========================================================================= Symantec Messaging Gateway (formerly Symantec Brightmail Gateway) version 9.5.0-23 software update notes ========================================================================= March, 2011 Before installing this software update, copy and paste the URL below into a Web browser to check for late-breaking issues: http://www.symantec.com/docs/tech153676 Special update instructions for 9.5.0-23 ========================================================================= This software update is version 9.5.0-23 of the Symantec Messaging Gateway. This replaces version 9.5.0-19 in order to address issues observed in a small number of upgrades. Special instructions for users upgrading from 9.5.0-19 Symantec strongly recommends that you upgrade your Control Center before upgrading your Scanners. If you do not upgrade the Control Center first, you must use the Command Line Interface (CLI) to upgrade remote Scanners. Special update instructions for all users When a Control Center has been configured so that HTTP port 41080 is used instead of HTTPS port 41443, the following issues may occur after an upgrade to 9.5: - After the upgrade, a browser connection to the Control Center cannot be established using the HTTP protocol. - If an upgrade has been initiated over an HTTP connection, the Control Center never shows the login screen after the upgrade completes. To resolve or mitigate this issue, a connection to the Control Center can be established using a browser via the default HTTPS port 41443. To connect to the Control Center using the HTTP protocol, HTTP port 41080 must be re-enabled after the upgrade: 1. Login to the Control Center machine using the Command Line Interface (CLI). 2. Verify that the upgrade to 9.5 has completed by executing the CLI 'show' command: show --version The correct 9.5 version should be shown. 3. Enable HTTP connections to the Control Center using the CLI 'cc-config' command: cc-config http --on This command restarts the Control Center and enables HTTP connections. ============================================================================ Please thoroughly review the following sections: --Translated software update notes --Documentation --Update considerations --Running software update --What's new in Version 9.5 --General improvements --End User License Agreement (EULA)
Translated software update notes ================================ These software update notes have been translated into the following languages: --Simplified Chinese --Traditional Chinese --Japanese --Korean To read the translated software update notes, copy and paste the URL below into a Web browser and then click the "Documentation" Link: Chinese (Simplified) http://www.symantec.com/business/support/index?page=landing&key=53991&locale=zh_cn Chinese (Traditional) http://www.symantec.com/business/support/index?page=landing&key=53991&locale=zh_tw Japanese http://www.symantec.com/business/support/index?page=landing&key=53991&locale=ja_jp Korean http://www.symantec.com/business/support/index?page=landing&key=53991&locale=ko_kr Documentation ============= The Installation Guide, Administration Guide, and online help have been updated for Symantec Messaging Gateway version 9.5. You can access the version 9.5 release notes before installing this version. Copy and paste the URL below into a Web browser: http://www.symantec.com/business/support/index?page=landing&key=53991 The site provides best practices, troubleshooting information, and other resources for Symantec Messaging Gateway. PDFs are also available in the Symantec Messaging Gateway help. After updating, click the "PDF documentation" link at the bottom of the Contents in the online help. Update considerations ===================== --Please read the Symantec Messaging Gateway 9.5 release notes for a complete list of update considerations. --For customers updating from version 8.0.3 using LDAP directories there may be a new communications requirement for LDAP connectivity from Scanners. Please read the release notes for details. --Symantec Messaging Gateway 9.x includes a restructuring of the data storage for content incidents and Spam Quarantine. If updating to 9.x from 8.0.3, systems storing large amounts of data with these features will see increased update time for the Control Center. Under extreme conditions the software update may take several hours. Delete as many content filtering incidents and quarantined spam messages as possible before you run the update. --Back up your existing data before running software update. --Do not reboot while software update is in process. The software update process may take several hours to complete. If you reboot before the process is complete, data corruption is likely. If data corruption occurs the appliance must be re-installed with a factory image. Supported previous versions --------------------------- You can only update version 8.0.3 or 9.0.x to version 9.5. Systems running versions prior to 8.0.3 must be updated completely, including all Scanners and the Control Center, before proceeding to the version 9.5 update.
