TMS zl Module Release Notes ST.1.0.090213

11
Known Issues
Release ST.1.0.090213
6. Multicast routing is disabled.
7. Add or edit a VLAN with Multicast enabled.
8. Refresh the Multicast page by pressing F5.
9. Multicast routing is now enabled (the box next to Enable multicast routing.. is checked).
Expected Result: Multicast routing should remain disabled.
PR_0000009404 — SSH Buffer errors are shown in logs with varying severity. These
messages represent temporary and recoverable conditions, but they should all be of the same
severity. Example log entries are as follows:
time="2008-09-30 22:14:25" severity=warning pri=5 fw=ProCurve-TMS-zl-Module
id=ssh msg="fatal: buffer_get_string: buffer error"
time="2008-09-30 22:14:25" severity=info pri=6 fw=ProCurve-TMS-zl-Module
id=ssh msg="fatal: buffer_get_string: buffer error"
time="2008-09-30 22:14:25" severity=minor pri=3 fw=ProCurve-TMS-zl-Module
id=ssh msg="fatal: buffer_get_string: buffer error"
PR_0000009486 — ICQ ALG does not allow two-way file transfer, but only one-way file
transfer. There is no workaround for this issue. An example of the problem is described
below:
Using ICQ 5.1., configure the firewall to allow TCP 5190-5193, HTTP, HTTPS and DNS.
Chatting between ICQ clients works find, but when it comes to file transfer, transferring a
file from a client on the Internal Zone to the External Zone works, but one cannot transfer
a file from a client on the External Zone to the Internal Zone.
PR_0000010267 — The TMS zl Module detects the denial of service attack 'jolt2' as 'jolt'
and does not detect 'jolt'. This issue is described as follows:
There are 2 mode of operation for jolt2
Invalidly fragmented ICMP ECHOs (pings)
Invalidly fragmented UDP packets
The TMS zl Module only detects invalidly fragmented UDP packets and generates a log with
mid=1001 with msg="Jolt attack detected". This log message should identify jolt2.
The TMS zl Module does not detect the following:
Jolt- which sends very large fragmented ICMP packets to a target machine.
Jolt2- Invalidly fragmented ICMP ECHOs (pings)
PR_0000010767 — When using RADIUS authentication, the field NAS-Identifier is sent for
CHAP and MS-CHAP authentication requests, but not for PAP requests. If any network
infrastructure requires the NAS-Identifier field, a user needs to use to CHAP or MS-CHAP at
this time.