I recently read about the new service pack for Netranger. I already have the sensor upgraded to 3.0(1)S7. Will I need to reinstall the latest signature pack after installing the service pack? Also, is there a mailing list I can get on to learn of these updates?
This service pack is a Beta release that adds additional decoding algorithms to the sensor. These algortihms are needed for the sensor to accurately deal with certain encoding techniques that could be used to obfscate or hide web traffic. It was released in Beta form to provide our customers with the most timely mechanism to protect against these new encoding techniques. This service pack has not completed QA and therefore there may be defects that we are currently unaware of in the software.
If this service pack is installed it will cause some difficulty in upgrading your systems in the future as the installers will recognize this as a Beta and won't want to install an FCS over it. There is a workaround for this. If you decide to install this Beta on your system I would recommend that after installation you manually change the following entry in your IMAGE_VERSION file locates in /usr/nr on the sensor:
change the line that reads 3.0(1.43)S5(0.43) to 3.0(1)S6
This will allow our installers to view the system as a base install 3.0(1)S6 sensor and you can then treat it as such. You will have to reapply the S7 sigupdate as this Betae is based on an S6 signature file.
Please note that in dealing with the TAC on any problems that you may encounter with this Beta you will have to identify it as v3.0(1.43)S5(0.43) or they will mistakenly attribute the problems to the incorrect binary file.
We should be releasing in 2-3 weeks barring any complications in QA. When we release the FCS version it will be released with the most bound with the most recent signature update. At the moment I would predict S9, but it could be S10. S8 will be posted sometime this week so I'm sure that we will be beyond it.
Login to the FXOS chassis manager.
Direct your browser to https://hostname/, and log-in using the user-name and password.
Go to Help > About and check the current version:
Check the current version availa...
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...