How To Fix A Fault Notification On A Network Security Platform 8.0.0 (Xc) (Xcus) (Network) (Networks) (Manual) (Manager) (Powerpoint) (Cisco) (Permanent



Similar documents
McAfee Network Security Platform 8.2

Network Security Platform 7.5

Network Security Platform 8.1

Release Notes 7.5 [formerly IntruShield]

McAfee Advanced Threat Defense 3.6.0

Managing Latency in IPS Networks

McAfee Network Security Platform Administration Course

Enterprise Manager. Version 6.2. Installation Guide

Cisco WebEx Meetings Server System Requirements

Installation Guide Revision E. McAfee Network Security Platform 8.2

Hardware and Software Requirements. Release 7.5.x PowerSchool Student Information System

Sage Grant Management System Requirements

McAfee Web Gateway 7.4.1

VMware vcenter Log Insight Getting Started Guide

Grant Management. System Requirements

VMware vcenter Log Insight Getting Started Guide

Installation Guide Revision G. McAfee Network Security Platform 8.1

Junos Space. Virtual Appliance Deployment and Configuration Guide. Release 14.1R2. Modified: Revision 2

Virtualization Guide. McAfee Vulnerability Manager Virtualization

Enterprise Manager. Version 6.2. Administrator s Guide

Sostenuto 4.9. Hardware and Software Configuration Guide. Date: September Page 1 of 13

Virtual Web Appliance Setup Guide

LabStats 5 System Requirements

Sharp Remote Device Manager (SRDM) Server Software Setup Guide

Abila Grant Management. System Requirements

How To Set Up A Firewall Enterprise, Multi Firewall Edition And Virtual Firewall

Cisco Application Networking Manager Version 2.0

Core Protection for Virtual Machines 1

McAfee Firewall for Linux 8.0.0

Barracuda Backup Vx. Virtual Appliance Deployment. White Paper

Virtual Managment Appliance Setup Guide

Chapter 8 Monitoring and Logging

Adonis Technical Requirements

HP Universal CMDB. Software Version: Support Matrix

Proof of Concept Guide

Rebasoft Auditor Quick Start Guide

ZEN LOAD BALANCER EE v3.02 DATASHEET The Load Balancing made easy

FortiAnalyzer VM (VMware) Install Guide

Molecular Devices High Content Data Management Solution Database Schema

McAfee Content Security Reporter 2.0.0

Virtual Appliance Installation Guide

Rally Installation Guide

formerly Help Desk Authority Upgrade Guide

Samsung device management solutions Manage, monitor and diagnose multiple print devices easily and cost effectively

WatchGuard Training. Introduction to WatchGuard Dimension

Release Notes for McAfee(R) VirusScan(R) Enterprise for Linux Version Copyright (C) 2014 McAfee, Inc. All Rights Reserved.

VMware Identity Manager Connector Installation and Configuration

McAfee Data Loss Prevention Endpoint 9.4.0

OpenScape Web Collaboration

TABLE OF CONTENTS NETWORK SECURITY 2...1

Sage 300 ERP 2014 Compatibility guide

The SSL device also supports the 64-bit Internet Explorer with new ActiveX loaders for Assessment, Abolishment, and the Access Client.

F-Secure Internet Gatekeeper Virtual Appliance

ZEN LOAD BALANCER EE v3.04 DATASHEET The Load Balancing made easy

RSA Authentication Manager 8.1 Setup and Configuration Guide. Revision 2

Installation Guide. McAfee VirusScan Enterprise for Linux Software

Virtual Appliance Setup Guide

alcatel-lucent vitalqip Appliance manager End-to-end, feature-rich, appliance-based DNS/DHCP and IP address management

VCCC Appliance VMware Server Installation Guide

QuickSpecs. HP PCM Plus v4 Network Management Software Series (Retired) Key features

FortiAuthenticator v2.0 MR1 Release Notes

SMART Vantage 1.0. SMART Vantage 1.0 server software updates

McAfee Asset Manager Console

Panorama PANORAMA. Panorama provides centralized policy and device management over a network of Palo Alto Networks next-generation firewalls.


SNOW LICENSE MANAGER (7.X)... 3

WatchGuard SSL v3.2 Update 1 Release Notes. Introduction. Windows 8 and 64-bit Internet Explorer Support. Supported Devices SSL 100 and 560

Gigabyte Management Console User s Guide (For ASPEED AST 2400 Chipset)

Symantec Advanced Threat Protection: Network

McAfee Public Cloud Server Security Suite

Server Software Installation Guide

Asta Powerproject Enterprise

Analyzer 7.1 Administrator s Guide

System requirements for A+

StruxureWare Data Center Expert Release Notes

RSA Authentication Manager 8.1 Virtual Appliance Getting Started

Desktop Release Notes. Desktop Release Notes 5.2.1

Cisco is a registered trademark or trademark of Cisco Systems, Inc. and/or its affiliates in the United States and certain other countries.

Aras Innovator 11. Platform Specifications

EMC Smarts SAM, IP, ESM, MPLS, NPM, OTM, and VoIP Managers 9.4 Support Matrix

Ports utilisés. Ports utilisés par le XT1000/5000 :

EMC Smarts SAM, IP, ESM, MPLS, NPM, OTM, and VoIP Managers Support Matrix

Install Guide for JunosV Wireless LAN Controller

Active Fabric Manager (AFM) Plug-in for VMware vcenter Virtual Distributed Switch (VDS) CLI Guide

Centralized Orchestration and Performance Monitoring

HP PCM Plus v4 Network Management Software Series

Release Notes. LiveVault. Contents. Version Revision 0

Interact Intranet Version 7. Technical Requirements. August Interact

WatchGuard Dimension v1.1 Update 1 Release Notes

Sage Compatibility guide. Last revised: October 26, 2015

NetScaler VPX FAQ. Table of Contents

DocuShare Installation Guide

Sophos UTM Software Appliance

Minimum System Requirements

StruxureWare TM Data Center Expert

Acronis Backup & Recovery 10 Advanced Server Virtual Edition. Quick Start Guide

Installing and Administering VMware vsphere Update Manager

Best Practices Guide Revision B. McAfee epolicy Orchestrator Software

Transcription:

XC-Cluster Release Notes Network Security Platform 8.0 Revision A Contents About this document New features Resolved issues Known issues Installation instructions Product documentation About this document This document contains important information about the current release. We strongly recommend that you read the entire document. This release of Network Security Platform is to provide a few fixes on the XC-Cluster Sensor software. Network Security Manager software version: 8.0.5.11 Signature Set: 8.6.23.5 M-8000XC Sensor software version: 8.0.3.23 XC-240 Load Balancer software version: 2.11.7 This version of 8.0 Manager software can be used to configure and manage the following hardware: 7.1, 7.5, and 8.0 M series Sensors 7.1, 7.5, and 8.0 NTBA Appliance software 7.1 and 8.0 NS-series Sensors 7.1 I-series Sensors 7.1, 7.5, and 8.0 XC Cluster Appliances Manager 8.0 cannot manage N-series Sensors. Use Manager version lower than 8.0 to manage N-series Sensors. Manager software version 7.5 and above are not supported on McAfee-built Dell based Manager Appliances. Currently port 4167 is used as the UDP source port number for the SNMP command channel communication between Manager and Sensors. This is to prevent opening up all UDP ports for inbound connectivity from SNMP ports on the sensor. Older JRE versions allowed the Manager to bind to the same source port 4167 for both IPv4 and IPv6 communication. But with the latest JRE version 7.45, it is no longer possible to do so, and the Manager uses port 4166 as the UDP source port to bind for IPv6. 1

