background image

Patch 86222-10 For Rapier Switches and AR800 Series Modular Switching Routers

5

Patch 86222-10 for Software Release 2.2.2
C613-10319-00 REV J

Debug messages are no longer generated when a Q.931 Advise of Charge 
Notification message is received.

TCP sessions would get stuck in the FINWAIT2 state if the remote host did 
not send a FIN message when required. The router now starts a timer when 
a TCP session enters the FINWAIT2 state and will automatically close the 
session if the timer expires.

The SET IP FILTER command was not correctly handling the ICMPTYPE 
and ICMPCODE parameters. This issue has been resolved.

The router will now accept DHCP messages that are greater than or equal 
to 576 bytes in size, and reject any message smaller than 576 bytes. This 
operation conforms to RFC 1541.

ISAKMP quick mode exchanges are now committed if any traffic is received 
over the newly generated SA. This improves stability in very lossy networks 
where the commit message may get lost.

ISAKMP debugging caused a fatal error when the debugging mode was set 
to ALL and PFS was enabled. This issue has been resolved.

PPPoE interfaces with IDLE set to ON would not retry active discovery 
when more data was received if active discovery had previously failed. This 
issue has been resolved.

A memory loss occurred when certificates were used by ISAKMP. This issue 
has been resolved.

ISAKMP heartbeats are no longer transmitted if the lower layer interface is 
down. This stops ISAKMP heartbeats from bringing up links in dial-up 
environments.

In some conditions it was possible for ISAKMP packets to be lost and not 
retransmitted. Incoming ISAKMP messages are now validated before 
stopping retransmission of the previous message.

The COS_DST bit on ARL for L3 interface should be 0x4 (higher priority) for 
CPU ports. This has been corrected.

PCR: 01197

Module: Q931

Network affecting: No

PCR: 01198

Module: TCP

Network affecting: No

PCR: 01199

Module: IPG

Network affecting: No

PCR: 01202

Module: DHCP

Network affecting: No

PCR: 01203

Module: ISAKMP

Network affecting: No

PCR: 01204

Module: ISAKMP

Network affecting: No

PCR: 01205

Module: PPP

Network affecting: No

PCR: 01206

Module: ISAKMP

Network affecting: No

PCR: 01207

Module: ISAKMP

Network affecting: No

PCR: 01209

Module: ISAKMP

Network affecting: No

PCR: 01211

Module: SWI

Network affecting: No

Summary of Contents for 86222-10

Page 1: ...www alliedtelesyn co nz documentation documentation html AR800 Series Modular Switching Router Documentation Set for Software Release 2 2 1 available on the Documentation and Tools CD ROM packaged wi...

Page 2: ...een made for the cold start trap After a 10s delay all interfaces which are UP have a link trap generated for them After that link traps are sent as normal Processing invalid UDP packets caused a memo...

Page 3: ...re Release 2 2 2 and the following enhancements Tunnel creation failed when attempting to establish a point to point tunnel from an ATR router tunnel originator to another vendor s router This issue h...

Page 4: ...A watchdog timout occurred when the router received an HTTP message with an over length header Normal HTTP requests would also occasionally cause watchdog timeouts These issues have been resolved The...

Page 5: ...o ALL and PFS was enabled This issue has been resolved PPPoE interfaces with IDLE set to ON would not retry active discovery when more data was received if active discovery had previously failed This...

Page 6: ...g corruption of the ARL table eventually causing the switch to lock up This issue has been resolved Tagged packets with invalid VLAN identifiers are now discarded The INFILTERING parameter of the SET...

Page 7: ...e receiver did not get the data stream This issue has been resolved The Rapier G6 base ports sometimes experienced spurious link up or link down events This issue has been resolved Features in 86222 0...

Page 8: ...a result after multiple additions and deletions no more IPv6 interfaces could be added These issues have been resolved The CREATE CONFIG command now adds PKI certificates to the script in the same ord...

Page 9: ...oducts in aggressive mode exchanges Support has been added for the 8624XL 80 switch with 48VDC power supply In a dual policy configuration the firewall would lock up under load The firewall would also...

Page 10: ...rfaces Ethernet interface events can now generate triggers The Telnet server s listen port can now be configured to a number in the range 1 to 65535 excluding any ports already assigned as listen port...

Page 11: ...olved and enhancements released in previous patches for Software Release 2 2 2 and the following enhancements When an interface on the firewall was configured with a global IP address of 0 0 0 0 outgo...

Page 12: ...ase 2 2 2 The DHCP server identified the wrong port numbers for incoming DHCP requests causing DHCP replies to be sent to the wrong port This issued has been resolved The IP flow cache occasionally ge...

Page 13: ...dress of the interface and defaults to INFINITE PREF must be less than or equal to VALID IPV6 now checks and ensures that if either PREF or VALID is specified PREF is less than or equal to VALID When...

Page 14: ...14 Patch Release Note Patch 86222 10 for Software Release 2 2 2 C613 10319 00 REV J...

Reviews: