McAfee Network Security Platform

Similar documents
McAfee Network Security Platform 9.1

McAfee Network Security Platform 9.1

McAfee Network Security Platform 9.1

McAfee Network Security Platform 9.2

McAfee Network Security Platform

McAfee Network Security Platform 9.1

McAfee Network Security Platform 9.1

McAfee Network Security Platform 9.1

McAfee Network Security Platform 8.3

McAfee Network Security Platform 8.3

McAfee Network Security Platform 9.2

McAfee Network Security Platform 8.3

McAfee Network Security Platform 8.3

McAfee Network Security Platform 9.1

McAfee Network Security Platform 9.1

McAfee Network Security Platform 8.3

McAfee Network Security Platform 9.1

Network Security Platform 8.1

McAfee Network Security Platform 8.1

McAfee Network Security Platform 8.3

McAfee Network Security Platform

Network Security Platform 8.1

McAfee Network Security Platform 9.2

McAfee Network Security Platform 8.3

McAfee Network Security Platform 8.3

Network Security Platform 8.1

McAfee Network Security Platform 9.1

McAfee Network Security Platform 8.1

Network Security Platform 8.1

Network Security Platform 8.1

McAfee Network Security Platform 8.3

McAfee Network Security Platform 8.3

Network Security Platform 8.1

McAfee Network Security Platform 8.3

McAfee Network Security Platform 9.2

McAfee Virtual Network Security Platform 8.4 Revision A

Network Security Platform 8.1

Network Security Platform 8.1

McAfee Network Security Platform 8.1

McAfee Network Security Platform 8.3

Network Security Platform 8.1

McAfee Network Security Platform

McAfee Network Security Platform 9.2

McAfee Network Security Platform 8.3

Network Security Platform 8.1

Network Security Platform 8.1

Network Security Platform 8.1

Network Security Platform 8.1

McAfee Network Security Platform

Network Security Platform 8.1

Network Security Platform 8.1

Network Security Platform 8.1

McAfee Network Security Platform 9.1

McAfee Network Security Platform 8.3

Network Security Platform 8.1

Network Security Platform 8.1

McAfee Network Security Platform 8.3

Network Security Platform 8.1

McAfee Network Security Platform 8.3

Network Security Platform 8.1

McAfee Network Security Platform 8.3

Network Security Platform 8.1

Manager Appliance Quick Start Guide

McAfee Advanced Threat Defense 3.4.8

McAfee Network Security Platform 8.1

McAfee Advanced Threat Defense Release Notes

McAfee Advanced Threat Defense 3.4.4

Stonesoft Management Center. Release Notes Revision A

McAfee Next Generation Firewall 5.9.1

McAfee Network Security Platform

Next Generation Firewall

McAfee Firewall Enterprise 8.3.2P05

Stonesoft Management Center. Release Notes Revision A

McAfee Network Security Platform

McAfee Data Loss Prevention 9.3.3

Endpoint Intelligence Agent 2.2.0

NGFW Security Management Center

Stonesoft Next Generation Firewall. Release Notes Revision A

NGFW Security Management Center

McAfee Data Loss Prevention Prevent 11.1.x Release Notes

McAfee Data Loss Prevention 9.3.2

Installing Cisco APIC-EM on a Virtual Machine

Stonesoft Next Generation Firewall. Release Notes Revision B

NGFW Security Management Center

Stonesoft Next Generation Firewall. Release Notes Revision C

Sidewinder. Release Notes 8.3.2P11. Revision A

McAfee Network Security Platform Administration Course

NGFW Security Management Center

McAfee epolicy Orchestrator Release Notes

NGFW Security Management Center

McAfee epolicy Orchestrator Release Notes

McAfee Web Gateway

NGFW Security Management Center

Stonesoft Management Center. Release Notes Revision A

NGFW Security Management Center

NGFW Security Management Center

NGFW Security Management Center

This release of the product includes these new features that have been added since NGFW 5.5.