Manager 8.0.5 uses JRE version 7.45. If you have IPv6 Sensors behind a firewall, you need to update your firewall rules accordingly such that port 4166 is open for the SNMP command channel to function between those IPv6 Sensors and the Manager. New features This release notes is to announce the availability of a maintenance release for McAfee's M-8000XC Sensor software version 8.0. This release provides few fixes on the M-8000XC Sensor software issues. Resolved issues These issues are resolved in this release of the product. For a list of issues fixed in earlier releases, see the Release Notes for the specific release. Resolved Manager software issues The following table lists the high-severity Manager software issues: 883846 Disabled traffic management policy is enabled upon upgrade by creating separate policy rules. The following table lists the medium-severity Manager software issues: 921590 The "iv_alert_uri_info" table is included during configuration backup when taken from the infocollector utility. 919365 Source IP address for traffic detected from an anonymous proxy is displayed as A1 in the Real-time Threat Analyzer. 918668 Bulk edit of attack filters results in duplicate entries in the database. 917302 Leap framework is not initialized due to wrong port assigned during upgrade. 915174 Enable/Disable action of SNMP Fault Notification is not logged in the "User Activity Report". 914080 User Activity Report does not log changes made in the NTBA policy. 913006 Evidence report does not work with epo enabled, and works when epo or "Enable detailed host query" is disabled. 910991 Fault report generation fails for an MDR pair. 910551 Layer 7 data collection has missing host, URI from the alerts and does not contain HTTP headers for the alert event. 910422 Codebase and permission attribute warnings are missing when Applet and Webstart are launched. 910377 Editing or removal of Attack filter association "java.lang.nullpointer Exception" generates an error. 910376 Traditional reports cannot be viewed when a custom role is assigned to a user. 906353 When the alerts are synchronized from the peer Manager in MDR, the uuid is not updated correctly in the "iv_alert" table. 904289 Customized syslog message cannot be saved due to duplication of the <br> token. 904197 Database is not connected due to SQL exceptions. 903275 Manual database tuning does not complete. 2

901344 UDS attack syslog message contains "ffffffff" in its attack before the correct ID. 899797 The Enable Blocking settings are lost when the Manager is rebooted. 886490 The Disk Space Warning fault message is generated with severity "critical" and continues regardless of the disk usage. 878370 Alert archive created on Manager 7.1 does not import to Manager 7.5. 872722 Auto synchronization between the Primary and Secondary in MDR pair does not work when there is a switchover. 810378 Database tuning generates a Failure report upon completion. 809595 BTP value assigned from custom reconnaissance attack shows different value when detected. 767932 The Manager timeout causes the flapping of channels. The following table lists the low-severity Manager software issues: 885424 The Performance Monitor Monthly Data and Packet Capture Files values are not passed correctly after the upgrade. Resolved Sensor software issues The following table lists the medium-severity Sensor software issues: 927314 The failover Sensors experience stalled sibyte issue due to a memory leak. 927127 Under rare condition, the Sensor fails to apply new updates internally due to FD leak issue and gives Reason# 42: Sensor fails to apply new updates internally in the Manager. 924389 Under certain conditions and on certain attacks, when aid log is enabled, the Sensor goes to layer 2 mode. 918002 The hosts quarantined due to "BOT CC" attack, remains quarantined forever. 909809 Attacks are successful with some of the evasion options using the Stonesoft Evader tool. Resolved XC-240 software issues The following table lists the medium-severity XC-240 software issues: 876784 [XC-240] Management port will not be linked up when the Auto-negotiation feature is disabled. 876783 [XC-240] In case of XC-240 HA, synchronization might not happen for dynamic spare port. 876778 [XC-240] IPv6 address is not persisted on Management port with XC-240 reboot. 876775 [XC-240] Help required for commands. 876765 [XC-240] Changes to the CLI commands in XC-240. 876764 [XC-240] 8-bit fragmented packets with VLAN header were being dropped by the Sensor. 876762 [XC-240] On rare occasions, the Manager might show incorrect link information when LBG is modified. 876760 [XC-240] Breaking and forming HA of XC-240 might result in HA not coming up. 3

Known issues For a list of known issues in this product release, see this McAfee KnowledgeBase article: Manager software issues: KB79229 XC-Cluster Sensor software issues: KB79233 Installation instructions Manager server/client system requirements The following table lists the 8.0 Manager server requirements: Operating system Minimum required Any of the following: Windows Server 2008 R2 Standard or Enterprise Edition, English OS, SP1 (64 bit) (Full Installation) Windows Server 2008 R2 Standard or Enterprise Edition, Japanese OS, SP1 (64 bit) (Full Installation) English OS Japanese OS Only X64 architecture is supported. Recommended Same as the minimum required. Memory 8 GB 8 GB or more CPU Server model processor such as Intel Xeon Same Disk space 100 GB 300 GB or more Network 100 Mbps card 1000 Mbps card Monitor 32-bit color, 1440 x 900 display setting 1440 x 900 (or above). The following are the system requirements for hosting Central Manager/Manager server on a VMware platform. 4

Table 5-1 Virtual machine requirements Component Minimum Recommended Operating system Any of the following: Windows Server 2008 R2 Standard or Enterprise Edition with SP1 (English) (64 bit) Windows Server 2008 R2 Standard or Enterprise Edition with SP1 (Japanese) (64 bit) English OS Japanese OS Only X64 architecture is supported. Same as minimum required. Memory 8 GB 8 GB or more Virtual CPUs 2 2 or more Disk Space 100 GB 300 GB or more Table 5-2 VMware ESX server requirements Component Minimum Virtualization software VMware ESX Server version 4.0 update 1 and version 4.1 ESXi 5.0 ESXi 5.1 CPU Memory Internal Disks Intel Xeon CPU ES 5335 @ 2.00 GHz; Physical Processors 2; Logical Processors 8; Processor Speed 2.00 GHz. Physical Memory: 16 GB 1 TB The following table lists the 8.0 Manager client requirements when using Windows 7 or Windows 8: Operating system Minimum Windows 7 English or Japanese Windows 8 English or Japanese The display language of the Manager client must be same as that of the Manager server OS. Recommended RAM 2 GB 4 GB CPU 1.5 GHz processor 1.5 GHz or faster Browser Internet Explorer 9 or 10 Mozilla Firefox Google Chrome Internet Explorer 10 Mozilla Firefox 20.0 or above Google Chrome 24.0 or above If you are using Google Chrome, add the Manager certificate to the trusted certificate list. 5

For the Manager client, in addition to Windows 7 and Windows 8, you can also use the operating systems mentioned for the Manager server. The following table lists the 8.0 Central Manager / Manager client requirements when using Mac: Mac operating system Lion Mountain Lion Browser Safari 6 For more information, see McAfee Network Security Platform Installation Guide. Upgrade recommendations McAfee regularly releases updated versions of the signature set. Note that automatic signature set upgrade does not happen. You need to manually import the latest signature set and apply it to your Sensors. The following is the upgrade matrix supported for this release: Component Minimum Software Version Manager/Central Manager software 7.1: 7.1.3.5, 7.1.5.7, 7.1.5.10, 7.1.5.14 7.5: 7.5.3.11, 7.5.5.6, 7.5.5.7 8.0: 8.0.5.9 M-8000XC Sensor software 7.1: 7.1.3.6, 7.1.3.51, 7.1.3.88 7.5: 7.5.3.16, 7.5.3.30 8.0: 8.0.3.10 XC-240 2.9.2 2.9.4 Product documentation Every McAfee product has a comprehensive set of documentation. Find product documentation 1 Go to the McAfee Technical Support ServicePortal at http://mysupport.mcafee.com. 2 Under Self Service, access the type of information you need: To access... User documentation Do this... 1 Click Product Documentation. 2 Select a product, then select a version. 3 Select a product document. KnowledgeBase Click Search the KnowledgeBase for answers to your product questions. Click Browse the KnowledgeBase for articles listed by product and version. 6

Copyright 2014 McAfee, Inc. Do not copy without permission. McAfee and the McAfee logo are trademarks or registered trademarks of McAfee, Inc. or its subsidiaries in the United States and other countries. Other names and brands may be claimed as the property of others. 0A-00