Cntent Security esafe SmartSuite Release Ntes Versin: 8.5.25.0 Release Ntes Issue Date: May 20, 2010 Abut this release These release ntes prvide a list f the latest additins t esafe SmartSuite. esafe SmartSuite is a cmprehensive, practive and future prfed cntent security slutin that ges beynd leading-edge technlgy. This release f esafe SmartSuite fcuses n the enhanced Data lss /leak preventin (DLP) feature that includes DLP plicies, dictinaries, and prfiles that extends esafe s cntent security and CMF (Cntent Mnitring and Filtering) abilities. It als features imprvements t the central management feature, and varius changes t the esafe Security Center (GUI) that makes fr a better user experience, including media cntrl, actinable management, imprved alerting capabilities, web quarantine reprts and mre. This versin is an evlutin f esafe SmartSuite V8.0 which was released in Q4 f 2009. Fr detailed infrmatin n that release, please refer t the esafe SmartSuite Release Ntes fr V8.0. Availability esafe SmartSuite is nly available fr new installatins n the fllwing platfrms: esafe XG110 appliances esafe HG200 appliances esafe XG210 appliances esafe XG300 appliances IBM Blade Center, HS21/HS22 Blade VMware ESXi (*) esafe SmartSuite is available fr the fllwing implementatin/installatin mdes: Web Security Gateway In-line Bridge/Cluster esafe Ruter/Cluster esafe Prxy 2010 SafeNet, Inc. All rights reserved. Page 1 f 8 www.safenet-inc.cm
Release Ntes esafe ICAP esafe Frwarding Prxy esafe Web SSL Mail Security Gateway *Nte: esafe n VMware is available nly fr the fllwing implementatin mdes: Web Security Gateway esafe Prxy (includes WCCP supprt) esafe Web SSL Mail Security Gateway Upgrade Infrmatin Currently, this versin des nt supprt autmatically upgrading frm previus versins f esafe; it is nly pssible t perfrm new installatins. At this stage, users wh wish t upgrade their esafe machines must install esafe SmartSuite, and then apply the same cnfiguratin as the previus installatin. Further details are available at the end f these release ntes. Installatin Instructins Nte: Due t the GUI s new lk and feel, the minimum screen reslutin shuld be 1024 x 768. Detailed installatin instructins appear in the esafe SmartSuite Deplyment Guide. A separate dcument is available with instructins fr installing n VMware. Take nte that the fllwing prts need t be pened when a firewall exists between the esafe appliance and the Security Center: Prt 43970 Security Center (regular prtcl) Prt 5432 Security Center (esafe internal SQL) Prt 8888 Security Center (Dashbard updates) Prt 37233 Webmin management Prt 22 SSH remte cntrl Nte: As f this versin, we have eliminated the need fr an internal USB n XG appliances. Installatin r reimaging the appliance is dne via the external USB nly. Fr further details see the fllwing dcument: http://upd5.esafe.cm/pub/autupdate/ver85/prduct/xg-hg_appliance_usb_installatin.pdf 2010 SafeNet, Inc. All rights reserved. Page 2 f 8 www.safenet-inc.cm
Release Ntes New Features and Enhancements in esafe SmartSuite V8.5 esafe SmartSuite V8.5 includes the fllwing new features and enhancements: DLP: New DLP capabilities with enhanced features fr enfrcement, mnitring, and classificatin f sensitive files sent via email and web uplad. Supprts analysis f mre than 150 file types, including: MS Office dcuments, Open Office, and PDF files HTML, email, surce cde files Archived files New ptins allw taking specific actins when detecting data that matches the DLP dictinaries, including: Reprt: Lgs all file prperties in the event lg. Blck: Blcks utging files/email. Ntify sender: Sends a ntificatin t the email sender (fr mail events nly). Archive: Archives the file/email in a special repsitry fr later investigatin. Frward file/email by email: Frwards the file/email t a special DLP inspectr email address. Includes mre than 20 predefined ut-f-the-bx dictinaries that supprt Unicde. Includes predefined ut-f-the-bx DLP alerts with predefined Smart Alerts. Central Management: Imprved Central Management experience allws getting an instant verview f what s happening n the gateway by mnitring traffic, getting alerts, investigating events, and taking immediate actin. The central management features include: Single sign-n Centralized machine tree with easy navigatin between machines Supprt f data aggregatin and statistics fr grups/clusters Central lg server Real-time indicatrs abut machine status Advanced rle-based administratin. 2010 SafeNet, Inc. All rights reserved. Page 3 f 8 www.safenet-inc.cm
