Resolved Issues
The Fireware XTM v11.4 release resolves a number of problems found in earlier Fireware XTM v11.x releases.
General
- IP address and port scanning detection no longer applies to traffic from any trusted or optional networks, or to VPN traffic. [57592]
- Policy-based routing no longer stops working when a WatchGuard security subscription expires. [57858]
- A problem has been resolved that caused the server down detection probes used in server load balancing to fail when you use RDP services on Windows 2008 R2. [57438]
- It no longer takes 15-20 minutes for PPPoE to reconnect after you reboot your XTM device. [56351]
- In traffic log messages, the PPPoE interface name no longer appears incorrectly as Eth0. [56591]
- Server load balancing no longer stops working when your LiveSecurity subscription expires. [57526]
- You can now import the WatchGuard Products MIB without errors. [56754]
- There is a new TCP idle connection timeout setting available in the Global Settings configuration. [56026]
Authentication
- You can now use manual authentication and Single Sign-On at the same time for different users through the XTM device. [43298]
- Mobile VPN with SSL Active Directory authentication requests now work correctly through branch office VPN tunnels. [57418]
- We now support multiple Active Directory domains for SSO and authentication, instead of just one. [44221]
Single Sign-On
- Single Sign-On accuracy and scalability has been improved. [58376, 57076, 57087, 44267, 58375]
- To improve efficiency and reduce load on the Single Sign-On Agent, the XTM device no longer needs to send queries to the SSO Agent for the IP addresses in the exception list. [57075]
CLI
- We now include CLI commands that enable you to see the number of concurrent connections through the XTM device. [34523]
WebUI
- It is now possible to configure all components of proxy policies from the Web UI.
- You can now use the wildcard * character in spamBlocker exceptions you add through the Web UI. [56878]
FireCluster
- You can now configure an active/passive FireCluster with XTM devices configured in drop-in mode. [37287]
- A problem that caused a stack trace for active/passive FireCluster devices with the error message Process `ctd' died unexpectedly on signal 11 has been resolved. [58312]
- A problem that caused the trusted network subnet mask to change after a FireCluster failback has been fixed. [43506]
- You can now configure an active/passive FireCluster when all trusted interfaces are also configured as part of a VLAN. [56498]
- If you change the IP address for the Primary or Backup cluster interface, when you save the configuration to the FireCluster, both clustered devices no longer restart at the same time without warning. [57716]
Mobile VPN
- You can now use an address pool that is part of the drop-in network with Mobile VPN with IPSec. [56399]
- You can now use an address pool that is part of the drop-in network with Mobile VPN with SSL. [55711]
- Mobile VPN with SSL will now connect successfully when you use a quotation mark in the passphrase. [57764]
- Alphanumeric characters are now accepted when you use two factor authentication. [57327]
- When you use Mobile VPN with PPTP with an address pool from the primary subnet on a trusted interface the XTM device now replies to an ARP request for the assigned PPTP address. [56190]
- Frequent PPTP connection attempts no longer cause high CPU use. [56005]
- A problem has been resolved that caused PPTP connections to disconnect with log messages that show: pptp Unsupported protocol received [56101, 45477]
Branch Office VPN
- A problem has been resolved that caused an IKED stack trace error in branch office VPN tunnels configured to use dynamic NAT. [57453]
- The ID field of the IP header after ESP encapsulation is now correctly changed in fragmented packets. [56956]
Networking
- Log traffic, syslog traffic, and SSO authentication requests are now correctly routed through VPN tunnels. [57701, 57702]
- A problem that caused the Eth4, Eth5, and Eth6 interfaces on XTM 2 Series devices to not respond to ARP requests if the cable has been disconnected for 24 hours has been resolved. [56422]
- XTM 2 Series Wireless devices no longer generate excessive amounts of log messages with ath9k: missed 1 consecutive beacon. [41690]
- Traffic management now works correctly when applied to an FTP policy. [42784]
- You can now bridge wireless to a trusted or optional interface that is bridged to another trusted or optional interface. [39603]
- All external interfaces are no longer restarted each time the configuration of one external interface changes. [42443]
- Traffic management actions applied to your local device can now control connections to both clients and servers, as they did in Fireware v10.x. [57242]
- A problem that occurred when you use an XTM 5 Series device with a Metrobility fiber converter model has been resolved. [56276]
- Interface speed information is now correctly displayed through SNMP. [45174]
Proxies
- The HTTPS proxy (by default) does not allow HTTPS connection that negotiate SSLv2 protocol. The user interface now includes a check box to override this default behavior. [55908]
- Several problems that caused WebBlocker to consume large amounts of CPU have been resolved. [56331, 55998]
- A problem that caused file downloads through the HTTP proxy to stall has been resolved. [57462]
- A problem that cased cfm stack traces and slow traffic through the Fireware XTM proxies has been resolved. [57506]
- The FTP proxy setting to control the number of failed login attempts allowed now works correctly. [56983]
- Call quality when you use LifeSize video conferencing equipment has been improved. [56737]
- The HTTP proxy is now more flexible with the initial TCP handshake between the XTM device and certain web servers so that web access to these web servers is not blocked. [56603]
- HTTPS deep packet inspection no longer fails if you import a duplicate CA certificate. [42701]
- Traffic through the SMTP proxy no longer stalls in high latency connections. [56395]
- File transfer through the SIP proxy no longer fails in hairpin configurations. [56997]
- Gateway AV scanning behavior of compressed files has been improved so that risky files are blocked until AV scanning is complete. [55648]
WatchGuard Log Server and Report Server
- From WatchGuard Server Center, you can now successfully change the maximum log database size to a size less than the current database size. If you try to do this, you will see a warning, but can continue. [56285]
- You can now successfully change the maximum log database size through psql. [57961]
- The classification of the log message Error (8199), DB_Cursor: exception in execute: could not open relation with OID has been changed to Info. [57897]
- A problem that caused an exception stack trace error when you tried to generate a per-client web activity report has been fixed. [58370]
- Per-client web reports now generate more quickly than in previous v11.x releases. [58228, 58230]
- Two new reports have been added in Report Manager to show the transfer rate for external interfaces and VPN tunnels. These two reports appear under the Firebox Reports category. [57122]
- The Most Popular Domain report now includes a section that shows the domain data sorted by total bytes transferred. [57127]
- The Most Active Client report now includes a section that shows the client data sorted by total bytes transferred. [57128]
WatchGuard System Manager (WSM)
- Policy Manager now opens locally stored configuration files correctly when your status passphrase starts with a “-“ character. [42616]
- You can now save a configuration file from WSM, even when you log in as a different user than that used to install WSM. [58292]
- When you select the File > Save > Save as File option from Policy Manager on a computer installed with Microsoft Windows 7 OS, icons now display correctly. [57703]
- Managed devices no longer stop trying to connect to the Management Server after 180 seconds. Once the device does connect and gets an updated status from the server, it reschedules the connection attempt based on the configured lease period. [58844]
- In new configuration files, the option to send log messages for reporting that is part of each proxy action is now set to disabled across all types of proxies. [44038]
Firebox System Manager
- The Traffic Monitor search functionality now includes the ability to set your default search preference as either a literal search, or a regular expression search. [57199]