HP Switch Services Modules - HP SECBLADEII-CMW520-R3175 Release Notes Release Notes

4
Item
MIB file
Module
Description
Modified
/
/
/
SECBLADEII-CMW520-F3174P10
New
/
/
/
Modified
H3C-FIREWALL-MIB
Firewall
Added a MIB node to
save the rate of created
connections. You can
obtain the rate of the
connections that are
created on the firewall.
Operation changes
None.
Restrictions and cautions
1. USB is not supported.
2. ICMP packets larger than 35000 bytes are discarded.
3. The W eb interface can display a maximum of 5000 sessions.
4. An Ethernet interface that is set to bridge mode does not support loopback function.
5. The deny ip destination rule configured in the ACL used by nat outbound affects ALG
function, so we recommend to not configure that rule when ALG is enabled.
Open problems and workarounds
HSD109369
Symptom: If a VPN instance name that contains uppercase letters is bound to an NQA
ICMP operation, the uppercase letters are automatically changed to lowercase
letters.
Condition: This symptom occurs if a VPN instance name that contains uppercase
letters is bound to an NQA ICMP operation.
Workaround: Use lowercase letters in the VPN instance name.
HSD112168
Symptom: Configurations such as IPsec and NAT on a subinterface cannot be
synchronized to the standby device after the two devices enter synchronization state.
Condition: This symptom occurs if the Layer-3 subinterface or Layer-3 aggregate
subinterface are created before the two devices enter synchronization state.
Workaround: Configure the two devices to enter synchronization state, and then
creat e a Layer-3 subinterface or Layer-3 aggregat e subinterface for configurations.