Software Multicloud Defense
Activity Cloud Deployment

Version 23.10-01 November 3, 2023

Enhancements

The following enhancements are included in this upgrade:

  • Moves the policy type mismatch message generated for each session that is processed by two rules that have mismatched policy type (forwarding and forward proxy) to an event related to each session. This eliminates many system log messages when this scenario occurs and generates error as an event associated with each session. When this scenario occurs, the session will be denied and the event will report the reason. The deny will also be represented in the traffic summary log.

  • Enhances the forward proxy policy to validate the server certificate when negotiating the backend TLS session. The certificate validation is disabled by default, but can be configured in a decryption profile for all TLS sessions and in an FQDN match object on a per-domain (or set of domains) basis.

  • Integrates with teleport to accommodate reverse SSH making it easier to SSH to the gateway instance management interface especially when the gateway is orchestrated without public IPs. The requirements to SSH is rare and only necessary for advanced troubleshooting purposes. Inbound communication is inhibited by default using cloud service provider restrictions (security groups, network security groups, firewall rules).

Fixes

The following fixes are included in this upgrade:

  • Fixes an issue related to a forward proxy rule that uses an FQDN match object for decryption exception could result in traffic processing issues.

  • Fixes an issue where traffic would be incorrectly denied by a forward proxy rule configured with an FQDN match profile due to delays in certificate validation. The deny will be seen as an FQDNFILTER security eent even though an FQDN filtering profile is not applied.

  • Fixes an issue where a rule that uses an FQDN match object would incorrectly process traffic for an uncategorized domain.

  • Fixes an issue related to dynamic address objects where a large number of IPs and a large number of changes to those IPs could result in the datapath not accepting changes, causing matching issues resulting in traffic being processed incorrectly.

  • Fixes an issue with DNS-based FQDN caching where setting the DNS resolution interval would not change the frequency of DNS resolution.

  • Fixes an issue with packet collection that could cause the gateway to become unhealthy.

  • Fixes an issue where certain logs from the gateway could contain private key information.

  • Fixes various gateway stability issues.

  • Fixes a gateway memory leak that could also cause a CPU issue resulting in traffic processing issues.

  • Fixes an issue where the URI information is not shown in traffic summary log.

  • Fixes an issue where L7DOS event does not properly show the URI.