Firewall Analyzer - Readme

Table of Contents

  1. About Firewall Analyzer

    Firewall Analyzer is an easy-to-use, web-based tool that provides in-depth analysis of incoming and outgoing network activity through firewalls, VPNs, and proxy servers. Firewall Analyzer analyzes these logs and generates useful reports on bandwidth usage, user trends, detect anomalies, and firewall activity.

    Such information helps IT administrators manage their enterprise networks pro actively and also accelerates the troubleshooting process.

  2. Release Overview
    1. 12.5 Build 125160

      New device/Log format supported:

      1. Support ID - 6012127: New VPN log format supported for Palo Alto PANOS Version-9.

      New features and enhancements:

      1. Support ID - 5635866: 'Unused Rules' report based on ACEs as separate view is available under 'Rule Cleanup' for Cisco ASA devices.
      2. Support ID - 6044231: Option to configure 'row count' for scheduled exports if number of rows > 10.
      3. Support ID - 5965247, 5843882: Time filter option has been provided for 'Normal Alert' profiles.
      4. A new 'Review Us' tab is provided under 'Support' page.

      Issues fixed:

      1. Support ID - 5573528: Rule reorder position for Cisco ASA is not following the actual rule position mentioned in firewall configuration. This issue is fixed.
      2. Support ID - 6062468: FortiGate VDOM devices change management failed for active-active cases. This issue is fixed.
      3. Support ID - 6092052: FortiGate device 'Security Audit' report showing wrong data under the section 'user is configured with no password'. This issue is fixed.
      4. Support ID - 6082857: Cisco device rule parsing issue is fixed.
      5. Support ID - 6043992: Clavister device logs parsing issue is fixed.
      6. Support ID - 6034187: Attack log parsing issue in SonicWALL device is fixed.
      7. Support ID - 6074602: VPN log parsing issue in Check Point Log Exporter Format (CEF) is fixed.
      8. Support ID - 6015906: 'Active VPN User' report is not showing properly in case of two VPN login events for single user with different assigned IPs from FortiGate firewall is received. Fixed this issue.
      9. Support ID - 6049687, 6052964: Few VPN disconnected users are showing in 'Active VPN Users' report. This issue is fixed.
      10. Custom dashboard and expanded widget page for Excel export drill down is not working. This issue is fixed.
      11. Graph drill down not redirecting to proper device snapshot from dashboard issue is fixed.
      12. Security of authentication and communication between 'Admin' and 'Collector' servers in Enterprise edition is tightened.
    2. 12.5 Build 125142

      Issue Fixed:

      1. In ‘Device Rule’ page, when the device credential is validated the status is shown as ‘Failed’, if the language selected is other than English for Firewall Analyzer. Fixed the issue.
    3. 12.5 Build 125141

      New device/Log format supported:

      1. Support ticket ID: 6001827 - New device support - WinGate proxy server.
      2. Support ticket ID: 5851232 - New timestamp format is supported in FirePOWER 6.4 or later version.

      New features and enhancements:

      1. Rule administration support (Add, Edit, Delete rules) for the below devices:
        • Sophos XG
        • Sophos UTM
      2. Report profiles widget selection option given for all reports.
      3. Individual report scheduling (on demand) with widget selection as custom report from report pages.
      4. New separate 'VPN Reports' tab to view all VPN reports with more VPN statistics.
      5. On demand and report profile schedule option for 'Active VPN Users' report for devices.
      6. Store VPN session details in separate tables to maintain individual connections to get more VPN reports.
      7. Customers can get more granular VPN data like start-time, end-time, duration, server and client IP addresses for each VPN connection without crunching.
      8. Support ticket ID: 5981132 - VPN report support for Cisco Meraki device.
      9. Support ticket ID: 5957139 - VPN report support for Stormshield device.
      10. Support ticket ID: 6011399 - Internet service objects based policy handling supported for FortiGate device.
      11. Support ticket ID: 6019522 - Rule management support for Juniper SRX logical systems.
      12. Support ticket ID: 5844575 - NAT and WAF object supported for Sophos XG devices.

      Issues fixed:

      1. Support ticket ID: 6012236 - VPN log parsing issue in Cyberoam device has been fixed.
      2. Support ticket ID: 6017044 - VPN user transaction report shows all the VPN traffic logs for SonicWall. The issue has been fixed.
      3. Support ticket ID: 6036968 - Fixed the Sophos XG device 'Policy Optimization' shows inappropriate redundant rules issue.
      4. Support ticket ID: 5844575 - Handled the Sophos XG case rule position support changes.
      5. Support ticket ID: 5937364 - Handled the Check Point case, access layers containing empty values case exception.
      6. Support ticket ID: 5958716 - Handled Check Point cases, cluster name based device rule data population changes.
      7. Support ticket ID: 5785893 - Juniper SRX device cases partial configuration, rule fetched issue fixed for bigger configuration from device.
      8. Support ticket ID: 5993848 - SonicWall case security audit report contains duplicated wrong rules list issue fixed.
      9. Support ticket ID: 5988050 - Not able to edit and save the daily schedule report profiles issue fixed.
      10. Support ticket ID: 6011399 - Cisco device rule service group parsing issue fixed.
      11. Support ticket ID: 6019019 - Change management report is not generated for SonicWall device. Fixed the issue.
      12. Support ticket ID: 6020245 - NetScreen device rule parsing issue fixed.
      13. Support ticket ID: 6036387 - Juniper SRX device rule IPv6 address objects parsing issue fixed.
      14. Support ticket ID: 5847978 - Archive zip handled for 'Schedule import' case.
      15. Support ticket ID: 6036968 - Time value parsing issue in Cyberoam device has been fixed.
      16. Support ticket ID: 5993441 : Change Management report has included additionally in the Scheduled PDF report even it is not selected. Fixed the issue.
      17. Support ticket ID: 6000518, 5995440 - URL log parsing issue in Cisco ASA and Juniper SRX has been fixed.
      18. Support ticket ID: 6010922, 6006728 - IPSec VPN parsing issue in FortiGate device has been fixed.
      19. OpManager Issue ID: 26814 - Import of encrypted log file (.enc file) is not working properly. This issue is fixed.
      20. Issue manager ticket ID: 29873 - Firewall Analyzer version 8.x to 12.5 migrated cases, Sophos UTM device rule add failed issue fixed.
      21. Fixed the Check Point security audit report not getting generated issue.
      22. Check Point interface details population code correction issue fixed.
      23. Alarm profile name parameter is restricted to "alphanumeric_basic" with few special characters. Fixed the issue.
      24. 'VPN Trend report' drill-down related issue fixed.
    4. 12.5 Build 125129
      1. General : After upgrading the product, there was an "Unable to start the product" error. This issue has now been fixed.
      2. General: Previously, the backup functionality was not working for non-English installations. This issue has now been fixed.
    5. 12.5 Build 125125

      Security Issue Fixed:

      1. General : Path Traversal vulnerability in URLs starting with has been fixed. (Refer CVE-2020-12116)
    6. 12.5 Build 125122

      New Features:

      1. Graphs and tables in scheduled PDF report generation are modified to match with client.
      2. Scheduled CSV report generation is modified to get more no of rows.


      1. 'Raw Search' page is enhanced with more search criteria, 'not contains' and 'not starts with'.
      2. Custom reports saved in 'Raw Search' result page is enhanced with 'Edit' option.
      3. In 'Raw Search' result page, if the 'Columns' are customized, it will be retained for the entire session.
      4. Support ID: 5852482 - User IP mapping - Single firewall can be associated with multiple AD now..

      Issues Fixed:

      1. sco disconnection issue fixed.
      2. SonicWall VPN log parsing issue fixed.
      3. Syslogs timestamp with 'No Year' are handled.
      4. Standard pages refresh icon was missing if PCI zone was not configured. This issue is fixed.
      5. Raw Proxy Log search result showed traffic as Bytes. This issue is fixed to show proper value.
      6. SonicWall default Service list has been updated and fixed the some configuration parsing issues.
      7. Support ID: 5950522 - SonicWall policy optimization issue is fixed.
      8. Support ID: 5998072, 5981314 - Palo Alto VPN log parsing issue is fixed.
      9. Support ID: 5964530 - Compliance standards - SANS - Section 15 did not detect rules with ICMP protocol. This issue is fixed.
      10. Support ID: 5891108 - Unable to generate PCI-DSS compliance for FortiGate firewall due to nested object group. This issue is fixed.
      11. Support ID: 5978910 - Cisco ASA - Single VPN user with two different IP addresses shown as one login in Active VPN Users.This issue is fixed.
      12. Support ID: 5938539 - Default Exclude Criteria has been added for Encrypted Keys to avoid invalid change management in SonicWall configuration.
    7. 12.5 Build 125120

      Issues Fixed:

      1. General : Unauthenticated access to API key disclosure from a servlet call.
        CVE-2020-11946 - @kuncho, an independent Security Researcher, has reported this vulnerability to SSD Secure Disclosure program. The issue has been fixed.
    8. 12.5 Build 125115

      Issues Fixed:

      1. PostgreSQL connection close issue due to CopyManager is fixed.
      2. Vulnerability in Import log page is fixed.
      3. In OpM Plus, 'Rule Reorder' page was overlapped with FAQ contents. This issue is fixed.
      4. In OpM Plus, 'Fetch now' button was missing in 'Unused Rules' page. It is fixed now.
    9. 12.5 Build 125109

      New device/log format support:

      1. New Log Support - VMware NSX Edge Firewall.

      New Feature/Enhancements:

      1. Rule Management and Compliance reports support for Linux iptables.
      2. On-demand PDF report generation using JasperReports changed to PhantomJS for Search, Compliance and Rule Management reports.
      3. Support ID: 5654552 - Resolve DNS option provided in RAW Search page.
      4. Support ID: 5826180 - Cisco FirePOWER Device Rule support enhanced to use TFTP protocol.
      5. Support ID: 5847978 - Schedule Remote Host log import enhanced to use FTP protocol.
      6. Support ID: 5555538 - Time stamping of Archive files handled properly.
      7. Support ID: 5683114 - PaloAlto 'Panorama' config download enhanced to handle in API mode.
      8. Time period selection is enhanced as drop down.
      9. Enhanced 'From' and 'To' time period shown near 'Time' selection box.

