Embedded NGX 7.0 Release Notes General Availability Version Contents
Total Page:16
File Type:pdf, Size:1020Kb
Embedded NGX 7.0 Release Notes General Availability Version December 2007 – Document Revision 10 Contents INTRODUCTION.................................................................................................. 3 Highlights of This Version................................................................................................ 3 Supported Platforms......................................................................................................... 3 Availability......................................................................................................................... 3 Copyright ........................................................................................................................... 4 CHANGES FROM 7.0 TO 7.0.52......................................................................... 5 7.0.52................................................................................................................................... 5 7.0.48................................................................................................................................... 5 7.0.45................................................................................................................................... 6 7.0.41................................................................................................................................... 6 7.0.39................................................................................................................................... 7 7.0.33................................................................................................................................... 8 7.0.31................................................................................................................................... 9 7.0.27................................................................................................................................... 9 NEW FEATURES ...............................................................................................11 New Security Features .................................................................................................... 11 New Wireless Features.................................................................................................... 18 1 New Networking Features .............................................................................................. 19 2 Introduction This document contains a summary of new features in Embedded NGX 7.0 GA Version and describes the differences between Embedded NGX 7.0 GA and previous versions. Highlights of This Version Embedded NGX 7.0 incorporates a host of new and improved features, including: • Bridge Mode • WDS (Wireless Distribution System) & Wireless Roaming • Remote Desktop • USB Dialup & Cellular Modem Support Supported Platforms Embedded NGX 7.0 GA supports the following hardware platforms: • Check Point Safe@Office 100B series • Check Point Safe@Office 200 series • Check Point Safe@Office 400W series • Check Point Safe@Office 500 series • Check Point VPN-1 Edge X series • Check Point VPN-1 Edge W series • Check Point ZoneAlarm Z100G • NEC SecureBlade 300 Availability • Embedded NGX 7.0 GA is available to existing Embedded NGX customers with a valid software subscription contract. For additional information and documentation, click here . 3 Copyright © Copyright 2008 SofaWare Technologies Ltd. SofaWare is a registered trademark of SofaWare Technologies Ltd. Check Point is a registered trademark of Check Point Software Technologies Ltd. 4 Changes from 7.0 to 7.0.52 7.0.52 New Features • USB Modems : Sierra Wireless Aircard 595U USB modem is now supported. Issues resolved Firewall and SmartDefense • Resolved issue : In some cases, SmartDefense falsely rejected long CIFS sessions. 802.1x authentication • Resolved issue : When using WPA-Enterprise, the "master-key-update-interval" parameter determines the 802.1X rekeying period. The value of this parameter was ignored, and the default of 802.1X negotiation every 1 hour was used. The parameter is now handled correctly. • Resolved issue : When using 802.1x, "set port lan1 security eap-reauth-period none" resulted in reauthentication after one hour, rather than never requiring reauthentication. The parameter is now handled correctly. 7.0.48 New Features New SmartDefense Protection: Checksum Verification When this protection is enabled, SmartDefense will identify and drop IP, TCP, or UDP packets with incorrect checksums. New SmartDefense Protection: Urgent Flag Clearing The URG flag is used to indicate that urgent data exists in a TCP stream, and that the data should be delivered with high priority. Since handling of the URG flag is inconsistent between different operating systems, allowing the URG flag may enable an attacker to conceal certain attacks. By default, SmartDefense automatically clears the URG flag to ensure security. To allow the URG flag, in the SmartDefense tree's TCP > Flags node, set the URG Flag field to Allow. To prevent the URG flag from being used, set the URG Flag field to Clear. Issues resolved ADSL • Resolved issue : In certain rare cases, ADSL appliances may reboot unexpectedly, and may revert to their backup ADSL firmware. 5 Wireless • Resolved issue : In certain rare cases, the wireless access point may cease to respond following a wireless configuration change or an appliance reboot. Firewall and SmartDefense • Resolved issue : Hotspot authentication does not function as expected for networks with Hide-NAT disabled. • Resolved issue: OfficeMode VPN clients may be unreachable from certain networks unless the client initiate traffic towards this network. 7.0.45 Issues resolved Firewall and SmartDefense • Resolved issue : A compatibility issue between ZoneAlarm Security Suite 3rd party cookie protection and Embedded NGX diagnostics tools. • Resolved issue : Remote desktop feature does not work when the appliance is behind a NAT device. • Resolved Issue: Appliance may fail to respond after installing certain X.509 security certificates. • Resolved issue: Cross site request forgery may be possible when browsing https://my.firewall and a malicious site simultaneously within a single browser. 7.0.41 New Features • Support Added for EAP-FAST user authentication over RADIUS • Support Added for disabling the WAN hide NAT when using the ADSL port as the WAN connection. • A new CLI command was added in order to configure a delay from the moment the primary Internet connection disconnects until the secondary dial-up connection attempts to connect. The command syntax is: “set net wan demand- connect delay <value in seconds>” Issues resolved VPN • Resolved issue : SecuRemote / SecureClient connecting to the appliance VPN server fails to connect if the site name in the client side includes a space character. • Resolved issue : Tunnel test packets are sent from the appliance LAN IP address, even if this address is not included in the encryption domain of the appliance. GUI 6 • Resolved issue : "Unknown Sites" checkbox in the URL filtering categories page is not changeable using the GUI. 7.0.39 New Features • Bridge Mode Supported in Z100G and Safe@Office: Bridge mode is now supported in additional Embedded NGX appliance models, as shown in the following table. Concurrent WAN Port can be Bridges used in bridge? ZoneAlarm Z100G 1 No Safe@Office 500 Series 1 Yes Safe@Office 500 (With Power Multiple Yes Pack) VPN-1 Edge X / W Series Multiple Yes • Bridge Mode in Wireless Wizard: The wireless setup wizard now allows an easy way to configure the wireless LAN in bridge mode. • DHCP Server : An additional DHCP option was added for Thomson VoIP devices. • Secure HotSpot : When using Secure HotSpot with RADIUS authentication, the RADIUS server can now return a session timeout value for each user. • High Availability : When using WAN connection High Availability, A virtual MAC Address is now applied to the WAN ports. • USB Modems : The following additional modems are now supported: Huawei E220, Novatel Wireless Ovation U720 3G. • USB Modem Test A test button was added to the USB modem configuration page. Issues resolved Firewall and SmartDefense • Resolved issue : In certain cases, IPSEC and L2TP connections cannot pass through the firewall to an internal server (libsw). • Resolved Issue: In certain cases, NBT Domain login does not succeed over VPN. • Resolved Issue: When using HTTPS to login to the appliance with a RADIUS user, the RADIUS authentication occurs every 60 seconds. • Resolved Issue: In certain cases, L2TP VPN connection to a bridged WAN interface may fail. • Resolved Issue: In certain cases, SmartDefense Worm Catcher does not work when managed from SmartCenter. VPN • Resolved Issue: When downloading a Manual Encryption Domain from SmartCenter, the appliance does not accept the new setting. Wireless 7 • Resolved Issue: Super-G 108Mbps connections are incorrectly shown in the UI as 54Mbps. Networking and High Availability • Resolved Issue: Under some conditions, High Availability (HA) may not operate as expected when used in conjunction with port based VLANs. • Resolved Issue : In some cases, High Availability (HA) may not operate as expected when used over the WAN2 port. • Resolved Issue: Dead Connection Detection (DCD) does not work as expected with high availability (HA). • Resolved Issue: After reboot, Ethernet port link configuration may reset to the default values. 7.0.33 New Features • ADSL : It is now possible to use PPPoA ADSL connections in router mode without