NGFW Security Management Center

Release Notes McAfee Change Control 8.0.0

Transcription:

Revision A McAfee Network Security Platform (9.1.7.73-9.1.3.54 Manager-NTBA Release Notes) Contents About this release New features Enhancements Resolved issues Installation instructions Known issues Product documentation About this release This document contains important information about the current release. We recommend that you read the whole document. Network Security Platform follows a release process that is based on customer requirements and best practices followed by other McAfee teams. For details, read KB78795. This release of Network Security Platform delivers the high performance NTBA software for Virtual NTBA Appliances. NTBA version 8.3.4.58 is the minimum required version to upgrade to 9.1. This applies to all physical Appliances (T200, T500, T600, and T1200) and all NTBA Virtual Appliances (T-VM, T-100VM, T-200VM). The 9.1 NTBA software images are SHA2 signed. The GRUB needed to load a SHA2 NTBA image requires support for validating SHA2 signed images. This support has been added in the GRUB in the 8.3.4.58 release. All appliances running on any previous 8.1 or 8.3 versions must upgrade to this SHA1 signed intermediate version, before upgrading to 9.1. Release parameters Version Network Security Manager software version 9.1.7.73 Signature Set 9.8.23.5 Virtual NTBA appliance software version 9.1.3.54 1

Currently port 4167 is used as the UDP source port number for the SNMP command channel communication between Manager and Sensors. This is to prevent opening up all UDP ports for inbound connectivity from SNMP ports on the Sensor. Older JRE versions allowed the Manager to bind to the same source port 4167 for both IPv4 and IPv6 communication. But with the JRE version 1.8.0_172, it is no longer possible to do so, and the Manager uses port 4166 as the UDP source port to bind for IPv6. Manager 9.1 uses JRE version 1.8.0_172 and MySQL version 5.6.40. If you have IPv6 Sensors behind a firewall, you need to update your firewall rules accordingly such that port 4166 is open for the SNMP command channel to function between those IPv6 Sensors and the Manager. Manager software version 9.1 is not supported on McAfee-built Dell-based Manager Appliances. McAfee recommends that you use Intel-based Manager Appliances instead. Upgrade support McAfee regularly releases updated versions of the signature set. You can choose to automatically download and deploy the signature set in the Manager. The following are the upgrade matrices supported for this release: Manager software versions: Current version Upgrade path to 9.1 8.1.3.4, 8.1.3.6, 8.1.7.5, 8.1.7.12, 8.1.7.13 8.1.7.82 9.1.7.73 8.1.7.33, 8.1.7.52, 8.1.7.82, 8.1.7.91, 8.1.7.96, 8.1.7.100, 8.1.7.105 9.1.7.73 8.3.7.7, 8.3.7.28, 8.3.7.52, 8.3.7.64, 8.3.7.68, 8.3.7.86 9.1.7.73 9.1.7.11, 9.1.7.15, 9.1.7.49, 9.1.7.63 9.1.7.73 All intermediate Manager versions, such as Hotfixes, below 8.1.7.33 must upgrade to 8.1.7.82 before upgrading to the latest 9.1 Manager version. All Manager versions above 8.1.7.33 can directly upgrade to the latest 9.1 Manager version. Virtual NTBA software versions (T-VM, T-100VM, T-200VM): Current version Upgrade path to 9.1 8.1.3.6, 8.1.3.10, 8.1.3.40 8.3.4.58 9.1.3.54 8.3.3.2, 8.3.4.1 8.3.4.58 9.1.3.54 8.3.4.58 9.1.3.54 9.1.3.3, 9.1.3.7, 9.1.3.9 9.1.3.54 NTBA Appliance software versions (T-200, T-500, T-600, T-1200, T-VM, T-100VM, T-200VM): Current version Upgrade path to 9.1 8.1.3.6, 8.1.3.10, 8.1.3.40 8.3.4.58 9.1.3.9 8.3.3.2, 8.3.4.1 8.3.4.58 9.1.3.9 8.3.4.58 9.1.3.9 9.1.3.3, 9.1.3.7 9.1.3.9 All intermediate NTBA versions, such as Hotfixes, below 8.3.4.58 must upgrade to 8.3.4.58 before upgrading to the latest NTBA 9.1 version. All NTBA versions above 8.3.4.58 can directly upgrade to the latest NTBA 9.1 version. All Virtual NTBA Appliance versions (T-VM, T-100VM, and T-200VM) can upgrade to the latest T-200VM Virtual NTBA Appliance version. Upgrade for physical appliances to 9.1.3.54 is not supported. 2