      Issues Fixed:

      1. Support ID: 5780720 - Active VPN trend report graph shows multiple points for single day. This issue is fixed.
      2. Support ID: 5314890 - If log import is scheduled with 24 hours gap, schedule will run with fixed interval. Fixed the issue.
      3. Support ID: 5811442 - Alarm profile specific drill down page is empty. Fixed the issue.
      4. Support ID: 5683114 - Issue in PaloAlto auth token based 'device rule'/'rule administration' support is fixed.
      5. Support ID: 5842665 - For PaloAlto device SCP configuration cases, occasionally password prompt value missing in CLI response. Fixed the issue.
      6. Support ID: 5871724 - Column chooser not reflecting in CSV and XLS export in Policy Overview tab. Fixed the issue.
      7. Support ID: 5697672 - FortiGate policy optimization and rule re-order shows wrong data due to improper handling of security policies. Fixed the issue.
      8. Support ID: 5827994 - Fixed the Cisco FirePOWER trust rules parsing issue.
      9. Support ID: 5866185 - In the SonicWALL scheduled configuration fetch cases, Security Audit report is not generated. Fixed the issue.
      10. Support ID: 5844575 - Fixed the Sophos XG configuration parsing issue.
      11. Support ID: 5314890 - In Imported logs, for FTP connection failed cases, 'Processing logs' status is shown. Fixed the issue. This has been changed to 'Connection refused' status and added an entry in Audit report.
      12. Support ID: 5778181 - In case of configuration download via TFTP, Firewall Analyzer was not waiting till full configuration transfer, because of that partial data is downloaded in configuration file and device rule data is not populated properly. Fixed the issue.
      13. In the case of adding FortiGate VDOM devices and not restarting Firewall Analyzer, if device rule is created, reports are populated only for physical firewall devices. This issue is fixed.
      14. In Rule Administration, earlier validation was not done before deleting Objects. Issue fixed by validating before deleting Objects.
      15. In some Cisco ASA webVPN cases, wrong source IP was shown. This has been fixed.
      16. FortiGate device rule add, edit cases VDOM data is populated for main physical device. This has been fixed now.
      17. Cisco Admin and SonicWALL VPN log parsing issues fixed.
      18. Action Column removed from Archive Files page.
      19. Loading icon added, while generating Rule Impact report.
      20. Showing 'No data' message beside widget name during on-demand export.
    10. 12.5 Build 125108
      • General : The obsolete code causing Remote Code Execution vulnerability in Mail Server Settings v1 APIs have been removed.
    11. 12.5 Build 125003

      Issues Fixed:

      1. PostgreSQL connection close issue has been fixed.
    12. 12.5 Build 125000
      • General : PostgreSQL has now been migrated to version 10.10.
      • General : The PostgreSQL vulnerability issues from version 9.2.4 have now been fixed.
    13. 12.5 Build 124196

      Security Issue Fixed:

      • General : Path Traversal vulnerability in URLs starting with has been fixed. (Refer CVE-2020-12116).
    14. 12.5 Build 124188
      • General : Unauthenticated access to API key disclosure from a servlet call.
        CVE-2020-11946 - @kuncho, an independent Security Researcher, has reported this vulnerability to SSD Secure Disclosure program. The issue has been fixed.
    15. 12.4 Build 124181

      Vulnerability Issue Fixed:

      OpManager: Previously, the users were able to read the Arbitrary file. This file read vulnerability has now been fixed.

    16. 12.4 Build 124179

      New Feature:

      1. Rule Administration feature supported for below devices:
        1. Check Point
        2. PaloAlto


      1. Support ID - 5672098: Admin report supported for pfSense firewall.
      2. Support ID - 5657055: For Scheduled PDF report, Time Filter (Custom Time, Working Hour, Non-Working Hour) will be shown in 'Report Criteria' field.
      3. Support ID - 5458268: Enhanced Time Zone value handling for FirePOWER FTD 6.2, 6.3, 6.4 and above versions.
      4. Enhanced report export to PDF, XLS, and CSV formats.
      5. Enhanced the widget selection option for CSV and XLS export in reports.
      6. 'All Records' option given for export to CSV and XLS in 'Inventory', 'Reports' and 'Audit Log' pages.
      7. In 'Inventory', 'Reports' and 'Audit Log' pages, enhanced export to PDF option up to 50,000 records in single page.
      8. Report pages enhanced with two more row count options 'Top 50' and 'Top 100'.
      9. Enhanced all reports export to generate PDF, CSV and XLS formats with 'Report Name' & 'Row Count' combinations.
      10. Enhanced CSV export record count to 100,000 records and 'Advanced' option is provided.
      11. Enhanced XLS export record count to 25,000 records and 'Advanced' option is provided.
      12. In 'Inventory' list page, 'Time Period' option moved, so that hiding left section won't affect time period change.

      Issues Fixed:

      1. Support ID - 5676695: Fixed VPN log parsing issue for pfSense firewall.
      2. Support ID - 25422: Fixed the rule fetching failure issue for FortiGate VDOM - physical device.
      3. Support ID - 5783874: FortiGate VDOM Device Rule failed for HA pair. Fixed this issue.
      4. Support ID - 5447344: For i-FILTER device, 'Vendor Type' is shown as 'Unknown CLF'. Fixed the issue to show the 'Vendor Type' as 'i-FILTER'.
      5. Support ID - 5672749: Fixed the 'Traffic' log parsing issue in MicroTik firewall.
      6. Support ID - 5694946: FortiGate FGT90E logs are shown under 'Unsupported' logs. Fixed the issue.
      7. Support ID - 5715854: Fixed the 'Security XML' issue, when log is imported with 'Map this log file to existing device' option.
      8. Support ID - 5640654: Fixed the FirePOWER date parsing issue.
      9. Support ID - 5555538: Custom Report schedule failed, when 'Firewall Unused Objects' report selected in 'Report' list. Fixed the issue.
      10. Support ID - 5686648, 5726632: FortiGate log ID 'logid=0000000020' has the aggregated value of Sent bytes, Received bytes and Duration. The populated data is huge and the log is intermittent. Dropped the logs to fix the issue for proper reporting.
      11. Support ID - 5827506: 'Active VPN User' report is not showing for PaloAlto device. Fixed this issue.
      12. Support ID - 5778181: Parsing issue in 'Admin' logs for PaloAlto firewall is fixed.
      13. Support ID - 5785313: Device name changes to Profile name in 'Custom Reports' page. Fixed this issue.
      14. Support ID - 5807625: For PaloAlto device, Change Management alert triggered based on 'Logout' event syslog. Fixed the issue by changing the Change Management alert trigger based on 'Commit' event syslog.
      15. FortiGate VDOM device rule 'On demand' options are not working. This issue is fixed.
      16. 'Resolve DNS' not working in 'Snapshot' page when drilled down from traffic statistics widget in the Dashboard. Fixed this issue.
      17. In Snapshot page, 'Alert' and 'Report' profile buttons are not visible. Fixed this issue.
      18. In the 'Inventory' and 'Snapshot' pages, column header and page navigation components were made static for the expand widgets.
      • General: The obsolete code causing Remote Code Execution (RCE) vulnerability in Mail Server Settings v1 APIs have been removed. (Reported by Jason Nordenstam) (Refer: CVE-2020-10541)
    17. 12.4 Build 124168


      1. Alarms page has been completely revamped for better user experience.
      2. Under Mail Server Settings, the length of the 'User Name' field has now been increased from 50 to 100 characters.
      3. Under User Management, the maximum length of the 'Password' field has now been increased from 25 to 100 characters.
      4. Support-ID : 5603075, 5518885 : Fetching and applying global configuration in device rule for Fortigate VDOM.
      5. Support-ID : 5566735 : VPN Report, Admin Report and Attack Report supported for Barracuda Firewall F600.
      6. In the device snapshot inventory page, device rule creation for a VDOM is currently mapped to its respective physical firewall device.
      7. Firewall Analyzer Support page usability has been enhanced with more details.

      Issues fixed:

      1. Previously, auto-login was not working when the special character '&' was present in the username or password. This issue has now been fixed.
      2. The JCE compatibility issue that occurred during PPM migration has now been fixed.
      3. Previously, while installing a collector server, any unauthenticated collector could register with the admin server. This issue has now been fixed.
      4. Support-ID : 5539649 : Previously in the Device rule, the On-demand option for physical firewalls was not listed. This issue has now been fixed.
      5. Support-ID : 5603075 : Previously, it was not possible perform rule re-order for VDOM devices. This issue has now been fixed.
      6. Support-ID : 5603075 : The Device rule configuration status for VDOM devices was not updated properly in Inventory -> Device snapshot page. This issue has now been fixed.
      7. Support-ID : 5603075 : Rule parsing issue in Fortigate device has been fixed.
      8. Support-ID : 5672098 : Rule parsing issue in pfSense device has been fixed.
      9. Support-ID : 5614148 : Previously there was a Security XML issue in Intranet settings. This issue has now been fixed.
      10. Support-ID : 5641993 : There was a parsing issue in Sophos UTM URL log. This has been fixed in this build.
      11. Support-ID : 5566735 : Timezone and protocol parsing issue for Barracuda Firewall has been fixed.
      12. Support-ID : 5313119 : Adding a special character in the UserName field resulted in a failure when trying to "Add SNMP" in the setting. This issue has now been fixed.
      13. Support-ID : 5657055 : Custom Report was not generated when Non-Working hour filter was applied. This issue has now been fixed.
      14. Support-ID : 5494598 : The Active VPN users report displayed data for even unmanaged devices. This issue has now been fixed.
      15. Support-ID : 5529314 : Any Fortigate VDOM devices configured in HA mode resulted in duplication. This has now been fixed and the same will now be added as a single device.
      16. Standard page NERC-CIP Report - Redirection URL issue has been fixed.
      17. Previously, adding a Barracuda device resulted in duplication. This issue has now been fixed.
      18. Previously, it was not possible to map a VDOM from user config page for HA mode firewalls. This has now been fixed.
    18. 12.4 Build 124099

      New features/enhancements:

      1. Support ID: 5535440 - Check Point multi access layer supported for Rule Management.
      2. Option to enter 'Gateway Name' under 'Add Device Credential' page for Check Point firewalls.

