STEALTHWATCH SYSTEM VERSION RELEASE NOTES

Size: px
Start display at page:

Download "STEALTHWATCH SYSTEM VERSION RELEASE NOTES"

Transcription

1 STEALTHWATCH SYSTEM VERSION RELEASE NOTES This document provides the following information: What's New Fixes for issues reported by customers including previous releases: o Version o Version o Version Issues known to exist in this release. For additional information about the Stealthwatch System, go to the Lancope Customer Community web site ( For a list of alarm types and their IDs, access the Alarm IDs v6.9.0 file. You can also access this document via the Alarm List topic in the SMC Client Interface online help. Important: If you currently do not have pxgrid configured, then when you update to Stealthwatch v6.9.2 you must reconfigure Cisco ISE. (If you configured pxgrid in Stealthwatch 6.8.x, then your configuration will be copied forward to Stealthwatch v6.9.2) Due to changes with APIs, customers running the Host Group Automation Service require a service software upgrade. Please contact See "Contacting Support" for upgrade assistance. For enhanced security, before you add a Flow Collector or Flow Sensor in the System Setup Tool, you must have first created a management channel between the Flow Collector and/or Flow Sensor and the Stealthwatch Management Console (SMC). If you have not done this, you will receive an error message when you try to add either appliance in the System Setup Tool. The specific instructions are on page 43 in the Stealthwatch Management Console VE and Flow Collector VE Installation and Configuration Guide or page 15 in the Hardware Configuration Guide Cisco Systems, Inc. All Rights Reserved. 1

2 For increased security, we recommend updating the IDentity 1000/1100 appliance to v3.3.0.x to take advantage of the new openssl version with TLS 1.2. Notes: This document uses the term "appliance" for any Stealthwatch System product, including virtual editions (VEs) such as the Flow Collector VE. The Stealthwatch System requires Java version 8 (v1.8) or later. The Stealthwatch System requires TLS v1.1 or later. The Stealthwatch System supports Internet Explorer v11 and later. For this release, the security category point contributions have been recalibrated. After updating to v6.9.2 from v6.8.x, it could take 10 days for the system to rebaseline the security categories. You may see an increase or decrease in alarms at first and then a gradual return to a more standard level. Upgrading from v6.9.0/v6.9.1 to v6.9.2 will not cause a re-baselining of security categories. Where once the setting "disabled" for a security event disabled the event, now disabling will disable the alarm. To view the supported hardware platforms for each system version, refer to the Hardware and Version Support Matrix on the Customer Community. What's New These are the new features and improvements for the v6.9.2 release: Flow Sensor and Load Balancer Integration Flow Sensor and Load Balancer Integration Use the Flow Sensor and Load Balancer Integration guide to configure the load balancer and Flow Sensor. This configuration stitches the client side and server side flows together, so the outside host connects to the inside host, providing visibility and enhanced security on the Flow Sensor and the Stealthwatch System. You will disable the X-Forwarded-For (XFF) option for HTTP, create an irule, and enable a virtual server resource. If you have an existing irule, it can be modified Cisco Systems, Inc. All Rights Reserved.

3 Contacting Support If you need technical support, please do one of the following: Contact your local Cisco Partner Contact Cisco Stealthwatch Support o To open a case by web: o To open a case by tac@cisco.com o For phone support: (U.S.) o For worldwide support numbers: worldwide_contacts.html 2017 Cisco Systems, Inc. All Rights Reserved. 3

4 What's Been Fixed This section summarizes fixes made in this release for issues (bugs/defects) reported by customers in previous releases. The Stealthwatch Defect (SWD or LSQ) number is provided for reference. Version LVA-221 Vim did not properly validate values for tree length when handling a spell file, which may have resulted in an integer overflow at a memory allocation site and a resultant buffer overflow. STE-97 Updated Support Contact information within Stealthwatch. SWD-7143 The lc_profiles process on the Flow Collector was very slow. Revamped the host group lookup functionality to fix a bottleneck. LSQ-2713 SWD-7735 SWD-8210 SWD-8200 SWD-8314 SWD-8317 SWD-8323 SWD-8340 ISE "devicetype" and "Security Group ID" fields were empty. Provided value to the fields from the applicable pxgrid fields. A Flow search with too many characters for a IP address range caused Vertica to crash. Changed the logic around constructing IP range searches. The Flow Collector was not processing a non-zero DSCP field. Added support for the DSCP field. External Lookup failed with a 500 internal server error. Fixed the null pointer error when loading the External Lookup configuration page. The SMC was utilizing a high amount of memory. We refactored the SMC client interface code to improve UI responsiveness. Disk expansion was not working on virtual appliances. We modified the partitions to make sure /lancope/var partition was not mounted at resize_fs function, and we added the ability for the expanddatapartition to be able to run again and complete the operation if the previous version had failed. LSQ-2880 LSQ-2869 LSQ-2911 LSQ-2912 LSQ-2904 LSQ Cisco Systems, Inc. All Rights Reserved.

5 SWD-8438 The Flow Collector saved flow records from one source ID and discarded records with the other source ID. Added observation domain binding to the exporter stats in the cases where more than one exporting engine is exporting from a single exporter IP address using different source ID values. LSQ-2557 SWD-8477 SWD-8542 SWD-8559 SWD-8590 SWD-8591 SWD-8598 SWD-8629 SWD-8635 SWD-8636 Vertica MergeOut process was very slow for the flow_stats table. Added several Vertica database tuning parameters to remedy the ROS container backup problems. Security Event details were missing in web application interface. Fixed an issue where Security Event details were always empty. The Online Help referred to an incorrect alarm name. Updated the help to refer to "Ping Oversized Packet" instead of "Long Ping". Tor traffic with no packets from server were alarming as "Successful". The alarm was updated to "Attempted". The Flow Sensor eth4 log was showing an invalid pointer error. Fixed the code to output the log message correctly. The Flow Sensor 3000 was not processing packets with multilayer VLAN tags. The engine has been modified to handle up to 4096 layered tags. The SMC client interface was missing the "user management" menu. Updates users with "SMC manager" rights to have access to the "user management" menu. Cisco Senderbase links were incorrect on the External Lookup configuration page. Fixed broken links. The Traffic by Peer Host Group component was not displaying flow information. Updated the component to display flow data correctly. LSQ-2935 LSQ-2963 LSQ-2982 LSQ-2989 LSQ-2992 LSQ-2995 LSQ-3013 LSQ-3002 LSQ Cisco Systems, Inc. All Rights Reserved. 5

6 SWD-8661 SWD-8670 SWD-8689 Updated the flow-forwarder Docker container v2.2.2 to use less memory and turned on heap debugging options so that more information may be gathered when there is an issue with the Java (JVM) heap. The support information updated for STE-97 was translated into Korean, Chinese, and Japanese. "Client Port Filtering" was not working with Fast Query selected. A query fix has been provided to make Client Port Filtering work correctly, with or without enabling fast query. LSQ-3022 LSQ-3031 SWD-8701 SWD-8702 SWD-8708 SWD-8727 SWD-8771 SWD-8791 SWD-8807 OVF resource defaults did not match documented minimums. Updated the SMC and Flow Collector OVFs to 16 GB ram. Unable to edit response management rules in the SMC client interface. Fix added to handle null pointer errors when editing the rules in response management. TextCopyHandler failed to read files at /lancope/var/smc/tmp. Scheduled reports temporary file handling process has been improved to avoid SQL errors. Top Alarming Hosts widget was not loading due to unknown host exception error. The svc-sw-reporting container was updated to better handle dealing with exceptional data within the database. The MongoDB compact script failed to save SMC configuration. Fixed a typo that caused the script to fail. The client interface would redirect the user to the license manager page on a licensed SMC. Updated the code so that users are able to access the client interface on a properly licensed appliance. LSQ-3038 LSQ-2987 LSQ-3048 LSQ-2987 LSQ-3004 LSQ-3048 LSQ-3012 LSQ-3124 LSQ-3132 LSQ-3133 SWD-8819 The Interface Service Traffic report was broken (LSQ-3066). Corrected an issue with the database query group used by the report. CTA could not be enabled on the Flow Collector 5000 series. Created an API to handle the Flow Collector 5000 Database and Engine. LSQ Cisco Systems, Inc. All Rights Reserved.

