Release Notes Threat Management Services zl Module ST.1.2.110427 06-2011
71
Known Issues
Release ST.1.1.100226/ST.1.1.100330
HP E-5406zl(tms-module-C:config)#exit
HP E-5406zl(tms-module-C)#write memory
HP E-5406zl(tms-module-C)#boot
Device will be rebooted, do you want to continue [y/n]? y
At this point, the TMS product will initialize the VLANs correctly and new VLANs can be added.
VPN
■ PR_40382 — Importing a CRL file which does not contain the 'nextUpdate' field is not
successful.
■ PR_41431 — Field Validation failure for IKEv1 identities, distinguished-name field. While
configuring an IKEv1 policy, the CLI will take any value for the distinguished-name field when
setting identities. The manual states that this value should include the proper attribute id and
value: attributeid=value.
■ PR_41535 — Field validation failure when setting position on an IPsec policy. The CLI will
take any given positive value when setting the position of an IPsec policy. The allowed values
are between 1-65535
■ PR_42272 — In the web browser interface, an obscure error message is displayed if the
Peer IP address is set with a value 224.x.x.x or greater. Steps to recreate:
A GRE Tunnel has already been created.
1. Open the TMS zl Module web browser interface.
2. Go to the VPN section.
3. Select the GRE link.
4. Go to the GRE Tunnels tab
5. Click the edit button from the previously created GRE tunnel.
6. Edit the Peer IP address field with a value 224.x.x.x or greater.
7. Click the OK button.
■ PR_43471 — With IPsec using a DSA or RSA Certificate, a TMS zl Module and a ProCurve
Secure Router 7100 fail to authenticate as IPsec peers.
■ PR_43916 — RADIUS authentication for L2TP users could result in the user's connection
getting established and immediately getting disconnected without notification. The RADIUS
server must return the service-type attribute with a value of framed. If the service-type attribute
is not set to framed or is not available, the L2TP session gets established and immediately
disconnected without notification.
■ PR_44356 — Using a VPN with L2TP and IPsec Certificates is not supported.
■ PR_44478 — TMS zl Module does not support CRL retrieval via HTTP, LDAP, or OCSP.