      Issues fixed :

      1. Support ID: 5625819 - Unable to assign 'Credential Profile' while creating device rule. Fixed the issue.
      2. Support ID: 5625819 - Changing credential profile to none clears the default info in device rule. This issue is fixed.
      3. Support ID: 5474215 - Issue in 'column chooser', while selecting multiple column using 'control' key, is fixed for 'Raw Log Search' page.
      4. Weaker file permission for Nipper file has been fixed (CVE-2019-17421 - Bug found by: Guy Levin (@va_start)).
    19. 12.4 Build 124096

      New device/log format support :

      1. Support ID: 5485772 - Symantec Endpoint Protection 14 device.
      2. Support ID: 5585856 - Huawei default 'Syslog' format support along with existing MTN format.

      Enhancements :

      1. Support ID: 5535440 - VPN report supported for Check Point Log Exporter CEF format.
      2. The interface IP address field is empty when fetched via SNMP for Cisco Meraki and Sophos XG devices. Because of this issue, interface is not getting added in Firewall Analyzer. Enhanced to fetch interface IP address.

      Issues Fixed :

      1. Support ID: 5535440 - Fixed the Interface value parsing issue in Check Point Log Exporter CEF format.
      2. Support ID: 5605740 - Fixed the Palo Alto port scan attack parsing issue.
      3. Support ID: 5586838 - Fixed the SonicWALL device rule parsing issue for SonicOS 5.6
      4. Support ID: 5567083 - Fixed the SonicWALL device rule service group parsing issue.
      5. Support ID: 5586113 - Palo Alto ISO compliance standards > Firewall Management configuration details - fixed the device rule parsing issue.
      6. Bandwidth alert issues fixed:
        1. Bandwidth alert triggered frequently. Threshold criteria is not applied properly.
        2. Alert mail is not showing the 'latest log' message properly.
        3. In Alarms page, the bps, bps_in & bps_out values of the alert details message are not displayed properly.
      7. Fixed the Huawei device rule parsing issue.
      8. 'Availability Alert' is getting triggered for the lowest time selected in case of multiple alert case. Fixed the issue.
      9. 'Archive Security Settings' is reset to default values, when 'archived file' settings is changed. Fixed the issue.
      10. Internally identified 'local file inclusion' vulnerabilities are fixed to make the product secure.
    20. 12.4 Build 124088

      New device/log format support :

      1. Support ID: 5447104 - Kerio Control Firewall version 9.2.8

      New features and enhancements :

      1. Rule Cleanup Enhancements:
        1. Identify unused source, destination and service objects defined in used rules.
        2. Identify unused any port and protocols defined in the objects of used rules.
      2. Revamped the Rule Management report pages to improve the usability.
      3. Option to assign multiple collectors while creating Operator privilege users in Central server.
      4. A new device audit report for login, logout for devices.
      5. User based 'Commands executed' details for every configuration change.
      6. Log flow parsing rate has been improved to handle more proxy server logs.
      7. Source and Destination countries are now listed in the drop down for selection while creating 'Normal' alerts.
      8. Support ID: 5377251 - SSL VPN report supported for Sophos XG devices.
      9. Support ID: 5377251, 5045675 - Now users can search the source port, destination port and URL category as criteria in the 'Raw Search' report.
      10. Support ID: 5377251 - Rule enable and disable syslogs are parsed to show in 'Commands executed' report for Sophos XG in Admin reports.

      Issues Fixed :

      1. Support ID: 5518885 - Device rule addition got failed for VDOM devices, when we assign existing credential profiles. Fixed the issue.
      2. Support ID: 5519348 - Editing of Change Management report schedule was not working after the product restart. Fixed the issue.
      3. Support ID: 5465688 - Hit count mismatch between 'Denied Events' report under Security report and 'Raw Deny' logs in Raw Search for Palo Alto device is fixed.
      4. Support ID: 5485772 - Excluding the user name, if the user name is coming as IP address for proxy. Fixed the issue.
      5. Support ID: 5414153 - Excluding 'Management' syslogs from user name - IP address mapping. Fixed the issue.
      6. Support ID: 5465784 - WatchGuard traffic log parsing issue fixed.
      7. Support ID: 5024679 - Fixed the 'Directory' validation handling issue in 'Imported Logs' page.
      8. Support ID: 5407203 - VPN User transaction report showing different names in Custom report page issue is fixed.
      9. Internally identified SQL Injection, Remote Code Execution and Local File Inclusions vulnerabilities are fixed to make the product more secure.
      10. Support ID: 5547592, 5425257 - Fixed the SRX and Cisco device rule parsing issues.
      11. Support ID: 5539886, 5566735 - Unable to configure SNMP v3 due to community string being mandatory and special character limitation. This issue is fixed.
    21. 12.4 Build 124083

      Enhancement :

      1. Rule management and compliance reports for Stormshield devices using CLI.
    22. 12.4 Build 124079

      Issues fixed :

      1. Security Update: Weaker file permission for Nipper file has been fixed (CVE-2019-17421).
    23. 12.4 Build 124068

      Enhancements :

      1. Rule management and compliance reports for Juniper NetScreen devices using SSH protocol.
      2. Added SSH protocol to fetch configuration files for Sonicwall Firewall.
      3. Rule management and compliance reports for SonicWALL devices using API.
      4. Configuration diff page has been enhanced with 'Lines around Changes' option.
      5. In Discovery page, option to configure port has been provided.
      6. SonicWALL device rule UUID supported to display it along with rule name in Policy Overview and Optimization reports.
      7. Virus report supported for Cisco FirePOWER devices.
      8. API Document has been released for public.
      9. New columns source 'src' & destination 'dst' interface added for Policy Optimization report.

      Issues Fixed :

      1. The timezone was not handled properly while parsing FirePOWER log. Fixed the issue.
      2. WatchGuard SSH connection close was not handled properly. Fixed the issue.
      3. Change Management support provided for Sophos XG User Name and Password content.
      4. Devices with same name caused license count issue in Central Server. This issue is fixed.
      5. Active VPN trend report was not showing 24 hours data. The issue has been fixed.
      6. Cisco WebVPN events were not detected properly. The issue has been fixed.
      7. Machine name parsing has been added in AD user/IP mapping.
      8. Sophos XG admin log parsing issue fixed.
      9. SonicWALL duration value parsing issue fixed.
      10. Policy Overview XLS format export issue fixed.
      11. Few device configuration parsing issues fixed.
    24. 12.4 Build 124053

      Issue Fixed: :

      1. Device credential validation failed issue has been fixed for Juniper SRX and Cisco FirePOWER devices
    25. 12.4 Build 124052

      New features and enhancements :

      1. For Cisco FirePOWER devices - Rule impact analysis supported.
      2. In the 'Policy Optimization' report, provided options for pie chart and table drill down.
      3. Search' option in the 'Policy Overview' report is enhanced to provide results for CIDR and multiple values (comma separated) with multiple columns combined.
      4. Source, Destination and Service object details can be viewed in 'Object Repetitiveness' reports of the 'Rule Impact' analysis reports from the product UI.
      5. Option to export 'Security Audit' report as HTML from the product UI.
      6. Widget specific refresh option is provided in Firewall reports, Proxy reports, Custom reports and all the expand view pages.
      7. Retain the time period in expand view of Firewall reports, Proxy reports and Custom report pages.
      8. In the case of device credential validation, all commands execution status has been shown in the main results page.
      9. Alarm profiles enhancements in 'Settings' tab,
        • Option to view profile specific alerts and it's details.
        • Option to export as PDF, CSV and XLS for alert profiles.
        • Option to clear alerts generated for profiles in single click.
      10. 'Cloud Repository' list page enhancements in 'Settings' tab,
        • A new search option.
        • Page navigation component given with top-N select option.
        • Sorting option given for the table headers.
      11. New custom options are provided in the add 'Device Credential' page for below parameters,
        • Timeout.
        • FWA Server IP.
        • isManagedbyPanorama for PaloAlto.

      Issues Fixed :

      1. Support ID: 4978071 - Fixed the Japanese characters garbled issue in the policy overview report.
      2. Support ID: 5383226 - New added/updated/deleted cloud services data not effective till the application is restarted. Fixed the issue.
      3. Support ID: 5382799 - In the Aggregated search report 'VPN Usage report' was shown as empty for Cisco ASA device. Fixed the issue.
      4. Support ID: 5273379 - Timezone parsing issue for Sophos XG device is fixed.
      5. Support ID: 5363136 - Wrong values are displayed in 'From Time' and 'To Time' fields of the custom schedule option. Fixed the issue.
      6. Support ID: 5402088 - In the 'VPN User Transaction' report, new column 'Source IP Address' added.
      7. Support IDs: 5377292, 5400991 - Few duplicate and unused i18n keys are removed.
      8. Support IDs: 5391699, 5399454 - ' Denied' log parsing issue for Juniper SRX and Netscreen devices fixed.
      9. Support ID: 17190 - 'Attack' log parsing issue for Sophos UTM device fixed.
      10. Support ID: 16319 - 'UserName' parsing issue for Fortigate device logs fixed.
    26. 12.4 Build 124044

      New features and enhancements :

      1. You can edit, rearrange and hide the default tabs in the horizontal menu.
      2. New custom tabs can also be added, edited, rearranged and deleted from the horizontal menu.
    27. 12.4 Build 124037

      New features and enhancements :

      1. Firewall Analyzer Standard Edition has been launched for SMEs with basic firewall log monitoring requirements.
      2. Firewall Analyzer Premium Edition is now renamed as Firewall Analyzer Professional Edition.
      3. Firewall Analyzer Distributed Edition is now renamed as Firewall Analyzer Enterprise Edition.
      4. Support ID: 5160784 - VPN report supported for Sophos UTM-9 device.