7 Version STE-84 SWD-7120 Port number for the server and protocol information have been added to the Response. In the SMC client interface, gaps appeared on the FlowCollector Trend chart on a Flow Collector running a Host Group Automation script. Improved the process so that the host group updates would work without causing gaps in the Flow Collection Trend graphs. LSQ-2462 SWD-7260 In the SMC client interface the Host Manager displayed duplicate entries. New code has been written to transfer values from Java list object to Hash set object, which does not allow duplicates. LSQ-2590 SWD-7322 The Flow Collector engine did not stop inserting data when the disk was 100% full. LSQ-2606 SWD-7371 SWD-7411 SWD-7470 SWD-7525 SWD SWD Added code to disable the stats the database writes at maximum disk utilization and to trigger the performance degraded alarm. A false alarm that the License Term would expire in less than 3 days occurred after a Flow Sensor was added to a Flow Collector. The code was updated to calculate the license expiration date correctly. The Flow Collector Database failed to back up admin hsql database when upgrading. The directory permission is now handled automatically, which allows the backup of the hsql database. The SMC client interface contained settings which are no longer applicable. VM Status and VM Server Status was removed from the Status drop-down menu. After upgrade, deleted exporters caused error "Thread interrupted" to occur. A bottleneck was discovered in the code and removed so that exporter deletions can be performed within a reasonable time period. The selection for "Second" in Flow Table Filter was removed because the seconds rounded up to the next minute anyway. LSQ-2615 LSQ-2433 LSQ-2646 LSQ Cisco Systems, Inc. All Rights Reserved. 7

8 SWD-7541 The delete option for an SSL Client certificate did not work on a secondary SMC. The fix was to allow the add/delete function for SSL client certificates in a secondary SMC. LSQ-2626 SWD-7549 SWD-7599 SWD-7615 SWD-7621 SWD-7631 SWD-7644 The flow traffic on the Flow Sensor 4010 showed no utilization with non-zero inbound traffic. We fixed the SMC detection of the Flow Sensor fiber port interface speeds used in utilization calculations. There was a database backup return error on system configuration. Updated the backup routines to handle file copies to CIFS destinations differently. The Hardware Configuration Guide had an error in the Configure Primary UDP Director section. The guide was updated with the correct information. The Top Conversations Report was not returning all results when a host filter was used. The fix was to correct the miscalculation while computing the transaction report values in the Top Conversations Report. The Flow Collector's Vertica database was using all of it's memory. We upgraded Vertica to fix issues with it consuming blocks of memory that it does not free until shutdown and issues with it allocating unused virtual memory. The Top Conversations transaction report was showing incorrect values. A fix has been provided to avoid duplicate values and show the appropriate number of records for each Flow Collector in the transaction report. LSQ-2649 LSQ-2621 LSQ-2572 LSQ-2674 LSQ-2679 LSQ-2593 LSQ-2698 LSQ-2593 SWD-7653 IDentity v3.3.0 does not support TLS 1.0 or 1.1. LSQ-2712 The SMC Java client was updated so that the customer could use TLS v1.2 for connections back to the SMC Cisco Systems, Inc. All Rights Reserved.

9 SWD SWD-7689 Users could not create a diagnostics pack for an appliance. The fix corrected an exception in the audit log when creating a diagnostics pack. The CPU average load calculation, on the SMC client interface dashboard, was incorrect. The CPU average load has been updated to reflect the updated appliances. LSQ-2692 LSQ-2677 SWD-7692 SWD SWD SWD-7739 SWD-7765 SWD-7787 SWD-7824 SWD-7862 The Top Conversations Report did not return all results when filtering hosts. In the Top Conversations report, the problem was in generating reports if more than one Flow Collector was configured. The fix corrects the query to collect all required data from data base for all required Flow Collectors. Users could not import of DAR and XML files to Document Builder. Fixed an issue with launching a new report from document builder that has several pages that are named alphabetically. Tomcat socket got stuck on an IP address. We implemented code to clear tomcat socket and firewall rule. Flow data queries across multiple Flow Collectors did not return consistent ordering. The fix is to order the records returned for a flow query by flowid when a specific ordering is not requested. This prevents different invocations of this method from returning different results. The Flow Table Service Summary and Service Port columns had mismatched port addresses. Fixed an issue where the service summary port was not updated to match the server port for certain flows. Flow query was failing for IPv6 IP address range 0000-FFFF. The flow query filter has been corrected to recognize and search IPv6 input values. Associated flow table carried previous advanced filter values. The Flow Table retain filter option has been excluded from the associated flow table. LSQ-2593 LSQ-2738 LSQ-2724 LSQ-2652 LSQ-2710 LSQ-2613 LSQ Cisco Systems, Inc. All Rights Reserved. 9

10 SWD-7865 Stealthwatch Management Console had high memory usage for uwsgi appliance update process. Implemented a mechanism designed to prevent memory usage exceeding 4 GB by the uwsgi UPServ application. LSQ-2722 SWD-7939 SWD-7963 SWD-8072 SWD-8089 SWD-8095 SWD-8107 SWD-8128 SWD-8136 SWD-8182 Uploading certificates will continue to display error message even after subsequent successful uploads. Stopped the service call whenever uploading invalid certificate so that the error does not persist after successful certificate upload. The client interface help was not showing topics when using the search tab. Fixed encoding error caused by a tomcat update. Top Reports returns more records than the set limit when there are two or more Flow Collectors. The Top Reports queries have been updated to split the amount of records evenly between Flow Collectors. The selection for "Second" in Flow Table Filter was removed because the seconds rounded up to the next minute anyway. Unable to activate SLIC after recent update to proxy settings. Added code to restart the tomcat process after updating proxy settings. notifications for scheduled documents were not being logged properly. We fixed the log base path location from pointing to the incorrect directory. Creating a diagnostic pack on the Flow Collector Database node triggered DB Channel Down alarm. We increased the session time-out period to avoid false DB Channel Down alarms. Cognitive Threat Analytics (CTA) API calls using JWT tokens were not being made correctly. JWT tokens are now being passed through Authorization headers. UDP Director 2010 could not boot after upgrade. Fixed an issue with the kernel upgrading process. LSQ-2862 LSQ-2822 LSQ-2652 LSQ-2807 LSQ-2834 LSQ-2755 LSQ-2845 LSQ-2876 LSQ Cisco Systems, Inc. All Rights Reserved.

