SonicOS 6.1.2.4 Release Notes for NSA 2600

Release Notes
SonicOS
SonicOS 6.1.2.4 Release Notes
SonicOS
Contents
Release Purpose ........................................................................................................................................................... 1
Platform Compatibility ................................................................................................................................................... 1
Upgrading Information ................................................................................................................................................... 1
Browser Support............................................................................................................................................................ 2
Resolved Issues ............................................................................................................................................................ 2
Known Issues ................................................................................................................................................................ 3
Related Technical Documentation ................................................................................................................................ 5
Release Purpose
SonicOS 6.1.2.4 is an Early Release that fixes a number of known issues in earlier 6.1 releases. This release
addresses the “POODLE” vulnerability (CVE-2014-3566).
This release provides all the features and contains all the resolved issues that were included in previous releases of
SonicOS 6.1.2.x. For more information, see the previous release notes at:
https://support.software.dell.com/sonicwall-nsa-series/release-notes-guides:
•
•
•
SonicOS 6.1.2.2 NSA 2600 Release Notes
SonicOS 6.1.2.1 NSA 2600 Release Notes
SonicOS 6.1.2.0 NSA 2600 Release Notes
Platform Compatibility
The SonicOS 6.1.2.4 release is supported on the following Dell SonicWALL appliance:
•
NSA 2600
The Dell SonicWALL WXA series appliances (WXA 6000 Software, WXA 500 Live CD, WXA 5000 Virtual
Appliance, WXA 2000/4000 Appliances) are supported for use with Dell SonicWALL NSA appliances running
6.1.2.4. The recommended WXA firmware version is WXA 1.3.0.
Upgrading Information
For information about obtaining the latest firmware, upgrading the firmware image on your Dell SonicWALL
appliance, and importing configuration settings from another appliance, see the SonicOS 6.1 Upgrade Guide
available on MySonicWALL or on the www.sonicwall.com Product Documentation page for the NSA series:
http://www.sonicwall.com/us/en/support/3643.html
Note: Upgrading to SonicOS 6.1.2.4 is not supported from SonicOS 5.9. You can upgrade to SonicOS 6.1.2.4
from SonicOS 6.1.2.x, SonicOS 5.8.1.x, or SonicOS 5.8.4.x.
SonicOS 6.1.2.4 Release Notes
P/N 232-002693-00 Rev A
Release Notes
Browser Support
SonicOS uses advanced browser technologies such as HTML5, which are supported in most recent browsers. Dell
SonicWALL recommends using the latest Chrome, Firefox, Internet Explorer, or Safari browsers for administration
of SonicOS. This release supports the following Web browsers:
•
•
•
•
Chrome 18.0 and higher (recommended browser for dashboard real-time graphics display)
Firefox 16.0 and higher
Internet Explorer 8.0 and higher (do not use compatibility mode)
Safari 5.0 and higher
Mobile device browsers are not recommended for Dell SonicWALL appliance system administration.
Resolved Issues
This section contains a list of issues that are resolved in the SonicOS 6.1.2.4 release.
DPI-SSL
Symptom
Condition
Issue
DPI-SSL needs optimization for YouTube.
Occurs when accessing YouTube using HTTPS.
153739
Symptom
Condition
Issue
The Policy list under the Policy tab of the
Configure CFS dialog on the Security Services
> Content Filter page does not show all the
policies. It shows only 18 policies when there
are 20 policies, because the last few rows of
the list window overlap the dialog window and
are hidden. The dialog window has to be
manually extended to show the Add button, but
cannot be extended to show all the policies.
Occurs after adding CFS policies with the Add
button and there are more than 18 policies.
147411
Symptom
Condition
Issue
A vulnerability in the design of the SSL 3.0
protocol can result in unauthorized access to
encrypted communication between a client and
server. This is the "POODLE" (Padding Oracle
On Downgraded Legacy Encryption) issue
(CVE-2014-3566).
Occurs when SonicOS uses the SSL v3.0 protocol.
