- A crash on ALIKE daemon task is fixed by merging the two tasks "ALIKE_d"
and
"ALIKEMonitor since the crash is identified as these are trying to
access/free
common objects in the VPN.
- The maximum URL size is increased to 2048 as it is recognised to cause
problem
in content filtering.
- The PPPoE issue with some servers is fixed, as the box will remove the
existing
AP protocol objects whenever LCP re-establishes, to make it compatible
with such
server behaviour. Updates for handling LCP/AP connection abort is added.
- Updates for VPN hangs issue when simultaneous negotiation happens is
included.
- The issue of VPN with 1-2-1 NAT is not working is solved by adding the
static IPs
with mask 255.255.255.255 for each 1-2-1 NAT alias interfaces.
- Updates to resolve VPN issue with INVALID_MAJOR_VERSION error when re-
negotiating
Phase 2 is added. The root cause is that phase 2 negotiation is three-
message
exchange, there is a chance that because the last phase 2 message is
processed by
IKE, IPsec packet has already arrived. In NAT traversal scenario, the
IPsec packet
is encapsulate in IKE NAT-T UDP, thus, will reach IKE daemon. The update
prevents
IKE from processing IPsec NAT-T packet.
- PPTP would fail with no such user message just after the boot time since
the VPN
requires 5 minutes delay to complete its configuration. Now the VPN will
complete
its configuration when the box rebooted.
- Fixed an issue with Safenet client that safenet client is not
renegotiating phase1
after the SA life timeout. VPN Firewall is modified to make it compatible
with
safenet client's behaviour.
________________________________________________________________________________
3. Recommendations when using this release
____________________________________________________________________________
4. Known problems with this release
- The VPN is updated to start without any delay. Though the other components
Commentaires sur ces manuels