Release Ntes Nte: Since this versin uses the new central management and lg server, when installing an esafe machine, the Central Management ptin must be enabled. When installing esafe in a multiple esafe machine envirnment (mre than ne machine), ne machine must be installed with the Central Management mdule, and all thers withut. Only ne central management machine is allwed per rganizatin. In large envirnments (abve fur esafe machines), it is recmmended t install the central management/lg server as a standalne machine that des nt intercept r scan traffic. Direct Cnnectin: By default, the esafe Security Center cnnects t the central machine which allws mnitring and managing all machines in the rganizatin. In case f an emergency r if yu need t manage a specific machine NOT via the esafe Security Center management server, yu can cnnect t the machine directly (with limited capabilities), using the fllwing esafe management cmmand: "C:\Prgram Files\eSafe\eSafeMNG\8.5\esafemng.exe" /lg /p2p Prductivity Imprvements This versin includes varius Prductivity Imprvements, including: Cntrlling and blcking streaming traffic per URL categry with prfile and streaming prperties (RTSP, RTP, MMS, Flash, etc.). New warn/gray URL filter categries per plicy and verriding rules (Caching). Supprt fr nn-inspected SSL sites per URL categry. (Only esafe Web SSL) Mnitring and Reprting Enhanced Smart Alerts with granular DLP alerts. Allwing fast Smart Alert rule creatin when viewing Track & Care events. Dashbard Enhancements Enhanced Dashbard graphic charts with drill-dwn capabilities by duble-clicking n the chart r legend t see actual events fr a specific query. Supprt fr 4Eye lg viewing. When viewing infrmatin in the Dashbard and Track & Care screens, users will see annymus details. In rder t see real data, a secndary administratin passwrd is defined (4Eye), allwing viewing f actual infrmatin. User Management Prxy authenticatin t supprt multiple AD Dmains. Added a new feature that allws end users t view quarantined email via Web-based reprts, and manage/release quarantined email. This Web-based quarantine reprt supprts NTLM Authenticatin and multiple dmains. Glbalizatin Supprt This versin includes Unicde supprt t allw glbalizatin f the Security Center UI and data. Perfrmance Enhancements This versin includes a new results scanning cache. 2010 SafeNet, Inc. All rights reserved. Page 4 f 8 www.safenet-inc.cm
Release Ntes Imprved web perfrmance using real-time HTTP gzip cmpressin allws cntent real-time extractin and data analysis f cntent reaching esafe in cmpressed frmat. Imprved URL Filter perfrmance using internal cache and restructuring. Restructured the AppliFilter engine t imprve efficiency and perfrmance. Knwn Limitatins GUI: In the event that an esafe appliance is recnfigured r the peratin mde is changed, the appliance must be deleted frm the list f machines in the esafe Security Center and added manually. The number f days (currently 10 days) that the database recrds are saved can nly be changed manually via the esaferep.ini file n the esafe Appliance, and requires restarting the esafe service. When viewing the Security Center screen at the recmmended reslutin f 1024 x 768, the Updates tab under Plicy Settings disappears frm view n laptps. (Tip: After selecting the esafe machine yu want t manage, hide the machine tree in rder t see all the tabs.) DLP: When esafe is cnfigured t check utging traffic fr spam, by design, this traffic will nt be checked fr DLP rules. Encded file names inside archive files may be replaced with questin marks in the DLP lgs. MS Office 2007/2010 files appear in the DLP reprt as archive files since these file are actually archive frmats. Deplyment: This versin des nt allw upgrades frm previus versins; it nly supprts new installatins. When installing esafe Web Bridge mde with mail supprt, make sure that the inner and uter NIC have real IP addresses, r else SMTP will nt functin. When wrking with esafe in ICAP mde, file cmpressin (gzip) must be turned ff at the prxy side. Management: Change Cnfiguratin events may appear several times in the lg fr the same event. This is due t the fact that the changes are dne n all the remte machines and are therefre als lgged as events in the central machine. Central management machines nly supprt English language user names, passwrds, and machine names. When the Syslg methd is selected fr Smart Alerts, the alert event is written in the central machine message file and nt at the remte esafe machine. Make sure t define SNMP and Syslg servers at the Central Management machine as well. When defining a Smart Alert n a machine that is part f a grup/cluster, the smart alert definitins are saved lcally and are nt deplyed t ther machines in the grup/cluster. 2010 SafeNet, Inc. All rights reserved. Page 5 f 8 www.safenet-inc.cm
Release Ntes When defining LDAP parameters in the LDAP Settings screen, nly the DN is supprted (dmain/user frmat is nt supprted). esafe Quarantine: Releasing email frm the quarantine reprt sent by email desn't wrk in Windws Live Mail (n Windws 7). T slve this, use the new web-based quarantine reprt. The Web Quarantine nly supprts lg-in names that use English characters. The Web Quarantine Reprt can nly be created in English and des nt supprt additinal languages at this stage. When using the Web Quarantine Reprt, the LDAP server must be defined. By default the Web Quarantine Reprt wrks with HTTPS prtcl and therefre a permanent certificate must be issued. Fr instructins n changing the default prtcl frm HTTPS t HTTP, see the relevant technical nte in the Knwledge Base. esafe Web SSL: In esafe Web SSL, the website IP address (surce IP address) is the same as the URL hst and appears as 127.0.0.1, due t the fact that esafe Web SSL uses the internal parent prxy and desn t knw the real IP address. URL Filter: When an HTTPS site is fund t belng t a restricted categry, an apprpriate HTML warning des nt appear, nly a standard brwser message ntifying that Internet Explrer cannt display the webpage appears. The URL Filter redirect warning page (blck r gray list mde) cannt be displayed in HTTPS (SSL traffic prtcl), due t technical limitatins that prevent changing page cntent (unless using the esafe Web SSL prduct). esafe Cluster Initially defining a cluster requires lgging n t esafe Security Center via the central machine, defining a new cluster, dragging the esafe machine (which appears under the ALL branch in the machine tree) t the cluster, and then define the ther cluster members. esafe Appliance Manager: When defining the hstname in the esafe Appliance Manager (Settings > Hst Name & DNS), define a hstname shrter than 15 characters. The LCD display n the HG200 appliance can n lnger be used t recnfigure the appliance; it nly supprts viewing the status and changing IP addresses. 2010 SafeNet, Inc. All rights reserved. Page 6 f 8 www.safenet-inc.cm
Release Ntes Appendix: Upgrade Instructins Fllw the instructins belw t upgrade frm an earlier versin f esafe: 1. On the current esafe machine, create a zip files with the fllwing files: esafecfg.ini applifilter2.ini esafenipca.ini esdsprv.dat 2. Install esafe v8.5 n the machine. 3. Cnnect t the new machine via the v8.5 GUI. 4. Imprt the files frm the zip file yu created in step 1. 5. Restart the esafe services. 2010 SafeNet, Inc. All rights reserved. Page 7 f 8 www.safenet-inc.cm
Release Ntes Abut SafeNet In 2007, SafeNet was acquired by Vectr Capital, a $2 billin private equity firm specializing in the technlgy sectr. Vectr Capital acquired Aladdin in March f 2009, and placed it under cmmn management with SafeNet. Tgether, these glbal leading cmpanies are the third largest infrmatin security cmpany in the wrld, which brings t market integrated slutins required t slve custmers increasing security challenges. SafeNet s encryptin technlgy slutins prtect cmmunicatins, intellectual prperty and digital identities fr enterprises and gvernment rganizatins. SafeNet s sftware prtectin, licensing and authenticatin slutins prtect cmpanies infrmatin, assets and emplyees frm piracy and fraud. Tgether, SafeNet and Aladdin have a cmbined histry f mre than 50 years f security expertise in mre than 100 cuntries arund the glbe. Fr mre infrmatin, visit http://www.safenet-inc.cm. Cntact Infrmatin Fr mre infrmatin, please cntact SafeNet Technical Supprt at: 800-545-6608 (USA) 410-931-7520 (Internatinal) supprt@safenet-inc.cm Revisin 16, 5/20/2010 2010 SafeNet, Inc. All rights reserved. Page 8 f 8 www.safenet-inc.cm