background image

Upgrade to Fireware v11.12.1

Release Notes

15

Upgrade Notes for XTMv

You cannot upgrade an XTMv device to FireboxV. For Fireware v11.11 and higher, the XTMv device is a 64-bit
virtual machine. You cannot upgrade an XTMv device from Fireware v11.10.x or lower to Fireware v11.11 or
higher. Instead, you must use the OVA file to deploy a new 64-bit Fireware v11.11.x XTMv VM, and then use
Policy Manager to move the existing configuration from the 32-bit XTMv VM to the 64-bit XTMv VM. For more
information about how to move the configuration, see

Fireware Help

. For more information about how to deploy

a new XTMv VM, see the latest

WatchGuard XTMv Setup Guide

available

here

. When your XTMv instance has

been updated to v11.11 or higher, you can then use the usual upgrade procedure, as detailed below.

WatchGuard updated the certificate used to sign the .ova files with the release of Fireware
v11.11. When you deploy the OVF template, a certificate error may appear in the OVF template
details. This error occurs when the host machine is missing an intermediate certificate from
Symantic (Symantec Class 3 SHA256 Code Signing CA), and the Windows CryptoAPI was
unable to download it. To resolve this error, you can download and install the certificate from
Symantec.

Back Up Your WatchGuard Servers

It is not usually necessary to uninstall your previous v11.x server or client software when you upgrade to WSM
v11.12.1. You can install the v11.12.1 server and client software on top of your existing installation to upgrade
your WatchGuard software components. We do, however, strongly recommend that you back up your
WatchGuard Servers (for example, your WatchGuard Management Server) to a safe location before you
upgrade. You will need these backup files if you ever want to downgrade.

To back up your Management Server configuration, from the computer where you installed the Management
Server:

1. From WatchGuard Server Center, select

Backup/Restore Management Server

.

The WatchGuard Server Center Backup/Restore Wizard starts

.

2. Click

Next

.

The Select an action screen appears.

3. Select

Back up settings

.

4. Click

Next

.

The Specify a backup file screen appears.

5. Click

Browse

to select a location for the backup file. Make sure you save the configuration file to a

location you can access later to restore the configuration.

6. Click

Next

.

The WatchGuard Server Center Backup/Restore Wizard is complete screen appears.

7. Click

Finish

to exit the wizard.

Summary of Contents for Firebox 1500

Page 1: ...oviding several minor feature enhancements For more information on the bug fixes and enhancements in this release see the Enhancements and Resolved Issues section With this release we re also proud to...

Page 2: ...icate If you use the CLI to regenerate these certificates after you upgrade you must redistribute the new Proxy Authority certificate to your clients or users will receive web browser warnings when th...

Page 3: ...can use your existing feature key If you do not have a feature key for your device you can log in to the WatchGuard website to download it Note that you can install and use WatchGuard System Manager...

Page 4: ...s provided by third party companies remain in English Fireware Web UI The Web UI will launch in the language you have set in your web browser by default WatchGuard System Manager When you install WSM...

Page 5: ...or information on WatchGuard Dimension see the Dimension Release Notes Single Sign On Agent Includes Event Log Monitor Single Sign On Client Single Sign On Exchange Monitor1 Terminal Services Agent2 M...

Page 6: ...lient for Mac powered by NCP Authentication Support This table gives you a quick view of the types of authentication servers supported by key features of Fireware Using an authentication server gives...

Page 7: ...N client Mobile VPN with IPSec for Android devices Mobile VPN with SSL for Windows 4 4 Mobile VPN with SSL for Mac Mobile VPN with SSL for iOS and Android devices Mobile VPN with L2TP 6 Mobile VPN wit...

Page 8: ...ave WatchGuard System Manager client software only installed If you install WatchGuard System Manager and WatchGuard Server software Minimum CPU Intel Core or Xeon 2GHz Intel Core or Xeon 2GHz Minimum...

Page 9: ...install WSM v11 12 1 or to upgrade WatchGuard System Manager from an earlier version to WSM v11 12 1 Fireware OS If your Firebox is running Fireware v11 10 or later you can upgrade the Fireware OS on...

Page 10: ...XTM 8 Series XTM_OS_XTM8_11_12_1 exe xtm_xtm8_11_12_1 zip Firebox M500 Firebox_OS_M400_M500_11_12_1 exe firebox_M400_M500_11_12_1 zip XTM 5 Series XTM_OS_XTM5_11_12_1 exe xtm_xtm5_11_12_1 zip Firebox...

Page 11: ...his release l WG Authentication Gateway_11_11_1 exe SSO Agent software required for Single Sign On and includes optional Event Log Monitor for clientless SSO l WG Authentication Client_11_11 msi SSO C...

Page 12: ...hat s New in Fireware v11 12 presentation or Fireware Help TCP port 4100 now used for firewall user authentication only Beginning with Fireware v11 12 TCP port 4100 is used only for firewall user auth...

Page 13: ...ault policies and services that the setup wizards configure depend on the version of Fireware installed on the Firebox and on whether the Firebox feature key includes a license for subscription servic...

Page 14: ...rocess l We recommend you use Fireware Web UI to upgrade to Fireware v11 12 1 You can also use Policy Manager if you prefer l We strongly recommend that you save a local copy of your Firebox configura...

Page 15: ...ng CA and the Windows CryptoAPI was unable to download it To resolve this error you can download and install the certificate from Symantec Back Up Your WatchGuard Servers It is not usually necessary t...

Page 16: ...ou have already installed Fireware v11 12 1 on your computer you must run the Fireware v11 12 1 installer twice once to remove v11 12 1 software and again to install v11 12 1 Upgrade to Fireware v11 1...

Page 17: ...the Gateway Wireless Controller Summary tab select Manage Firmware to download the latest AP firmware to the Firebox again You cannot install the AP firmware on a Firebox that uses Fireware v11 4 x o...

Page 18: ...orted version the upgrade is prevented If you try to schedule an OS update of managed devices through a Management Server the upgrade is also prevented If you use the Fireware Web UI to upgrade your d...

Page 19: ...atchGuard servers are running Downgrade from Fireware v11 12 1 to Fireware v11 x If you use the Fireware Web UI or CLI to downgrade from Fireware v11 12 1 to an earlier version the downgrade process r...

Page 20: ...e resolves kernel crashes on Firebox T70 M200 and M300 devices configured in drop in mode 92760 92677 l The Turkish timezone settings have been adjusted to eliminate timezone changes throughout the ye...

Page 21: ...when Gateway AV signatures are manually updated in Firebox System Manager 90792 Proxies and Services l The Firebox now includes the host IP address when it sends data to the WebBlocker Websense datab...

Page 22: ...sites list in Fireware Web UI 90621 l Failed authentication attempts from WatchGuard System Manager for the status user now produce a log message log in attempt was rejected invalid credentials 92445...

Page 23: ...upported for v11 x releases For information on how to start and use the CLI see the Command Line Reference Guide You can download the latest CLI guide from the documentation web site at http www watch...

Page 24: ...Technical Assistance Release Notes 24...

Reviews: