
8 Patch Release Note
Patch 86261-09 for Software Release 2.6.1
C613-10388-00 REV J
Changing the time on the router by using the set time command was
causing any temporary firewall rules configured, i.e. those rules specified
with a TTL parameter, to timeout. This issue has been resolved.
If a mirror port was configured using the command, set switch mirror=port
x, then another port was configured to be tagged using the command, set
vlan=default port=y frame=tag, the tagging configured for port x would be
removed. This issue has been resolved.
When a firewall rule was added using the commands,
add firewall policy rule action=nat list=text file name
(where the text file contained a list of IP addresses), the device dropped
packets that matched the rule parameters in the list, instead of translating
them.
This issue has been resolved by ensuring that the device translates the
addresses of packets that match the rule parameters and whose addresses
exist in the list file, but drops packets whose addresses do not exist in the
list file.
For outbound packets that match the rule parameters, but not the list, the
rule matching process continues until a matching rule is found. If no
matching rule is found, the default rule allow all is applied. For inbound
packets that match the rule parameters, but not the list, the rule matching
process is terminated and the packets will be dropped as they are when
action=allow is specified.
When proxy ARP was enabled on an interface that was set up as a VRRP
virtual router, the switch was sending proxy ARP response messages using
its own switch’s MAC address rather than that assigned to the Virtual
Router. This issue has been resolved, by ensuring that Proxy ARP responses
now use the MAC address assigned to the virtual Router.
The NVS read and write routines were not displaying the correct number
for the permanent log entries when the default was changed. This issue has
been resolved.
The command add firewall policy=policy1 dynamic=remote
file=filename.txt was not accepted when the filename exceeded eight
characters (excluding the three suffix characters). This issue has been
resolved by enabling the device to shorten these file names before writing
them to the config file.
When a switch port is set with a learn limit, and the packet source address
is a broadcast or multicast address. Then, rather than ignoring these
addresses the switch was learning them and entering them into its forward
database. This issue has been resolved.
PCR: 40097 Module: FW Level: 2
PCR: 40099 Module: VLAN Level: ?
PCR: 40100 Module: FIREWALL Level: 2
PCR: 40101 Module: VRRP Level: 2
PCR: 40103 Module: NVS Level:3
PCR: 40106 Module: FIREWALL Level: 3
PCR: 40107 Module: SWI Level:3
Comentários a estes Manuais