      Issues Fixed:

      1. Support ID: 5256108, 5266114 - Fixed Cisco ASA, Cisco Meraki device log parsing issue.
      2. Support ID: 5298823 - Fixed Sophos-XG550, Netscreen 6.3.0 r18.0 log parsing issue.
      3. Support ID: 5243703 - In custom schedule reports, row count restriction for PDF export removed.
      4. Support ID: 5364221 - While creating vdom device rule using credential profile, failed to update device credentials. Fixed the issue.
      5. Support ID: 5375112 - Export report failed, when the number of rows selected for custom reports is changed. Fixed the issue.
      6. Support ID: 5188524, 5209521 - 'Data-Crunch' message added as title in the device and interface live report graphs.
      7. Support ID: 5087229, 5273379 - Traffic conversation report displayed the total bytes value as 0, because of wrong unit conversion. This issue is fixed.
      8. Support ID: 5165994 - Cisco Firepower device was detected as Cisco device, due to some unsupported logs received from device. Fixed the issue.
      9. Support ID: 50191188 - In SNMP settings and Reports filter configuration pages, fixed the usability issues.
    28. 12.4 Build 124033

      Issues fixed :

      1. General: HTML Injection vulnerability issue in Google maps has now been fixed. (CVE-2017-11560)
    29. 12.4 Build 124025

      New device/log format support :

      1. Structured log format support for Juniper SRX.
      2. Log Event Extended Format (LEEF) custom log format support for PaloAlto.
      3. pfSense 2.5 version log format supported.

      New features and enhancements :

      1. Perform object definition level search in Policy Overview reports for any object/IP across existing rule set.
      2. Rule impact analysis enhancements:
        • Option to select custom blacklisted IPs (from file) in UI.
        • Object repetitiveness report for source, destination, and service objects.
      3. Device Rule page enhancements:
        • Option to add credential profile at the time of device rule configuration.
        • Unified the device rule configuration in Inventory device list and snapshot pages (Similar to the Settings page)
        • Device rule credential validation is made mandatory now using 'Validate' button.
        • Included validation status for rule and configuration commands
        • Change notification and schedule availability provided in the Change Management page.
      4. In the 'Search' reports page, CSV and XLS export options provided.
      5. In device and interface live traffic drill down pages, CSV and XLS options provided.
      6. Selected widgets can be exported as PDF or trigger an email(on-demand) from report pages.
      7. Search option has been provided for reports and inventory drill down pages. The same is also available in the respective expanded view page.
      8. Top 5 (Graph and Table), Top 10 (Graph and Table), Top 15 (Table only), Top 20 (Table only) options are provided in firewall reports and proxy reports.
      9. For easy navigation, 'Report' pages drill down can be expanded to full page instead of slide and the tabs are moved as left side menu in reports and inventory page.
      10. Selected report type will be retained as default for other selected devices.
      11. Option to show/hide filter section (log flow received, vendor and device-type) in 'Inventory' page.
      12. On demand PDF export of security audit page has been enhanced to look like the UI.

      Issues Fixed:

      1. The SQL injection vulnerability in 'SubmitQuery' page has been fixed.
      2. Support ticket ID: 4978071, 5148764 - Firewall Analyzer uses the secondary IP Address to export the configuration from SonicWALL devices. Fixed the issue.
      3. Support ticket ID: 5186465, 5169152 - Fixed Juniper SRX3400 , SRX4100 device rule parsing issue.
      4. Support ticket ID: 5251059 - Fixed PaloAlto (PAN-OS 8.0.16) device rule parsing issue.
      5. Support ticket ID: 5190721 - If the device has VDOM, Device (Physical-Device IP) not listed for SNMP configuration. Fixed the issue.
      6. Support ticket ID: 5160784 - Unable to update interface details if the interface-name contains .(dot) in it. Fixed the issue.
      7. Support ticket ID: 5200605 - No data in dashboard for a few FortiGate devices as the destination field contained junk characters. Fixed the issue.
      8. Support ticket ID: 5234629 - Port details are shown under 'Destination' column in reports, for SonicWALL firewalls. Fixed the issue.
      9. Support ticket ID: 5279308 - FortiGate firewall logs were dropped due to filename length limitation. Fixed the issue.
      10. Support ticket ID: 5339523 : Fixed Cisco object-groups parsing issue
    30. 12.4 Build 124024

      Issues Fixed:

      • General: Previously, when HTTPS was enabled in the WebClient, some unexpected loading issues were observed. This has now been resolved by upgrading the Tomcat version used in the product.
      • General: Scroll issue while listing custom dashboards has been fixed now.

      Vulnerability Fixes :

      • General: The 'local privilege escalation' vulnerability has now been fixed.
    31. 12.4 Build 124000

      Vulnerability Fixes :

      • JRE has been migrated to 1.8 and various vulnerabilities from JRE 1.7 have been eliminated. Highlights of JRE 1.8 migration:
        • General: Cipher algorithms AES-192 and AES-256 are supported in addition to AES-128 algorithm.
        • General: TLSv1.2 protocol is now supported by default.
    32. 12.3 Build 123324

      New device/log format support:

      1. Barracuda Next Generation Firewall (F-600 model) support.
      2. Cisco FirePOWER v6.3.0 and above with modified time stamp support.

      New features & enhancements:

      1. Rule management and compliance reports support with vendor API.
        1. PaloAlto.
      2. 'Rule Impact Analysis' functionality assesses the impact of a new rule, on the existing rules with anomalies, vulnerabilities and security threats analysis.
      3. On demand options available in UI for sending reports via email and exporting reports in CSV, Excel formats:
        1. For individual widgets.
        2. For all report pages and drill down report pages.
      4. New 'Tools' tab to help access the other network devices for availability check and basic monitoring.
      5. Change management configuration difference view has been enhanced to show clear information for PaloAlto and WatchGuard devices for XML format configurations.
      6. 'Custom time' option has been provided in 'Custom' report schedule section.
      7. 'Report type' and 'Report filter' options are moved from settings tab to reports tab for easy access.
      8. 'Resolve DNS' option has been moved from individual widgets into page-level in Firewall, Proxy and Custom report pages.
      9. A new list page is added under 'User-IP Mapping' table which shows the existing IP address or MAC address/User name details in the web UI.
      10. 'Edit Interface' now helps to change interface name and interface IP addess and sub-net mask are made optional.
      11. In AD user authentication, you can now configure scope to be auto-assigned to users logging in for the first time, when auto login is enabled.

      Issues Fixed:

      1. For PaloAlto devices, Active VPN Users reports details are not displayed properly.This issue is fixed.
      2. Fixed the NTP configuration parsing issue, for Huawei devices.
      3. Fixed the Sophos UTM device rule parsing issue.
      4. Fixed the log parsing issue, for Sonicwall Blocked URL report.
      5. When any report profile is edited or deleted the assigned report filters got deleted. This issue is fixed.
      6. Main Tabs are not selected properly while redirecting from other reports and some sub-tabs.
      7. Fixed parsing issues for Cisco management, SRX and pfSense logs.
      8. Fixed the vulnerability issue in Alarm Profile page, when 'Run Script' option is selected.
      9. 'View Report' is not displayed in the 'Imported Logs' page, for some imported logs in the list. Fixed the issue.
      10. Remote host log file import failed due to missing parameter in security.xml file. Fixed the issue.
      11. When 'Intranet settings' is configured for a device, unable to add two IP networks. Fixed the issue.
      12. 'All Reports' in Firewall/Proxy server reports page, instead of displaying only reports of all firewalls in 'Firewall Reports' page and only reports of all proxy servers in 'Proxy Server Reports' page, reports of all the devices. Fixed the issue.
    33. 12.3 Build 123309

      New device/log format support:

      1. Log Exporter (CEF format) support for Check Point devices (R-77.3, R-80.10 with Jumbo Hotfix and R-80.20 versions)

      New features & enhancements:

      1. On demand PDF export option in Web UI has been enhanced using PhantomJS.
        1. Page level PDF export with multiple widgets.
        2. Individual widget level PDF export.
        3. PDF export for all drill-down report pages.
      2. Rule management and compliance support using vendor API.
        1. Sophos-UTM.
        2. Sophos-XG.
      3. Rule management and compliance support using CLI.
        1. Check Point devices R-80.1 and above.
      4. Message framework guideline for proper usage of all features and configuration pages.
      5. 'Bytes' and 'Hits' details are added in the Dashboard Top 'N' widget reports.
      6. Quick links and Help cards added in Diagnose Connection, Report Filter, Customize Report, Rule Management reports and Settings pages.

      Issues Fixed:

      1. Fixed the improper error handling message shown for 'Test connection' action in 'Device Rule' configuration page.
      2. Multiple IP ranges can't be added in Intranet settings page. Fixed the issue.
      3. Linux installation users were unable to save "Nipper" location in User Config page. Fixed the issue.
      4. Unable to configure SNMP v3. Fixed the issue.
    34. 12.3 Build 123304

      Issues Fixed:

      1. General: Previously, validation of session failed when the URL contained two or more consecutive backslashes. This vulnerability has been fixed now.
    35. 12.3 Build 123281

      New features:

      1. Cisco FirePOWER - Firewall policy, rule analysis, and compliance report support using CLI to fetch configurations.
      2. To prevent vulnerabilities, Firewall Analyzer now verifies each request parameters type and value before it is processed.