Heterogeneous support This version of 9.1 Manager software can be used to configure and manage the following devices: Device NS-series Sensors (NS3100, NS3200, NS5100, NS5200, NS7100, NS7200, NS7300, NS9100, NS9200, NS9300) NS-series Sensors (NS7150, NS7250, NS7350) 9.1 Version 8.1, 8.3, 9.1 Virtual IPS for ESXi server (IPS-VM100, IPS-VM600) IPS-VM100: 8.1, 8.3, 9.1 Virtual IPS for KVM (IPS-VM100, IPS-VM600) 8.3 Virtual IPS for VMware NSX (IPS-VM100-VSS) 8.1, 8.3, 9.1 Virtual IPS for AWS (IPS-VM100-VSS) 8.3, 9.1 M-series Sensors (M-1250, M-1450, M-2850, M-2950, M-3050, M-4050, M-6050, M-8000) IPS-VM600: 8.1, 8.3, 9.1 8.1, 8.3, 9.1 Mxx30-series Sensors (M-3030, M-4030, M-6030, M-8030) 8.1, 8.3, 9.1 M-8000XC Cluster Appliance 8.1, 8.3, 9.1 NTBA Appliances (T-200, T-500, T-600, T-1200) 8.1, 8.3, 9.1 Virtual NTBA Appliances (T-VM, T-100VM, T-200VM) 8.1, 8.3, 9.1 New Sensor image for IPS-VM100 and IPS-VM100-VSS Sensor models are not supported from version 9.1.7.12. Integration support The above mentioned Network Security Platform software versions support integration with the following product versions: Table 1-1 Network Security Platform compatibility matrix Product Version supported McAfee epo 5.9.1, 5.9.0 McAfee Global Threat Intelligence McAfee Endpoint Intelligence Agent 2.6 McAfee Logon Collector 3.0.7 McAfee Threat Intelligence Exchange 2.1.1, 2.0.0 McAfee Data Exchange Layer 3.1.0, 3.0.0 McAfee Advanced Threat Defense 4.2.0.20 McAfee Virtual Advanced Threat Defense 4.2.0.4 McAfee Vulnerability Manager 7.5 McAfee Host Intrusion Prevention 8.0 Compatible with all versions Starting with release 9.1.7.63, integration with McAfee Cloud Threat Defense is no longer supported. New features This release provides fixes for some of the previously known issues, and does not include any new features. 3

Enhancements This release of Network Security Platform includes the following enhancement for the NTBA Virtual Appliance: High performance Virtual NTBA Appliance configurations From this release of Virtual NTBA Appliance software 9.1.3.54, you can now obtain higher flow processing rates by configuring the number of virtual sockets, number of cores per socket, and the memory. The following table shows the achievable flow processing rate for different configurations on the T-200VM NTBA Virtual Appliance. Table 3-1 Resource limit matrix SKU RAM CPU Maximum Exporters T-200VM 16 (Default) 4 (Default) Sensor/Routers: 256 32 8 Sensor/Routers: 256 46 16 Sensor/Routers: 256 96 32 Sensor/Routers: 256 Maximum Hosts Flow processing rate (flows per second) 200000 60000 1000 200000 70000 1000 200000 80000 1000 200000 95000 1000 Maximum zones For more information, see McAfee Network Security Platform 9.1 NTBA Administration Guide. Resolved issues The current release of the product resolves these issues. For a list of issues fixed in earlier releases, see the Release Notes for the specific release. Resolved Manager software issues The following table lists the medium-severity Manager software issues: ID # Issue Description 1240819 Excessive packet logging on the emsout.log file causes it to roll over in few minutes. 1239636 Vulnerability identified for MySQL version 5.6.39. 1239618/ 1232051 Audit logs from the Secondary Manager should appear without duplicate IPS event syslog. 1238533 Sensor update fails when the number of customized attacks are more than 20,000. 1238275 The manual callback detectors update fails as the update file has.0 suffix. 1237406 During the Sensor software upgrade, the Gateway Anti-Malware update from the Manager to Sensor fails. 1237008 The Manager IP address is populated in the Sensor IP address field for SNMP traps. 1234533 After disabling port setting in a failover pair, the Sensor information is not available through API. 1234127 The Manager has an Apache Tomcat vulnerability which allows an attacker to uncover information about the Apache Tomcat version. 4

