Release Notes Threat Management Services zl Module ST.1.2.110427 06-2011

87
Known Issues
Release ST.1.0.090213
time="2009-04-15 16:14:04" severity=warning pri=4 fw=ProCurve-TMS-zl-Module
id=fw_l2l3_attack msg="TCP: invalid ACK packet, packets dropped"
srczone=INTERNAL src=192.168.80.5 srcport=60290 dstzone=INTERNAL
dst=192.168.80.1 dstport=22 proto=TCP subfamid=tcpconnectionanomaly
mtype=attack mid=675
time="2009-04-16 17:49:17" severity=minor pri=3 fw=ProCurve-TMS-zl-Module
id=system_error msg="FW: ICMP echo packets exceeds to maximum limit,
connection dropped" srczone=UNKNOWN_ZONE dstzone=UNKNOWN_ZONE error-
type=memory_allocation subfamid=resourceallocationfailure mtype=syserr
mid=715
time="2009-04-16 18:08:59" severity=info pri=6 fw=ProCurve-TMS-zl-Module
id=fw_l2l3_attack msg="Overlapped IP fragment recieved"
srczone=UNKNOWN_ZONE src=10.29.32.10 dstzone=UNKNOWN_ZONE dst=88.1.10.12
proto=ICMP subfamid=intergritycheck mtype=attack mid=1008
time="2009-04-16 18:08:59" severity=critical pri=1
fw=ProCurve-TMS-zl-Module id=fw_l2l3_attack msg="IP fragment datalength is
not in units of 8 octets" srczone=UNKNOWN_ZONE src=0.0.0.0 srcport=0
dstzone=UNKNOWN_ZONE dst=0.0.0.0 dstport=0 proto=0 subfamid=intergritycheck
mtype=attack mid=1356
Release ST.1.0.090213
The following problems are known issues as of release ST.1.0.090213.
PR_665 — When an IPv4 address is entered into a field, regardless of whether the
administrator is using the web browser interface or CLI interface, the TMS zl Module is not
doing the complete validation on the address based upon the field being used. For example,
a multicast or broadcast address can be entered into source address fields. It is up to the
user to ensure the correctness of the address for the field in question.
Related PRs:
PR_665
PR_1794
PR_2068
PR_2252
PR_2253
PR_2254
PR_2424
PR_2613
PR_3824
PR_906 — When the web browser interface of the TMS zl Module is left at the login screen
without the user logging into the TMS zl Module, the inactivity timer still applies, resulting
in the user having to go back to the login screen manually. The inactivity timer should only
apply once a user has logged in, but instead applies at all times.