      Issues Fixed:

      1. Support-ID: 4882018 - In Japanese installation, if 'Trend graph' report is exported, it displays the same graph for hourly and weekly comparison graphs. This issue is fixed.
      2. Cisco Meraki is discovered as 'proxy server' instead 'firewall' in Firewall Analyzer. This issue is fixed.
      3. When server side PDF export is set as 'All', it is not working. This issue is fixed.
      4. When 'Denied User Report' is drilled down from Dashboard, page is empty. This issue is fixed.
      5. Raw search result displayed in the UI is grouped based on the specified criteria.
      6. Quick links are added for 'Credential Profile' page.
      7. Quick links are added for 'Archive Encryption' page under Security settings.
    36. 12.3 Build 123277

      Issues Fixed:

      1. General : The SQL injection vulnerability in 'getDeviceCompleteDetails' and 'getAssociatedCredentials' API's have been fixed.
    37. 12.3 Build 123268


      1. Check Point device API based Compliance Standards report.
      2. For all drill down pages of Inventory and Reports, provided export as CSV and Excel option.

      Issues Fixed:

      1. Delete button alignment issue in Device Rule list page is fixed.
      2. In the 'Traffic Statistics' graph, one of the 'Protocol' groups was assigned with 'Grey' color and it was looking odd. Changed the color to fix the issue.
      3. Loading of 'Dashboard' pages was slow, removed unwanted resource checks to fix the issue.
      4. The 'Delete' option was hidden in individual rows in Imported Logs, Device-Rule, Exclude-Criteria, Credential Profiles and Archived Files list pages. 'Delete' option is displayed as button to fix the issue.
      5. Removed the 'Group Chat' icon in vertical tab of UI.
    38. 12.3 Build 123263

      New Device Supported:

      1. VarioSecure firewall.


      1. Automatic Security Audit report generation for Check Point (R-80.10 & above) devices using API.
      2. CLI based Policy analysis, Rule management and Compliance support for pfSense firewall s.
      3. Added Line & Bar graph options for device and interface Live reports.

      Issues Fixed:

      1. Support-ID: 4909346 - Fixed the Device Rule configuration failure issue, in HA mode of FortiGate with VDOM setup.
      2. Support ID 4909346: Fixed the issue of showing password in plain text, in the Device Rule submit response.
      3. Support ID 4919514: Fixed the issue of embed widget not working, in CCTV view.
      4. Support ID 4927087: New column added to display Cisco ACE hex code in Raw search results page.
      5. Support ID 4553065: Fixed Squid proxy server parsing issue.
      6. Support ID 4934078, 4950793: Fixed the issue of wrong client IP assignment for Cisco VPN.
      7. Fixed the issue of Scheduled Rule fetching failure for Check Point, due to CLI connection attempt.
      8. Huawei device change management reports are loaded with full configuration instead of changes alone. Fixed the issue.
      9. Added default exclude criteria for SonicWall devices to remove dynamic key updates as changes from Change Management Report. Fixed the issue.
      10. Displayed inputs in response when Assign Credential Profile to a device is saved. Fixed the issue by removing the inputs and displaying only status.
      11. Policy Overview Schedule list page displayed schedule details of all the devices. Fixed the issue to display the schedule details of only selected devices.
      12. Was able to configure SNMP for Unmanaged devices. Fixed the issue.
      13. When working hours is updated in Advanced settings, it was reflected in General settings. Fixed the issue.
      14. No criteria is displayed for Policy Overview Scheduled reports when report specific criteria is provided. Fixed the issue.
      15. For proxy devices Live Traffic is displayed in dashboard but not in Inventory page. Fixed the issue.
      16. Device display name changes are not reflected in alarms page. Fixed the issue.
      17. In Raw Search mail content PDF Report, Criteria value had extra details other than user configured criteria. Removed those unconfigured criteria and fixed the issue.
      18. Exception thrown when Diagnose connections page is clicked in Settings tab. Fixed the issue.
      19. In Settings > User Management > Add/Edit User > Device list page, the deleted devices are also listed. Fixed the issue.
      20. In Configuration Changes Mail Notification, Mail content has Disable link in the start of the mail. Moved the Disable link message to end of the Mail to fix the issue.
      21. In Reports > Custom Report > Edit & Save the existing report profile, the success message was displayed as 'Report added successfully'. Message changed to fix the issue.
      22. UI issue: Properly conveyed the new category addition for Cloud Repository.
      23. UI issue: Fixed the improper Header alignment in API Access page.
      24. UI issue: Fixed the image misalignment issue in Inventory > Users tab.
      25. UI issue: Fixed the irrelevant Status message shown, when Device Rule for a device is deleted.
      26. UI issue: Fixed the issue of custom widget addition for Live Traffic without selecting a device, by ignoring the status message.
      27. UI issue: Fixed the issue of no redirection to reports page when the 'Unknown' user is clicked in Inventory > Users tab.
      28. UI issue: Added the missing 'Security settings' option in Admin server.
      29. UI issue: When device configuration fetching is in progress, other tabs cannot be accessed. This issue is fixed.
      30. UI issue: When no Firewall/Proxy was added, link to add device is displayed in Reports tab. Fixed the broken link issue to direct it to Getting Started page.
      31. UI issue: Settings tab, System sub-tab selection is not proper, while selecting Working Hours option. Fixed the issue.
      32. UI issue: Due to pagination, in Rule Management page the 'Export to Excel' option was hidden. The issue is fixed to display the option.
      33. UI issue: Remove the unwanted horizontal scroll displayed in Compliance > Standards > Schedule option.
      34. UI Change: Column header changed from 'SRC/DST Interface' to 'SRC/DST Zone' for Huawei devices in Policy Overview page.
      35. UI Change: In menu hover option, configured custom reports are displayed.
      36. UI Change: When a device is deleted from the Inventory page, 'Please wait...,' message is displayed.
      37. UI Change: Proper Enable/Disable SNMP configuration message is displayed in device snapshot page.
      38. UI Change: Graph misalignment with table is aligned in Policy Optimization page.
      39. UI Change: New help page links provided for Syslog server, Manual DNS and Security Audit report pages.
    39. 12.3 Build 123239

      Issues Fixed:

      1. General : There was an SQL injection vulnerability in the Alarms section. This issue has been fixed. (Refer: CVE-2018-20338)
      2. General : In Alarms, there was an XSS vulnerability in the Notes column. This issue has been fixed. (Refer: CVE-2018-20339)
    40. 12.3 Build 123237

      Issues Fixed:

      1. General : XSS vulnerability issue in domain controller has been fixed. (Refer: CVE-2018-19921)
    41. 12.3 Build 123231

      Issues Fixed:

      1. General : Apache's 'commons-beanutils' jar has been updated to version 1.9.3 due to 'Remote Code Execution' vulnerability in an older version. (Refer: CVE-2018-19403)
      2. General : Unauthenticated access to 'DataMigrationServlet' has been fixed. (Refer: CVE-2018-19403)
      3. General : The 'Browser Cookie theft' vulnerability has been fixed.
    42. 12.3 Build 123224

      Issues Fixed:

      1. XML External Entity Injection Vulnerability is fixed, while importing Custom Report/Alert profile.xml (Refer: CVE-2019-11677)
      2. Cross Site Scripting Vulnerability is fixed, while adding User defined DNS name. (Refer: CVE-2019-11676)
      3. Support-4811677: Raw Search returned no data if search period is more than a month. This issue is fixed
    43. 12.3 Build 123223

      Issues Fixed:

      1. In the Inventory Snapshot page, the pie chart had a legend status color mismatch. This issue has been fixed.
      2. The XSS vulnerability issue in updateWidget API has now been fixed. (Refer: CVE-2018-19288)
    44. 12.3 Build 123222

      Issues Fixed:

      1. Security vulnerability: SQL injection vulnerability in Mail Server settings has been fixed. (Refer: CVE-2018-18949)
    45. 12.3 Build 123218

      New Log Format Supported:

      1. Barracuda Email Security Gateway

      New Features and Enhancements:

      1. Policy/Rule analysis, compliance report support and fetching configuration using firewall vendor API
        • Check Point devices
      2. Policy/Rule analysis, compliance report support and fetching configuration using CLI
        • Vyatta firewalls
        • Huawei firewalls
      3. Added 'Tray' Icon for Windows installation to start, stop, and get status of Firewall Analyzer.
      4. Changed 'Support' tab look and feel.
      5. New widgets 'Active VPN Users' and 'VPN User Session Details' are added under VPN tab of Inventory Device drill down page.
      6. Quick links and Help cards provided for Discovery and Search reports.
      7. Selected 'Time Period' retained in all drill down snapshot reports, after zooming the time in live traffic widget.
      8. Enterprise Edition data exchange between Admin and Collector servers made secure for each requests and response.
      9. Firewall Analyzer startup time optimized; Made the internal modules to start in parallel.
      10. 'Raw Settings' page moved to 'Search' tab from 'Settings' page to avoid shuffling between tabs.

