background image

Authentication

l

Active Directory authentication no longer allows concurrent connections from user names that differ only
in case.

[67433]

l

The session table now correctly displays users that authenticate with SSO.

[92759]

Certificates

l

CA Manager now correctly prevents the generation of a certificate with an invalid lifetime setting.

[92803]

l

The CLI command

Upgrade certificate

now regenerates the default self-signed certificates if they have

been removed.

[92496]

l

This release resolves an issue that prevented the certificate portal from providing the correct Proxy
Authority certificate for download.

[92802]

l

An issue that caused managed device templates to fail to apply to devices installed with Fireware
v11.10.x because of the WG-Cert Portal Policy has been resolved.

[92755]

l

You can now connect remotely to manage a Firebox configured with PPPoE that uses a third-party
certificate as its Webserver Certificate.

[92489]

Logging and Monitoring

l

You can now resize the Traffic Monitor search input field.

[88613]

l

You can now configure logging and notification settings for the blocked sites list in Fireware Web UI.

[90621]

l

Failed authentication attempts from WatchGuard System Manager for the

status

user now produce a log

message:

log in attempt was rejected - invalid credentials

.

[92445]

Wireless and AP

l

AP 100/102/200 firmware v1.2.9.11 and AP300 firmware v2.0.0.6 resolve several stability issues.

[88333, 91689, 91711, 92104, 92128, 92711, 92823]

l

AP 100/102/200 firmware v1.2.9.11 and AP300 firmware v2.0.0.6 resolve issues with Remote
VPN deployment.

[92454, 92562, 92579, 92580, 92909]

l

This release resolves several issues that caused crashes of the

gwcd

process.

[92840, 92863, 92864]

l

Gateway Wireless Controller now supports wireless country settings of AP devices in New Caledonia.

[92851]

l

Clients connected to AP120 and AP320 devices managed by Gateway Wireless Controller now show
correct signal strength values.

[92805]

l

The Gateway Wireless Controller Wireless Client List now shows a location that matches the location
configured for the AP device.

[90228]

l

Gateway Wireless Controller can now correctly manage an AP120 or AP320 located behind a routed
network.

[92972]

l

Gateway Wireless Controller can now discover unpaired AP300 devices installed with AP firmware
v2.0.0.6 over-the-air.

[91318]

Enhancements and Resolved Issues in Fireware v11.12.1

22

WatchGuard Technologies, Inc.

Summary of Contents for Firebox 1500

Page 1: ...oviding several minor feature enhancements For more information on the bug fixes and enhancements in this release see the Enhancements and Resolved Issues section With this release we re also proud to...

Page 2: ...icate If you use the CLI to regenerate these certificates after you upgrade you must redistribute the new Proxy Authority certificate to your clients or users will receive web browser warnings when th...

Page 3: ...can use your existing feature key If you do not have a feature key for your device you can log in to the WatchGuard website to download it Note that you can install and use WatchGuard System Manager...

Page 4: ...s provided by third party companies remain in English Fireware Web UI The Web UI will launch in the language you have set in your web browser by default WatchGuard System Manager When you install WSM...

Page 5: ...or information on WatchGuard Dimension see the Dimension Release Notes Single Sign On Agent Includes Event Log Monitor Single Sign On Client Single Sign On Exchange Monitor1 Terminal Services Agent2 M...

Page 6: ...lient for Mac powered by NCP Authentication Support This table gives you a quick view of the types of authentication servers supported by key features of Fireware Using an authentication server gives...

Page 7: ...N client Mobile VPN with IPSec for Android devices Mobile VPN with SSL for Windows 4 4 Mobile VPN with SSL for Mac Mobile VPN with SSL for iOS and Android devices Mobile VPN with L2TP 6 Mobile VPN wit...

Page 8: ...ave WatchGuard System Manager client software only installed If you install WatchGuard System Manager and WatchGuard Server software Minimum CPU Intel Core or Xeon 2GHz Intel Core or Xeon 2GHz Minimum...

Page 9: ...install WSM v11 12 1 or to upgrade WatchGuard System Manager from an earlier version to WSM v11 12 1 Fireware OS If your Firebox is running Fireware v11 10 or later you can upgrade the Fireware OS on...

Page 10: ...XTM 8 Series XTM_OS_XTM8_11_12_1 exe xtm_xtm8_11_12_1 zip Firebox M500 Firebox_OS_M400_M500_11_12_1 exe firebox_M400_M500_11_12_1 zip XTM 5 Series XTM_OS_XTM5_11_12_1 exe xtm_xtm5_11_12_1 zip Firebox...

Page 11: ...his release l WG Authentication Gateway_11_11_1 exe SSO Agent software required for Single Sign On and includes optional Event Log Monitor for clientless SSO l WG Authentication Client_11_11 msi SSO C...

Page 12: ...hat s New in Fireware v11 12 presentation or Fireware Help TCP port 4100 now used for firewall user authentication only Beginning with Fireware v11 12 TCP port 4100 is used only for firewall user auth...

Page 13: ...ault policies and services that the setup wizards configure depend on the version of Fireware installed on the Firebox and on whether the Firebox feature key includes a license for subscription servic...

Page 14: ...rocess l We recommend you use Fireware Web UI to upgrade to Fireware v11 12 1 You can also use Policy Manager if you prefer l We strongly recommend that you save a local copy of your Firebox configura...

Page 15: ...ng CA and the Windows CryptoAPI was unable to download it To resolve this error you can download and install the certificate from Symantec Back Up Your WatchGuard Servers It is not usually necessary t...

Page 16: ...ou have already installed Fireware v11 12 1 on your computer you must run the Fireware v11 12 1 installer twice once to remove v11 12 1 software and again to install v11 12 1 Upgrade to Fireware v11 1...

Page 17: ...the Gateway Wireless Controller Summary tab select Manage Firmware to download the latest AP firmware to the Firebox again You cannot install the AP firmware on a Firebox that uses Fireware v11 4 x o...

Page 18: ...orted version the upgrade is prevented If you try to schedule an OS update of managed devices through a Management Server the upgrade is also prevented If you use the Fireware Web UI to upgrade your d...

Page 19: ...atchGuard servers are running Downgrade from Fireware v11 12 1 to Fireware v11 x If you use the Fireware Web UI or CLI to downgrade from Fireware v11 12 1 to an earlier version the downgrade process r...

Page 20: ...e resolves kernel crashes on Firebox T70 M200 and M300 devices configured in drop in mode 92760 92677 l The Turkish timezone settings have been adjusted to eliminate timezone changes throughout the ye...

Page 21: ...when Gateway AV signatures are manually updated in Firebox System Manager 90792 Proxies and Services l The Firebox now includes the host IP address when it sends data to the WebBlocker Websense datab...

Page 22: ...sites list in Fireware Web UI 90621 l Failed authentication attempts from WatchGuard System Manager for the status user now produce a log message log in attempt was rejected invalid credentials 92445...

Page 23: ...upported for v11 x releases For information on how to start and use the CLI see the Command Line Reference Guide You can download the latest CLI guide from the documentation web site at http www watch...

Page 24: ...Technical Assistance Release Notes 24...

Reviews: