Release Notes 4.5.0.39

Clarifications and Usage Notes
5
regenerated via a DHCP lease renewal. If the information can be obtained through DHCP,
then the information may be renewed by deleting a related local subnet, waiting about 10-15
seconds and then re-entering the local subnet configuration for the subnet. The lease should
be renewed and the information in the lease renewal will be used to recreate the global subnet
group.
The failover functionality of the built-in RADIUS server when in proxy mode is as follows:
When the first remote RADIUS server is found to be down, an Access-Reject is sent to
the client and the proxy server marks the remote server as dead. If the client retries during
the dead time (by default—two minutes), the request is sent to the alternate remote
server.
The end user experience is that the first authentication fails if the primary remote server is
dead and the second attempt, if made within the two minute timeframe, will succeed.
Clock synchronization intervals are as follows:
External NTP server—30 minutes
Internal NTP server between redundant Access Control Servers—25 minutes
Internal NTP server between Access Control Server and Access Controller—8 minutes
(19724)
If the Access Control Server has previously recognized an Access Controller, any changes
made to the Access Controller while it is disconnected from the network will be overwritten
with the saved configuration file stored on the Access Control Server once the Access
Controller is reconnected to the network. If this is not the intention, then delete the Access
Controller using the Access Control Server’s Administrative Interface before reconnecting it
to the network. However, it is recommended that the Access Control Server handle all Access
Controller configurations.
Clients running Windows XP and using L2TP/IPSec or IPSec VPN to authenticate need to
disable the Internet Connection Firewall (ICF) service. If ICF is enabled, the client’s
connection will be dropped when the IPSec security association has expired. For further
information please refer to the Microsoft knowledge base article Troubleshooting Windows
Firewall settings in Windows XP Service Pack 2 at
http://support.microsoft.com/default.aspx?kbid=875357. (19360)
Clients running Windows 98 that have logged off, or have been logged off automatically,
need to wait 20 seconds before logging on again. This is a Windows 98 constraint. (18987)
Displaying the status of the primary or secondary Access Control Server while they are
synchronizing may result in either an error message stating “DB Error: connect failed” or
“Page data is invalid.” This only occurs in redundant systems with unusually high
configuration activity. If this error message does occur, click the Back button on the browser
to clear it. (19336)
After changing the time zone on a 700wl Series system unit, it takes approximately seven
seconds for the new time to take effect. (19355)
Before merging two 700wl Series system networks together to create a redundant system,
where both Access Control Servers are active, first deactivate the Access Control Server that
is designated to be the secondary Access Control Server in the redundant system. (19359)
There are a number of functions that will result in termination of an active SSH session.
These include any CLI commands (or the equivalent function done through the
Administrative Interface) that cause a global restart, such as changing the NAT DHCP