      Issues Fixed:

      1. SQL Injection vulnerability in Firewall Analyzer default reports has been fixed. (Refer: CVE-2019-11678)
      2. Support ID: 4795348 - Change Management report for SonicWALL displays user names, who do not have access to firewall configuration. Fixed the issue.
      3. Cisco-Meraki log parsing issue fixed.
      4. Log parsing of Sophos and Cyberoam devices tuned to handle more log rate.
      5. Occasionally, 'Raw Tables' are not split properly, when log rate is high. Fixed the issue.
      6. In 'Rules Report' page, if the number of rows is less than 10, the CSV, Excel export option is missing. Fixed the issue.
      7. SNMP settings page is not closed automatically on successful configuration from 'Inventory' snapshot and list page.
      8. Fixed the issue of removing unnecessary API calls when criteria based 'Search' reports is loaded.
      9. Fixed the issue of table border misalignment for all the report table grids.
      10. Fixed the issue of headers for PaloAlto and NetScreen devices in 'Policy Overview' report by changing the 'Source Interface' & 'Destination Interface' headers to 'Source Zone' & 'Destination Zone'.
      11. When 'Only on Week Days' option is selected in 'Daily-Schedule', it was not working. This issue is fixed.
      12. 'Policy Overview' tab name changed.
      13. 'Unused Rule' header name changed.
      14. In 'Remote Host' option of 'Import Logs' page, the selected file is not getting marked. This issue is fixed.
      15. Fixed the issue of device name display in 'Live Traffic' widget even after the device is unselected.
      16. Fixed the issue of unrestricted 'Save' in 'Live Traffic' widget, if no device is selected.
      17. Fixed the issue of 'Icon' only option for horizontal menu change is not working in Central-Server.
      18. Fixed the issue of empty 'Standards' page, when the status of all firewall devices is 'UnManaged'.
      19. When 'Intranet Settings' is saved without any criteria, instead of alert message, it is getting saved. Fixed the issue to show alert message.
      20. In the 'Inventory - Device' detail widget, page redirection happens only when text is clicked. Fixed the issue for page redirection when clicked anywhere in the device row.
      21. Fixed the issue of missing 'On Demand' column header in 'Device Rule' settings page.
      22. Fixed the issue of missing tool tips for few icons.
      23. For Windows firewall, UDP port unblock rules added for Syslogs packets.
      24. For Windows firewall, TCP port unblock rules added for Telnet and SSH.
    46. 12.3 Build 123208


      • Menu hover feature helps to access all sub tab options without the hassle of navigation.
    47. 12.3 Build 123197

      New Device Supported:

      • F5 firewall device.

      New Features & Enhancements:

      • Horizontal menu bar made as default.
      • 'Add-Device' menu added to export Syslogs from firewalls.
      • SSH or Telnet based 'CLI terminal' to access firewalls from Firewall Analyzer.
      • 'Getting Started GUI' to guide the user to add devices and reports.
      • 'Quick links' and 'Help cards' for settings and report pages.
      • For trial and registered users, 'Live Chat' facility to contact sales-engineering team.
      • Introduced 'Password Policy' configuration for user management.
      • Login page customization for rebranding custom images.
      • In all report pages, optimized alignment of widgets.
      • Firewall Analyzer users can set their default menu bar (horizontal or vertical) using 'Menu Bar' menu.

      Issues Fixed:

      • Support ID: 4502293 - Fixed the issue of failure to fetch the device rule for Fortigate Vdom, because 'Pager' command was not working.
      • Support ID: 4502293 - Fixed the issue of failure to display of rule management reports for Vdom firewalls.
      • 'Select Policy' menu not working properly in Firefox browser. Fixed the issue.
      • Fixed the drill down issue in 'Dashboard - Security - Top N Attacks by Hits'.
      • Single device and all devices selection not working in 'Short summary' page of 'Inventory' device lists. Fixed the issue.
      • If the widget subtitle contains 'drill down link' - we need to provide the drill down/redirect to inventory action, when we click the link alone
      • In the 'Inventory - Short summary' page, 'Create Report/Alert Profile' tabs missing, navigating after add or edit from the 'Intranet, Exclude Host, Availability Alert' pages. Fixed the issue.
      • Minor UI enhancements in 'Inventory' page.
      • In the Firewall Analyzer - Distributed Edition - Admin Server, when a firewall was deleted, there was no processing message shown. Fixed the issue to show firewall delete processing message.
      • 'Delete widget' was not working in the 'Reports - Standard Report' page. Fixed the issue.
      • In the 'Inventory - Devices - Protocols' page, 'Protocol identifier' options were missing. Fixed the issue.
      • In the 'Active VPN Trend Report' page, Y-axis values were not displayed properly & was throwing NullPointerException while drill-down. Fixed these issues.
      • In the 'Device Rule, Exclude Criteria, Protocol Groups, Device Groups, Intranet Settings, Cloud-Repository, Exclude Hosts, SNMP settings, Alarm Profiles and User-IP Mapping (DHCP, AD/Proxy, Manual Mapping)' pages, to edit an entry you have to click on it. Now a proper 'Edit' icon is provided for each entry.
    48. 12.3 Build 123194


      • Firewall Analyzer now extends customization options to the login page. You can now choose to show/hide the copyrights and also change the background to an image of your choice.
    49. 12.3 Build 123182

      Issues Fixed:

      • When Alarm profile is exported, alarm profile created by other users is not available in the xml file. This issues is fixed to show all profiles.
      • When syslog is imported, the IP address of the device was updated with link-local IP. Now the device is added with local IP.
      • Device rule configured firewall is listed as first resource in drop down of configuration related reports. This issue is fixed.
      • In Policy Overview page, drill down on some of the services showed no data. This issue is fixed.
      • SMS Setting shows 'Not Configured', even after 'SMPP' or 'SMS Gateway (Clickatell)' is configured. This issue is fixed.
      • Unknown protocol report drill down showed sent and received as kilobytes (KB), where as it is in bytes. Changed the header to fix this issue.
      • When the Report Profile is edited, 'Run on Week Days' could not be selected. This issues is fixed.
      • If schedule for Search Report is created, it did not get added properly. The issue is fixed.
      • In the Device Detail page, executed report profile details are not displayed. The issue is fixed.
      • Support ID: 4594278 - Raw Search result page sorting not working. Fixed the issue.
      • When Working Hour is configured, ranges like 8-12,15-18,19,20,21 were not allowed. The issue is fixed.
      • Assigning Credential Profile without selecting a profile was not throwing any error. This issue is fixed.
      • If only Traffic Log is selected, raw search was not allowed. Fixed the issue.
      • In Standards > Edit Settings page, after editing when Save button is clicked, page refreshes and goes to different device. This is fixed.
      • In the Inventory snapshot page, device edit slide comes over user settings page.This issues is fixed.
      • 'All device' option for 'operator' user in Snapshot page has been removed.
      • In the Collector list page, if any action is performed, the page will be refreshed automatically.
      • In the Inventory > Users list page, 'username' search was not working. This issue is fixed.
      • In the Alarms page of Operator user, Close icon-title is not shown properly on hover. This issue is fixed.
      • Free license text is removed from the DE Alert image.
      • For 'Operator' user, Support page icon was not working. Fixed the issue.
    50. 12.3 Build 123179

      Issues Fixed:

      • Previously, the upgradation to build 123158 and above caused network interruptions in Windows 7 & 2008 R2. The issue is fixed now.
    51. 12.3 Build 123177

      Enhancements :

      • Support - 4709829: Added SSH protocol to fetch WatchGuard firewall configuration.
      • In Anomaly alert criteria page, a help message 'CIDR and CSV formats are allowed' has been added to Source and Destination fields.
      • When Report Profiles are created, removed unnecessary API call to improve UI performance.
      • In Cloud Services page of Inventory, 'Add repository' option is provided.

      Issues Fixed:

      • Support - 4669580: SNMP based Live Report of PaloAlto devices was not working properly. This issue is fixed.
      • Local File Inclusion vulnerability is fixed.
      • Device drill down from Policy Optimization page of Dashboard was not working. The issues is fixed and redirected to Optimization page.
      • In Firewall Live Traffic widget of Inventory page, when 'Gbps' is selected as unit, the values shown were not accurate. The issue is fixed to plot the graph with granular values.
      • Alarm Profile notification option 'Run As Script' didn't accept arguments. The issue is fixed.
      • Support - 4623647: In Import Log page, Local Schedule option was not shown even when the client can be accessed from localhost.
      • Support - 4697639: In Fortigate syslog, VPN close log has duplicate entry which led to incorrect data. Handled it to fix the issue.
      • Support - 4723997: Traffic Trend Report graph was not plotted in order. This issue is fixed
      • Support - 4732194: Syslog port details were not shown properly in Device Details Page of Settings tab. The issue is fixed
      • Support - 4566694 : When a PaloAlto Rule Name contains 'index' value, wrong unused rule list is displayed. The issue is fixed.
      • Support - 4707871: Checkpoint VPN log parsing issue is fixed.
      • In MSSQL setup, Yearly table drop was not proper. The issue is fixed.
      • When extra device license was applied in the product, the manage and unmanage actions couldn't be performed till user restarts the product. This issue is fixed.
      • Header of SMS notification in Alert Profile page changed from 'Send Email based SMS' to 'Send SMS' to avoid misunderstanding.
      • In the Report Profile Notification page, a message "Use comma ',' separator for multiple mail ids" has been added for clear understanding.
      • Edit and Save Report Profile action returned wrong status message. The issue is fixed to show proper status message.
      • While saving Compliance Report Schedule, there was no status message. This issue is fixed to show the status message.
    52. 12.3 Build 123169

      Issues Fixed:

      • Security vulnerability: Cross site scripting(XSS) and arbitrary file read vulnerability in Fail Over has been fixed. (Refer: CVE-2018-12997CVE-2018-12998)
    53. 12.3 Build 123164

      New device supported:

      • MikroTik

      New features:

      • Simulate firewall logs - You can simulate firewall logs for different vendors to check all the reports in Firewall Analyzer. Log simulation is available for Fortigate, PaloAlto, CheckPoint, Juniper SRX and Squid Proxy devices.


      • Added more than 3000 websites to the Cloud Repository.
      • Option to plot Dashboard Live traffic graph in 'Kbps/Mbps/Gbps' is available.
      • Support ID: 4598454 - Updated IP to Country database.
      • Support ID: 4573349 - When you import syslog, you can map the logs to the existing device.
      • Support ID: 4590527 - Export to CSV format option is available for expanded view of all 'Inventory' page widgets.
      • 'Admin Report' for PaloAlto available. It covers details of user login, log out, and commands executed.
      • Auto refresh option provide to 'Live Syslog Viewer' page.
      • Mail content format enhanced for scheduled 'Standards' report.
      • Additional tabs Bandwidth, Sites, Apps, and VPN are added in 'Device' inventory snapshot page for better access.
      • License count, number of managed devices and remaining devices count now available under ' License Management' page.
      • Now 'bps' value is formatted to readable format in Bandwidth Alert mail content.

