Dell SonicWALL WXA 1.3.1

Similar documents
Dell SonicWALL Security 8.1.1

Dell SonicWALL SonicOS 5.9 Upgrade Guide

Spotlight Management Pack for SCOM. User Guide

Dell Statistica. Statistica Enterprise Server Installation Instructions

One Identity Quick Connect Express

Cloud Access Manager How to Deploy Cloud Access Manager in a Virtual Private Cloud

SonicWall Analyzer 8.4 SP1

Dell Secure Mobile Access Connect Tunnel Service User Guide

SonicWall Directory Connector with SSO 4.1.6

SonicWall Mobile Connect for Chrome OS

Dell GPOADmin 5.7. About Dell GPOADmin 5.7. New features. Release Notes. December 2013

One Identity Active Roles 7.2

MySonicWall Secure Upgrade Plus

One Identity Starling Two-Factor AD FS Adapter 6.0. Administrator Guide

One Identity Starling Two-Factor Desktop Login 1.0. Administration Guide

One Identity Management Console for Unix 2.5.1

One Identity Starling Two-Factor HTTP Module 2.1. Administration Guide

SonicWall Secure Mobile Access

The Privileged Appliance and Modules (TPAM) 1.0. Diagnostics and Troubleshooting Guide

One Identity Active Roles Diagnostic Tools 1.2.0

Dell SonicWALL SonicOS

SonicWall SonicOS 5.9

One Identity Starling Two-Factor Authentication. Administrator Guide

SonicWall Secure Mobile Access SMA 500v Virtual Appliance 8.6. Getting Started Guide

Cloud Access Manager SonicWALL Integration Overview

One Identity Starling Two-Factor Authentication. Administration Guide

Cloud Access Manager How to Configure for SSO to SAP NetWeaver using SAML 2.0

SonicWall SMA 8200v. Getting Started Guide

One Identity Password Manager User Guide

SonicWall Mobile Connect ios 5.0.0

SonicWall Content Filtering Client for Windows and Mac OS

Dell Change Auditor 6.5. Event Reference Guide

SonicWall Analyzer 8.4

About Toad for Oracle 2017 Editions 2. Product release notes 4. Installation 5

SonicWall Secure Mobile Access

July SonicWall SonicOS 6.2 Upgrade Guide

SonicWall Mobile Connect for Android

Quest One Password Manager

Setting up the DR Series System with vranger. Technical White Paper

One Identity Starling Two-Factor Authentication

Rapid Recovery License Portal Version User Guide

Metalogix Intelligent Migration. Installation Guide

Spotlight on SQL Server Enterprise Spotlight Management Pack for SCOM

SQL Optimizer for Oracle Installation Guide

Dell One Identity Cloud Access Manager 8.0. Overview

SonicWall Analyzer 8.4

EAM Portal User's Guide

One Identity Password Manager 5.7.1

Quest Unified Communications Diagnostics Data Recorder User Guide

One Identity Active Roles 7.2. Management Pack Technical Description

SQL Optimizer for IBM DB2 LUW 4.3.1

Setting Up Quest QoreStor with Veeam Backup & Replication. Technical White Paper

1.0. Quest Enterprise Reporter Discovery Manager USER GUIDE

About One Identity Quick Connect for Base Systems 2.4.0

Setting up the DR Series System on Acronis Backup & Recovery v11.5. Technical White Paper

SonicWall Global VPN Client Getting Started Guide

Setting up Quest QoreStor as an RDA Backup Target for NetVault Backup. Technical White Paper

Quest Migration Manager Upgrade Guide

A Rapid Recovery Technical Whitepaper. Lenovo Nutanix Data Protection: Best Practices for Quest Software Data Protection Solutions

Metalogix Archive Manager for Files 8.0. IIS Installation

Dell SonicWALL Analyzer 8.1 Virtual Appliance. Getting Started Guide

Quest VROOM Quick Setup Guide for Quest Rapid Recovery and Foglight Windows Installers

Dell Migration Manager 8.11 Collection Management Utility

One Identity Active Roles 7.2. Replication: Best Practices and Troubleshooting Guide

Dell SonicWALL Content Filtering Client on Chrome About Content Filtering Client on Chrome OS

KACE GO Mobile App 4.0. Release Notes

Quest Knowledge Portal 2.9

Dell SonicWALL SonicOS 6.2

Quest VROOM Quick Setup Guide for Quest Rapid Recovery for Windows and Quest Foglight vapp Installers

One Identity Starling Identity Analytics & Risk Intelligence. User Guide

Toad Edge 2.0 Preview

KACE GO Mobile App 3.1. Release Notes

One Identity Safeguard for Privileged Sessions 5.9. Remote Desktop Protocol Scenarios

Toad DevOps Toolkit 1.0

About Space Manager with LiveReorg

One Identity Defender 5.9. Product Overview

Quest Migration Manager for Exchange Granular Account Permissions for Exchange 2010 to 2013 Migration

Dell Statistica Silent Installer Instructions

Quest Migration Manager for Exchange Resource Kit User Guide

KACE GO Mobile App 5.0. Release Notes

Dell AppAssure. PowerShell Module Reference 5.4.3

Dell SonicWALL SonicOS

Quest Recovery Manager for Active Directory 9.0. Quick Start Guide

SonicWall Security 9.0.6

Authentication Services ActiveRoles Integration Pack 2.1.x. Administration Guide

KACE GO Mobile App 5.0. Getting Started Guide

Rapid Recovery DocRetriever for SharePoint User Guide

Dell SonicWALL SonicOS

Dell Migration Solutions for SharePoint 4.8. User Guide

Quest Migration Manager for Exchange Granular Account Permissions for Exchange 2010 to 2010 Migration

Quest Collaboration Services 3.6. Installation Guide

Quest VROOM Quick Setup Guide for Quest Rapid Recovery for Windows and Quest Foglight vapp Installers

One Identity Manager Administration Guide for Connecting to SharePoint

Quest Recovery Manager for Active Directory Forest Edition 9.0. Quick Start Guide

One Identity Active Roles 7.2. Configuration Transfer Wizard Administrator Guide

Cloud Access Manager How to Configure Microsoft Office 365

voptimizer Pro Version What s New

Quest Migrator for Notes to Exchange SSDM User Guide

Authentication Manager Self Service Password Request Administrator s Guide

LiteSpeed for SQL Server 6.1. Configure Log Shipping

Transcription:

Complete Product Name with Trademarks Version Dell SonicWALL March 2015 These release notes provide information about the Dell SonicWALL release. About... 1 New features... 1 Supported platforms... 2 Resolved issues... 4 Known issues... 5 Product licensing... 6 Upgrade and deployment instructions... 6 Technical support resources... 10 About Dell... 10 About introduces new features and fixes a number of known issues. See the New features and the Resolved issues sections for more information. This release contains all the features and resolved issues that were in previous releases. For more information, see the previous release notes: WXA 1.3.0 https://support.software.dell.com/sonicwall-wan-accelerationseries/release-notes-guides IMPORTANT: runs in 64-bit mode for WXA 5000 and 6000 series appliances. New features This release introduces new features and greatly improves stability, by utilizing the 64-bit mode to handle more concurrent connections. The following new features are introduced in : Adding New Virtual Disks to the Cache The Dell SonicWALL WXA 5000 is an Open Virtualization Appliance (OVA). The WXA 5000 has a 250 GB hard disk. The hard disk is partitioned such that most of the space is allocated as a cache partition. The cache partition holds the TCP and WAFS acceleration databases and the Web Cache objects. The 1