ID # Issue Description 1233834 Configuration of a non-standard port at the device level displays the error Error adding non-standard port. 1233285 Addition of XC Cluster to the Manager fails with the error Error in adding XC Cluster: Internal Error. 1232114 In the Manager under Analysis <Admin Domain Name> Traditional Report Trend Analysis, the report contains duplicate Sensor names. 1232060 After Manager upgrade, syslog contains IPS event messages with no information. 1231963 The Top N Blocked Attacks report includes data for attacks with inconclusive attack results. 1231669 In a trend analysis report, once the report is generated in HTML format, there is no option to go back to the report configuration page. 1231333 The customized VPC name is incorrectly displayed for users and groups in the Manager. 1231287 When you click the Back button after generating a Next Generation report, the expiration page appears instead of the run report < report name>page. 1230161 When a port is disabled in NTBA in the Manager, Link Failure of Port: <port number> fault is generated. 1228772 Packet capture in attack log captures only the attack packet in an alert and not the subsequent packets or the entire flow. 1225510 Managers send events to the Central Manager even when Manager is not configured. 1225503 The date format in Primary and Secondary Central Managers are different in the Last Synchronized Time monitor in the Dashboard page. 1225366 After an upgrade, the logging in ems.log file continues even after reaching the maximum file limit. 1223185 API query does not return data for country. 1217412 Gateway Anti-Malware update fails for few Sensors due to a proxy configuration. The following table lists the low-severity Manager software issues: ID # Issue Description 1236685 The Manager has the following Spring Framework vulnerabilities: CVE-2018-1270 - An attacker can craft a message to the broker to execute a remote code attack. CVE-2018-1271 - An attacker can send a specially crafted URL request which can lead to directory traversal attack. CVE-2018-1272 - Multiple multipart in the server request could lead to part content exposure. CVE-2018-1275 - An attacker can craft a message to the broker to execute a remote code attack. Resolved NTBA software issues This release does not contain any resolved issues for NTBA. 5

Installation instructions Manager server/client system requirements The following table lists the 9.1 Manager server requirements: Operating system Minimum required Any of the following: Windows Server 2008 R2 Standard or Enterprise Edition, English operating system, SP1 (64-bit) (Full Installation) Windows Server 2008 R2 Standard or Enterprise Edition,, SP1 (64-bit) (Full Installation) Windows Server 2012 R2 Standard Edition (Server with a GUI) Windows Server 2012 R2 Standard Edition (Server with a GUI) Windows Server 2012 R2 Datacenter Edition (Server with a GUI) Windows Server 2012 R2 Datacenter Edition (Server with a GUI) Windows Server 2016 Standard Edition (Server with a GUI) Windows Server 2016 Standard Edition (Server with a GUI) Windows Server 2016 Datacenter Edition (Server with a GUI) Windows Server 2016 Datacenter Edition (Server with a GUI) Only X64 architecture is supported. Recommended Windows Server 2016 Standard Edition operating system Memory 8 GB Supports up to 3 million alerts in Solr. >16 GB Supports up to 10 million alerts in Solr. CPU Server model processor such as Intel Xeon Same Disk space 100 GB 300 GB or more Network 100 Mbps card 1000 Mbps card Monitor 32-bit color, 1440 x 900 display setting 1440 x 900 (or above) The following are the system requirements for hosting Central Manager/Manager server on a VMware platform. 6

