HP OfficeConnect Firewall manual

Page 2

-A crash on ALIKE daemon task is fixed by merging the two tasks "ALIKE_d"

and

"ALIKEMonitor since the crash is identified as these are trying to access/free

common objects in the VPN.

-The maximum URL size is increased to 2048 as it is recognised to cause problem

in content filtering.

-The PPPoE issue with some servers is fixed, as the box will remove the existing

AP protocol objects whenever LCP re-establishes, to make it compatible with such

server behaviour. Updates for handling LCP/AP connection abort is added.

-Updates for VPN hangs issue when simultaneous negotiation happens is included.

-The issue of VPN with 1-2-1 NAT is not working is solved by adding the static IPs

with mask 255.255.255.255 for each 1-2-1 NAT alias interfaces.

-Updates to resolve VPN issue with INVALID_MAJOR_VERSION error when re- negotiating

Phase 2 is added. The root cause is that phase 2 negotiation is three- message

exchange, there is a chance that because the last phase 2 message is processed by

IKE, IPsec packet has already arrived. In NAT traversal scenario, the IPsec packet

is encapsulate in IKE NAT-T UDP, thus, will reach IKE daemon. The update prevents

IKE from processing IPsec NAT-T packet.

-PPTP would fail with no such user message just after the boot time since the VPN

requires 5 minutes delay to complete its configuration. Now the VPN will complete

its configuration when the box rebooted.

-Fixed an issue with Safenet client that safenet client is not renegotiating phase1

after the SA life timeout. VPN Firewall is modified to make it compatible

with

safenet client's behaviour.

________________________________________________________________________________

3.Recommendations when using this release

____________________________________________________________________________

4.Known problems with this release

- The VPN is updated to start without any delay. Though the other components

Image 2
Contents Important Read this Before Installing or Using this Software Page