Showing posts with label firewall. Show all posts
Showing posts with label firewall. Show all posts

Friday, February 24, 2017

pfSense 2.3.3 RELEASE Now Available!

pfSense 2.3.3 RELEASE Now Available!

We are happy to announce the release of pfSense® software version 2.3.3!
This is a maintenance release in the 2.3.x series, bringing numerous stability and bug fixes, fixes for a handful of security issues in the GUI, and a handful of new features. The full list of changes is on the 2.3.3 New Features and Changes page, including a list of FreeBSD and internal security advisories addressed by this release.
This release includes fixes for 101 bugs, 14 Features, and 3 Todo items.
If you haven’t yet caught up on the changes in 2.3.x, check out the Features and Highlights video. Past blog posts have covered some of the changes, such as the performance improvements from tryforward, and thewebGUI update.

Upgrade Considerations

As always, you can upgrade from any prior version directly to 2.3.3. The Upgrade Guide covers everything you’ll need to know for upgrading in general.  There are a few areas where additional caution should be exercised with this upgrade if upgrading from 2.2.x or an earlier release, all noted in the 2.3 Upgrade Guide.

Known Regressions

While, nearly all of the common regressions between 2.2.6 and 2.3-RELEASE have been fixed in subsequent releases, the following still exist:
  • IPsec IPComp does not work. This is disabled by default. However in 2.3.1, it is automatically not enabled to avoid encountering this problem. Bug 6167
  • IGMP Proxy does not work with VLAN interfaces, and possibly other edge cases. Bug 6099. This is a little-used component. If you’re not sure what it is, you’re not using it. This has been fixed on our 2.4 development branch.
  • Those using IPsec and OpenBGPD may have non-functional IPsec unless OpenBGPD is removed. Bug 6223

Packages

Compared to pfSense 2.2.x, the list of available packages in pfSense 2.3.x has been significantly trimmed.  We have removed packages that have been deprecated upstream, no longer have an active maintainer, or were never stable. A few have yet to be converted for Bootstrap and may return if converted. See the 2.3 Removed Packages list for details.  pfSense 2.3.3 does bring back tinc (Mesh VPN), LCDproc, TFTP Server, and a new package “cellular” for use with some Huawei model 3G/4G cellular cards. Also noteworthy in case you missed it is the recently added ACME package for use with Let’s Encrypt which is available on 2.3.2-p1, 2.3.3, and 2.4.

pfSense software is Open Source

For those who wish to review the source code in full detail, the changes are all publicly available in three repositories on Github. 2.3.3 is built from the RELENG_2_3_3 branch of each repository.
Main repository – the web GUI, back end configuration code, and build tools.
FreeBSD source – the source code, with patches of the FreeBSD 10.3 base.
FreeBSD ports – the FreeBSD ports used.

Download

Downloads are available on the mirrors as usual.
Downloads for New Installs and Upgrades to Existing Systems – note it’s usually easier to just use the auto-update functionality, in which case you don’t need to download anything from here. Check the Firmware Updates page for details.

Supporting the Project

Our efforts are made possible by the support our customers and the community. You can support our efforts via one or more of the following.
  • pfSense Store –  official hardware, apparel and pre-loaded USB sticks direct from the source.  Ourpre-installed appliances are the fast, easy way to get up and running with a fully-optimized system. All are now shipping with 2.3 release installed.
  • Gold subscription – Immediate access to past hang out recordings as well as the latest version of the book after logging in to the members area.
  • Commercial Support – Purchasing support from us provides you with direct access to the pfSense team.
  • Professional Services – For more involved and complex projects outside the scope of support, our most senior engineers are available under professional services.

I hope I have time to explore it!


- wong chee tat :)

Monday, August 1, 2016

Changelog EFW Community 3.2.1

Changelog EFW Community 3.2.1
=============================

* COMMUNITY-163 Automatically add the rpm channel in efw-upgrade using the major version

* COMMUNITY-167 Icon is missing, applying configuration

* COMMUNITY-196 Save username on efw-upgrade call

* COMMUNITY-219 Create community-appliance package

* COMMUNITY-223 Event notifications edit not working on Community

* CORE-1367 Replace deprecated Perl calls

* CORE-1379 3.2 cannot be installed on vmware 5.5

* CORE-1382 Update translations

* CORE-1397 Evaluate OpenSSL CVE-2016-0800 and others

* CORE-1410 Raid failing event not detected

* CORE-1413 Rpm database rebuild procedure slow

* CORE-1422 connection.cgi use 100% of CPUs

* CORE-1427 endian.logger raises an exception mixing message parameters and exc_info

* CORE-1429 Add SSL/TLS and STARTTLS support to email notifications

* CORE-1438 Signature updates may leave files in inconsistent state

* CORE-1448 Add default pythonrc

* CORE-1454 Add methods for matching/deleting iptables connections and conntack

* CORE-1455 Add an to DomainNameRegex for validating non-FQDN

* CORE-1456 Allow wildcards hostname in Dnsmasq configuration

* CORE-1467 Fix sshd reload call

* CORE-1472 Fix ebtables path

* CORE-1483 Execute a trigger when a visit is deleted for inactivity

* CORE-1487 Ulogd does not start on netwizard

* CORE-1491 Factory default does not restore ethernet settings

* CORE-1498 Fix wrong imports in endian.restartscripts.getblackholedns

* CORE-1500 Restoring a 3.0 backup on 3.2 will leave files with wrong permissions

* CORE-1505 Support additional parameters in endian.authentication.auth_client.authenticate

* CORE-1508 Ability to set a custom Diffie-Hellman group for Apache

* CORE-1511 Ipsec logs not rotated due to missing folder in /var/log/archives

* CORE-1523 Improve ciphers used by Apache

* CORE-1525 Mountpoints are shown on "Hardware information" in dashboard page

* CORE-1532 Apache job fail to start due to missing certificate

* CORE-1535 Cannot create archive only backups

* CORE-1539 syslog-ng runs in multiple instances

* CORE-1560 Network hosts imported from 3.0 to 3.2 cause a traceback

* EOS-1005 Forced dependency to db-bin because on some products was missing in

* EOS-1020 Duplicate package after an update that restarts sshd

* EOS-1026 shadow: update to 4.2.1

* EOS-1067 Single user mode for password recovery is not working in yocto

* EOS-1084 usb_modeswitch segfault when pluggin 3G modem

* EOS-1098 vim: disable mouse default

* EOS-1105 Post installation trigger for cyrus-sasl-bin slows down or even block installation

* EOS-632 Implement multilib

* EOS-881 glibc - getaddrinfo stack-based buffer overflow CVE-2015-7547

* EOS-916 Update script used to create .pot files

* EOS-922 Introduce initrd in x86 kernels

* EOS-927 usb_modeswitch doesn't create ttyUSB if usb modem is plugged before boot start

* EOS-944 Grub: missing conffile in /etc/default/grub

* EOS-964 vim: remove backup file creation at all

* EOS-997 OpenSSL is unable to verify certificates issued by default root CA

* UTM-1389 DHCP failed to run

* UTM-1397 SSLv3 POODLE for SMTP Proxy

* UTM-1422 Squid going IPv6 on IPv6 sites resulting in (101) Network is unreachable

* UTM-1435 Disable ipv6 on postfix

* UTM-1440 Unable to disable Snort rules due to a TypeError

* UTM-1445 Snort rules based on "preprocessor ssl" prevent snort to start

* UTM-1451 Error joining Proxy not Active Directory

* UTM-1457 Show the total number of connections in "show openvpn"

* UTM-1460 Can't download content filter signatures on Alpha 3.2.0

* UTM-1463 proxy.pac improvements

* UTM-1483 Allow at (@) character in certificates common name

* UTM-1491 Allow wildcard certificates generation

* UTM-1492 Allow wildcards certificate pkcs12 upload

* UTM-1496 Certificated with a CA chains with more than one CA cannot be used in VPN server and VPN portal

* UTM-1515 Missing saslauthd on yocto

* UTM-1528 Proxy authentication is not working with AD

* UTM-1530 CA certificate symlink is not created

* UTM-1531 Postfix access control rewrite

* UTM-1536 Custom DHCP configuration not applied

* UTM-1549 Web filter profile containing space in the name are not applied to proxy ACL

* UTM-1555 Wrong DHCP lease expire time

* UTM-1559 Webfilter configurations are not removed and prevent c-icap to start
Source: README, updated 2016-07-26




- wong chee tat :)

Thursday, July 28, 2016

Ports needed by ePolicy Orchestrator for communication through a firewall

Ports needed by ePolicy Orchestrator for communication through a firewall

Summary

The following tables display the ports needed by ePO for communication through a firewall.

For the purpose of this article:
  • Bi-directional means that a connection can be initiated from either direction.
  • Inbound means the connection is initiated by a remote system.
  • Outbound means the connection can be initiated by the local system.
PortDefaultDescriptionTraffic direction
Agent-server communication port80TCP port that the ePO server service uses to receive requests from agents.Inbound connection to the Agent Handler and the ePO server from the McAfee Agent. Inbound connection to the ePO server from the remote Agent Handler.
Agent-server communication secure port

Software Manager, Product Compatibility List, and License Manager port
443TCP port that the ePO server service uses to receive requests from agents and remote Agent Handlers.
TCP port that the ePO server's Software Manager uses to connect to McAfee.
TCP port that the ePO server uses to connect to the McAfee software updates server (s-download.mcafee.com), McAfee license server (lc.mcafee.com), and McAfee Product Compatibility List (epo.mcafee.com).
Inbound connection to the Agent Handler and the ePO server from the McAfee Agent. Inbound connection to the ePO server from the remote Agent Handler.
Outbound connection from the ePO server to McAfee servers.
Agent wake-up communication port

SuperAgent repository port
8081TCP port that agents use to receive agent wake-up requests from the ePO server or Agent Handler.
TCP port that the SuperAgents configured as repositories that are used to receive content from the ePO server during repository replication, and to serve content to client machines.
Inbound connection from the ePO server/Agent Handler to the McAfee Agent.
Inbound connection from client machines to SuperAgents configured as repositories.
Agent broadcast communication port8082UDP port that the SuperAgents use to forward messages from the ePO server/Agent Handler.Outbound connection from the SuperAgents to other McAfee Agents.
Console-to-application server communication port8443TCP port that the ePO Application Server service uses to allow web browser UI access.Inbound connection to the ePO server from the ePO console.
Client-to-server authenticated communication port8444TCP Port that the Agent Handler uses to communicate with the ePO server to get required information (such as LDAP servers).Outbound connection from remote Agent Handlers to the ePO server.
SQL server TCP port1433TCP port used to communicate with the SQL server. This port is specified or determined automatically during the setup process. Outbound connection from the ePO server/Agent Handler to the SQL server.
SQL server UDP port1434UDP port used to request the TCP port that the SQL instance hosting the ePO database is using.Outbound connection from the ePO server/Agent Handler to the SQL server.
LDAP server port389TCP port used to retrieve LDAP information from Active Directory servers.Outbound connection from the ePO server/Agent Handler to an LDAP server.
SSL LDAP server port636TCP port used to retrieve LDAP information from Active Directory servers.Outbound connection from the ePO server/Agent Handler to an LDAP server.
SMB Windows domain controller port445TCP port used for ePO console login when authenticating Active Directory users.Outbound connection from the ePO server to the domain controller (Active Directory) server.


ePO (Ports/Traffic Quick Reference)
ePO Server

Default portProtocolTraffic direction
80TCPInbound connection to the ePO server
389TCPOutbound connection from the ePO server
443TCPInbound/outbound connection to/from the ePO server
445SMBOutbound connection from the ePO server
636TCPOutbound connection from the ePO server
1433TCPOutbound connection from the ePO server
1434UDPOutbound connection from the ePO server
8081TCPOutbound connection from the ePO server
8443TCPInbound connection to the ePO server
8444TCPInbound connection to the ePO server

Remote Agent Handler(s)

Default portProtocolTraffic direction
80TCPInbound/outbound connection to/from the Agent Handler 
389TCPOutbound connection from the Agent Handler
443TCPInbound/outbound connection to/from the Agent Handler
636TCPOutbound connection from the Agent Handler
1433TCPOutbound connection from the Agent Handler
1434UDPOutbound connection from the Agent Handler
8081TCPOutbound connection from the Agent Handler
8443TCPOutbound connection from the Agent Handler
8444TCPOutbound connection from the Agent Handler

McAfee Agent

Default portProtocolTraffic direction
80TCPOutbound connection to the ePO server/Agent Handler
443TCPOutbound connection to the ePO server/Agent Handler
8081TCPInbound connection from the ePO server/Agent Handler. If the agent is a SuperAgent repository, inbound connection from other McAfee Agents.
8082UDPInbound connection to agents. Inbound/outbound connection from/to SuperAgents.
8083UDPRelay server discovery for version 4.8 agents

SQL Server

Default portProtocolTraffic direction
1433TCPInbound connection from the ePO server/Agent Handler
1434UDPInbound connection from the ePO server/Agent Handler
McAfee Updates

Default portProtocolTraffic direction
21TCPOutbound from the ePO server to ftp://ftp.nai.com
80TCPOutbound from the ePO server to http://update.nai.com
443TCFOutbound from the ePO server to s-download.mcafee.com and epo.mcafee.com
NOTE: These URLs are not accessible in browsers.



- wong chee tat :)

Wednesday, July 27, 2016

pfSense 2.3.2-RELEASE Now Available!

pfSense 2.3.2-RELEASE Now Available!




We are happy to announce the release of pfSense® software version 2.3.2!
This is a maintenance release in the 2.3.x series, bringing a number of bug fixes. The full list of changes is on the 2.3.2 New Features and Changes page.
This release includes fixes for 60 bugs, 8 features and 2 todo items completed.
If you haven’t yet caught up on the changes in 2.3.x, check out the Features and Highlights video. Past blog posts have covered some of the changes, such as the performance improvements from tryforward, and thewebGUI update.

Upgrade Considerations

As always, you can upgrade from any prior version directly to 2.3.2. The Upgrade Guide covers everything you’ll need to know for upgrading in general.  There are a few areas where additional caution should be exercised with this upgrade if upgrading from 2.2.x or an earlier release, all noted in the 2.3 Upgrade Guide.
For those upgrading from a 2.3 beta or RC version who have not yet upgraded to 2.3-RELEASE, please see this post.

Known Regressions

While, nearly all of the common regressions between 2.2.6 and 2.3-RELEASE have been fixed in subsequent releases, the following still exist:
  • IPsec IPComp does not work. This is disabled by default. However in 2.3.1, it is automatically not enabled to avoid encountering this problem. Bug 6167
  • IGMP Proxy does not work with VLAN interfaces, and possibly other edge cases. Bug 6099. This is a little-used component. If you’re not sure what it is, you’re not using it.
  • Those using IPsec and OpenBGPD may have non-functional IPsec unless OpenBGPD is removed. Bug 6223

Packages

Compared to pfSense 2.2.x, the list of available packages in pfSense 2.3.x has been significantly trimmed.  We have removed packages that have been deprecated upstream, no longer have an active maintainer, or were never stable. A few have yet to be converted for Bootstrap and may return if converted. See the 2.3 Removed Packages list for details.  pfSense 2.3.2 does bring back ntopng, and the vnstat (traffic totals) package is new.

pfSense software is Open Source

For those who wish to review the source code in full detail, the changes are all publicly available in three repositories on Github. 2.3.2-RELEASE is built from the RELENG_2_3_2 branch of each repository.
Main repository – the web GUI, back end configuration code, and build tools.
FreeBSD source – the source code, with patches of the FreeBSD 10.3 base.
FreeBSD ports – the FreeBSD ports used.

Download

Downloads are available on the mirrors as usual.
Downloads for New Installs and Upgrades to Existing Systems – note it’s usually easier to just use the auto-update functionality, in which case you don’t need to download anything from here. Check the Firmware Updates page for details.

Supporting the Project

Our efforts are made possible by the support our customers and the community. You can support our efforts via one or more of the following.
  • pfSense Store –  official hardware, apparel and pre-loaded USB sticks direct from the source.  Ourpre-installed appliances are the fast, easy way to get up and running with a fully-optimized system. All are now shipping with 2.3 release installed.
  • Gold subscription – Immediate access to past hang out recordings as well as the latest version of the book after logging in to the members area.
  • Commercial Support – Purchasing support from us provides you with direct access to the pfSense team.
  • Professional Services – For more involved and complex projects outside the scope of support, our most senior engineers are available under professional services.