administrator can increase the size of the cache partition by simply adding a new virtual hard disk to the WXA appliance. The new disk space is then automatically allocated to the cache partition. Logging Enhancements The WAN Acceleration > Log page has a new button to clear all the logs in the panel. The panel has a new column that shows the ID number of the message which should make diagnosing issues through Technical Support much faster. The Logging messages have been reviewed and made to read more relevant to the end user. Store and Forward The Config option provides the administrator with the ability to set up the Store and Forward feature for WFS. The Store and Forward feature is useful in cases where a user wants to transfer large files to an off-site WFS server, and then disconnect their PC without having to wait for a lengthy transfer to complete. WFS Signed SMB A new page has been introduced for configuring Signed SMB. Basic and Advanced Modes can now be used alternately. Auto Download of Firmware Images When configured, new firmware images can be automatically downloaded to the WXA in readiness to be applied. Supported platforms The release is supported on the following Dell SonicWALL WAN Acceleration (WXA) series appliances: WXA 6000 Software WXA 5000 Virtual Appliance WXA 4000 WXA 2000 WXA 500 Software is supported to work with Dell SonicWALL E-class NSA, NSA, or TZ series appliances running SonicOS 5.8.1.0 or higher firmware. WXA 6000 Software requirements The WXA 6000 Software requires: A Dell SonicWALL E-class NSA, NSA, or TZ series appliance An unused interface on the Dell SonicWALL NSA/TZ series appliance configured with a LAN Static IP address and a DHCP lease scope. Please refer to the WXA Quick Start Guide for more information A Monitor and Keyboard A Dell PowerEdge R320 server with the following specifications: Processor Memory RAID Controller Intel Xeon CPU E5-2420 0 @ 1.90GHz, 6 Cores RAM : 32 GB ECC DDR3, 1333 MHz Video Memory : 16 MB PERC H310 Mini Hard Drive 2x 400 GB SSD (Intel SSD DC S3700 Series) 2.5" SATA SSD with 3.5" Hard drive bracket Embedded NIC 2x Broadcom 5720 dual-port 1Gb LOM 2

WXA 5000 Virtual Appliance requirements The WXA 5000 Virtual Appliance requires: An E-class NSA, NSA, or TZ security appliance An unused interface on the NSA or TZ security appliance configured with a LAN Static IP address and a DHCP lease scope. Please refer to the WXA Quick Start Guide for more information A server running VMware ESX or ESXi version 5.0 or higher is recommended 2 virtual CPUs 250 GB hard disk 4GB RAM A layer 2 network between the ESX Server and the NSA/TZ series appliance. This is required for communication between the WXA 5000 on your ESX Server and the NSA/TZ series appliance WXA 500 Software requirements The WXA 500 Software requires: An E-class NSA, NSA, or TZ security appliance An unused interface on the NSA/TZ series appliance configured with a LAN Static IP address and a DHCP lease scope. Please refer to the WXA Quick Start Guide for more information Monitor and Keyboard A Dell OptiPlex 3010, Dell Inspiron 660s, or Dell Vostro 270s with: Processor Memory Hard Drive Optical Drive Pentium 4 or higher Minimum of 2GB Minimum of 80 GB CD/DVD ROM bay Firmware compatibility The table below details the SonicOS and WXA firmware compatibility. WXA 1.3 1.2 1.1 6.1 and above X X SonicOS 5.9 X X 5.8.1.11 or higher X X 5.8.1.0 5.8.1.10 X* X* X * Some WXA features will not be available. 3

Resolved issues The following issues are resolved in this release. Resource Monitor Resolved issue CPU and Memory utilization are reported in logs and remedies applied in sustained conditions. Occurs when the appliance becomes heavily loaded. 148884 SMB Resolved issue WFS Signed SMB does not respond. Occurs when a share is removed without the WFS component being restarted. WFS Unsigned SMB traffic forwarding stops. Occurs after a reboot where Unsigned SMB connections may not be forwarded to the acceleration component. 153110 149323 System Resolved issue System internal components rely on a version of the BASH software that is vulnerable to the SHELLSHOCK issue CVE-2014-6271. WXA is a closed system, so there are no known external exploit vectors. OpenSSL software for SSLv3 is vulnerable to the POODLE issue (CVE-2014-3566). WXA is a closed system, so there are no known external exploit vectors. WXA Web Cache has DNS lookup vulnerabilities. Occurs when SonicOS forwards packets to the Web Cache. 152525 153185 156862 TCP Acceleration Resolved issue Network File System (NFS) shares cannot be mounted, and the error message, Operation Not Permitted is displayed. Occurs when WAN Acceleration is enabled. A high CPU load occurs when transferring a single file. Occurs when too many data cache database messages are flooding Syslog. These messages should be suppressed or removed. 155966 154004 WFS Acceleration Resolved issue File shares cannot be accessed. Occurs when a client tries to open file shares on a Windows server that only serves Signed SMB traffic. 153270 4