      Issues Fixed:

      • Support ID: 4588018 - While creating Alarm profile, configuring more than 50 criteria makes the page unresponsive. This issue is now fixed.
      • Refresh option in 'Dashboard Live Traffic' widget was not working. Now the issue is resolved.
      • AD User-IP Mapping had two entry for an user with Old and New IP. The duplication issue is rectified now.
      • Support ID: 4579510 - Incorrect Rule Name was shown for Zyxel firewall. This issue is now fixed.
      • Support ID: 4480507 - Invalid Byte Sequence Error while loading FirewallRecords table is fixed.
      • While parsing Sonicwall configuration, network objects with IP-range and IPv6 objects were not handled properly. It is fixed now.
      • Finding 'Unused Objects' from configuration file had discrepancy. Now it is rectified.
      • In Japanese Installation, when logs are imported, reports were generated for current time instead of log time. This issue is resolved.
      • 'Edit Interface' & 'Edit Interface Names' were not working, when edited for the second time. This issue is now fixed.
      • Occasionally, the 'Inventory' page became empty when 'Back' icon was clicked. This issue is now resolved.
      • Even after changing display name of Firewall, ' Resource Name' was displayed when user was added from User Management page. Now the issue is fixed to show the device list with display name while assigning device.
      • When Credential Profile was edited, the 'Email' field became empty. Now the issue is fixed to show the given Email Id in that field.
    54. 12.3 Build 123156
      • License Agreement has been updated.
      • Promotions related to ITOM Events will be displayed in the UI header after login.
    55. 12.3 Build 123151

      Issues Fixed:

      • In Group Chat Module, "Operator" user was not restricted from viewing the list of users, their User ID and Email addresses. This issue has been fixed.
      • EncryptPassword.bat has been removed due to DOS attack.
      • Path Traversal vulnerability in uploadMib API has been fixed (Reported by Pulse Security).
    56. 12.3 Build 123137

      New features:

      • Introduced 'Audit Report' for all add, delete, and update actions done by Firewall Analyzer user. All the user actions are logged.
      • Option to search personal information like Email, phone number and user name across the product and replace them with another user is available under 'Privacy Settings'


      • 'Security Audit Report' is now available in PDF format. You can export the report in PDF format from client.
      • Disclaimer added in exported PDF & CSV to convey availability of Personally Identifiable Information (PII) of GDPR.

      Issues Fixed:

      • Option to add new Custom Report was not visible in UI. Now the issue is fixed.
    57. 12.3 Build 123129
      • Path Traversal vulnerability in uploadMib API has been fixed.
      • The RemodeCodeExecution(RCE) vulnerability occurring while testing scripts has been fixed.
      • The SQL injection vulnerability in "FailOverHelperServlet" for the operation 'standbyprobestatus' has been fixed.
      • The SQL injection vulnerability in "FailOverHelperServlet" for the operation 'getprobenetworkshare' has been fixed.
      • In Group Chat Module, "Operator" user was not restricted from viewing the list of users, their User ID and Email addresses. This issue has been fixed.
      • Previously, "Operator" user was not restricted from viewing the URL monitors in the Inventory Page. This issue has been fixed.
      • Previously, "Operator" user was not restricted from being able to modify the background color and the tile color in the 3D floor view page. This issue has been fixed.
    58. 12.3 Build 123126

      Admin Server

      • Enterprise edition for 12.3 version
      • Data Migration tool for enterprise edition 8.5 customers to upgrade to 12.3

      Standalone/Collector Server

      • Compliance reports and Policy/Rule Management support for WatchGuard device
      • Compliance reports and Policy/Rule Management support for SonicWALL device.
      • Policy/Rule re-order report for PaloAlto device
    59. 12.3 Build 123092


      • Default reports enhanced with drill down option to second and third level. Particularly for 'Unknown Protocols', you can drill down up to raw log level.
      • 'End User' feature moved to 'Firewall Inventory' tab. You can get 'End User' details from 'Users' Tab.
      • 'Rule Management' and 'Compliance Reports' files stored in Firewall Analyzer server directory are encrypted now.
      • User information is encrypted at the database storage.
      • 'CSV Export' option is available for 'Rule Management' reports.
      • 'Scheduled Report' mail format is enhanced to show properly aligned mail content.
      • Support - 4458020: In 'Change Management' report, new column has been added to show the IP address of user from which he did configuration changes.
      • Support - 4429668: 'Admin' report is available for Huawei Firewall. You can view user login, logout and command executed reports.

      Issues Fixed

      • Support - 4477638: Fixed the issue of incorrect data shown in 'Policy Optimization reports' for some PaloAlto devices.
      • Support - 4519337: Fixed the issue of not fetching configuration files from SonicWALL firewalls due to incorrect SCP command.
      • Support - 4497009: Fixed issues in 'Denied Events' and URL log parsing for Juniper SRX devices.
      • Support - 4510780: Fixed the issue of wrong time period shown in i-Filter reports data, due to non-processing of time stamp available in the logs.
      • Support - 4496764: Fixed the issue of mismatch in rules count of unused rules and total rules displayed for some PaloAlto firewalls.
      • Issue - 126991: In PaloAlto firewall 'Policy Overview' page, no data was displayed when clicked on some source and destination objects. This issue is fixed.
      • Fixed the issue of no data display in 'Total Bytes' column in Trend Micro device reports, due to non-processing of byte value available in the logs.
    60. 12.3 Build 123083


      • Dashboard loading has been revamped and optimized for better performance.
      • In the Login page, iPhone/Android and iPad application download links have been included.
      • License expiry information in header had a few alignment issues. This has now been fixed.
      • User Icon with product details and about information has been moved to right top corner.
      • In the Inventory page, product based tabs have been moved horizontally.
      • Sign out option has been moved from Quick links to User details menu.
      • Support icon has been added for (Mail, Apply license, phone number, SIF, User guide, Videos, Service pack, ThreadDump, DB Query & view Logs) links.
      • In support page, the Query page under DB Query will be opened in a new window without ember.
    61. 12.3 Build 123064


      • Provision to configure each device in the Inventory itself. For a single device, you can configure Report, Alert, Device Rule, and SNMP in one place.
      • Ad-hoc reports are listed in the drill down page of 'Device' under Inventory.
      • 'Device' summary widget under Inventory, is enhanced to show more device configuration options.
      • Cloud Control Repository updated and new services added.
      • 'No Data' message will be displayed in widget header, if a widget has no data to display. If the widget has data, total number of rows will be displayed.
      • Reduced the 'Inventory' page loading time.
      • By default, indexing enabled for Security Logs.
      • Support Id: 4400799 - New widget added under drill down page of 'Cloud Control'. The widget shows all source IP addresses, who accessed the corresponding 'Cloud' service.

      Issues Fixed

      • Support Id: 4223153 - Bandwidth Alert profiles created with criteria 'mbps' were not working. This issue is fixed.
      • Support Id: 4223153 - URL report, date and priority parsing issues of pfSense firewall is fixed.
      • Support Id: 4275699 - When one Juniper SRX device was added it was displayed as two devices. This was due to absence of firewall name in some syslogs. This issue is fixed to show it as a one device.
      • Issue Id: 124479 - Earlier user couldn't edit the report filter while creating 'Report Profile'. Now 'Edit' option provided for the report filters to fix the issue.
      • Issue Id:126112 - After selecting custom time period in 'Inventory' drill down page, the end time was not shown properly. This issue is fixed.
      • Issue Id:126077 - In 'Add Credential Profile' page, 'Device Type' option is moved up near 'Protocol' for better accessibility.
      • Issue Id:126332 - In 'Device Rule' list page, sorting of any column, removed 'Fetch Rules' and 'Security Audit Report' icons. This issue is fixed.
    62. 12.3 Build 123057

      Vulnerability fixes

      • DDI-VRT-2018-02 – Unauthenticated Blind SQL Injection via /servlets/RegisterAgent
      • DDI-VRT-2018-03 – Unauthenticated Blind SQL Injection via /servlets/StatusUpdateServlet and /servlets/AgentActionServlet
      • DDI-VRT-2018-04 – Multiple Unauthenticated Blind SQL Injections via /embedWidget
      • DDI-VRT-2018-05 – Unauthenticated XML External Entity Injection via /SNMPDiscoveryURL
      • DDI-VRT-2018-06 – Unauthenticated Blind SQL Injection via /unauthenticatedservlets/ELARequestHandler and /unauthenticatedservlets/NPMRequestHandler
      • DDI-VRT-2018-07 – User Enumeration via /servlets/ConfServlet.
    63. 12.3 Build 123052

      Issues Fixed

      • Issue: The possibility to fetch user details through ConfServlet has been fixed and is secured now.
    64. 12.3 Build 123045

      New device/log format support

      • Support Id: 4385377 - i-Filter Version10 device logs support


      • System settings (General and logging) page added for Firewall Analyzer module to enhance the customization
      • Drill-down, from graph, for all reports along with table values
      • Labels for the reports graph for X and Y axis are shown
      • Custom time period has been shown properly in Inventory, Reports, Standards and End-Users reports based on earlier time selection
      • Inventory snapshot start-time and end-time shown for all time periods under clock icon
      • Filter option provided for source in live Syslog viewer

      Issues Fixed

      • Issue Id: 122137 - Missed internationalization keys in Compliance Standard Reports fixed.
      • Issue Id: 123950 - Non-internationalized Total & other key are internationalized in Firewall reports.
      • Issue Id: 125439 - Disabling VDOM in User Config option deletes all device rules configured.
      • Issue Id: 125440 - Newly supported 'Device Rule Vendor' list added in Credential Profile page.
      • Issue Id: 121670 - Log Level debug settings for logger-name not handled.
      • Issue Id: 125070 - Graph Unit is not internationalized in snapshot widget header.
      • Issue Id: 123955 - 'No Data' string in some graph is not internationalized.
      • Issue Id: 123859 - Live Report drill-down didn't pass proper time-range.
      • Issue Id: 125582 - While sorting the column in table data leads to table empty in Traffic Trend report.
      • Issue Id: 125598 - Getting 'NullPointerException' in weekly trend comparison reports page.
      • Issue Id: 125456 - Getting 'NullPointerException' while parsing SonicWall logs.
      • Support Id: 4343907 - Data movement to data tables isn't working due to large duration value in few Syslogs in SonicWALL device.
    65. 12.3 Build 123027