- wong chee tat :)

Monday, July 18, 2016

Untangle Announces NG Firewall Version 12.1

Untangle Announces NG Firewall Version 12.1

Features Geolocation, Fully Responsive Mobile Management

SAN JOSE, Calif. – July 13, 2016 – Untangle® Inc., a security software and appliance company, announced the release of version 12.1 of its award-winning NG Firewall software. Untangle NG Firewall version 12.1 brings new features and functionality to the popular and powerful small business firewall platform.

NG Firewall delivers a comprehensive solution for small-to-medium businesses, schools, governmental organizations and nonprofits that require enterprise-grade perimeter security with the flexibility of a convergent Unified Threat Management (UTM) device. Untangle’s industry-leading approach to network traffic visibility and policy management gives its customers deep insight into what’s happening on their network via its database-driven reporting engine and 360° dashboard.

“Version 12.1 is the next step in the evolution of the Untangle NG Firewall user interface,” said Dirk Morris, founder and chief product officer at Untangle. “Building on the base provided by the last two major releases, version 12.1 provides a fully responsive mobile management console as well as faster performing, more flexible reporting and dashboard widget capabilities.”


Geolocation
In addition to the user interface enhancements, NG Firewall version 12.1 provides new geolocation capabilities for all traffic. NG Firewall’s Integrated Rules EngineTM can utilize geolocation data to allow network administrators to create and apply rules based on client or server latitude and longitude or country. This enables network administrators to quickly triangulate where a threat is originating and create an appropriate policy response. Geolocation data is also available in NG Firewall’s reports and widgets.


Other Updates
Event-based Reporting. Event lists are now a type of Report entry. Network administrators can more easily create custom event list reports, allowing them to keep tabs on specific users, domains, sites, policies and more.

Performance. NG Firewall now performs a “dynamic bypass” function for UDP such that if all layer-7 applications “release” interest in the session, the data will be passed at layer 3, greatly boosting performance.

SSL Certificate Management. Management of client SSL certificates required for SSL Inspector has been further streamlined.

Google & Facebook Authentication. NG Firewall’s Directory Connector application now offers experimental support for authenticating users against their Google or Facebook accounts. This provides a flexible alternative for simplifying Captive Portal deployments.




- wong chee tat :)

Sunday, June 19, 2016

Changelog EFW Community 3.2.0-beta1

Changelog EFW Community 3.2.0-beta1
===================================

* COMMUNITY-163 Automatically add the rpm channel in efw-upgrade using the major version

* COMMUNITY-167 Icon is missing, applying configuration

* COMMUNITY-196 Save username on efw-upgrade call

* CORE-1367 Replace deprecated Perl calls

* CORE-1379 3.2 cannot be installed on vmware 5.5

* CORE-1382 Update translations

* CORE-1410 Raid failing event not detected

* CORE-1413 Rpm database rebuild procedure slow

* CORE-1422 connection.cgi use 100% of CPUs

* CORE-1427 endian.logger raises an exception mixing message parameters and exc_info

* CORE-1429 Add SSL/TLS and STARTTLS support to email notifications

* CORE-1438 Signature updates may leave files in inconsistent state

* CORE-1448 Add default pythonrc

* CORE-1454 Add methods for matching/deleting iptables connections and conntack

* CORE-1455 Add an to DomainNameRegex for validating non-FQDN

* CORE-1456 Allow wildcards hostname in Dnsmasq configuration

* CORE-1467 Fix sshd reload call

* CORE-1472 Fix ebtables path

* EOS-1005 Forced dependency to db-bin because on some products was missing in

* EOS-1020 Duplicate package after an update that restarts sshd

* EOS-632 Implement multilib

* EOS-881 glibc - getaddrinfo stack-based buffer overflow CVE-2015-7547

* EOS-916 Update script used to create .pot files

* EOS-922 Introduce initrd in x86 kernels

* EOS-927 usb_modeswitch doesn't create ttyUSB if usb modem is plugged before boot start

* EOS-944 Grub: missing conffile in /etc/default/grub

* EOS-964 vim: remove backup file creation at all

* UTM-1389 DHCP failed to run

* UTM-1397 SSLv3 POODLE for SMTP Proxy

* UTM-1422 Squid going IPv6 on IPv6 sites resulting in (101) Network is unreachable

* UTM-1435 Disable ipv6 on postfix

* UTM-1440 Unable to disable Snort rules due to a TypeError

* UTM-1445 Snort rules based on "preprocessor ssl" prevent snort to start

* UTM-1451 Error joining Proxy not Active Directory

* UTM-1460 Can't download content filter signatures on Alpha 3.2.0

* UTM-1483 Allow at (@) character in certificates common name
Source: README, updated 2016-05-06


- wong chee tat :)

Saturday, April 30, 2016

EFW-2.5.2 Release Notes - Version 2.5.2

Release Notes - Version 2.5.2

** New Features
* [UTM-250] - PhishTank as anti-phishing protection
* [CORE-82] - Show signatures update time in the dashboard
* [CORE-477] - Intel drivers for the newest Intel network
interface cards
* [CORE-222] - Support for USB Huawei E173 USB UMTS modem


** Improvements
* [UTM-68] - ClamAV engine update to version 0.97.8
* [CORE-184] - The collectd netlink plugin stores information
that is never used
* [CORE-89] - EMI does not load sqlite anymore
* [CORE-259] - EMI storage is not read/write-safe
* [CORE-63] - In Port forwarding / DNAT the default mode
should be simple instead of advanced
* [UTM-250] - PhishTank lists replace lists from
malwaredomains
* [CORE-285] - Packaged signatures tarball with new PhishTank
signatures instead of those from
malwaredomains
* [CORE-105] - Monit method needs an additional attribute
monitor=False which prevents monitor/unmonitor
command from getting sent to monit
* [CORE-189] - Store collectd RRD files in /tmp and
periodically synchronize to /var
* [CORE-164] - Delete archived log files when free space is
needed
* [CORE-231] - Use collectd graphs instead of squid-graph
* [CORE-206] - Replace makegraphs.pl with collectd graphs
* [UTM-110] - Remove collectd's ntp RRD files
* [UTM-80] - New version of ntop
* [CORE-240] - Ethernet bonding support
* [UTM-40] - DansGuardian custom *regexp file is not handled
correctly