This has been disabled now and the more secure
TLS version is being used in SonicOS 6.1.2.4.
154333
Security Services
Vulnerabilities
SonicOS 6.1.2.4 Release Notes
P/N 232-002693-00 Rev A
2
Release Notes
Known Issues
This section contains a list of known issues in the SonicOS 6.1.2.4 release.
DPI-SSL
Symptom
Condition / Workaround
Issue
The YouTube website is not displayed for the
URL https://www.youtube.com, and the client
reports the reason as "Bad certificate".
Occurs when using the Chrome browser and
accessing YouTube via the NSA 2600 appliance.
154055
DPI-SSL Client cannot use a custom CA
certificate.
Occurs when first importing the custom CA
certificate in the System > Certificates page and
then attempting to load the custom certificate on
the Client SSL page.
153903
Symptom
Condition / Workaround
Issue
Commands in the edit-category prompt of the
CLI, such as show current-config, do not work.
Occurs when in App Control configuration mode.
147412
App Control Settings that are changed in the
CLI do not appear in the GUI. The GUI still
shows the old settings before the change.
Occurs when App Control Settings are changed in
the CLI using commands such as “edit log
redundancy filter”.
147414
Symptom
Condition / Workaround
Issue
The Clear Statistics button on the Firewall
Settings > Flood Protection page does not
clear the UDP or ICMP statistics, and there are
no separate buttons to clear the UDP or ICMP
statistics.
Occurs when trying to clear the UDP or ICMP
statistics from the Traffic Statistics panel list.
147348
Symptom
Condition / Workaround
Issue
The link status of a Wire Mode interface
unexpectedly changes to up after the interface
is administratively shut down.
Occurs when two unassigned interfaces are
configured as a Wire Mode pair, then Link
Propagation is enabled while their link state is up,
and then one of the interfaces is administratively
shut down.
153407
A DHCP lease scope with the range 0.0.0.1 –
0.0.0.254 is automatically added to X0
although it is configured as a Wire Mode
interface.
Occurs when the primary LAN interface X0 is
configured for Wire Mode or Tap Mode, which do
not use an IP address, and then the firewall is
restarted.
153404
Symptom
Condition / Workaround
Issue
A Java Script error is displayed.
Occurs when renewing or activating a license with
the manual upgrade key, then clicking the Submit
button on the System > Licenses page.
147297
CLI
Firewall
Networking
System
SonicOS 6.1.2.4 Release Notes
P/N 232-002693-00 Rev A
3
Release Notes
Security Services
Symptom
Condition / Workaround
Issue
Anti-Spyware is still active after it is disabled.
Occurs when the Enable Anti-Spyware Service
option has been enabled and then is disabled by
clearing the Enable Anti-Spyware Service
checkbox. Spyware can still be downloaded.
140543
Symptom
Condition / Workaround
Issue
Adding a Terminal Services Agent displays
“Error: Host name/IP address.”
Occurs when the host name begins with a number.
140030
In a Terminal Services Agent environment,
users are not logged out of the firewall
automatically.
Occurs when users log in to a Terminal Server
using the Remote Desktop Protocol (RDP), and
then log out via RDP.
139917
Users
SonicOS 6.1.2.4 Release Notes
P/N 232-002693-00 Rev A
4
Release Notes
Related Technical Documentation
Dell SonicWALL Release Notes and User Guides are available on the Dell Software Support site:
https://support.software.dell.com/release-notes-product-select
Knowledge articles and links to related community forums and other resources are available on the Dell Software
Support site:
https://support.software.dell.com/kb-product-select
Dell SonicWALL instructional videos are available on the Dell Software Support site:
https://support.software.dell.com/videos-product-select
For basic and advanced deployment examples, refer to SonicOS Guides and SonicOS TechNotes available
on the website.
______________________
Last updated: 11/26/2014
SonicOS 6.1.2.4 Release Notes
P/N 232-002693-00 Rev A
5