11 SWD-8239 Error when creating and configuring Custom Applications. LSQ-2765 A new java constructor has been added to avoid a bad request error when adding multiple custom application rules in the SMC. LSQ-2829 LSQ-2865 LSQ-2893 Version SWD-6607 Flow Collection drops for one minute when adding or editing custom applications. We changed Application Definitions to perform the update at the beginning of the next minute instead of updating instantly to avoid gaps in flow collection. LSQ-2052 SWD-6700 The SMC Client interface showed VM Server features. LSQ-2201 We removed instances of the VM Servers in the SMC Client interface Enterprise Tree and Traffic menu. SWD-6715 On the SMC the Flow Trend report for a Flow Collector but the other is indicating that there was "no data available." LSQ-2217 We adjusted database queries used by the Flow Collection Trends report to allow larger values for the FPS and flow count values. SWD-6726 In the SMC client interface, Flow Collector alarm details incorrectly displayed "I/O error." LSQ-2170 The error message was changed to: "Unable to connect. Timeout waiting for connection." SWD-6745 The Flow Collector crashed, and in the SMC Web App interface, the Flow Collection Trend had a 25-minute gap. LSQ-2253 Additional protection against a future potential crash was added to string handling in the flows. SWD-6777 A custom service that had been set to "Exclude Security Event" was still triggering Security Events. LSQ-2261 We updated the code to fetch the required service details from the configuration file and use it for event triggering Cisco Systems, Inc. All Rights Reserved. 11

12 SWD-6823 The Flow Collector 5000 Engine node did not show its associated database node. We added a link to the database node on the Flow Collector 5000 support page. LSQ-2328 SWD-6824 The Flow Collector had performance problems. LSQ-2026 Special handling was added for broadcast hosts to prevent thread contention. SWD-6839 The Flow Collector Database Storage Statistics showed incorrect capacity when the number of days of "Flow Interface Details" was smaller than those in "Flow Details." LSQ-2238 We fixed the code to correctly calculate "Capacity in Days" and "Remaining Days." SWD-6857 The defect was that the SMC was not polling the ifhighspeed value for 10 Gbs interface of an exporter. LSQ-2325 We enhanced logging information to aid in determining the solution for the defect. SWD-6858 A segment failure in the Flow Collector occurred when the flow interface buffer size was dynamically increased. LSQ-2026 The code was changed to make the buffer reallocation conflict safe. SWD-6869 The SMC was not using the Secondary pxgrid Mitigation ISE Node when the Primary was down. LSQ-2367 The code was looking at only the primary host. A Java file was changed so that it would look at the next available host. SWD-6886 The Vertica log file was growing too large. A log rotate entry in the config file was added so that old logs are purged and the log will not grow out of control. SWD-6891 The SMC client took about 35 minutes to search a host and open its snapshot. SWD-6873 The locking behavior was adjusted to allow greater concurrency. SWD-6901 SWD-6904 After the SMC was updated, the Scheduled Documents showed errors and would not display any graphs LSQ-2400 The problem for both defects was that an update to Java 8 still required some client groups to have Java 7. The coding was changed so that the SMC will use Java 8 properly Cisco Systems, Inc. All Rights Reserved.

13 SWD-6922 The FlowSensor was dropping 90% of packets. We updated the drivers so the network interface card could pass the packets to the engine to process. LSQ-2410 SWD-6928 The defect was that the SMC Java client took 10 to 15 minutes to finish loading cache. LSQ-2416 We adjusted the lock acquisition behavior of a portion of the SMC Web application so that the loss of communication with Cisco ISE nodes does not cause long delays in the login process through the SMC Java client. SWD-6939 The defect was that the Database Storage Statistics page on the Flow Collector Appliance Admin interface was not loading. LSQ-2238 We updated the JavaScript on the Database Storage Statistics page to use a different library function for greater browser support. SWD-6941 The defect is that a UDP Director flowfan.xml modification and flowfan restart resulted in a High Availability (HA) cluster service error. LSQ-2442 The error was caused by the HA service detecting that the flowfan process was not running because of a delay during manual restart of the service. The delay has been removed. SWD-6955 A custom service that had been set to "Exclude Security Event" was still triggering Security Events. LSQ-2261 We updated the code to fetch the required service details from the configuration file and use it for event triggering. SWD-6960 SWD-6967 Customer had an issue with multiple Cisco ASA's reporting longest duration exports of 1,800. LSQ-2467 The fix was to ignore the Summary Flows that are sent at the end of each firewall flow. SWD-6976 The defect is that the customer was unable to configure custom certificates for SSL/TLS communications on the Stealthwatch appliances. LSQ-2461 The fix provides the ability to install and use certificates with a trust chain longer than 1. The update will restart nginx. The fix is applicable to all appliances. SWD-7061 User received a SMC internal server error. LSQ-2576 To avoid this error message, an intermediary was placed between the interface requests that were causing this error and the Mongo database Cisco Systems, Inc. All Rights Reserved. 13

14 SWD-7107 The FlowCollector was not processing user name. The engine now processes Create events that have no bytes or packets so that it can process the AAA user name from the ASA "Flow created" record. LSQ-2506 SWD-7131 SWD-7132 Some Stealthwatch appliances did not respond to ICMP requests from a Nagios monitoring server. LSQ-2527 The default Docker IP address and the netmask for eth2 on the Flow Collector 5000 series database node were changed. SWD-7149 A customer had an Internal Server error. LSQ-2545 The fix was to decrease the frequency of certain operations made by the SMC Web interface that can cause increased load on the Mongo database. SWD-7229 The Flow Collector home page would not load in an Internet Explorer browser. LSQ-2558 The fix is to change some functions used in loading the Flow Collector home page, which were not supported by IE/Edge browsers. SWD-7322 NetFlow decode was not properly retrieving ICMP type and code. LSQ-2606 An initialization problem in the NetFlow decoder was fixed to properly retrieve the ICMP type and code from the first ICMP Netflow record that it decodes. SWD-7324 The Flow Collector engine did not stop inserting data when the disk was 100% full. LSQ-2606 Added code to disable the stats the database writes at maximum disk utilization and to trigger the performance degraded alarm. SWD-7621 The Top Conversations Report was not returning all results when a host filter was used. LSQ-2593 The fix was to correct the miscalculation while computing the transaction report values in the Top Conversations Report. SWD-7653 IDentity v3.3.0 does not support TLS 1.0 or 1.1. LSQ-2712 The SMC Java client was updated so that the customer could use TLS v1.2 for connections back to the SMC. SWD-8163 Cognitive Threat Analytics (CTA) API calls using JWT tokens were not being made correctly. JWT tokens are now being passed through Authorization headers Cisco Systems, Inc. All Rights Reserved.

15 Known Issues This section summarizes issues (bugs) that are known to exist in this release. Where possible, workarounds are included. The defect number is provided for reference. Defect Number LVA-306, LVA-307 Description If you have an untrusted virtual machine installed on the same physical cluster/system as a Stealthwatch appliance, the Stealthwatch appliance is vulnerable to a side-channel attack that can expose private keys. A vulnerability was disclosed for the gnupg software package suite. This vulnerability involves a side-channel attack against the gnupg implementation of the RSA cryptographic algorithm. When RSA keys are in use on the system, the implementation allows for the recovery of 1024-bit length private keys. Additionally, it experimentally appears that 13% of the 2048 keyspace is vulnerable as well. More details about the vulnerability can be found by reading the white paper located at The risk from this side-channel attack applies where the private key is in use on the system. For Stealthwatch customers, this applies to SSH and HTTPS sessions. For customers running hardware appliances and in fully controlled Virtual Machine infrastructures, the risk of exposure is mitigated by access to the physical and virtual systems. For customers running in a co-located VM infrastructure, the risk of exposure is greater. Workaround Important: Do not install an untrusted physical or virtual machine on the same physical cluster/system as your Stealthwatch System appliances. Important: If you are upgrading the system to v6.10 from an earlier version, confirm all appliances have the latest patch files installed. To review the Stealthwatch appliance vulnerability, complete the following steps: 1. Log in to the Stealthwatch Appliance Admin. 2. Click Configuration > Services. Review the SSH section. If the Enable SSH box is checked, you need to regenerate the RSA host key pair using the instructions shown below. 3. Click Configuration > SSL Certificate. Review the installed certificates. If there are custom certificates installed using the using RSA-1024 or RSA-2048 bit keys, you must regenerate new certificates. 4. Click Configuration > Certificate Authority Certificates. Review the installed certificates. If there are custom certificates installed using RSA-1024 or RSA-2048 bit keys, you must regenerate new certificates. If the SSH service is enabled on the appliance, regenerate the RSA host key using the following instructions. You will regenerate the RSA host key on every appliance in the system. 1. SSH onto the SW Appliance as root or using the root terminal option in the sysadmin menu. 2. To delete the public and private keys in the primary location, run the following command: rm f /etc/ssh/ssh_host_rsa_key /etc/ssh/ssh_host_rsa_key.pub Cisco Systems, Inc. All Rights Reserved. 15