** Bugs
* [UTM-115] - ClamAV blocks .exe files due to issues in its
DetectBrokenExecutables check
* [UTM-86] - HAVP does not run after an upgrade to 2.5
* [UTM-65] - “Block encrypted archives” flag was doing
exactly the opposite of what had been
configured
* [UTM-63] - Wrong status message in ClamAV page before the
first signature update
* [CORE-132] - The Authentication layer does not start due to
an UTF-8 problem
* [CORE-125] - Authentication job is not started after
finishing the initial wizard
* [CORE-367] - Old backups cannot be downloaded after
migrating to 2.5
* [CORE-288] - USB stick not detected correctly by
efw-backupusb
* [CORE-278] - When cleaning the system USB backups are not
considered
* [CORE-148] - Instead of keeping 3 USB backups when rotating
only 2 are kept
* [CORE-113] - Error creating the cron link for scheduled
automatic backups
* [CORE-220] - More backups than configured are stored
* [CORE-427] - Deadlock during the reading/writing of
SettingFiles
* [CORE-264] - Logout button does not work for all browsers
* [CORE-236] - After an update efw-shell does not display
correctly the new/updated commands"
* [CORE-122] - In policy routing rules only CS0 Type of
Service can be selected
* [CORE-107] - Dnsmasq sometimes fails to restart which causes
monit to use a huge amount of resources
* [CORE-88] - Backup uplinks do not work if they are Ethernet
uplinks
* [CORE-497] - Collectd does not start on boot with new
version of monit
* [CORE-211] - Dependency to efw-httpd is missing
* [COMMUNITY-15] - RPM triggers interrupt update process
* [CORE-451] - GUI port is hardcoded for redirection
* [CORE-268] - Reboot required not shown after kernel upgrade
* [CORE-482] - emicommand hangs because of curl blocking
* [CORE-137] - YAML storage raises an exception when trying to
load a valid YAML file that contains a list
instead of a dictionary
* [CORE-369] - Interzone firewall rules are not created after
migration to 2.5
* [CORE-119] - When switching from advanced to simple mode
editing destination NAT rules the filter policy
is changed to ALLOW
* [CORE-118] - Target port of Destination NAT is not disabled
when the incoming protocol is "Any"
* [CORE-115] - Incoming Service/Port field of Port forwarding/
Destination NAT is editable, even if Service
and Protocol are both set to "Any"
* [CORE-106] - The bridges job status is wrong, "restart"
instead of "start"
* [CORE-335] - jobcontrol hangs when sync restarting jobs
* [CORE-326] - Jobengine exception during update
* [CORE-257] - Jobs are unnecessarily restarted multiple times
* [CORE-248] - Jobsengine memory leak when OpenVPN client
connects
* [CORE-131] - The efw-shell command "job" does not work due
to a syntax error
* [CORE-124] - AnaCronJob uses Job.start which sets force=True
even if not needed
* [CORE-123] - DownloadJob uses Job.start which sets
force=True even if not needed
* [CORE-120] - Timestamping signatures are recreated although
force is not set to true in CrawlerJob
* [CORE-321] - After migration from 2.4 to 2.5 RAID controller
mptsas is not working anymore
* [CORE-303] - Intel Network driver igb not supported for Quad
Intel 82580 Gigabit Network
* [CORE-190] - Enable FUSION_SAS driver
* [CORE-332] - twistd.log are not compressed and rotated in /
* [CORE-247] - Logrotate not run under various circumstances
* [CORE-87] - ntop UI is not accessible
* [CORE-251] - Logrotate configuration file is removed when
logrotate package is upgraded after efw-syslog
* [CORE-203] - purge-log-archives script fails under special
circumstances
* [UTM-414] - ntop segfault in libc-2.3.4.so/libntop-4.1.0.so
* [UTM-244] - ntop crashes if it is asked to monitor a
interface that is down
* [CORE-343] - VLAN configuration problem
* [CORE-174] - Local routes are missing in ip rule so user
defined rules always overrule local routes
* [CORE-86] - Policy Routing rules are not applied
* [CORE-80] - Upgrade of stripped RPM packages destroys
configuration files
* [UTM-378] - Double efw-dnsmasq packages after upgrade
* [UTM-338] - When updating efw-dnsmasq the httpd
configuration file is removed
* [UTM-322] - Anti-spyware signatures last update date is
inconsistent
* [UTM-320] - DNS black- and whitelists are ignored until the
cron job runs
* [UTM-317] - DNS anti-spyware blacklist is not working
* [UTM-316] - Black- and whitelisted domains are not erased
after saving settings
* [UTM-88] - Unable to download malwaredomains information
* [UTM-181] - Proxy PAC is not applied
* [UTM-93] - Denial of service triggered by access to the
proxy port
* [UTM-90] - DansGuardian blacklists and phraselists are
missing after an upgrade to 2.5
* [UTM-87] - DansGuardian blacklists and phraselists cannot
be downloaded
* [UTM-55] - Clamd is not started before HAVP
* [UTM-194] - HTTP proxy configuration ignores rules under
certain circumstances
* [UTM-81] - IMAP authentication fails if username contains
a @domain part.
* [CORE-219] - TOS/DSCP option breaks Quality of Service
* [UTM-119] - Snort is restarted twice during boot time
* [CORE-138] - System uptime is shown incorrectly
* [CORE-396] - Migration not called after upgrade to 2.5 due
to collectd
* [CORE-159] - Certain migration scripts are not executed
* [CORE-129] - Migration framework causes tracebacks if an RPM
package has an epoch set and a migration script
for it exists
* [UTM-108] - OpenVPN client calls missing "remove_rules"
method which is not controlled by jobengine and
uses a deprecated function
* [UTM-95] - Selecting GREEN in IPsec GUI corrupts IPsec
configuration file
* [UTM-230] - OpenVPN job fails to create user configuration
files if the push orange or push blue options
are enabled
* [UTM-97] - OpenVPN process cannot remove temporary files
because of wrong file owner
* [CORE-221] - OpenVPN client TUN device configuration is
broken
* [UTM-200] - Route to subnet behind OpenVPN gateway-to-
gateway user is set with wrong gateway IP
address if the user has a static IP assigned

Source: README, updated 2013-08-23





- wong chee tat :)




Tuesday, April 26, 2016

Exclusive: SWIFT warns customers of multiple cyber fraud cases

Exclusive: SWIFT warns customers of multiple cyber fraud cases

SWIFT, the global financial network that banks use to transfer billions of dollars every day, warned its customers on Monday that it was aware of "a number of recent cyber incidents" where attackers had sent fraudulent messages over its system.

Posted 26 Apr 2016 05:55 Updated 26 Apr 2016 18:30

REUTERS: SWIFT, the global financial network that banks use to transfer billions of dollars every day, warned its customers on Monday that it was aware of "a number of recent cyber incidents" where attackers had sent fraudulent messages over its system.

The disclosure came as law enforcement authorities in Bangladesh and elsewhere investigated the February cyber theft of US$81 million from the Bangladesh central bank account at the New York Federal Reserve Bank. SWIFT has acknowledged that the scheme involved altering SWIFT software on Bangladesh Bank's computers to hide evidence of fraudulent transfers.

Monday's statement from SWIFT marked the first acknowledgement that the Bangladesh Bank attack was not an isolated incident but one of several recent criminal schemes that aimed to take advantage of the global messaging platform used by some 11,000 financial institutions.

"SWIFT is aware of a number of recent cyber incidents in which malicious insiders or external attackers have managed to submit SWIFT messages from financial institutions' back-offices, PCs or workstations connected to their local interface to the SWIFT network," the group warned customers on Monday in a notice seen by Reuters.

The warning, which SWIFT issued in a confidential alert sent over its network, did not name any victims or disclose the value of any losses from the previously undisclosed attacks. SWIFT confirmed to Reuters the authenticity of the notice.

SWIFT, or the Society for Worldwide Interbank Financial

Telecommunication, is a cooperative owned by 3,000 financial institutions.

Also on Monday, SWIFT released a security update to the software that banks use to access its network to thwart malware that security researchers with British defense contractor BAE Systems said was probably used by hackers in the Bangladesh Bank heist.

BAE's evidence suggested that hackers manipulated SWIFT's Alliance Access server software, which banks use to interface with SWIFT's messaging platform, to cover their tracks.

BAE said it could not explain how the fraudulent orders were created and pushed through the system.

But SWIFT provided some evidence about how that happened in its note to customers, saying that in most cases the modus operandi was similar.

It said the attackers obtained valid credentials for operators authorized to create and approve SWIFT messages, then submitted fraudulent messages by impersonating those people.

FireEye, the internet security company whose Mandiant unit was hired by Bangladesh Bank to help investigate the heist, said the same group behind that hack had probably attacked other financial targets.

"FireEye has observed activity in other financial services organizations that is likely by the same threat actor behind the cyber attack on the Bank of Bangladesh," Vivek Chudgar, Mandiant's senior director for the Asia Pacific said in a statement emailed to Reuters.

FireEye declined to go into detail.

Rakesh Asthana, the World Informatix Cyber Security CEO, who is overseeing Bangladesh Bank's probe into the hack, declined to discuss the other attacks that SWIFT referred to.

He did, though, urge banks to conduct independent security assessments to make sure their networks are secure and prevent future attacks.

“SWIFT builds on security practices established by the customer itself and therefore it is imperative that in the wake of this attack, customers using SWIFT Alliance Access must strengthen their cyber security posture,” Asthana said

FOLLOWING THE MONEY

Cyber security experts said more attacks could surface as SWIFT's banking clients look to see if their SWIFT access has been compromised.

Shane Shook, a banking security consultant who investigates large financial crime, said hackers were turning to SWIFT and other private financial messaging platforms because such attacks can generate more revenue than going after consumers or small businesses.

"These hacks specifically target financial institutions because smaller efforts result in much larger thefts," he said. "It's much more efficient than stealing from consumers."

Justin Harvey, chief security officer with Fidelis Cybersecurity, said hackers followed the money and would be drawn into such schemes in hopes of emulating a big heist like the one on Bangladesh Bank.

"After the Bangladesh Bank heist became public, every other attacker out there is looking to see if they can do the same," he said.

SWIFT spokeswoman Natasha Deteran told Reuters that the commonality in these cases was that internal or external attackers compromised the banks’ own environments to obtain valid operator credentials.

"Customers should do their utmost to protect against this," she said in an email to Reuters.

SWIFT told customers that the security update must be installed by May 12.

"We have made the Alliance interface software update mandatory as it is designed to help banks identify situations in which attackers have attempted to hide their traces - whether these actions have been executed manually or through malware," she said.

(Reporting by Jim Finkle in Boston; Additional reporting by Serajul Quadir in Dhaka; Editing by Jonathan Weber, Martin Howell and Peter Cooney)

- Reuters


- wong chee tat :)

Thursday, March 31, 2016

Changelog EFW-3.0.0-beta2

Changelog EFW-3.0.0-beta2

** Features
  * [UTM-694] - SMTP Delivery Status Notification configuration


** Improvements
  * [UTM-740]  - Connections page for VPN users: frontend
  * [UTM-739]  - Connections page for VPN users: backend
  * [CORE-617] - Add the option "required" to the Multiline validator


** Bugs
  * [UTM-761]  - HTTP proxy information popup is not shown correctly
  * [UTM-752]  - YAML Traceback in Domain Routing until first domain
                 route configuration
  * [UTM-750]  - Spam Black and Whitelists typo in tooltip displayed
                 text
  * [UTM-729]  - IPsec status connection don't explain the right status
  * [UTM-725]  - Serial port speed is set to 115200bps (was 38400bps)
  * [UTM-712]  - GUI of ntopng is not shown correctly
  * [UTM-708]  - Windows 7 cannot connect to IPsec with IKEv2
  * [UTM-704]  - First attempt in establishing a Net-to-Net IPsec
                 connection fails
  * [UTM-703]  - Dedicated smarthost assigned to a specific uplink
                 does not work
  * [UTM-701]  - Generating a certificate from IPsec global settings
                 fails
  * [UTM-699]  - Traceback during ClamAV start/restart
  * [UTM-696]  - Openvpn certificate .pem not migrated after upgrade
                 from 2.5 to 3.0
  * [UTM-695]  - Certificate field in Vpn Users not clear
  * [UTM-676]  - Generating new certificates and having the CA in
                 revoked list as well will sign certificates making
                 them invalid
  * [UTM-664]  - Certificates are allowed to be reuploaded even if
                 were previously revoked
  * [UTM-663]  - Certificate name is represented as "pem" and "p12"
                 on Chrome web browser
  * [UTM-661]  - Certificate Revocation List still includes the CA
                 of a deleted Certificate
  * [UTM-660]  - 'Unable to get local issuer certificate' error message
                 when viewing uploaded certificate
  * [UTM-658]  - System status graphs are lost after every reboot
  * [UTM-655]  - Spam withelisted mail address is being blocked whilst
                 spamassassin shortcircuit is enabled
  * [UTM-629]  - HTTPS Proxy breaks Windows Updates as well as other
                 services
  * [CORE-616] - Changing the root password from the console menu
                 does not work
  * [CORE-613] - /var directory not owned by root
  * [CORE-596] - Traffic through Snort gets dropped
  * [CORE-595] - Sanitized logs
  * [CORE-583] - Redundant subsections in dashboard page
  * [CORE-575] - Unable to add additional addresses to a new ethernet
                 static uplink
  * [COMMUNITY-30] - Images for SMTP mail statistics graphs are not
                     found

Source: README, updated 2013-11-19


- wong chee tat :)

Tuesday, March 29, 2016

Changelog EFW Community 3.0.5-beta1

Changelog EFW Community 3.0.5-beta1
===================================


Webfilter: integrated
---------------------

[UTM-962] - EFW 3.0 Webfiltering - Blanket Blacklist
[UTM-911] - Automatically download URL filter lists after upgrade
[UTM-893] - Web URL filter - "Activate Antivirus Scan" blocks the
            navigation
[UTM-876] - Wrong permissions on migrated content filter profiles file
[UTM-860] - Proxy authentication keep asking credentials
[UTM-814] - Content filter profiles removed after upgrade
[UTM-810] - Optimize memory usage by using 'file' instead of 'hash' for
            urlfilter lookup tables
[UTM-698] - Unable to download the content filter signatures

Antivirus: ClamAV
-----------------

[UTM-1091] - Exclude selected signatures from ClamAV
[UTM-1060] - ClamAV: new version and bugfixes
[UTM-1049] - ClamAV cron is started when ClamAV is stopped
[UTM-909] - ClamAV throws traceback due to AVENGINE DS empty settings
            file
[UTM-894] - Syntax error in clamavsignatureupdate
[UTM-806] - When clamd is not running when c-icap is starting and needs
            clamd, c-icap does not have a virus engine and let all pass.
[UTM-803] - ClamAV safebrowsing is still enabled also if disabled
[UTM-767] - ClamAV engine is outdated

Bootloader
----------

[CORE-587] - Align baud rate for all appliances

EMI
---

[CORE-1058] - Add command 'status.emi.commands' returning all the emi
              commands
[CORE-1053] - Issues in the script upload and validation procedure
[CORE-1046] - After a validation error some checkbox values are inverted
[CORE-1044] - HolisticLock does not delete the lock files
[CORE-1043] - Kendo Grid multi and all item actions support
[CORE-1040] - Traceback from emi core while loading schema
[CORE-1038] - Make PersistenDict locking working with both threads and
              processes
[CORE-1037] - Create a lock for both threads a processes
[CORE-1032] - Add a validator for host, port and protocol
[CORE-1020] - Add a validator for bindable IP address
[CORE-973] - Add is_installed function for check if a module is
             installed
[CORE-947] - jeditable encoding & turns into & when editing
[CORE-946] - Add a validator for network objects
[CORE-932] - UnicodeDecodeError traceback when browsing Events if
             language is other than English
[CORE-907] - Discording legend in VPN > Certificates
[CORE-877] - Kendo grid autorefresh does not works for pages > 1
[CORE-866] - Event notifications => Events page not displayed with
             Russian language
[CORE-861] - Remove excessive mongostorage log
[CORE-857] - JavaScript support broken in Internet Explorer 9
[CORE-843] - Update notifications gui
[CORE-831] - Change pages margins
[CORE-830] - Multiselect widget width is not correct for resizable pages
[CORE-819] - Icons and legend we are using are in conflict
[CORE-818] - Kendo Grid filters cannot be removed
[CORE-815] - Better connected/disconnected icons for connections page
[CORE-814] - Grids don't scale according with the window size
[CORE-813] - Select fields in editable tables are too wide
[CORE-811] - Wrong and missed fields are not clearly highlighted
[CORE-805] - Kendo style upgrade
[CORE-801] - Add tab-based container widget to EMI
[CORE-800] - Add global multicolumn search bar to Kendo grids
[CORE-794] - "Disconnect" Action in VPN connections page has no effect
             on client
[CORE-793] - An invalid jqGrid() method is called for Kendo grids
             actions
[CORE-788] - HTTP 404 on AD Join and HTTPS proxy tabs
[CORE-783] - Add support for server side filtered nested grid
[CORE-773] - Error modifying entities with invalid index
[CORE-768] - Auto-refresh functionality for KendoUI grid
[CORE-766] - Handle custom actions in legend
[CORE-755] - Add MongoDB storage
[CORE-733] - Installing stealth uplink after removal of packages won't
             register menu for EMI
[CORE-731] - Add ad a module endian.core.set_diff for comparing sets and
             lists
[CORE-721] - Grid rows can't be disabled or deleted
[CORE-696] - Browser is stucking at apply setting
[CORE-684] - You can't edit web filter profiles due to an emi error
[CORE-651] - In System Status some sub categories disappear when
             navigating to VPN connections
[CORE-643] - Wrong icon in VPN
[CORE-630] - Dashboard doesn't display status of Network and Service
[CORE-627] - Status menu changes depending on the selected item
[CORE-614] - EMI Package source is wrong
[CORE-457] - Create Kendo Web Grid widget for EMI

Proxy: HTTPS
------------

[UTM-1154] - Web proxy improvements
[UTM-1138] - Update HTTP Proxy User-Agent list
[UTM-1123] - Update CA bundle
[UTM-1105] - Insufficient HTTPS browser certificate lifespan
[UTM-1059] - Unable to use an upstream proxy for HTTPS traffic in
             transparent mode
[UTM-1041] - Squid stops authenticating because uses IPv6 helper
[UTM-1038] - Upstream HTTP Proxy doesn't forward HTTPS traffic
[UTM-1020] - gmail.com cannot be accessed with https proxy enabled
[UTM-951] - Allow subdomains in HTTPS whitelist
[UTM-943] - Ability just to do transparent URL Filtering opposed to
            Decrypt and Scan at the HTTPS Proxy
[UTM-746] - HTTPS input text field to allow to bypass from certain
            destinations
[UTM-629] - HTTPS Proxy breaks Windows Updates as well as other services

Base system
-----------

[CORE-1066] - OpenSSL security fixes
[CORE-1054] - Implement a class ReadOnlyPersistentDict (read only
              version of PersistentDict)
[CORE-1049] - Allow Zone Status Widget to be used for multiple
              configuration options
[CORE-1048] - OpenSSL remote exploit CVE-2015-0291
[CORE-1039] - OpenSSL CVE-2014-3572 Security Bypass Vulnerability
[CORE-1002] - CVE-2015-0235 - glibc gethostbyname buffer overflow -
              GHOST
[CORE-1001] - Vulnerabilities in rpm package manager: CVE-2014-8118,
              CVE-2013-6435
[CORE-996] - httpd fails to start due to semaphore leak
[CORE-981] - Apache xml2enc module "error Charset ISO-8859-1 not
             supported."
[CORE-975] - Introduce lshw
[CORE-945] - setrouting removes the IPSec table 5
[CORE-908] - SSLv3 POODLE and mitigation
[CORE-905] - Apache AH02550 failed to flush CGI output to client
[CORE-901] - Endian appliances are vulnerable to poodle bleed bug
             (CVE-2014-3566)
[CORE-871] - After Shellshock Bash Patches
[CORE-868] - Shell shock: CVE-2014-7169
[CORE-867] - Shell shock: CVE-2014-6271
[CORE-856] - In country selection rename "Taiwan, Province of China"
             into "Taiwan, Republic of China"
[CORE-761] - The /sbin/service script fails to call restart scripts
[CORE-689] - Missing gconv modules
[CORE-688] - Italian translations
[CORE-622] - During boot iptables rule is not applied
[CORE-592] - ClamAV restart action raises traceback
[CORE-587] - Align baud rate for all appliance
[CORE-551] - Implement a class PersistentDict (persistent dictionary
             stored on with pickle)
[CORE-525] - serial ttyUSB devices for USB 3G Modem keys are not created
[CORE-498] - Backup/Restore should allow inclusion/exclusion of hardware
             data as /etc/businfotab
[CORE-420] - Monit must always exec start/stop/restart in sync

Monitoring, Reporting
---------------------

[UTM-1048] - Translate also OpenVPN log to other languages
[UTM-1034] - Add the possibility to send the iptstate output to a remote
             server
[UTM-1001] - Notifications are not sent
[UTM-919] - Endian log files are all empty!
[UTM-841] - No firewall logs displayed in archive or real-time viewer
[UTM-658] - System status graphs are lost after every reboot
[UTM-650] - Traffic Monitoring documentation

Package management
------------------

[CORE-879] - Migration scripts fails - 481 Error calling function:
             'ConfigDict' object has no attribute 'append'
[CORE-640] - Call to JobsEngine's run_parts function fails

Quality of service
------------------

[CORE-624] - QoS is wrongly configured on PPPoE uplinks
[CORE-610] - Error on trying to modify existing QoS rule
[CORE-609] - Marked traffic is not properly redirected to specified QoS
             class
[CORE-12] - Deleting all QoS rules does not disable QoS entirely

Translations
------------

[CORE-1062] - Update russian templates
[CORE-751] - 3.0 translation update
[CORE-675] - Update Russian translations
[CORE-669] - Update Japanese translations
[CORE-658] - Update Portuguese translations

Service: Intrusion Prevention
-----------------------------

[UTM-1149] - Analysis of Snort performances
[UTM-949] - Policy action image not displayed in grid legend in
            /manage/ips/
[UTM-864] - Snort fails to start after upgrade to 3.0
[UTM-757] - IPS Performance
[UTM-735] - Snort establishes wrong pid filename

Certificate Management
----------------------

[UTM-969] - OpenVPN revoked server certificate still being assigned
[UTM-968] - OpenVPN stuck on default certificate
[UTM-696] - Openvpn certificate .pem not migrated after upgrade from 2.5
            to 3.0

Network configuration
---------------------

[CORE-1050] - Command line netwizard does not include Bridged mode
              option
[CORE-1047] - Command line netwizard does not apply changes
[CORE-1023] - Uplink is not correctly configured in Bridge mode
[CORE-993] - Creating a secondary uplink for HSDPA modem disables it by
             default
[CORE-903] - Netwizard shows "Invalid argument" listing nics
[CORE-796] - Bridged mode misleading error "Gateway must be within
             network"
[CORE-777] - When configuring bridged mode in the network wizard, step 4
             asks for the RED zone which does not exist
[CORE-759] - Rename stealth to bridge and gateway no uplink in the info
             and error messages
[CORE-757] - Switching from Bridged Stealth mode to Routed won't clear
             physdev-is-bridged
[CORE-732] - Stealth uplink can't be enabled without a previously
             configure uplink
[CORE-729] - Implement stealth uplink script
[CORE-726] - Implement stealth uplink type in uplinks editor
[CORE-725] - Implement netwizard dialogue for stealth uplink type
[CORE-724] - Implement 'STEALTH' uplink type
[CORE-718] - HSDPA uplink not working
[CORE-631] - Default gateway is lost after adding an uplink on the same
             interface the main one is using

Service: Quality of Service
---------------------------

[UTM-856] - QoS bandwith priority is not working as expected
[UTM-855] - Qos add automatically TOS value even if is not choosen
[UTM-617] - QoS configuration on a PPPoE or PPTP uplink is applied to
            wrong physical interface
[UTM-306] - "Some Error" is shown when adding QoS Rule with Type any
[UTM-300] - QoS device changes to VPN IPSEC after editing

Authentication layer
--------------------

[CORE-918] - HTTPS Cert Expired Date Extend
[CORE-825] - Error messages at boot about an "unexpected keyword"
[CORE-809] - Traceback on fetch_users()
[CORE-549] - Prepare the Endian Authentication Layer for 3.0

Configuration
-------------

[UTM-807] - Enable switch button does not work on IE

Proxy: HTTP
-----------

[UTM-1156] - Proxy allows access to services on localhost
[UTM-1154] - Web proxy improvements
[UTM-1138] - Updates HTTP Proxy User-Agent list
[UTM-1128] - Google Chrome should be in the useragents list
[UTM-1126] - GUI for TProxy settings
[UTM-1125] - Preserve source IP on non-transparent mode
[UTM-1124] - Preserve mark bits to make policy routing work
[UTM-1041] - Squid stops authenticating because uses IPv6 helper
[UTM-1033] - Transparent HTTP proxy does forward HTTPS connections to an
             upstream proxy
[UTM-1032] - Proxy Graphs is shown if proxy module is not installed
[UTM-986] - Use hash lookup for urlfilter tables
[UTM-966] - Squid's "number of different IP's per user" option doesn't
            work
[UTM-965] - Trying to download URLFilter lists raises ValueError
[UTM-962] - EFW 3.0 Webfiltering - Blanket Blacklist
[UTM-956] - Default virus only HTTP Proxy Access policy does not exist.
[UTM-930] - Dansguardian profile blacklist not migrated to Cyren
[UTM-923] - Squid try the DNS resolution with ipv6 firstly
[UTM-911] - Automatically download URL filter lists after upgrade
[UTM-910] - Add Outgoing Firewall which matches for Transparent HTTP
            Proxy traffic
[UTM-895] - Squid complains of unknown adaptation service or group name
[UTM-893] - Web URL filter - "Activate Antivirus Scan" blocks the
            navigation
[UTM-891] - Dansguardian custom blacklist and whitelist malformed after
            migration to webfilter
[UTM-887] - Special characters on webfilter/access policy prevent squid
            to start after upgrade
[UTM-884] - c-icap complains of not having enough threads per child
[UTM-876] - Wrong permissions on migrated content filter profiles file
[UTM-865] - After migrating Webfilter, Access Policy rule will trigger a
            KeyError Exception
[UTM-860] - Proxy authentication keep asking credentials
[UTM-821] - Replace Uncategorized with Others in the URLfilter
            categories
[UTM-814] - Content filter profiles removed after upgrade
[UTM-792] - Webfilter template is not properly shown when user is denied
            access
[UTM-773] - Dansguardian uninstall leaves a pending logrotate
            configuration file
[UTM-763] - LDAP-Authentication
[UTM-631] - Implement jobgroups to squid and icap jobs
[UTM-562] - Winbindd can't hadle more than 200 connections
[UTM-555] - Squid %postun trigger does not restart squid
[UTM-127] - DansGuardian Profile Name Migration

ICAP
----

[UTM-1111] - Improve release of semaphores for c-icap
[UTM-1076] - c-icap-client blocks on 0 bytes files
[UTM-962] - EFW 3.0 Webfiltering - Blanket Blacklist
[UTM-905] - srv_url_check_commtouch missing
[UTM-904] - Webfilter Update Frequency
[UTM-903] - no "virus found" warning when using Panda
[UTM-899] - Configurable setting for c-icap StartServers
[UTM-893] - Web URL filter - "Activate Antivirus Scan" blocks the
            navigation
[UTM-840] - c-icap can't find IT error template
[UTM-837] - c-icap templates are not properly generated
[UTM-810] - Optimize memory usage by using 'file' instead of 'hash' for
            urlfilter lookup tables
[UTM-806] - When clamd is not running when c-icap is starting and needs
            clamd, c-icap does not have a virus engine and let all pass.
[UTM-780] - c-icap daemon fails to start after migration when parsing
            configuration file

Antispam: SpamAssassin
----------------------

[UTM-845] - IMAP training returns invalid option when remove is ticked

Dashboard
---------

[CORE-996] - httpd fails to start due to semaphore leak
[CORE-870] - Update /usr/local/bin/check-kernel.sh to keep the flag
             until reboot regardless of Kernel
[CORE-745] - Traffic Monitoring always present "The configuration has
             been changed...."
[CORE-733] - Installing stealth uplink after removal of packages won't
             register menu for EMI
[CORE-643] - Wrong icon in VPN
[CORE-630] - Dashboard doesn't display status of Network and Service
[CORE-614] - EMI Package source is wrong

Time
----

[CORE-977] - NTP vulnerabilities ICSA-14-353-01
[CORE-520] - ntpd does not sync time in some conditions

Proxy: SMTP
-----------

[UTM-1108] - Cleanup invalid entry in smtpscan settings file
[UTM-730] - Block file extensions list doesn't include archives

System status
-------------

[CORE-825] - Error messages at boot about an "unexpected keyword"
[CORE-747] - Wrap NIC information in network status
[CORE-587] - Align baud rate for all appliance

Backup
------

[CORE-987] - USB Backup fails if there are only numbers in the name
[CORE-812] - Incoherent time usage in backup filenames
[CORE-770] - Backup restoring from initial wizard fails
[CORE-707] - Backup not sent via mail
[CORE-690] - Changes not applied after restoring a backup

Kernel
------

[CORE-1067] - Upgrade for megaraid_sas driver is required
[CORE-870] - Update /usr/local/bin/check-kernel.sh to keep the flag
             until reboot regardless of Kernel
[CORE-799] - installation fails on LSI 9260-4i
[CORE-657] - Kernel panic with python tainted
[CORE-629] - Update Intel network drivers
[CORE-556] - Fix SHA-256 kernel support

VPN
---

[UTM-1152] - Add a method for getting remote port from OpenVPN Status
[UTM-1147] - Missing INPUTFW rules for OpenVPN services
[UTM-1137] - Job method openvpnjob.client_connect in some situation does
             not create correct configuration
[UTM-1131] - Invalid chars in client-[dis]connect-immediate.d scripts
[UTM-1121] - If the options delayed_triggers is enabled, OpenVPN (and
             the switchboard) does not work as espected
[UTM-1120] - Routes to remote VPN networks are not created with
             delayed_triggers
[UTM-1119] - openvpnutils traceback while getting status the with
             delayed_triggers
[UTM-1118] - OpenVPN job traceback with delayed_triggers
[UTM-1113] - Disabling OpenVPN instance won't remove INPUTFW ACCEPT rule
[UTM-1110] - Unable to connect to OpenVPN instance with more than one
             processor
[UTM-1109] - Revert changes introduced with UTM-1019
[UTM-1094] - Periodically synchronize the OpenVPN sessions file with the
             actual daemons status
[UTM-1090] - Add a method for getting the parsed status information from
             OpenVPN servers
[UTM-1080] - Create a script for dumping the OpenVPN user config
[UTM-1073] - OpenVPN server unmonitored when openvpn package is updated
[UTM-1070] - OpenVPN incomplete version number
[UTM-1063] - OpenVPN Denial of Service (CVE-2014-8104)
[UTM-1056] - OpenVPN init.d script errors on status for an instance
[UTM-1054] - "Override OpenVPN options" not working correctly, "direct
             all client traffic through the VPN server" not working
[UTM-1053] - OpenVPN immediatly closing connection
[UTM-1050] - OpenVPN fails to start since 443 is already used by httpd
[UTM-1044] - OpenVPN fails to start having bogus key parameters in
             server config file
[UTM-1026] - Add on option for setting the OpenVPN log verbosity
[UTM-1019] - Unable to establish multiple net-to-net connection with
             IPSec
[UTM-1018] - Cannot create 2 OpenVPN instances with same port but
             different protocol
[UTM-1003] - Multicore DNAT rule fails functionality when client tries
             to connect
[UTM-989] - Disabling OpenVPN instance won't erase iptables rule
[UTM-987] - In the IPsec gui, '3DES' is translated as 'SHA1' in Italian
[UTM-970] - It is impossible to select existing certificates without the
            private key for IPsec tunnels
[UTM-969] - OpenVPN revoked server certificate still being assigned
[UTM-968] - OpenVPN stuck on default certificate
[UTM-959] - 'Bind only to' option is ignored enabling multiple cores or
            binding on 53/udp
[UTM-955] - Icon not found in VPN connections grid and legend
[UTM-952] - setdnat job is not run when OpenVPN is switched down
[UTM-948] - GW2GW Network Bridged not adding networking to routing
[UTM-947] - StrongSWAN security update due to CVE-2014-2338
[UTM-946] - Unable to create OpenVPN servers on the same TCP and UDP
            ports
[UTM-944] - Missing icon in IPsec connections grid legend
[UTM-940] - Permit to use auto=route instead of auto=add for IPsec
            Net2Net tunnels
[UTM-937] - IPsec IKE integrity migration not working for sha
[UTM-934] - Allow OpenVPN to bind to port 53/UDP
[UTM-913] - IPsec connections not showing anymore after "Action could
            not be performed" warning
[UTM-906] - OpenVPN init script does not identify the interface name in
            some cases
[UTM-885] - VPN Firewall won't filter the traffic
[UTM-877] - OpenVPN server fails to start because of default settings is
            missing
[UTM-875] - IPsec migration to 3.0 is not seamless
[UTM-869] - Error selecting Openvpn certificate
[UTM-867] - OpenVPN server tap interface not taken into account when
            having Gateway-to-Gateway configurations
[UTM-862] - After upgrade to 3.0 the SSL certificates are incorrectly
            chosen
[UTM-859] - Optimize concurrent OpenVPN clients connection speed
[UTM-858] - OpenVPN migration missing options
[UTM-857] - OpenVPN gw2gw logs are empty
[UTM-852] - Concurrent connections are limited to 1024 by ARP cache size
[UTM-848] - OpenVPN fails to start when HA is enabled as Master
[UTM-847] - Traceback when first starting OpenVPN on a Virtual system
[UTM-846] - Wrong IPsec status is reported in the System Status page
[UTM-834] - Net-to-Net IPsec connection between two Endian 3.0
            appliances doesn't establish routing
[UTM-833] - Refresh IPsec GUI page after starting for the first time the
            service
[UTM-828] - Routing between clients on different cores
[UTM-819] - When an OpenVPN connection is disconnected from the gui, all
            the connections for the same user are disconnected
[UTM-817] - Decrease OpenVPN connection time
[UTM-801] - IPsec ESP Group Type not migrated to 3.0
[UTM-799] - IPSec deprecated keyword in strongSwan or weakSwan
[UTM-797] - IPSec Target could not be a DNS name
[UTM-796] - Automatic OpenVPN certificate is shown only after a refresh
[UTM-770] - After upgrade IPsec restartscript fails while trying to
            fetch CIDR for local subnet
[UTM-754] - Enabling OpenVPN server doesn't generate default
            certificates on ARM
[UTM-741] - Disabling a Net-to-Net IPsec connection will leave it in a
            Connected or Connecting state
[UTM-739] - Connections page for VPN users: backend
[UTM-708] - Windows 7 cannot connect to IPsec with IKEv2 machine
            certificate authentication because of a missing Extended Key
            Usage parameter
[UTM-697] - IPsec 3.0 migration missing
[UTM-696] - Openvpn certificate .pem not migrated after upgrade from 2.5
            to 3.0
[UTM-695] - Certificate field in VPN Users not clear
[UTM-688] - Gateway to gateway connection is not initialized
[UTM-645] - IPsec GUI documentation rewrite
[UTM-641] - OpenVPN server documentation rewrite
[UTM-594] - OpenVPN client (GW2GW) GUI
[UTM-592] - OpenVPN client (GW2GW) backend
[UTM-583] - OpenVPN rewrite in EMI with multiple processes and support
            for external authentication backends
[UTM-297] - OpenVPN client crash prevents reconnection

Firewall
--------

[CORE-1013] - Wrong iptables rules in inter-zone if source and
              destination are physical interfaces
[CORE-994] - NEWNOTSYN drops lo traffic blocking Hotspot authentication
[CORE-978] - Squid should be able to run in fully transparent mode
[CORE-878] - Should be possible to disable SIP ALG ( nf_nat_sip ) from
             GUI
[CORE-846] - Interzone - ORANGE to GREEN allowed even if OpenVPN server
             is disabled
[CORE-838] - Reinstalling firewall package will move config files to
             .orig suffix
[CORE-787] - DNAT - rule like e.g "80:443" not work anymore
[CORE-769] - New BADTCP_LOGDROP rule drops invalid traffic
[CORE-763] - Stealth's SNAT exclusions results break iptables rules for
             source nat
[CORE-741] - Outgoing firewall needs a default drop policy rule
[CORE-739] - SNAT must exclude stealth uplink in "ANY Uplink" explosions
[CORE-727] - Implement that outgoing firewall handles stealth uplink
             interface as an uplink and create rules for it
[CORE-712] - VPN firewall is bypassed for specific ports if a DNAT rule
             exists for them
[CORE-656] - Introduce TPROXY functionalities to support Policy Routing
             rules for proxied traffic
[CORE-622] - During boot iptables rule is not applied

Logging & Monitoring
--------------------

[CORE-972] - Syslog complains configuration file is too old thus runs in
             compatibility mode
[CORE-955] - Monit reload ends up having all elements unmonitored
[CORE-938] - Introduce improvements in the logs rotation
[CORE-931] - Logrotate fails if destination directory is missing
[CORE-925] - Live Logs back in time
[CORE-881] - Apache is not reachable, httpd dead but pid file exists
[CORE-875] - Samba log is not rotated
[CORE-874] - Obsolete rrdfix script triggered by cron cyclic (every 5
             minutes)
[CORE-842] - Replace current logsurfer configuration
[CORE-795] - Configure monit to monitor OpenVPN Client and restart in
             case the process dies
[CORE-745] - Traffic Monitoring always present "The configuration has
             been changed...."
[CORE-742] - Patch for procps on ARM to get rid of "Unknown HZ value!"
[CORE-715] - Timestamp
[CORE-709] - Logs are not rotated
[CORE-701] - Logrotate fails after upgrading to 3.0
[CORE-700] - Logrotate fails if IPsec was never enabled
[CORE-667] - Hide configuration of trusted timestamping
[CORE-652] - System Status is not reflecting the true state of the
             services it reports
[CORE-602] - PID files removed when daemons are restarted
[CORE-491] - efw-update log is not rotated

Jobsengine
----------

[CORE-1061] - JobsEngine status duplicated
[CORE-1030] - restart job stuck / hanging - contiuously being delayed
              execution
[CORE-1027] - jobsengine restart deadlock state with defunct child and
              no socket file
[CORE-1005] - Continue on parsing error in /var/run/jobsengine.status
[CORE-920] - File descriptors are left open on jobs execution
[CORE-916] - Jobsengine lock is removed
[CORE-782] - Create the settings file path (if not exists) before
             executing require_enabled_service
[CORE-771] - Improve jobsengine module reload
[CORE-710] - Allow jobs to access to its current status
[CORE-640] - Call to JobsEngine's run_parts function fails

Artwork
-------

[COMMUNITY-30] - Images for SMTP mail statistics graphs are not found

Community packages
------------------

[COMMUNITY-98] - Unable to deactive uplinks on Dashboard screen
[COMMUNITY-96] - EFW 3.0 Webfiltering - Blanket Blacklist
[COMMUNITY-87] - Dependency loop between endian-release-community and
                 efw-community

Event Notifications
-------------------

[CORE-1051] - Event notifications improvements
[CORE-1045] - Sort in events notification kendo grid is broken
[CORE-1042] - checkboxes in Events grid are not clickable
[CORE-1041] - Filters are not working for Events grids
[CORE-1035] - Notifications logrotate configuration template is not
              applied
[CORE-1028] - Notifications mail tagged as 'Bad Header' warnings by
              amavis
[CORE-986] - After migration Notifications daemon keeps spawning
[CORE-985] - Provide SysV init script for Notifications daemon
[CORE-984] - Have Notifications daemon monitored
[CORE-983] - Restart notifications after migration and load its plugins
[CORE-974] - Missing configuration migration script for Event
             Notification
[CORE-948] - Mail subject does not contain ID anymore
[CORE-932] - UnicodeDecodeError traceback when browsing Events if
             language is other than English
[CORE-927] - Event notifications->Events page causes traceback
[CORE-898] - Grid colapses if an error is to be shown up
[CORE-895] - Change label to "Use SMTP Proxy service" for Event
             Notifications
[CORE-894] - After using SMTP Proxy settings mails still sent from there
             even if switching back to default
[CORE-890] - Uploading the same custom script twice for Event
             Notifications will raise EMI traceback
[CORE-889] - Assigning a script will prompt BASH syntax error script for
             Events
[CORE-886] - In events notification grid checkboxes aren't editable to
             change the event status
[CORE-885] - Remain on the same page after editing an element
[CORE-883] - Settings for Event Notifications aren't updated if set to
             use SMTP Proxy ones
[CORE-882] - Update settings against SMTP Proxy each time the service is
             reloaded
[CORE-880] - No e-mail notifications sent when triggered using Gmail as
             Smarthost
[CORE-866] - Event notifications => Events page not displayed with
             Russian language
[CORE-845] - Re-engineer current mailfile executable
[CORE-841] - Create a mail plugin for custom notification daemon
[CORE-840] - Custom notification daemon plugin-based
[CORE-839] - Remove logsurfer and create a new notification daemon
[CORE-833] - Permit Smarthost mail delivery for Events Notifications
[CORE-746] - Custom Event to notify
[CORE-603] - In event notification the icons legend is missing

Installer
---------

[CORE-1067] - Upgrade for megaraid_sas driver is required
[CORE-1065] - Adjust disk space calculation for small products (mini-25)
[CORE-799] - installation fails on LSI 9260-4i

Community Updates
-----------------

[COMMUNITY-85] - Unable to ADD second Uplink
[COMMUNITY-77] - setting red interface as a gateway i have the ping to
                 IP addresses
[COMMUNITY-75] - The Device name of Quality of service is changed after
                 modifying
[COMMUNITY-72] - Content filter does not appear to work
[COMMUNITY-71] - No access to webserver or ssh from green to orange
                 network (DMZ)
[COMMUNITY-70] - Can not enable or disable IPSEC connection by GUI
                 ceckbox
[COMMUNITY-66] - Upgraded to 3.0 from 2.5.2
[COMMUNITY-59] - Upgrading to development bleeding edge
[COMMUNITY-56] - Ipsec net-to-net errpr after save
[COMMUNITY-54] - unable to connect to remote ipsec/psk network
[COMMUNITY-39] - Squid package upgrade fails on upgrade to 3.0

Service: DHCP
-------------

[UTM-993] - Push DEFAULT_GATEWAY when in Stealth for DHCP
[UTM-916] - Clients are not registered in local DNS
[UTM-863] - DHCP daemon is not started after upgrade to 3.0 when Hotspot
            is enabled

Source: README, updated 2015-04-08



- wong chee tat :)