Known issues The following issues are resolved in this release. Firewall Known issue The Web Proxy Server NAT policies to a secondary WXA are not automatically synchronized. Occurs if the Web Cache is enabled on the primary WXA and there is a failover to the secondary WXA. Workaround: After enabling the Web Cache, manually synchronize the settings by clicking the Synchronize Settings button. Network Address Translation (NAT) policies are not added for the Web Cache feature. Occurs when enabling the Web Cache feature on an NSA/TZ series appliance with Virtual Local Area Networks (VLAN) configured. 127524 120986 Firmware Known issue WXA5000 vsphere/vcenter reports 32 bit Guest OS pre-boot. 141889 Occurs in L2B and Routed Mode where a NAT Policy is automatically created. Workaround: Either delete the NAT Policy or add the respective destination subnet in the Web Cache exclusions. System Settings Known issue Settings files using Japanese characters are not displayed correctly on the WAN Acceleration > System > Settings page. Occurs when saving configuration settings to a file with Japanese characters in the name. Upload the file in the WAN Acceleration > System > Settings page and see that the file name is not displayed correctly. Workaround: Use English characters in the file name. 126444 Web Cache Known issue Traffic is accelerated by the Web Cache component instead of the TCP Acceleration component as it should be. 147961 Occurs in L2B and Routed Mode where a NAT Policy is automatically created. Workaround: Either delete the NAT Policy or add the respective destination subnet in the Web Cache exclusions. The Web Cache does not work in Routed mode. Occurs when enabling the Web Cache in a WXA deployment using Routed mode. Since the Web Cache was enabled after Routed mode was configured, the NAT policy created for the Web Cache gets a lower priority. Workaround: Disable Routed mode, then re-enable it. This created a new NAT policy for Routed mode with a lower priority than the Web Cache NAT policy. Some videos on YouTube are allowed to be viewed as WebM files. 141255 122758 The WebM file format is not supported by this feature. The Web Cache feature can be incorrectly enabled. 122054 5

Known issue Occurs when running the WXA 500 Software in Memory Mode and enabling the Web Cache feature on the Network > Web Proxy page. This checkbox should not be available in Memory Mode. WFS Acceleration Known issue For some file formats and in certain bandwidth conditions, non-cached traffic may be slower than expected. Occurs when copying files between sites using WFS Acceleration > Unsigned SMB. A DNS registration failure: 68 displays in the Join Domain Results screen. Occurs when registering the WFS server in the Domain Name System (DNS). The WXA tries to obtain domain computer information through an offline or nonexisting domain controller instead of a working one, causing the management interface to display the following message: No server found on the domain, try again later. Occurs when the user adds a new server while using Signed SMB. Workaround: Remove offline, no public name, or incorrect IP name server records on the DNS server. 138503 134421 132953 Product licensing Dell SonicWALL WXA appliances must be registered on MySonicWALL to enable full functionality and the benefits of Dell SonicWALL security services, firmware updates, and technical support. After your Dell SonicWALL WXA appliance is connected to a registered Dell SonicWALL network security appliance, if connected to the Internet, SonicOS will automatically register it. It may take up to 24 hours for your WXA to be automatically registered. Optionally, you can manually register your WXA on MySonicWALL by logging into your account at: http://www.mysonicwall.com. All Dell SonicWALL WXA appliances include an initial subscription to Dell SonicWALL 24x7 Support. In order to receive technical support, your WXA must have an active Support subscription. Upgrade and deployment instructions For information about obtaining the latest firmware, upgrading the firmware image on your Dell SonicWALL WXA appliance, see the Dell SonicWALL Administrator s Guide, available on MySonicWALL or on the Dell Software Support page for Dell SonicWALL WXA appliances: https://support.software.dell.com/sonicwall-wan-acceleration-series/release-notes-guides WXA 500, WXA 2000, and WXA 4000 If you are upgrading a WXA 500, WXA 2000, or WXA 4000 running firmware version 1.0, you must perform the following steps: 1. Upgrade to version 1.2.2-0-7. 2. Clear the browser cache. 3. Upgrade to version 1.3.1. 6

4. Clear the browser cache. 5. If you are using WFS for Signed SMB, rejoin the WXA to the domain. WXA 5000 The WXA 5000 cannot be upgraded from version 1.2.2-0-7 (or before) to 1.3.0 (or later). The WXA 5000 was changed from a 32bit OS to 64bit OS. So, to make this upgrade, you must reinstall the virtual machine. The upgrade (.bin) files and OVA (for a fresh WXA 5000 install) can be downloaded from the Download Center on MySonicWALL under the appropriate model heading: https://www.mysonicwall.com/ Upgrading the WXA series appliance firmware Before making any changes to the firmware, Dell SonicWALL recommends that you download a copy of the current configuration settings. Upgrade files are large and the process of uploading can take a considerable length of time. It is recommended to change the period of inactivity before the Administrator is logged out (on the System > Administration page), so you are not logged out while waiting for the firmware file to upload. To upgrade to the latest WXA firmware, perform the following: 1. Login to your NSA/TZ series appliance. 2. Navigate to the WAN Acceleration > System page. 3. Select the Firmware tab. 7

4. In the Firmware Upgrade panel, click the Upload New Firmware button. 5. Click the Choose File button. 6. Select the WXA firmware image you downloaded from www.mysonicwall.com, and then click Open. 7. Click the Upload button. Note: When performing a firmware upload, do NOT navigate away from the System > Firmware tab. This could stop the uploading process or cause the management interface to become unresponsive. The firmware uploading process will take a few minutes. After the upload has completed, the Firmware Upgrade panel will repopulate with the updated information: 8. Click the Boot icon. A confirmation pop-up is displayed: 9. Click OK. The WXA series appliance reboots with the uploaded firmware version. This will take a few minutes. 10. Clear the browser s cache, and then restart the browser. 8

Deployment Consider the following when setting up the WXA series appliance within your network: When the WXA series appliance is placed on the LAN zone, connections from the WLAN zone will not be redirected to it. When the WXA series appliance is placed on the DMZ zone, connections from the WLAN zone can then be processed by the Web Cache. Upgrading from WXA 1.0.x firmware to WXA 1.1.1 and higher firmware requires re-joining the domain and clearing the browser cache. Using WFS Acceleration Signed SMB requires joining the WXA series appliance to the domain. Any paths to shares need to be remapped on each client PC. Internet Protocol Version 6 (IPv6) is not supported. Only Kerberos and NT LAN Manager Version 2 (NTLMv2) are supported for WFS Acceleration. Only Microsoft Windows based file servers are supported. This includes all supported versions of Microsoft Windows Server (2003, 2008, and 2012) and excludes Network Attached Storage appliances from third party vendors. The WAN Acceleration Client (WXAC) is supported on the following: o Windows Vista o Windows XP o Windows 7 o Windows 8 o Windows Server 2003 and 2008 Note: WXAC is not supported on Windows Server 2012. WXAC is not supported on Mac OS or Linux. Dynamic routing is not supported for TCP Acceleration. Network Address Translation (NAT) is not supported for TCP acceleration. Domain Auto-Join is not supported on the WXA 500 Software and WXA 5000 Virtual Appliance. Running the WXA 500 Software or 6000 Software inside a virtualization host (like ESXi, Xen or VirtualBox) is not supported. The default Web Cache maximum object size is 50 megabytes. Browser support SonicOS with Visualization uses advanced browser technologies such as HTML5, which are supported in most recent browsers. Dell SonicWALL recommends using the latest Chrome, Firefox, Internet Explorer, or Safari browsers for administration of SonicOS. This release supports the following Web browsers: Chrome 18.0 and higher (recommended browser for dashboard real-time graphics display) Firefox 16.0 and higher Internet Explorer 8.0 and higher (do not use compatibility mode) Safari 5.0 and higher Mobile device browsers are not recommended for Dell SonicWALL appliance system administration. 9

Technical support resources Technical support is available to customers who have purchased Dell software with a valid maintenance contract and to customers who have trial versions. To access the Support Portal, go to http://software.dell.com/support/. Dell SonicWALL Administration Guides and related documents are available on the Dell Software Support site at https://support.software.dell.com/release-notes-product-select. The Support Portal provides self-help tools you can use to solve problems quickly and independently, 24 hours a day, 365 days a year. In addition, the portal provides direct access to product support engineers through an online Service Request system. The site enables you to: View Knowledge Base articles at: https://support.software.dell.com/kb-product-select View instructional videos at: https://support.software.dell.com/videos-product-select Engage in community discussions Chat with a support engineer Create, update, and manage Service Requests (cases) Obtain product notifications About Dell Dell listens to customers and delivers worldwide innovative technology, business solutions and services they trust and value. For more information, visit www.software.dell.com. Contacting Dell Technical support: Online support Product questions and sales: (800) 306-9329 Email: info@software.dell.com 10

2015 Dell Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide is furnished under a software license or nondisclosure agreement. This software may be used or copied only in accordance with the terms of the applicable agreement. No part of this guide may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopying and recording for any purpose other than the purchaser s personal use without the written permission of Dell Inc. The information in this document is provided in connection with Dell products. No license, express or implied, by estoppel or otherwise, to any intellectual property right is granted by this document or in connection with the sale of Dell products. EXCEPT AS SET FORTH IN THE TERMS AND CONDITIONS AS SPECIFIED IN THE LICENSE AGREEMENT FOR THIS PRODUCT, DELL ASSUMES NO LIABILITY WHATSOEVER AND DISCLAIMS ANY EXPRESS, IMPLIED OR STATUTORY WARRANTY RELATING TO ITS PRODUCTS INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT. IN NO EVENT SHALL DELL BE LIABLE FOR ANY DIRECT, INDIRECT, CONSEQUENTIAL, PUNITIVE, SPECIAL OR INCIDENTAL DAMAGES (INCLUDING, WITHOUT LIMITATION, DAMAGES FOR LOSS OF PROFITS, BUSINESS INTERRUPTION OR LOSS OF INFORMATION) ARISING OUT OF THE USE OR INABILITY TO USE THIS DOCUMENT, EVEN IF DELL HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. Dell makes no representations or warranties with respect to the accuracy or completeness of the contents of this document and reserves the right to make changes to specifications and product descriptions at any time without notice. Dell does not make any commitment to update the information contained in this document. If you have any questions regarding your potential use of this material, contact: Dell Inc. Attn: LEGAL Dept 5 Polaris Way Aliso Viejo, CA 92656 Refer to our web site (software.dell.com) for regional and international office information. Patents For more information about applicable patents, refer to http://software.dell.com/legal/patents.aspx. Trademarks Dell, the Dell logo, and SonicWALL are trademarks of Dell Inc. Other trademarks and trade names may be used in this document to refer to either the entities claiming the marks and names or their products. Dell disclaims any proprietary interest in the marks and names of others. Legend CAUTION: A CAUTION icon indicates potential damage to hardware or loss of data if instructions are not followed. WARNING: A WARNING icon indicates a potential for property damage, personal injury, or death. IMPORTANT NOTE, NOTE, TIP, MOBILE, or VIDEO: An information icon indicates supporting information. Last updated: 3/4/2015 232-002726-01 Rev A 11