16 Defect Number Description Workaround 3. To delete the public and private keys in the backup location, run the following command: rm f /lancope/var/admin/ssh/ssh_ host_rsa_key /lancope/var/admin/ssh/ssh_host_rsa_ key.pub 4. To regenerate a new RSA host key pair, run the following command: /lancope/admin/bin/generatesshkeys 5. Do one of the following to restart the SSHD service: o If the appliance software version is 6.9 and later, run the following command: systemctl restart ssh.service o If the appliance version is earlier than 6.9, run the following command: /etc/init.d/ssh restart 6. Repeat these steps on every appliance in the Stealthwatch System. If you have installed custom certificates using RSA or RSA-2048 bit keys on your Stealthwatch appliances, you must regenerate new X509 certificates. 1. Log in to the Stealthwatch Appliance Admin. 2. Click Configuration > SSL Certificate. 3. Click the? icon to open the Help page. o o Use the SSL Certificate instructions to generate a new X509 certificate. If the certificate is X509 certificate is RSA, create it with a size of 4096 bits. 4. Delete the old (vulnerable) X509 certificate from the appliance. 5. Click Configuration> Certificate Authority Certificates. Review the installed certificates. If there are custom certificates installed using RSA-1024 or RSA-2048 bit keys, regenerate new certificates. o Click the? icon to open the Help page Cisco Systems, Inc. All Rights Reserved.

17 Defect Number Description Workaround o o Use the Certificate Authority Certificates instructions to add a new X509 certificate. If the certificate is X509 certificate is RSA, create it with a size of 4096 bits. SWD-7627 SWD-7655 SWD-8197 If you reboot your Flow Collector, it deletes all alarm history; however, if you replace your Flow Collector, the new Flow Collector retains the alarm history from the old Flow Collector instead of deleting it. Since the alarming host widgets (which display the number of hosts receiving alarms since the last reset hour for a specific category) on the Security Insight Dashboard and Host Group page then do not update until the next reset hour, you may see a discrepancy between these values and the alarm values in the Hosts table on the Host List View. The generation of a diagnostics pack may fail in large systems as a result of timing out. The Flow Sensor was not detecting enough applications. None currently available; the feature will be available in a future release. To overcome this, open the SSH console for the appliance and run this command: dodiagpack. This will allow the generation of the diagnostic pack without timing out. The diagnostic pack can be downloaded using Browse File in the /admin/diagnostics folder, and it can be copied off the box using SCP. To provide more accurate application classification, we updated the third-party library for Application Identification. Due to this update, some traffic will no longer be classified as it was in prior versions and support has been removed for a variety of applications. Updates to the applications supported are dependent on future releases from the third-party library. SWD-8673 SWD-9052 SystemConfig special character fonts look bad when using the SecureCRT client in ANSI mode. Offline license activation failing or "Storage Binding Break" error To overcome this, disable ANSI Color when connecting or use a different client to view the SystemConfig script. This error may occur if you moved a virtual machine, uploaded a license more than once, or if the license 2017 Cisco Systems, Inc. All Rights Reserved. 17

18 Defect Number SWD-9300 SWD-9563 Description The Selected Cipher Suite does not appear in the Flow Search Results when using a non-standard port. When you log in to the Stealthwatch Web App using Internet Explorer v11 and at any point you refresh the Home page, the Desktop Client drop-down arrow and the three navigation icons to the left of this list (top right corner of page) disappear. These three icons include the following: Search (magnifying glass icon) Help (person icon) Global Settings (geer icon) Additionally, the fonts look different from how they appear when displayed using other browsers. Workaround is corrupted. Please contact Stealthwatch Customer Community for assistance. None currently available; this will be fixed in a future release. Close the browser and log in again. SWD-7627 SWD-7655 On the Flow Sensor VE, Export Application Identification is off by default. If you reboot your Flow Collector, it deletes all alarm history; however, if you replace your Flow Collector, the new Flow Collector retains the alarm history from the old Flow Collector instead of deleting it. Since the alarming host widgets (which display the number of hosts receiving alarms since the last reset hour for a specific category) on the Security Insight Dashboard and Host Group page then do not update until the next reset hour, you may see a discrepancy between these values and the alarm values in the Hosts table on the Host List View. The generation of a diagnostics pack may fail in large systems as a result of timing To enable application identification, this advanced setting will need to be manually selected. None currently available; the feature will be available in a future release. To overcome this, open the SSH console for the appli Cisco Systems, Inc. All Rights Reserved.

19 Defect Number SWD-8197 SWD-8673 SWD-9258 SWD-9300 out. Description The Flow Sensor was not detecting enough applications. SystemConfig special character fonts look bad when using the SecureCRT client in ANSI mode. The Flow Collector Engine fails to connect a router mitigation device when using SSH. The Selected Cipher Suite does not appear in the Flow Search Results when using a non-standard port. On the Flow Sensor VE, Export Application Identification is off by default. Workaround ance and run this command: dodiagpack. This will allow the generation of the diagnostic pack without timing out. The diagnostic pack can be downloaded using Browse File in the /admin/diagnostics folder, and it can be copied off the box using SCP. To provide more accurate application classification, we updated the third-party library for Application Identification. Due to this update, some traffic will no longer be classified as it was in prior versions and support has been removed for a variety of applications. Updates to the applications supported are dependent on future releases from the third-party library. To overcome this, disable ANSI Color when connecting or use a different client to view the SystemConfig script. To overcome this, use Telnet to connect a router mitigation device instead of SSH. None currently available; this will be fixed in a future release. To enable application identification, this advanced setting will need to be manually selected Cisco Systems, Inc. All Rights Reserved. 19

20 2017 Cisco Systems, Inc. All Rights Reserved. SW_6_9_2_Release_Notes_DV_1_4

STEALTHWATCH SYSTEM VERSION RELEASE NOTES

STEALTHWATCH SYSTEM VERSION RELEASE NOTES STEALTHWATCH SYSTEM VERSION 6.9.1 RELEASE NOTES This document provides the following information: What's New Fixes for issues reported by customers including previous releases o Version 6.9.1 o Version

More information

STEALTHWATCH SYSTEM VERSION RELEASE NOTES

STEALTHWATCH SYSTEM VERSION RELEASE NOTES STEALTHWATCH SYSTEM VERSION 6.10.2 RELEASE NOTES This document provides the following information: What's New What's Been Fixed summarizes fixes made for issues reported by customers: o Version 6.10.2

More information

STEALTHWATCH SYSTEM VERSION RELEASE NOTES

STEALTHWATCH SYSTEM VERSION RELEASE NOTES STEALTHWATCH SYSTEM VERSION 6.10.0 RELEASE NOTES This document provides the following information: What's New What's Been Fixed summarizes fixes made for issues reported by customers: o Version 6.10.0

More information

STEALTHWATCH SYSTEM VERSION RELEASE NOTES

STEALTHWATCH SYSTEM VERSION RELEASE NOTES STEALTHWATCH SYSTEM VERSION 6.10.3 RELEASE NOTES This document provides the following information: What's New What's Been Fixed summarizes fixes made for issues reported by customers: o Version 6.10.3

More information

Stealthwatch System Version Update Guide

Stealthwatch System Version Update Guide Stealthwatch System Version 6.9.5 Update Guide Use this guide to update the following Stealthwatch appliances from v6.8.x to v6.9.5: UDP Director (also known as FlowReplicator ) Endpoint Concentrator Stealthwatch

More information

Stealthwatch System Version 6.10.x to Update Guide

Stealthwatch System Version 6.10.x to Update Guide Stealthwatch System Version 6.10.x to 6.10.5 Update Guide Use this guide to update the following Stealthwatch appliances from v6.10.x to v6.10.5: UDP Director (also known as FlowReplicator) Endpoint Concentrator

More information

Cisco Stealthwatch. Update Guide 7.0

Cisco Stealthwatch. Update Guide 7.0 Cisco Stealthwatch Update Guide 7.0 Table of Contents Introduction 5 Overview 5 Audience 5 Terminology 5 New Update Process 6 Before You Begin 7 Software Version 7 Java 7 TLS 7 Default Credentials 8 Third

More information

UDP Director Virtual Edition Installation and Configuration Guide (for Stealthwatch System v6.9.0)

UDP Director Virtual Edition Installation and Configuration Guide (for Stealthwatch System v6.9.0) UDP Director Virtual Edition Installation and Configuration Guide (for Stealthwatch System v6.9.0) Installation and Configuration Guide: UDP Director VE v6.9.0 2016 Cisco Systems, Inc. All rights reserved.

