Transcription of SonicWall™ SonicOS 5.9.1
1 sonicwall SonicOS Notes1 sonicwall SonicOS NotesOctober 2017 These release notes provide information about the sonicwall SonicOS : About SonicOS Supported Platforms Resolved Issues Known Issues System Compatibility Product licensing Upgrading information sonicwall SupportAbout SonicOS SonicOS is a maintenance release that enhances protection against the KRACK vulnerability. sonicwall TZ and SOHO wireless firewalls, as well as sonicwall wireless access points, are not vulnerable to KRACK. However, since a compromised client might communicate to the access point or firewall, an additional layer of protection was added to block such communications. This keeps the communication safe for all wireless clients. Upgrading to this release is recommended to fully mitigate all provides all the features that were included in previous releases of SonicOS and is a unified web post release with support for Gen5 platforms and SOHO.
2 For more information about other releases, see the previous release notes, available on MySonicWall at: Supported PlatformsThe SonicOS release is supported on the following sonicwall network security platforms:On sonicwall TZ series and some smaller NSA series platforms such as the NSA 220, performance may be affected after upgrading to SonicOS This is due to the large number of features, enhancements, and vulnerability fixes provided in SonicOS compared to the SonicOS releases. These features and updates are essential to improving your network E8510 NSA 2400TZ 215TZ 215 WirelessNSA E8500 NSA 2400 MXTZ 210TZ 210 WirelessSonicWall SonicOS Notes2 See the tables in the following sections for supported feature information: Supported key features by platform Supported SonicPoint and wireless features by platform Supported/unsupported IPv6 featuresSupported Key Features by PlatformThe following table lists the key features in SonicOS and shows which appliance series supports E7500 NSA 250 MTZ 205TZ 205 WirelessNSA E6500 NSA 250M WirelessTZ 200TZ 200 WirelessNSA E5500 NSA 240TZ 105TZ 105 WirelessNSA E5000 NSA 220TZ 100TZ 100 WirelessNSA 4500 NSA 220 wirelessSOHONSA 3500 Feature / EnhancementNSA E Class SeriesNSA SeriesTZ 215 SeriesTZ 210 SeriesTZ 205 SeriesTZ 200 SeriesTZ 105 SeriesTZ 100 SeriesSOHO SeriesActive Active ClusteringYNNNNNNNNA mazon VPC1 YYYYYYYYYApp Rules EnhancementYYYYYNYNYAppFlow ReportsYYYYNNNNNArcSight Syslog Format SupportYYYYYNYNYB
3 Andwidth Management EnhancementYYYYYYYYYBGP Advanced RoutingYY2Y3 NNNNNNCLI Enhancements4 YYYYYYYYYC lient CFS EnforcementYYYYYYYYYC ommon Access Card SupportYYYYYYYYYG uest Admin SupportYYYYYNYNYIKE Dead Peer DetectionYYYYYYYYYIKEv2 Configuration Payload SupportYYYYYYYYYS onicWall SonicOS Notes3 IPv6 YYYYYNYNYIPv6 6rdYYYYYNYNYIPv6 BGPYYYYYNYNYIPv6 DHCP PDYYYYYNYNYIPv6 for Backend ServersYYYYYNYNYLDAP User Group MonitoringYYYYYYYYYLDAP User Group MonitoringYYYYYYYYYLog Monitor Filter Input BoxYYYYYYYYYL ogging EnhancementYYYYYYYYYMOBIKEYYYYYNYNYNetEx tender WXAC IntegrationYYYYYYYYYN etwork Device Protection Profile (NDPP Mode)YYYYYYYYYN umbered Tunnel Interfaces for Route Based VPNYY5 NNNNNNNOne Touch Configuration OverridesYYYYYNYNYOpenSSH Vulnerability Security EnhancementsYYYYYYYYYPath MTU DiscoveryYYYYYYYYYP roxied Users Identification and LoginYYYYYYYYYR eassembly Free Regular Expression for DPI EngineYYYYYNYNYSHA 2 in IPsecYYYYYYYYYF eature / EnhancementNSA E Class SeriesNSA SeriesTZ 215 SeriesTZ 210 SeriesTZ 205 SeriesTZ 200 SeriesTZ 105 SeriesTZ 100 SeriesSOHO SeriesSonicWall SonicOS Notes4 SNMPv3 YYYYYYYYYSSL VPN Mobile Connect BookmarkYYYYYYYYYSSL VPN Multi Core ScalabilityYYYNYNNNYSSO RADIUS AccountingYY6 NNNNNNNTSR EnhancementsYYYYYYYYYUDP/ICMP Flood ProtectionYYYYYNYNYWire Mode 4G SupportYYYYYYYNYXD Lookup for Access VPC VPN connection using
4 Static routing is supported for all platforms. Amazon VPC VPN connection using dynamic rout ed is supported only on platforms that support supported on NSA 240. NSA 250M series and NSA 220 series require a license for a CLI command set is supported on NSA 240 and all TZ only on NSA 250M and higher models; not supported on NSA only on NSA 3500 and higher only on NSA 3500 and higher / EnhancementNSA E Class SeriesNSA SeriesTZ 215 SeriesTZ 210 SeriesTZ 205 SeriesTZ 200 SeriesTZ 105 SeriesTZ 100 SeriesSOHO SeriesSonicWall SonicOS Notes5 Supported SonicPoint and Wireless Features by PlatformThe following table lists the SonicPoint and wireless features in SonicOS and shows which appliance series supports / EnhancementNSA E Class SeriesNSA SeriesTZ 215 SeriesTZ 210 SeriesTZ 205 SeriesTZ 200 SeriesTZ 105 SeriesTZ 100 SeriesSOHO SeriesExternal Guest Service Apache / PHP SupportYYYYYYYYYE xternal Guides Service FQDN SupportYYYYYYYYYG uest Admin SupportYYYYYNYNYI nternal Radio IDS Scan Scheduling1 NYYYYYYYYS onicPoint (WMM)
5 OoSYYYYYYYYYS onicPoint Auto ProvisioningYYYYYYYYYS onicPoint Retain Custom ConfigurationYYYYYYYYYS onicPoint DFS SupportYYYYYYYYYS onicPoint Diagnostics EnhancementYYYYYYYYYS onicPoint FairNet SupportYYYYYYYYYS onicPoint RADIUS Server FailoverYYYYYYYYYSoniPoint WPA TKIP Countermeasures and MIC Failure Flooding Detection and ProtectonYYYYYYYYYS onicPoint Layer 3 ManagementYY2 YNNNNNNT raffic Quota Based Guest Svc PolicyYYYYYYYYYS onicWall SonicOS Notes6 Supported and Unsupported IPv6 FeaturesThe table in this section summarizes the key SonicOS features that support see which appliance platforms support IPv6, refer to the section about Supported SonicPoint and Wireless Features by Access Point ACL SupportYYYYYYYYYV irtual Access Point ACL SupportYYYYYYYYYV irtual Access Point SchedulingYYYYYYYYYW ireless Client Bridge Support3 NYYYYYYYYW ireless PCI Rogue Detect PreventionYYYYYYYYYW ireless Radio Built In Scan supported on platforms with internal wireless supported on NSA Supported on platforms with internal wireless Supported on platforms with internal wireless Available with IPv6 Features Not Available with IPv6 6to4 tunnel (allows IPv6 nodes to connect to outside IPv6 services over an IPv4 network) Access Rules Address Objects Anti Spyware Application Firewall Attack prevention.
6 Land Attack Ping of Death Smurf SYN Flood Connection Cache Connection Limiting for IPv6 connections Connection Monitor Content Filtering Service DHCP DNS client Anti Spam Command Line Interface DHCP over VPN DHCP Relay Dynamic Address Objects for IPv6 addresses Dynamic DNS FQDN Global VPN Client (GVC) GMS High Availability: Multicast Oracle SQL/Net RTSP VoIP IKEv1 IPv6 Syslog messages L2 TPFeature / EnhancementNSA E Class SeriesNSA SeriesTZ 215 SeriesTZ 210 SeriesTZ 205 SeriesTZ 200 SeriesTZ 105 SeriesTZ 100 SeriesSOHO SeriesSonicWall SonicOS Notes7 DNS lookup and reverse name lookup Dynamic Routing (RIPng and OSPFv3) EPRT EPSV FTP Gateway Anti Virus High Availability: Connection Cache FTP IPv6 management IP address NDP SonicPoint HTTP/HTTPS management over IPv6 ICMP IKEv2 Intrusion Prevention Service IP Spoof Protection IPv4 Syslog messages.
7 Including messages with IPv6 addresses IPv6 BGP IPv6 for Backend Servers Layer 2 Bridge Mode Logging IPv6 events Login uniqueness Multicast Routing with Multicast Listener Discovery NAT NAT load balancing Neighbor Discovery Protocol NetExtender connections for users with IPv6 addresses Packet Capture Ping Policy Based Routing PPPoE Remote management Security services for IPv6 traffic with DPI Site to site IPv6 tunnel with IPsec for security SonicPoint IPv6 support SNMP SSL VPN Stateful inspection of IPv6 traffic User status Visualization LDAP MAC IP Anti Spoof NAT between IPv6 and IPv4 addresses NAT High Availability probing NetBIOS over VPN NTP QoS Mapping RADIUS RAS Multicast Forwarding Route based VPNs Single Sign On SIP SMTP Real Time Black List (RBL) Filtering SSH Transparent Mode ViewPoint Virtual Assistant Web proxyFeatures Available with IPv6 Features Not Available with IPv6 sonicwall SonicOS Notes8 Resolved IssuesThis section describes the issues that were resolved with this IssuesThis section describes the known issues in this release.
8 VLAN interfaces with IPv6 addresses VPN policies Wireless WireModeWirelessResolved issueIssue IDA vulnerability in WPA2 (Wi Fi Protected Access version 2) protocol could allow an attacker to decrypt or forge network packets between the client and a Wi Fi access during the key negotiation (a four way handshake) when a vulnerable client joins the Wi Fi network. 194397 AppFlowKnown issueIssue IDThe Create Rule option on the Users tab in Dashboard > AppFlow Monitor does not work correctly, and log messages are displayed on the when attempting to create a rule for a RADIUS user to block LAN to WAN access, when the user already belongs to a group that has LAN to WAN VPN users are not displayed in Dashboard > AppFlow Monitor on the Users tab, only unknown users are when several (10)
9 SSL VPN users are connected to the firewall and AppFlow Reporting is ControlKnown issueIssue IDThe App Rule Match Object cannot match a during an FTP download or upload and the Match Type of the Firewall > Match Object is set to Prefix Match, the Input Representation is set to Hexadecimal Representation, and the Enable Negative Matching option is selected. Workaround: Do not enable the Negative Matching option with the Prefix Match Control policies do not block IPv6 traffic unless Intrusion Prevention Service is when IPS is disabled and an App Control policy is created from Firewall > App Control Advanced to block FTP traffic. A computer on the LAN side can still use an IPv6 IP address to connect to an FTP : Enable IPS. With IPS enabled, the App Control policy blocks the FTP Available with IPv6 Features Not Available with IPv6 sonicwall SonicOS Notes9 Command Line InterfaceKnown issueIssue IDThe CLI incorrectly indicates that Gateway Anti Virus is not when using the show status CLI command while GAV is licensed on the Rules are not removed on the Backup device of an HA pair and further configuration is not synchronized with the Backup when the access-rule restore-defaults CLI command is SSLK nown issueIssue IDThe SSL proxied connection count cannot be cleared from the when Client DPI SSL is enabled and HTTPS traffic is passed through X0 and X2 which are configured in Layer 2 Bridge mode.
10 And then X0 and X2 are changed to unassigned certificate from a secure website, such as , is not changed to a sonicwall DPI SSL certificate as it should be, and traffic cannot be when the Enable SSL Client Inspection option is set on the DPI SSL > Client SSL page, a SonicPoint NDR is connected to the appliance, Guest Services are enabled on the WLAN zone, a wireless client connects to the SonicPoint, and the user logs into the guest issueIssue IDRestore defaults button on Access not Advanced SettingsKnown issueIssue IDThe address group cannot be added when configuring VPN policy, especially if Gateway Setup Destination Network obtains IP address using DHCP through a VPN AvailabilityKnown issueIssue IDThe route polices added by OSPF/BGP/RIP route can't be when failover takes place.