17.3 Changelog
From Edge Threat Management Wiki - Arista
17.3
NG Firewall version 17.3 includes minor enhancements, bug fixes, and security updates.
General updates and enhancements
- Re-enabled Google Drive connector for automatic reports sync to Google Drive
- Updated ClamAV to LTS version
- Updated Webroot Brightcloud plugin
- Updated the root certificate store used by the system for SSL connections
- Added option to automatically remove devices from the device list after a defined period of inactivity
- Added option to automatically map Wireguard profile description as a username of the authenticated device
- Added option to define search domains to Wireguard profiles
- Added hard disk health check prior to upgrades
- Consolidated SNI extraction used by multiple apps to optimize performance of HTTPS filtering
Bug fixes
- Fixed WireGuard Interfaces not visible in rules for Cloud Appliances
- Fixed WireGuard access rule not added for Cloud Appliances
- Fixed Active Directory user and group names were not populating in rule dropdown list
- Fixed Google authentication failed if SSL inspection was enabled for all traffic
- Fixed WAN Failover not working with static IP configurations
- Fixed Apps could change to Invalid state in specific situations of license reassignment
- Fixed IPsec routes could become invalid in specific situations during upgrades or restarts
- Fixed Reporting data was missing events on systems under heavy load
- Fixed QoS value of 0 could cause instability and failure to start after upgrade
- Fixed IPsec Xauth sessions were implicitly NAT'd for local traffic
- Fixed Policy Manager session switching events were set to info, causing high disk usage on busy systems
- Fixed Kernel events were unnecessarily duplicated to syslog
Security updates
- Patched CVE-2024-47175 with updated libraries
- Added encryption of keys and passwords to exported data for specific screens that support export
- WPA password in WiFi configuration was not hidden in web administration
- Added sanitization of import function on multiple screens
Other changes
- Removed UPnP and associated access rule due to security implications
- Removed EU version of NGFW installer