this algorithm will not be successfully updated to version 5, edit your IPsec configuration and replace 3DES with another algorithm before the update.
  • Routing by interface is no longer available in SNS version 5: the system will prevent v4 configurations that use this feature from being migrated to SNS version 5.

Certificates

A certificate is automatically generated the first time a firewall in SNS version 5 is started. This certificate is used by the firewall's TLS-based authentication services (web administration interface and captive portal) for firewalls in factory configuration, or when the captive portal's certificate has not been explicitly defined.

SSL VPN

  • After a firewall in factory configuration is updated to version 5, the Data Channel Offload (DCO) option is enabled by default when the SSL VPN service is used. If you plan to set up TCP-based SSL tunnels, we strongly recommend that you disable the DCO option, which is intended for UDP-based SSL tunnels, and does not contribute to better performance for TCP-based SSL tunnels.
  • Enabling the Data Channel Offload (DCO) option that uses the AES-256-GCM encryption suite for SSL VPN makes TheGreenBow VPN clients incompatible with the Stormshield SSL VPN feature.

Passwords

  • The password policy set on firewalls in factory configuration has been hardened. It now imposes a minimum length of 16 characters (previously 8), a mandatory combination of alphanumeric, uppercase, lowercase and special characters, and a minimum entropy of 64 (previously 20).
  • UTF-8 is now the character set used by the firewall to encode passwords for firewalls in factory configuration. This prevents connection issues via SSH when the password contains non-ASCII characters (for example: “€”, accented characters, etc.).

Factory Reset – Network Interfaces

After restoring a firewall running SNS 5.0.2 EA or later to its factory settings, the firewall's first network interface is automatically set to dynamic IP addressing (DHCP).

Automatic backups

When the automatic backup module is configured to use a certificate that is signed with the obsolete SHA1 algorithm, the certificate will be rejected and the automatic backup will be suspended without sending data for security reasons. An error message prompts the administrator to generate a new customized certificate that is signed using a secure algorithm.

URL/SSL filtering

The embedded URL database has been removed. To continue applying URL/SSL filtering, you can:

SNMP agent

  • Obsolete password encryption algorithms can no longer be selected in the SNMP v3 agent control panel. Only the AES-SHA2 (SHA256) algorithm is available by default. When a configuration using an algorithm other than SHA256 is updated to SNS version 5, a message appears, stating that the algorithm used is obsolete. The algorithm can now be changed through the CLI/Serverd command CONFIG SNMP USERV3.
    More information on the command CONFIG SNMP USERV3.
  • SNMP tables with an index starting at 1 are now used by default, and older tables (index starting at 0) are tagged as obsolete. These older tables will be phased out in a future SNS version.
    When upgrading to version 5 or higher an SNS firewall using the older tables, a warning appears, prompting the administrator to enable new SNMP tables by following the procedure described in the SNS v5 user guide.
  • A message indicates that SNMP version 1 is obsolete. This version will be phased out in a future version of SNS.

EVAs (Elastic Virtual Appliances)

EVA firewalls in factory configuration are now equipped with a 4 GB /data partition, compared to 2 GB in previous SNS versions. This change does not apply to EVAs that were installed in an earlier version and updated to SNS version 5.
Please note that 2 GB of memory is required to use the antivirus software.

Explicit HTTP proxy

The explicit HTTP proxy is obsolete and will be removed in a future version of SNS.

Network captures

For security reasons, the permission required to make network captures is the "monitoring write" privilege (mon_write).

Alarms

The "Land style attack" alarm (ip:21 alarm) is no longer triggered in IPv6, and no longer generates a log entry. This protection is now provided in the firewall operating system kernel.

Objects

The maximum number of items that a group can contain is now limited to 3000 objects. While configurations containing groups of more than 3,000 items can be updated to version 5, objects can no longer be added to such groups after an update.

Obsolete features removed in version 5

  • CRYPT, MD5, SMD5, SHA, and SSHA hash functions for the internal LDAP directory,
  • MD4, MD5, RIPEMD-160 (rmd160), MD2 and MDC-2 hash functions, and the DES-EDE3-CBC encryption algorithm for SSL/TLS-based algorithms,
  • SNVM (Stormshield Network Vulnerability Manager),
  • PPTP (Point-to-Point Tunneling Protocol) VPN,
  • SSL VPN application portal (web application mode and Java applet),
  • ISDN modems (telephone modems connected by serial cable) no longer supported.