background image

Patch 86222-10 For Rapier Switches and AR800 Series Modular Switching Routers

9

Patch 86222-10 for Software Release 2.2.2
C613-10319-00 REV J

When large numbers of sessions were being handled the firewall would 
become overly aggressive in restricting new sessions. The 

Active TCP Opens

 

field in the output of the SHOW FIREWALL POLICY would show a very 
high number (42 

×

 10

8

). This issue has been resolved.

If the IGMP table was empty and a timeout was set, a fatal error occurred. 
This issue has been resolved.

Features in 86222-04

Patch file details for Patch 86222-04 are listed in Table 7.

Patch 86222-04 includes all issues resolved and enhancements released in 
previous patches for Software Release 2.2.2, and the following enhancements:

Message protection validation failures would occur intermittently. This 
issue has been resolved.

ISAKMP now interoperates with other vendor’s products in aggressive 
mode exchanges.

Support has been added for the 8624XL-80 switch with -48VDC power 
supply.

In a dual policy configuration, the firewall would lock up under load. The 
firewall would also mistakenly report SYN attacks. These issues have been 
resolved.

The CREATE CONFIG command generated duplicate PIM interface 
configuration command lines. This issue has been resolved.

Certificates containing 

GeneralisedTime

 with the year in YYYY format are 

now parsed correctly. The 

keyUsage

 field of certificates is now parsed 

PCR: 01186

Module: FIREWALL

Network affecting: No

PCR: 01187

Module: IPG

Network affecting: No

Table 7: Patch file details for Patch 86222-04.

Base Software Release File

86s-222.rez

Patch Release Date

24-Aug-2001

Compressed Patch File Name

86222-04.paz

Compressed Patch File Size

220220 bytes

PCR: 01124

Module: PKI

Network affecting: No

PCR: 01136

Module: ISAKMP

Network affecting: No

PCR 01138

Module: CORE, SWI

Network affecting: No

PCR: 01152

Module: FIREWALL

Network affecting: No

PCR: 01159

Module: PIM

Network affecting: No

PCR: 01162

Module: PKI

Network affecting: No

Summary of Contents for 86222-10

Page 1: ...www alliedtelesyn co nz documentation documentation html AR800 Series Modular Switching Router Documentation Set for Software Release 2 2 1 available on the Documentation and Tools CD ROM packaged wi...

Page 2: ...een made for the cold start trap After a 10s delay all interfaces which are UP have a link trap generated for them After that link traps are sent as normal Processing invalid UDP packets caused a memo...

Page 3: ...re Release 2 2 2 and the following enhancements Tunnel creation failed when attempting to establish a point to point tunnel from an ATR router tunnel originator to another vendor s router This issue h...

Page 4: ...A watchdog timout occurred when the router received an HTTP message with an over length header Normal HTTP requests would also occasionally cause watchdog timeouts These issues have been resolved The...

Page 5: ...o ALL and PFS was enabled This issue has been resolved PPPoE interfaces with IDLE set to ON would not retry active discovery when more data was received if active discovery had previously failed This...

Page 6: ...g corruption of the ARL table eventually causing the switch to lock up This issue has been resolved Tagged packets with invalid VLAN identifiers are now discarded The INFILTERING parameter of the SET...

Page 7: ...e receiver did not get the data stream This issue has been resolved The Rapier G6 base ports sometimes experienced spurious link up or link down events This issue has been resolved Features in 86222 0...

Page 8: ...a result after multiple additions and deletions no more IPv6 interfaces could be added These issues have been resolved The CREATE CONFIG command now adds PKI certificates to the script in the same ord...

Page 9: ...oducts in aggressive mode exchanges Support has been added for the 8624XL 80 switch with 48VDC power supply In a dual policy configuration the firewall would lock up under load The firewall would also...

Page 10: ...rfaces Ethernet interface events can now generate triggers The Telnet server s listen port can now be configured to a number in the range 1 to 65535 excluding any ports already assigned as listen port...

Page 11: ...olved and enhancements released in previous patches for Software Release 2 2 2 and the following enhancements When an interface on the firewall was configured with a global IP address of 0 0 0 0 outgo...

Page 12: ...ase 2 2 2 The DHCP server identified the wrong port numbers for incoming DHCP requests causing DHCP replies to be sent to the wrong port This issued has been resolved The IP flow cache occasionally ge...

Page 13: ...dress of the interface and defaults to INFINITE PREF must be less than or equal to VALID IPV6 now checks and ensures that if either PREF or VALID is specified PREF is less than or equal to VALID When...

Page 14: ...14 Patch Release Note Patch 86222 10 for Software Release 2 2 2 C613 10319 00 REV J...

Reviews: