Allied Telesis 86222-27 manual PCR Module NTP Network affecting No

Page 9

Patch 86222-27 For Rapier Switches

9

Features in 86222-24

Patch file details are listed in Table 4:

Table 4: Patch file details for Patch 86222-24.

Base Software Release File

86s-222.rez

 

 

Patch Release Date

6-Mar-2003

 

 

Compressed Patch File Name

86222-24.paz

 

 

Compressed Patch File Size

433360 bytes

 

 

Patch 86222-23 includes all issues resolved and enhancements released in previous patches for Software Release 2.2.2, and the following enhancements:

PCR: 02071

Module: NTP

Network affecting: No

When a NTP packet was received from an NTP server (mode 4) the router acted as a client, and sent a reply back to the server, but did not remove the peer association. This meant that the Dynamic Peers list, viewed using the SHOW NTP command, displayed incorrect dynamic peer associations. This issue has been resolved.

PCR: 02202

Module: FIREWALL/IP NAT

Network affecting: No

Previously, when Firewall or IP NAT was enabled, any fragmented IP packets had to be reassembled so they could be processed. If the fragments could not be reassembled, the packet was dropped. Reassembly could only occur if the combined packet (IP header, and protocol header, and data) was no more than 1800 bytes. An additional limit of no more than eight fragments was also imposed. This PCR implements enhanced fragment handling for Firewall and IP NAT. Each module can now be configured to process fragmented packets of specified protocol types without needing to reassemble the packet. The number of fragments a packet may consist of is also configurable. This enhanced fragment handling is disabled by default.

To enable enhanced fragmentation for Firewall, use the command:

ENABLE FIREWALL POLICY=policy_name

FRAGMENT={ICMPUDPOTHER}

To enable enhanced fragmentation for IP NAT, use the command:

ENABLE IP NAT FRAGMENT={ICMPUDPOTHER}

To disable enhanced fragmentation for Firewall, use the command:

DISABLE FIREWALL POLICY=policy_name

FRAGMENT={ICMPUDPOTHER}

To disable enhanced fragmentation for IP NAT, use the command

DISABLE IP NAT FRAGMENT={ICMPUDPOTHER}

To configure the number of fragments permitted per packet for Firewall, use the command:

SET FIREWALL FRAGMENT=8...50

To configure the number of fragments permitted per packet for IP NAT, use the command:

SET IP NAT FRAGMENT=8...50

Patch 86222-27 for Software Release 2.2.2 C613-10319-00 REV Z

Image 9
Contents Patch For Rapier Switches PCR Module IPG Level PCR 03615 Module Load LevelPCR Module STP, SWI Level PCR Module Firewall Level PCR 02498 Module Vlan Network affecting NoPCR Module SWI Level PCR Module IPG, SWI LevelPCR Module Ospf Level PCR 03438 Module Dhcp LevelPCR 03465 Module Dhcp Level PCR Module NTP LevelPCR Module STP Level PCR Module Firewall Network affecting NoPCR Module Network affecting No PCR Module Vrrp Level PCR Module TCP LevelPCR 03202 Module Core Level Some issues with Dvmrp forwarding have been resolvedPCR 03217 Module Dvmrp Level PCR 03218 Module Dvmrp LevelPCR Module TTY Level PCR Module FILE, INSTALL, SCR LevelPCR 03346 Module Snmp Level PCR 03378 Module Dhcp LevelPCR Module FIREWALL/IP NAT Network affecting No PCR Module NTP Network affecting NoPCR Module Ospf Network affecting No PCR Module IPG Ping Network affecting NoPCR Module IPG Network affecting No PCR 03027 Module Dhcp Network affecting NoPCR 03080 Module Dvmrp PCR 03067 Module Dhcp LevelPCR 03095 Module Dhcp Level PCR 02574 Module Dvmrp Network affecting NoPCR 02587 Module OSPFNetwork affecting No PCR 03012 Module TTYNetwork affecting NoPCR Module FFS File TTY Network affecting No PCR Module VRRP, TRG Network affecting No PCR Module IP Network affecting NoPCR 02396 Module Dhcp Network affecting No PCR Module CORE, FFS, File Network affecting NoPCR Module DVMRP, IPG Network affecting No PCR 02427 Module Dhcp Network affecting NoPCR Module TTY Network affecting No PCR Module OSPF, IPG Network affecting NoPCR Module IPG/FIREWALL Network affecting No PCR Module Vrrp Network affecting NoPCR 02329 Module Dhcp Network affecting No PCR Module Ipsec Network affecting NoPCR 02397 Module Dvmrp Network affecting No PCR Module IPG/IGMP Network affecting NoPatch file details for Patch 86222-20 are listed in Table PCR Module Igmp Network affecting YesProxy Arp can now be used on Vlan interfaces PCR Module CORE, Snmp Network affecting NoPCR 02198 Module Dhcp Network affecting Yes PCR Module LOG Network affecting No Log messages are no longer stored in NVSPCR Module File Network affecting No PCR Module DNS Network affecting No PCR Module DHCP, IPG Network affecting NoPCR Module PIM, DVMRP, SWI Network affecting No PCR Module DUART, TM Network affecting NoPatch file details for Patch 86222-19 are listed in Table PCR Module STP Network affecting No PCR Module IPG Network affectingNoPCR Module Dhcp Network affecting No Patch file details for Patch 86222-18 are listed in Table PCR Module Load Network affecting NoPCR Module Ospf Network affecting Yes PCR Module FILE, FFS Network affecting NoPCR Module FFS Network affecting No PCR Module TRG Network affecting NoPCR 02099 Module Dhcp Network affecting No Patch file details for Patch 86222-16 are listed in TablePatch file details for Patch 86222-15 are listed in Table PCR 02015 Module Snmp Network affecting NoStatic ARPs can now be added to tagged vlans PCR Module Switch Network affecting NoPCR 02035 Module Vlan Network affecting No PCR Module Ping Network affecting NoPCR Module Telnet Network affecting No Patch file details for Patch 86222-13 are listed in TablePatch file details for Patch 86222-12 are listed in Table Has been added to the following commandsPCR 01257 Module Dhcp Network affecting No PCR Module IPG/VRRP Network affecting NoPCR 01275 Module FIREWALLNetwork affecting No PCR 01274 Module SWINetwork affecting NoPCR 01276 Module SWINetwork affecting No PCR 01287 Module OSPFNetwork affecting NoPCR Module Trigger Network affecting No PCR 02007 Module Dhcp Network affecting NoPCR Module IPG, VLAN, SWI Network affecting No Patch file details for Patch 86222-11 are listed in TablePatch file details for Patch 86222-10 are listed in Table Patch file details for Patch 86222-09 are listed in TablePCR Module STP, SWI Network affecting Yes PCR Module SWI, CORE, IPG Network affecting No PCR Module PRI Network affecting NoPatch file details for Patch 86222-08 are listed in Table PCR Module PIM Network affecting No PCR Module L2TP Network affecting YesPCR 01018 Module Dhcp Network affecting No PCR Module IPG,FIREWALL Network affecting NoPCR Module L2TP, IPG Network affecting No PCR Module Http Network affecting NoPCR Module Q931 Network affecting No PCR Module TCP Network affecting NoPCR 01214 Module SWINetwork affecting No PCR 01209 Module ISAKMPNetwork affecting NoPCR 01216 Module STPNetwork affecting No PCR 01219 Module VLAN,SWINetwork affecting NoPatch file details for Patch 86222-06 are listed in Table PCR Module Core Network affecting No Patch file details for Patch 86222-05 are listed in TablePCR Module PKI Network affecting No PCR Module IPv6 Network affecting NoPCR 01187 Module IPGNetwork affecting No PCR 01186 Module FIREWALLNetwork affecting NoPatch file details for Patch 86222-04 are listed in Table PCR Module CORE, SWI Network affecting NoPCR 01165 Module Dhcp Network affecting No PCR 01167 Module Enco Network affecting NoPCR Module ETH, Trigger Network affecting No Patch file details for Patch 86222-01 are listed in Table PCR 01100 Module Dhcp Network affecting NoPKI enrolment no longer causes message validation to fail Description This command disables Icmp reply messages This enhancement introduces three new commandsSee Also Enable IP Echoreply See Also Enable IP IcmpreplyHas two new commands This enhancement modifies one commandSee Also Enable IP Igmp Allgroup Examples To show information about IGMP, use the commandSee Also Disable IP Igmp Allgroup New CommandsAvailability Disable IP Igmp Allgroup