Table 5-1 Virtual machine requirements Component Minimum Recommended Operating system Any of the following: Windows Server 2008 R2 Standard or Enterprise Edition,, SP1 (64-bit) (Full Installation) Windows Server 2008 R2 Standard or Enterprise Edition,, SP1 (64-bit) (Full Installation) Windows Server 2012 R2 Standard Edition (Server with a GUI) Windows Server 2012 R2 Standard Edition (Server with a GUI) Windows Server 2012 R2 Datacenter Edition (Server with a GUI) Windows Server 2012 R2 Datacenter Edition (Server with a GUI) Windows Server 2016 Standard Edition (Server with a GUI) Windows Server 2016 Standard Edition (Server with a GUI) Windows Server 2016 Datacenter Edition (Server with a GUI) Windows Server 2016 Datacenter Edition (Server with a GUI) Only X64 architecture is supported. Windows Server 2016 Standard Edition operating system Memory 8 GB >16 GB Supports up to 3 million alerts in Solr. Supports up to 10 million alerts in Solr. Virtual CPUs 2 2 or more Disk Space 100 GB 300 GB or more Table 5-2 VMware ESX server requirements Component Minimum Virtualization software ESXi 5.1 Update 2 ESXi 5.5 Update 3 ESXi 6.0 Update 1 ESXi 6.5 Update 1 The following table lists the 9.1 Manager Appliance (Linux) hardware and software specifications Table 5-3 Hardware and Software specifications Component Hardware Regulatory Model Name Specifications R1000 7

Table 5-3 Hardware and Software specifications (continued) Component CPU Hard Drive DVD ROM DIMM Integrated LAN USB ports Video Serial Port Software Specifications Intel Xeon Silver 4114 2.2Ghz10C, Skylake1 per system 2.5" Enterprise HDD2TBSATA III (6Gbps)7200 RPM2 per system None Manager software version 9.1 McAfee Linux OS (MLOS) version 64GB DDR42133Mhz 2 x 10 Gbe 2 x 3.0 on front and 3 x 3.0 on rear panel DB-15 HD VGA on front & rear panel RJ45 on rear panel 3.4.0.8756 or above The following table lists the 9.1 Manager client requirements when using Windows 7, Windows 8, or Windows 10: Operating system Minimum Windows 7, English or Japanese Windows 8, English or Japanese Windows 8.1, English or Japanese Windows 10, English or Japanese The display language of the Manager client must be the same as that of the Manager server operating system. Recommended Windows 10, English or Japanese RAM 2 GB 4 GB CPU 1.5 GHz processor 1.5 GHz or faster Browser Internet Explorer 10, 11 Mozilla Firefox Google Chrome (App mode in Windows 8 is not supported) To avoid the certificate mismatch error and security warning, add the Manager web certificate to the trusted certificate list. Internet Explorer 11 Mozilla Firefox 20.0 or later Google Chrome 24.0 or later In Mozilla Firefox version 52 or Google Chrome version 42 and above, the NPAPI plug-in is disabled by default. For the Manager client, in addition to Windows 7, Windows 8, Windows 8.1 and Windows 10, you can also use the operating systems mentioned for the Manager server. The following are Central Manager and Manager client requirements when using Mac: Mac operating system Yosemite El Capitan Browser Safari 8 or 9 8

For more information, see McAfee Network Security Platform Installation Guide. NTBA Virtual Appliance system requirements The following table lists the 9.1 NTBA Virtual Appliance requirements. Table 5-4 VMware ESX server requirements for NTBA Virtual Appliance Component Recommended Virtualization software VMware ESXi 5.1 and higher CPU 4 cores for T-200VM Memory T-200VM: 16 GB Network ports Storage 5 (One network management port and four monitoring ports for NTBA Virtual Appliance) 600 GB (partitions: 250 GB and 350 GB) The NTBA OVA image comes with pre-installed NTBA Appliance software, including the recommended configurations. Known issues For a list of known issues in this product release, see this McAfee KnowledgeBase article: Network Security Platform software issues: KB88813 Product documentation Every McAfee product has a comprehensive set of documentation. Go to McAfee Documentation Portal to find the product documentation for this product. Or 1 Go to the McAfee ServicePortal at http://mysupport.mcafee.com and click Knowledge Center. 2 Enter a product name, select a version, then click Search to display a list of documents. 9.1 product documentation list The following software guides are available for Network Security Platform 9.1 release: Quick Tour Virtual IPS Administration Guide Installation Guide (includes Upgrade Guide) CLI Guide Manager Administration Guide XC Cluster Administration Guide Custom Attack Definitions Guide Integration Guide Manager API Reference Guide Best Practices Guide IPS Administration Guide Troubleshooting Guide NTBA Administration Guide 9

Copyright 2018 McAfee, LLC McAfee and the McAfee logo are trademarks or registered trademarks of McAfee, LLC or its subsidiaries in the US and other countries. Other marks and brands may be claimed as the property of others. 0A00