More information

UDP Director Virtual Edition

UDP Director Virtual Edition UDP Director Virtual Edition (also known as FlowReplicator VE) Installation and Configuration Guide (for StealthWatch System v6.7.0) Installation and Configuration Guide: UDP Director VE v6.7.0 2015 Lancope,

More information

Stealthwatch Flow Sensor Virtual Edition Installation and Configuration Guide (for Stealthwatch System v6.9.0)

Stealthwatch Flow Sensor Virtual Edition Installation and Configuration Guide (for Stealthwatch System v6.9.0) Stealthwatch Flow Sensor Virtual Edition Installation and Configuration Guide (for Stealthwatch System v6.9.0) Installation and Configuration Guide: Flow Sensor VE v6.9.0 2017 Cisco Systems, Inc. All rights

More information

Cisco Stealthwatch. Release Notes 7.0

Cisco Stealthwatch. Release Notes 7.0 Cisco Stealthwatch Release Notes 7.0 Table of Contents Introduction 5 Overview 5 Terminology 5 Before You Update 5 Possible insufficient root partition space 5 Find the disk usage for an appliance 5 Previous

More information

AppGate 11.0 RELEASE NOTES

AppGate 11.0 RELEASE NOTES Changes in 11.0 AppGate 11.0 RELEASE NOTES 1. New packet filter engine. The server-side IP tunneling packet filter engine has been rewritten from scratch, reducing memory usage drastically and improving

More information

Cisco Stealthwatch. Installation and Configuration Guide 7.0

Cisco Stealthwatch. Installation and Configuration Guide 7.0 Cisco Stealthwatch Installation and Configuration Guide 7.0 Table of Contents Introduction 7 Overview 7 Virtual Edition (VE) 7 Hardware 7 Audience 7 New Process 7 Terminology 8 Abbreviations 8 Before You

More information

Stealthwatch and Cognitive Analytics Configuration Guide (for Stealthwatch System v6.10.x)

Stealthwatch and Cognitive Analytics Configuration Guide (for Stealthwatch System v6.10.x) Stealthwatch and Cognitive Analytics Configuration Guide (for Stealthwatch System v6.10.x) Copyrights and Trademarks 2018 Cisco Systems, Inc. All rights reserved. NOTICE THE SPECIFICATIONS AND INFORMATION

More information

Downloading and Licensing. (for Stealthwatch System v6.9.1)

Downloading and Licensing. (for Stealthwatch System v6.9.1) Downloading and Licensing (for Stealthwatch System v6.9.1) Contents Contents 2 Introduction 5 Purpose 5 Audience 5 Preparation 5 Trial Licenses 5 Download and License Center 6 Contacting Support 6 Registering

More information

Release Notes Version 7.8

Release Notes Version 7.8 Please Read Before Updating Before installing any firmware version, be sure to make a backup of your configuration and read all release notes that apply to versions more recent than the one currently running

More information

Cisco Stealthwatch Endpoint License with Cisco AnyConnect NVM

Cisco Stealthwatch Endpoint License with Cisco AnyConnect NVM Cisco Stealthwatch Endpoint License with Cisco AnyConnect NVM How to implement the Cisco Stealthwatch Endpoint License with the Cisco AnyConnect Network Visibility Module Table of Contents About This Document...

More information

IMC Network Traffic Analyzer 7.2 (E0401P04) Copyright 2016 Hewlett Packard Enterprise Development LP

IMC Network Traffic Analyzer 7.2 (E0401P04) Copyright 2016 Hewlett Packard Enterprise Development LP Network Traffic Analyzer 7.2 (E0401P04) Copyright 2016 Hewlett Packard Enterprise Development LP Table of Contents 1. What's New in this Release 2. Problems Fixed in this Release 3. Software Distribution

More information

IMC Network Traffic Analyzer 7.1 (E0301P04) Copyright (c) 2015 Hewlett-Packard Development Company, L.P. All Rights Reserved.

IMC Network Traffic Analyzer 7.1 (E0301P04) Copyright (c) 2015 Hewlett-Packard Development Company, L.P. All Rights Reserved. Network Traffic Analyzer 7.1 (E0301P04) Copyright (c) 2015 Hewlett-Packard Development Company, L.P. All Rights Reserved. Table of Contents 1. What's New in this Release 2. Problems Fixed in this Release

More information

WatchGuard Dimension v1.1 Update 1 Release Notes

WatchGuard Dimension v1.1 Update 1 Release Notes WatchGuard Dimension v1.1 Update 1 Release Notes Build Number 442674 Revision Date March 25, 2014 WatchGuard Dimension is the next-generation cloud-ready visibility solution for our Unified Threat Management

More information

McAfee Network Security Platform 8.3

McAfee Network Security Platform 8.3 8.3.7.28-8.3.3.9 Manager-Mxx30-series Release Notes McAfee Network Security Platform 8.3 Revision C Contents About this release New features Enhancements Resolved issues Installation instructions Known

More information

Viewing System Status, page 404. Backing Up and Restoring a Configuration, page 416. Managing Certificates for Authentication, page 418

Viewing System Status, page 404. Backing Up and Restoring a Configuration, page 416. Managing Certificates for Authentication, page 418 This chapter describes how to maintain the configuration and firmware, reboot or reset the security appliance, manage the security license and digital certificates, and configure other features to help

More information

Cisco Stealthwatch. Installation and Configuration Guide 7.0

Cisco Stealthwatch. Installation and Configuration Guide 7.0 Cisco Stealthwatch Installation and Configuration Guide 7.0 Table of Contents Introduction 7 Overview 7 Virtual Edition (VE) 7 Hardware 7 Audience 7 New Process 7 Terminology 8 Abbreviations 8 Before You

More information

DOWNLOADING AND LICENSING STEALTHWATCH PRODUCTS

DOWNLOADING AND LICENSING STEALTHWATCH PRODUCTS DOWNLOADING AND LICENSING STEALTHWATCH PRODUCTS Beginning with StealthWatch System v6.3.0, you must license all StealthWatch products. For some products, such as virtual appliances and software updates,

More information

McAfee Network Security Platform 8.3

McAfee Network Security Platform 8.3 8.3.7.28-8.3.7.6 Manager-Virtual IPS Release Notes McAfee Network Security Platform 8.3 Revision B Contents About this release New features Enhancements Resolved issues Installation instructions Known

More information

Cisco Unified Serviceability

Cisco Unified Serviceability Cisco Unified Serviceability Introduction, page 1 Installation, page 5 Introduction This document uses the following abbreviations to identify administration differences for these Cisco products: Unified

More information

McAfee Network Security Platform 8.3

McAfee Network Security Platform 8.3 8.3.7.44-8.3.7.14 Manager-Virtual IPS Release Notes McAfee Network Security Platform 8.3 Revision A Contents About this release New features Enhancements Resolved issues Installation instructions Known

More information

IMC Network Traffic Analyzer 7.3 (E0504) Copyright 2015, 2017 Hewlett Packard Enterprise Development LP

IMC Network Traffic Analyzer 7.3 (E0504) Copyright 2015, 2017 Hewlett Packard Enterprise Development LP Network Traffic Analyzer 7.3 (E0504) Copyright 2015, 2017 Hewlett Packard Enterprise Development LP Table of Contents 1. What's New in this Release 2. Problems Fixed in this Release 3. Software Distribution

More information

McAfee Network Security Platform 8.1

McAfee Network Security Platform 8.1 Revision C McAfee Network Security Platform 8.1 (8.1.7.91-8.1.3.124 Manager-M-series Release Notes) Contents About this release New features Enhancements Resolved issues Installation instructions Known

More information

Aventail README ASAP Platform version 8.0

Aventail README ASAP Platform version 8.0 Aventail README 1 Aventail README ASAP Platform version 8.0 Part No. 0850-000010-01 October 19, 2004 This README highlights new features and provides late-breaking information about the Aventail EX-1500

More information

WatchGuard Dimension v2.1.1 Update 3 Release Notes

WatchGuard Dimension v2.1.1 Update 3 Release Notes WatchGuard Dimension v2.1.1 Update 3 Release Notes Build Number 567758 Release Date 8 August 2018 Release Notes Revision Date 8 August 2018 On 8 August 2018, WatchGuard released the Dimension v2.1.1 Update

More information

StealthWatch System Disaster Recovery Guide Recommendations and Procedures. System version 6.7.x

StealthWatch System Disaster Recovery Guide Recommendations and Procedures. System version 6.7.x StealthWatch System Disaster Recovery Guide Recommendations and Procedures System version 6.7.x Disaster Recovery Guide: StealthWatch System v6.5.x 2015 Lancope, Inc. All rights reserved. Document Date:

More information

Snapt Accelerator Manual

Snapt Accelerator Manual Snapt Accelerator Manual Version 2.0 pg. 1 Contents Chapter 1: Introduction... 3 Chapter 2: General Usage... 3 Accelerator Dashboard... 4 Standard Configuration Default Settings... 5 Standard Configuration

More information

Network Security Platform 8.1

Network Security Platform 8.1 8.1.7.91-8.1.3.124-2.11.9 Manager-XC-Cluster Release Notes Network Security Platform 8.1 Revision B Contents About this release New features Enhancements Resolved issues Installation instructions Known

More information

Stealthwatch Flow Sensor Virtual Edition Installation and Configuration Guide (for Stealthwatch System v6.10.1)

Stealthwatch Flow Sensor Virtual Edition Installation and Configuration Guide (for Stealthwatch System v6.10.1) Stealthwatch Flow Sensor Virtual Edition Installation and Configuration Guide (for Stealthwatch System v6.10.1) Copyrights and Trademarks 2018 Cisco Systems, Inc. All rights reserved. NOTICE THE SPECIFICATIONS

More information

McAfee epolicy Orchestrator Release Notes

McAfee epolicy Orchestrator Release Notes McAfee epolicy Orchestrator 5.9.1 Release Notes Contents About this release What's new Resolved issues Known issues Installation information Getting product information by email Where to find product documentation

More information

AppSense DataNow. Release Notes (Version 4.0) Components in this Release. These release notes include:

AppSense DataNow. Release Notes (Version 4.0) Components in this Release. These release notes include: AppSense DataNow Release Notes (Version 4.0) These release notes include: Components in this Release Important Upgrade Information New Features Bugs Fixed Known Issues and Limitations Supported Operating

More information

McAfee Network Security Platform

McAfee Network Security Platform Revision B McAfee Network Security Platform (8.1.7.5-8.1.3.43 M-series Release Notes) Contents About this release New features Enhancements Resolved issues Installation instructions Known issues Product

More information

Network Security Platform 8.1

Network Security Platform 8.1 8.1.7.5-8.1.3.10 NTBA Appliance Release Notes Network Security Platform 8.1 Revision B Contents About this release New features Enhancements Resolved issues Installation instructions Known issues Find

More information

Network Security Platform 8.1

Network Security Platform 8.1 8.1.7.91-8.1.7.44 Manager-Virtual IPS Release Notes Network Security Platform 8.1 Revision B Contents About this release New features Enhancements Resolved issues Installation instructions Known issues

More information

Stealthwatch System Hardware Configuration Guide (for Stealthwatch System v6.10)

Stealthwatch System Hardware Configuration Guide (for Stealthwatch System v6.10) Stealthwatch System Hardware Configuration Guide (for Stealthwatch System v6.10) Copyrights and Trademarks 2017 Cisco Systems, Inc. All rights reserved. NOTICE THE SPECIFICATIONS AND INFORMATION REGARDING

More information

Configuring High Availability (HA)

Configuring High Availability (HA) 4 CHAPTER This chapter covers the following topics: Adding High Availability Cisco NAC Appliance To Your Network, page 4-1 Installing a Clean Access Manager High Availability Pair, page 4-3 Installing

More information

Network Security Platform 8.1

Network Security Platform 8.1 8.1.7.5-8.1.3.43 M-series Release Notes Network Security Platform 8.1 Revision A Contents About this release New features Enhancements Resolved issues Installation instructions Known issues Product documentation

More information

vrealize Operations Management Pack for NSX for vsphere 2.0

vrealize Operations Management Pack for NSX for vsphere 2.0 vrealize Operations Management Pack for NSX for vsphere 2.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition.

More information

CA Agile Central Administrator Guide. CA Agile Central On-Premises

CA Agile Central Administrator Guide. CA Agile Central On-Premises CA Agile Central Administrator Guide CA Agile Central On-Premises 2018.1 Table of Contents Overview... 3 Server Requirements...3 Browser Requirements...3 Access Help and WSAPI...4 Time Zone...5 Architectural

More information

Installing and Configuring VMware Identity Manager Connector (Windows) OCT 2018 VMware Identity Manager VMware Identity Manager 3.

Installing and Configuring VMware Identity Manager Connector (Windows) OCT 2018 VMware Identity Manager VMware Identity Manager 3. Installing and Configuring VMware Identity Manager Connector 2018.8.1.0 (Windows) OCT 2018 VMware Identity Manager VMware Identity Manager 3.3 You can find the most up-to-date technical documentation on

More information

Monitoring WAAS Using WAAS Central Manager. Monitoring WAAS Network Health. Using the WAAS Dashboard CHAPTER

Monitoring WAAS Using WAAS Central Manager. Monitoring WAAS Network Health. Using the WAAS Dashboard CHAPTER CHAPTER 1 This chapter describes how to use WAAS Central Manager to monitor network health, device health, and traffic interception of the WAAS environment. This chapter contains the following sections:

More information

Monitoring Windows Systems with WMI

Monitoring Windows Systems with WMI Monitoring Windows Systems with WMI ScienceLogic version 8.8.1 Table of Contents Introduction 4 Monitoring Windows Devices in the ScienceLogic Platform 5 What is SNMP? 5 What is WMI? 5 PowerPacks 5 Configuring

More information

McAfee Network Security Platform 8.3

McAfee Network Security Platform 8.3 8.3.7.52-8.3.3.27-2.11.9 Manager-XC-Cluster Release Notes McAfee Network Security Platform 8.3 Revision C Contents About this release New features Enhancements Resolved issues Installation instructions

More information

Branch Repeater :51:35 UTC Citrix Systems, Inc. All rights reserved. Terms of Use Trademarks Privacy Statement

Branch Repeater :51:35 UTC Citrix Systems, Inc. All rights reserved. Terms of Use Trademarks Privacy Statement Branch Repeater 6.0 2013-07-22 14:51:35 UTC 2013 Citrix Systems, Inc. All rights reserved. Terms of Use Trademarks Privacy Statement Contents Branch Repeater 6.0... 3 Branch Repeater 6.0... 4 Release Notes

More information

Host Identity Sources

Host Identity Sources The following topics provide information on host identity sources: Overview: Host Data Collection, on page 1 Determining Which Host Operating Systems the System Can Detect, on page 2 Identifying Host Operating

More information

McAfee Network Security Platform 8.3

McAfee Network Security Platform 8.3 8.3.7.64-8.3.3.35 Manager-M-series Release Notes McAfee Network Security Platform 8.3 Revision A Contents About this release New features Enhancements Resolved issues Installation instructions Known issues

More information

IPMI Configuration Guide

IPMI Configuration Guide IPMI Configuration Guide 1. Introduction of IPMI Server Manager... 2 2. IPMI Server Manager GUI Overview... 3 1 1. Introduction of IPMI Server Manager IPMI Server Manager allows remote access of computers

More information

McAfee Network Security Platform 9.1

McAfee Network Security Platform 9.1 9.1.7.15-9.1.5.9 Manager-NS-series Release Notes McAfee Network Security Platform 9.1 Revision A Contents About this release New features Enhancements Resolved issues Installation instructions Known issues

More information

Configuring Cisco TelePresence Manager

Configuring Cisco TelePresence Manager CHAPTER 3 Revised: November 27, 2006, First Published: November 27, 2006 Contents Introduction, page 3-1 System Configuration Tasks, page 3-2 Security Settings, page 3-3 Database, page 3-4 Room Phone UI,

More information

Cisco Stealthwatch. Internal Alarm IDs 7.0

Cisco Stealthwatch. Internal Alarm IDs 7.0 Cisco Stealthwatch Internal Alarm IDs 7.0 Stealthwatch Internal Alarm IDs Some previously used alarms are now obsolete and no longer listed in this file. 1 Host Lock Violation 5 SYN Flood 6 UDP Flood 7

More information

McAfee Network Security Platform 9.1

McAfee Network Security Platform 9.1 9.1.7.49-9.1.3.6 Manager-M-series, Mxx30-series, XC Cluster Release Notes McAfee Network Security Platform 9.1 Revision C Contents About the release New features Enhancements Resolved issues Installation

More information

User Manual. Admin Report Kit for IIS 7 (ARKIIS)

User Manual. Admin Report Kit for IIS 7 (ARKIIS) User Manual Admin Report Kit for IIS 7 (ARKIIS) Table of Contents 1 Admin Report Kit for IIS 7... 1 1.1 About ARKIIS... 1 1.2 Who can Use ARKIIS?... 1 1.3 System requirements... 2 1.4 Technical Support...

More information

Sign in and Meeting Issues

Sign in and Meeting Issues Account Activation Fails, page 2 Automatic Login Problems Occur After Cookies are Imported from Microsoft Internet Explorer, page 2 Browser Compatibility Issues, page 2 Cannot Connect to WebEx Site or

More information

vrealize Operations Management Pack for NSX for vsphere 3.0

vrealize Operations Management Pack for NSX for vsphere 3.0 vrealize Operations Management Pack for NSX for vsphere 3.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition.

More information

After you install WatchGuard XCS v10.2, make sure you install any additional software updates available for this release.

After you install WatchGuard XCS v10.2, make sure you install any additional software updates available for this release. WatchGuard XCS v10.2 Release Notes WatchGuard XCS Build 250118 Release Date February 12, 2018 Release Notes Revision Date June 5, 2018 After you install WatchGuard XCS v10.2, make sure you install any

More information

Release Notes. Lavastorm Analytics Engine 6.1.3

Release Notes. Lavastorm Analytics Engine 6.1.3 Release Notes Lavastorm Analytics Engine 6.1.3 Lavastorm Analytics Engine 6.1.3: Release Notes Legal notice Copyright THE CONTENTS OF THIS DOCUMENT ARE THE COPYRIGHT OF LIMITED. ALL RIGHTS RESERVED. THIS

More information

Administering vrealize Log Insight. September 20, 2018 vrealize Log Insight 4.7

Administering vrealize Log Insight. September 20, 2018 vrealize Log Insight 4.7 Administering vrealize Log Insight September 20, 2018 4.7 You can find the most up-to-date technical documentation on the VMware website at: https://docs.vmware.com/ If you have comments about this documentation,

More information

Eucalyptus User Console Guide

Eucalyptus User Console Guide Eucalyptus 3.4.1 User Console Guide 2013-12-11 Eucalyptus Systems Eucalyptus Contents 2 Contents User Console Overview...5 Install the Eucalyptus User Console...6 Install on Centos / RHEL 6.3...6 Configure

More information

Dell License Manager Version 1.2 User s Guide

Dell License Manager Version 1.2 User s Guide Dell License Manager Version 1.2 User s Guide Notes, Cautions, and Warnings NOTE: A NOTE indicates important information that helps you make better use of your computer. CAUTION: A CAUTION indicates either

More information

VMware Identity Manager Connector Installation and Configuration (Legacy Mode)

VMware Identity Manager Connector Installation and Configuration (Legacy Mode) VMware Identity Manager Connector Installation and Configuration (Legacy Mode) VMware Identity Manager This document supports the version of each product listed and supports all subsequent versions until

More information

McAfee Enterprise Security Manager

McAfee Enterprise Security Manager Release Notes McAfee Enterprise Security Manager 10.0.2 Contents About this release New features Resolved issues Instructions for upgrading Find product documentation About this release This document contains

More information

DreamFactory Security Guide

DreamFactory Security Guide DreamFactory Security Guide This white paper is designed to provide security information about DreamFactory. The sections below discuss the inherently secure characteristics of the platform and the explicit

More information

McAfee Network Security Platform 8.3

McAfee Network Security Platform 8.3 8.3.7.68-8.3.7.55-8.3.7.14 Manager-Virtual IPS Release Notes McAfee Network Security Platform 8.3 Revision A Contents About this release New features Enhancements Resolved issues Installation instructions

More information

vrealize Suite Lifecycle Manager 1.0 Installation and Management vrealize Suite 2017

vrealize Suite Lifecycle Manager 1.0 Installation and Management vrealize Suite 2017 vrealize Suite Lifecycle Manager 1.0 Installation and Management vrealize Suite 2017 vrealize Suite Lifecycle Manager 1.0 Installation and Management You can find the most up-to-date technical documentation

More information

This study aid describes the purpose of security contexts and explains how to enable, configure, and manage multiple contexts.

This study aid describes the purpose of security contexts and explains how to enable, configure, and manage multiple contexts. Configuring Security Contexts Created by Bob Eckhoff This study aid describes the purpose of security contexts and explains how to enable, configure, and manage multiple contexts. Security Context Overview

More information

McAfee Network Security Platform 8.3

McAfee Network Security Platform 8.3 Revision A McAfee Network Security Platform 8.3 (8.3.7.86-8.3.5.53 Manager-NS-series Release Notes) Contents About this release New features Enhancements Resolved issues Installation instructions Known

More information

McAfee Network Security Platform 8.3

McAfee Network Security Platform 8.3 Revision A McAfee Network Security Platform 8.3 (8.3.7.86-8.3.7.59 Manager-Virtual IPS Release Notes) Contents About this release New features Enhancements Resolves issues Installation instructions Known

More information

Stonesoft Management Center. Release Notes for Version 5.6.1

Stonesoft Management Center. Release Notes for Version 5.6.1 Stonesoft Management Center Release Notes for Version 5.6.1 Updated: January 9, 2014 Table of Contents What s New... 3 Fixes... 3 System Requirements... 6 Basic Management System Hardware Requirements...