Software update planning ------------------------ --There is not an option to update a Control Center and multiple Scanners simultaneously. Each appliance must be updated individually. --You do not have to update all of your Scanners at the same time. You can update some Scanners to version 9.5 and leave some with the older version so that some Scanners continue to protect your site while you update others. However, if the Control Center and Scanner versions are different, the Control Center cannot make configuration changes to the Scanner. Review the following KB article for more detailed information and the sequence order for the upgrades: http://www.symantec.com/business/support/index?page=content&id=tech134598 Running software update ======================= Before running software update from 8.0.3, be certain your appliance is not performing tasks that, if disrupted, could cause problems after updating. --Check for a running LDAP synchronization cycle --Check for a running Scanner replication cycle --Minimize the number of messages in any of the queues To prepare for the software update, follow the steps below. The Control Center locations presented below are for version 8.0 and may differ for earlier versions. 1 To check for a running LDAP synchronization cycle or Scanner replication cycle, access Status > System > LDAP Synchronization. 2 To halt incoming messages, access Administration > Hosts > Configuration/Edit, click "Do not accept incoming messages", and click Save. 3 To check the queues, access Status > SMTP > Message Queues. Monitoring software update using the command line interface ----------------------------------------------------------- while the software update is in progress, you can use the command line interface to monitor its progress. You can do this before you begin the update or after you have begun. To monitor the software update progress 1 Using an SSH client or the console, log into the appliance you are updating. You must use administrator credentials when logging on. 2 Type one of the following commands: for 8.0.3: watch update.log for 9.0.x: tail -f update.log The progress of the software update is displayed. When the update has completed, the appliance will reboot automatically. Do not reboot the appliance before the update has completed. Updating using the command line interface ----------------------------------------- If you prefer, you can update using the command line interface instead of the Control Center. Because the command line interface divides the update process into discrete steps, it may be more appropriate to use the command line interface than the Control Center over imperfect Internet connections. If updating using the Control Center does not work because of Internet connectivity issues, try to update using the command line interface. To update using the command line interface 1 Log into an appliance using an SSH client or log in at the console. You
must use your administrator credentials to log in. 2 To list available updates, type the following command: update list 3 To download the update, type the following command: update download 4 To install the update, type the following command: update install When the update completes, you'll see the following message: sms-appliance-release-version successfully installed. Rebooting appliance... The appliance reboots. If you've logged into the appliance using an SSH client, the connection will be lost. Testing update success ---------------------- To ensure that your appliance is running Symantec Messaging Gateway version 9.5, log into the command line interface on an appliance and type the following command: show --version What's new in Version 9.5 ========================= This section describes what's new in Symantec Messaging Gateway 9.5. New product name Version 9.5 introduces Symantec Messaging Gateway, powered by Brightmail, previously known as Symantec Brightmail Gateway. Handling unwanted email Symantec Messaging Gateway now has new configurable verdicts for unwanted email category. You can configure policies for emails pertaining to marketing, which are newsletters, and emails with suspicious URLs. You can choose whether or not to enable this functionality. Matching text in message audit log and content filtering incidents Symantec Messaging Gateway has enhanced message audit logs and content quarantine that capture the following for content filtering policies: --Matching policy --Matching text --Message part Symantec Messaging Gateway can scan email attachments with the following extensions for spam: --.doc --.htm --.html --.rtf --.txt --.wps --.xml Improved message tracking ID Symantec Messaging Gateway provides a new message tracking ID for unwanted emails. Unwanted emails include marketing emails, newsletters, and emails with suspicious URLs. The new message tracking ID helps reduce false positive and false negative submissions for unwanted email verdicts.
Enhanced user interface to upgrade to Symantec Messaging Gateway Symantec Messaging Gateway provides enhanced software update process in the Control Center with the following features: --A progress bar to view the download status provides improved feedback regarding the progression of software update download and installation. --Separate Download Only and Install buttons provide the ability to stage the software update process, allowing for download and installation at different times. Dell Remote Access Controller (DRAC) Support Symantec Messaging Gateway expands support for Integrated DRAC functionality in Symantec 8360 and 8380 hardware appliances. This lets you remotely monitor and manage the hardware environment. More Flexible Restore Symantec Messaging Gateway can restore a backup to a separate instance while preserving the network configuration of the restored instance. This enables easier appliance migration and disaster recovery. TLS Logging Symantec Messaging Gateway provides enhanced message audit logs to track messages with TLS encryption delivery status. This lets you confirm TLS delivery for auditing. Integration with Symantec Protection Center Symantec Protection Center provides unified management across Symantec security products, including single sign-on, composition of product management within the Protection Center console, and unified reporting across multiple products. DNS validation You can now reject messages based on DNS validation. Symantec Messaging Gateway can perform a reverse DNS lookup to confirm the validity of the DNS record. Expanded localization in Spanish and French The Control Center user interface is fully localized into Spanish and French, in addition to the existing translations into Japanese, Simplified and Traditional Chinese, and Korean. Sender authentication enhancements The implementation of SPF and Sender ID in Symantec Messaging Gateway has been re-engineered, correcting numerous known issues from previous versions. The user interface has some minor improvements. New default policies for SPF and Sender ID are available for your use or customization and use.
Subaddressing support for recipient validation You can now enable support for subaddressing in the recipient validation feature. Subaddressing is the practice of adding text in the local portion of an email address following a plus or minus sign. For example: user+role@samplecompany.com. General improvements ==================== The following known issues have been resolved for this release of Symantec Messaging Gateway version 9.5 Resolved login errors after software update Previously, after completing a software update with no errors in update.log, customers would occasionally receive an application error when attempting to login to the Control Center. This issue has been resolved. Improved delivery timeout functionality Previously, a message held after failed delivery attempts remained in the queue longer than the configured "Sent message time-out" period. This has been resolved. Improved DNS lookup timeout Symantec Messaging Gateway has improved DNS timeout functionality to provide more efficient queue removal and improved error messages and notifications. Battery Failure logged messages no longer incorrectly reported Previously, Battery Failure messages were sometimes incorrectly returned by the Control Center. This has been resolved. Messages signed by Outlook 2007 no longer treated as "unscannable". Previously, digitally-signed forwarded messages were treated as unscannable by Symantec Messaging Gateway. This issue has been resolved. Improved ENHANCEDSTATUSCODES Previously, Symantec Messaging Gateway did not provide all expected SMTP enhanced status codes. This has been resolved and all expected status codes are now returned by Symantec Messaging Gateway. Full display name is now provided by address masquerading Previously, a display name in a header without quotes was truncated by Address Masquerading. This issue has been resolved so that these display names are not truncated. Enhanced support for aliases in upgrade to 9.x Previously, Symantec Messaging Gateway provided limited upgrade support for aliases that used case-sensitivity. Symantec Messaging Gateway now supports the ability to migrate case-sensitive aliases when upgrading to 9.x.
Load balancing for MX records when MX Lookup is enabled Previously, load balancing was not being performed properly based on DNS results where MX resolution was specified for a downstream route. Symantec Messaging Gateway now provides load balancing for an enabled MX Lookup Host. Symantec Messaging Gateway now identifies RFC 2311 encrypted attachments as encrypted content. Previously, Symantec Messaging Gateway would fail to identify RFC 2311 encrypted attachments as encrypted content, creating a heightened risk leakage of viral content in encrypted messages without warning the end user. This issue has been resolved. End User License Agreement (EULA) ================================= After updating, you can display the End User License Agreement (EULA) from the command line interface. To view the EULA 1 Log into the appliance's command line interface and type: show --eula The EULA is displayed. 2 To page through the EULA, use the space bar. 3 To exit the display of the EULA, type: q The command prompt displays. </note> </notes>