More information

Proxy Log Configuration

Proxy Log Configuration Stealthwatch System Proxy Log Configuration (for Stealthwatch System v6.10.x) Copyrights and Trademarks 2018 Cisco Systems, Inc. All rights reserved. NOTICE THE SPECIFICATIONS AND INFORMATION REGARDING

More information

Network Security Platform 8.1

Network Security Platform 8.1 8.1.7.13-8.1.5.57 NS-series Release Notes Network Security Platform 8.1 Revision B Contents About this release New features Enhancements Resolved issues Installation instructions Known issues Product documentation

More information

WatchGuard Dimension v2.0 Update 2 Release Notes. Introducing New Dimension Command. Build Number Revision Date 13 August 2015

WatchGuard Dimension v2.0 Update 2 Release Notes. Introducing New Dimension Command. Build Number Revision Date 13 August 2015 WatchGuard Dimension v2.0 Update 2 Release Notes Build Number 483146 Revision Date 13 August 2015 On 13 August 2015, WatchGuard released Dimension v2.0 Update 2. This update resolves an issue that caused

More information

McAfee Network Security Platform 8.3

McAfee Network Security Platform 8.3 8.3.7.64-8.3.5.47 Manager-NS-series Release Notes McAfee Network Security Platform 8.3 Revision A Contents About this release New features Enhancements Resolved issues Installation instructions Known issues

More information

Backup and Restore Operations

Backup and Restore Operations Backup Data Type, page 1 Backup and Restore Repositories, page 2 On-Demand and Scheduled Backups, page 3 Cisco ISE Restore Operation, page 8 Export Authentication and Authorization Policy Configuration,

More information

Stealthwatch Management Console VE and Flow Collector VE Installation and Configuration Guide (for Stealthwatch System v6.10.1)

Stealthwatch Management Console VE and Flow Collector VE Installation and Configuration Guide (for Stealthwatch System v6.10.1) Stealthwatch Management Console VE and Flow Collector VE Installation and Configuration Guide (for Stealthwatch System v6.10.1) Copyrights and Trademarks 2018 Cisco Systems, Inc. All rights reserved. NOTICE

More information

SOURCEFIRE 3D SYSTEM RELEASE NOTES

SOURCEFIRE 3D SYSTEM RELEASE NOTES SOURCEFIRE 3D SYSTEM RELEASE NOTES Version 5.3.0.2 Original Publication: April 21, 2014 Last Updated: April 25, 2016 These release notes are valid for Version 5.3.0.2 of the Sourcefire 3D System. Even

More information

Compare Security Analytics Solutions

Compare Security Analytics Solutions Compare Security Analytics Solutions Learn how Cisco Stealthwatch compares with other security analytics products. This solution scales easily, giving you visibility across the entire network. Stealthwatch

More information

Entuity for TrueSight Operations Management 16.5 Patch Notification

Entuity for TrueSight Operations Management 16.5 Patch Notification Entuity for TrueSight Operations Management 16.5 Patch Notification Technical Bulletin Version 2017.04.18 April 18, 2017 We are pleased to confirm the availability of patch P01 for Entuity for TrueSight

More information

vrealize Operations Management Pack for NSX for vsphere 3.5.0

vrealize Operations Management Pack for NSX for vsphere 3.5.0 vrealize Operations Management Pack for NSX for vsphere 3.5.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new edition.

More information

VMware AirWatch Content Gateway for Linux. VMware Workspace ONE UEM 1811 Unified Access Gateway

VMware AirWatch Content Gateway for Linux. VMware Workspace ONE UEM 1811 Unified Access Gateway VMware AirWatch Content Gateway for Linux VMware Workspace ONE UEM 1811 Unified Access Gateway You can find the most up-to-date technical documentation on the VMware website at: https://docs.vmware.com/

More information

vrealize Suite Lifecycle Manager 1.1 Installation, Upgrade, and Management vrealize Suite 2017

vrealize Suite Lifecycle Manager 1.1 Installation, Upgrade, and Management vrealize Suite 2017 vrealize Suite Lifecycle Manager 1.1 Installation, Upgrade, and Management vrealize Suite 2017 You can find the most up-to-date technical documentation on the VMware website at: https://docs.vmware.com/

More information

IBM Security QRadar Deployment Intelligence app IBM

IBM Security QRadar Deployment Intelligence app IBM IBM Security QRadar Deployment Intelligence app IBM ii IBM Security QRadar Deployment Intelligence app Contents QRadar Deployment Intelligence app.. 1 Installing the QRadar Deployment Intelligence app.

More information

Installing and Configuring vcloud Connector

Installing and Configuring vcloud Connector Installing and Configuring vcloud Connector vcloud Connector 2.6.0 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new

More information

Sentinel 8.0 includes new features, improves usability, and resolves several previous issues.

Sentinel 8.0 includes new features, improves usability, and resolves several previous issues. Sentinel 8.0 Release Notes November 2016 Sentinel 8.0 includes new features, improves usability, and resolves several previous issues. Many of these improvements were made in direct response to suggestions

More information

McAfee Network Security Platform 9.2

McAfee Network Security Platform 9.2 McAfee Network Security Platform 9.2 (9.2.7.22-9.2.7.20 Manager-Virtual IPS Release Notes) Contents About this release New features Enhancements Resolved issues Installation instructions Known issues Product

More information

Cisco Prime Service Catalog Virtual Appliance Quick Start Guide 2

Cisco Prime Service Catalog Virtual Appliance Quick Start Guide 2 Cisco Prime Service Catalog 11.1.1 Virtual Appliance Quick Start Guide Cisco Prime Service Catalog 11.1.1 Virtual Appliance Quick Start Guide 2 Introduction 2 Before You Begin 2 Preparing the Virtual Appliance

More information

Managing System Administration Settings

Managing System Administration Settings This chapter contains the following sections: Setting up the Outgoing Mail Server, page 2 Working with Email Templates, page 2 Configuring System Parameters (Optional), page 5 Updating the License, page

More information

ForeScout Extended Module for ServiceNow

ForeScout Extended Module for ServiceNow ForeScout Extended Module for ServiceNow Version 1.2 Table of Contents About ServiceNow Integration... 4 Use Cases... 4 Asset Identification... 4 Asset Inventory True-up... 5 Additional ServiceNow Documentation...

More information

Release Notes for Snare Enterprise Agent for MSSQL Release Notes for Snare Enterprise Agent for MSSQL v1.2/1.3

Release Notes for Snare Enterprise Agent for MSSQL Release Notes for Snare Enterprise Agent for MSSQL v1.2/1.3 Release Notes for Snare Enterprise Agent for v1.2/1.3 InterSect Alliance International Pty Ltd Page 1 of 19 About this document This document provides release notes for the Snare Enterprise Agent for version

More information

Troubleshooting APPENDIX

Troubleshooting APPENDIX APPENDIX A This appendix addresses some common issues you might encounter while using the NAM Traffic Analyzer. Username and Password Issues, page A-2 Login Issues, page A-3 Packet Capturing and Spanning

More information

Using the vrealize Orchestrator Operations Client. vrealize Orchestrator 7.5

Using the vrealize Orchestrator Operations Client. vrealize Orchestrator 7.5 Using the vrealize Orchestrator Operations Client vrealize Orchestrator 7.5 You can find the most up-to-date technical documentation on the VMware website at: https://docs.vmware.com/ If you have comments

More information

Modular Policy Framework. Class Maps SECTION 4. Advanced Configuration

Modular Policy Framework. Class Maps SECTION 4. Advanced Configuration [ 59 ] Section 4: We have now covered the basic configuration and delved into AAA services on the ASA. In this section, we cover some of the more advanced features of the ASA that break it away from a

More information

McAfee Network Security Platform 8.1

McAfee Network Security Platform 8.1 Revision A McAfee Network Security Platform 8.1 (8.1.7.105-8.1.5.219 Manager-NS-series Release Notes) Contents About this release New features Enhancements Resolved issues Installation instructions Known

More information

Set Up Cisco ISE in a Distributed Environment

Set Up Cisco ISE in a Distributed Environment Cisco ISE Deployment Terminology, page 1 Personas in Distributed Cisco ISE Deployments, page 2 Cisco ISE Distributed Deployment, page 2 Configure a Cisco ISE Node, page 5 Administration Node, page 8 Policy

More information

User Identity Sources

User Identity Sources The following topics describe Firepower System user identity sources, which are sources for user awareness. These users can be controlled with identity and access control policies: About, on page 1 The

More information