      • The 'Automatic/On-click/No lookup' options of Resolve DNS in global settings synchronized for all widgets.
      • Two more SMS service Clickatell and AppSMS supported to send SMS notifications for 'Alarms, Configuration changes, and Availability Alerts'

      Issues Fixed

      • 123396 - If dashboard data is with '\', in its drilldown page data is shown without '\' . The issue is resolved to display it properly.
      • 121669 - When Traffic Conversation Table in Interface drilldown page is expanded, it was displaying only top 10 rows. Issue fixed to display complete data.
      • 123760 - In CCTV view, Operator can view unauthorized device's Live Traffic. Issue is fixed by hiding it.
      • 122774 - In one of the 'Proxy Reports', when Search icon is clicked, empty page was displayed. Issue fixed to display appropriate page.
      • 123955 - 'No Data' message not internationalized in some graphs, issue fixed by internationalizing it.
      • 122298 - In dashboard traffic and security statistics report, when Search icon is clicked, empty page was displayed. Issue fixed to display appropriate page.
      • 124212 - 'In' & 'Out' legends in Device Summary graph were not internationalized, issue fixed by internationalizing it.
      • 121712 - Fixed memory handling issue, during user association and manual IP mapping when device is deleted.
      • 123826 - Fixed an issue in reimport option of manual IP mapping.
      • 120736 - Fixed issues in FWA Availability alert page UI and Disable notification link in the alert notification mail
      • 122140 - Fixed an issue in script error handling, when a schedule is added for Compliance report without selecting any type of standards.
      • 125095 - In standard compliance reports, if clicked to drill down the report, the table values are not displayed. Fixed the issue for table value display.
      • 125093 - User with '\' character could not be added, for 'End Users' reports. Fixed the issue to add user.
      • 123942 - There was an UI alignment issue in NetFlow widget populated in OpManager's End Users report. Fixed the issue to align the UI.
      • 122493 - In the dashboard, snapshot view of Cloud Users report, fixed the issue of missing 'Expand View' icon.
      • 124899 - Fixed the issue in Disable notification option of the change management alert notification mail.
      • 124613 - When TLS option was configured in Mail Server settings, mail notifications for alerts were not sent. Fixed the issue to send mails.
      • 124090 - Fixed the misalignment issue in Policy Overview report table. This was for MS SQL database.
      • 122970 - When a new report type is added with the existing name, 'Success' message is displayed. Fixed the issue to display 'Failed' message.
      • 125067 - Fixed the issue to populate rule details of SRX devices, when the configuration file is not having network object details.
      • 125059 - In the 'Unused Rules' report of 'Rule Management', the resource criteria is not applied properly. Fixed the issue to apply the resource criteria properly.
      • 4245966 - In FWA, log entries for unsuccessful console login attempt on Cisco ASA devices are not there. Fixed the issue to get entries.
      • 4206352 - Issue, in SonicWALL log parsing for protocol, is fixed.
      • 4086698 - All the IPs are not getting resolved into names, when 'Resolve DNS' is set to 'Automatic'. Fixed the issue to resolve all IPs.
      • 4250080 - When scheduled PDF report page count is more than 100, the total page count in PDF footer was not proper. Fixed the issue for proper page count.
      • 4300246 - Fixed the out of memory error generated when change management report was accessed.
    66. 12.3 Build 123008

      Issues Fixed

      • Device rule configuration using SCP protocol was not functioning in build 12300. Now this issue is fixed.
      • Sometimes, SRX marked as unsupported device, if Firewall Analyzer receives unsupported log as the very first record. Now, wait time is added to check more received logs to avoid unparsed error.
      • System performance and custom dashboard view were missing when logged in for the first time. Now the issue is fixed and the user can view both.
      • Editing widget "Top N Hosts by Traffic" and selecting Protocol under category makes the widget to show data of protocol-group by traffic. Now, the issue is fixed by showing Protocol-Group instead of Protocol in dashboard widget - edit section.
      • 'Live Syslog Viewer' status shown as 'undefined' when we do continuous refresh. Now the status message handling issue is fixed in the server side to show proper status in the UI for continuous refresh.
      • Increased the data dumb volume from base table 'Firewall Records' to next level data table for database performance increase.
      • Inventory Interface snapshot traffic conversation report's last row was not shown properly in UI. Now the issue is fixed and the report loads the data properly.
      • Graph units option provided in the Inventory LiveReports page was not in proper sequence. This is issue is fixed and the units are now shown in proper order like kbps,mbps and gbps.
      • When the user selects all predefined reports while creating a report profile, received PDF shows all the reports name in the home page without proper alignment. Now, Alert Message added for Report Profile reports selection

      New Features

      • Previously, there was no option to view the selected time-period of each dashboard widgets. Now, sub-header details will be shown in each widgets with device information along with time-period applied.
    67. 12.3 Build 12300

      New Devices/Log Formats Supported

      • Trend Micro IWSVA 6.5
      • Palo Alto VPN logs
      • FortiGate Management logs
      • Juniper SRX Management logs
      • SonicWall IPSec VPN logs
      • New easy to use revamped web client

      New Features

      • 'Insider Threat' reports to track internal user's cloud application usage
      • Drill down for all dashboard reports
      • Exclude IP/IP range/network from reporting
      • URL and VPN reports for Inventory report user drill down
      • Live report for Proxy servers
      • Live report drill down for device and interfaces from Inventory
      • Interface Live Traffic widgets in Custom Dashboard
      • End User widgets in Custom Dashboard
      • Anomaly Alerts based on Country
      • User specific reports for Proxy servers
      • Option to export report as CSV on demand
      • Option to use Management IP address to fetch device configuration
      • Option to configure 'Row Count' for on-demand PDF/CSV report export
      • More reports for Rules in Device snapshot
    68. 12.2 Build 12200

      12.2 - Build 12200 - Standalone Edition

      The general features available in this release are:

      New Features

      • Firewall Analyzer is integrated with OpManager
      • New easy to use revamped web client
      • Schedule option for Interface live report

      New Device/Logs/Reports

      • WebMarshal Proxy Server
      • Juniper-SRX - VDOM logs support
      • McAfee - SideWinder Firewall
      • i-Filter Proxy Server
      • PfSense open source firewall
  • System Requirements
    1. Platform Requirements

      Hardware Platform

      • 1GHz Pentium Dual Core processor or equivalent
      • 2 GB of RAM
      • 5 GB of disk space
      • Monitor that supports 1024x768 resolution

      Please refer our web site for recommended system requirements

      Software Platform


      • Windows 8
      • Windows 7
      • Windows NT
      • Windows 2000
      • Windows XP
      • Windows Vista
      • Windows 2000 Server
      • Windows 2003 Server
      • Windows 2008 Server
      • Windows 2012 Server
      • Windows 2016 Server


      • Ubuntu
      • Fedora
      • OpenSuSE
      • CentOS
      • Red Hat RHEL
      • Mandrake
      • Mandriva
      • Debian


    2. Web Browser Requirements
      • Internet Explorer 8 and later
      • Firefox 4 and later
      • Chrome 8 and later
  • Installation
    1. Installing and Uninstalling

      This section explains the key steps for installing Firewall Analyzer. Refer the User Guide for detailed Firewall Analyzer installation information.

      Installing on Windows

      • Double-click the ManageEngine_OpManager_FireWall.exe or ManageEngine_OpManager_FireWall_64bit.exe file to launch setup program

      Uninstalling from Windows

      • Click on Start > Programs > ManageEngine Firewall Analyzer x > Uninstall Firewall Analyzer to uninstall Firewall Analyzer from the machine.

      Installing on Linux

      • Assign execute permission to the ManageEngine_FireWallAnalyzer.bin or ManageEngine_FireWallAnalyzer_64bit.bin file using the following command:
        chmod a+x ManageEngine_FireWallAnalyzer.bin or ManageEngine_FireWallAnalyzer_64bit.bin
      • Execute the following command:
        ./ManageEngine_FireWallAnalyzer.bin or

        Note: If you get an error message stating that the temp directory does not have enough space, try executing this command with the -is:tempdir <directory_name> option (where <directory_name> is the absolute path of an existing directory)
        ./ManageEngine_Firewall_Analyzer_x_linux.bin -is:tempdir <directory_name>

      • Follow the instructions in the setup program.

      Uninstalling from Linux

      • Navigate to the <Firewall Analyzer Home>/server/_uninst directory.
      • Execute the command:
      • You will be asked to confirm your choice, after which Firewall Analyzer is uninstalled.
    2. Default ports used by Firewall Analyzer

      The following are the default ports used by Firewall Analyzer:

      Web Server port (to access from a web browser): 8500 (TCP)

      Firewall Listener port (to direct firewall, proxy logs): 514, 1514 (UDP)

      PostgreSQL port (to connect to the built-in PostgreSQL database): 33336 (TCP)

  • Starting and Shutting Down

    Starting in Windows

    1. Click on Start > Programs > ManageEngine Firewall Analyzer x > Firewall Analyzer to start the server.
      Alternatively you can navigate to the <Firewall Analyzer Home>\bin folder, and invoke the run.bat file.
    2. Once the server has successfully started, you can either use the Start WebClient tray-icon option or alternatively open a web browser and type the URL, http://<hostname>:8500
      (replace <hostname> with the name of the machine on which Firewall Analyzer is installed, and 8500 with the web server port specified during installation).

    Shutting Down from Windows

    1. Click on Start > Programs > ManageEngine Firewall Analyzer x > Shutdown Firewall Analyzer to shut down the server. Alternatively you can navigate to the <Firewall Analyzer Home>\bin folder, and invoke the shutdown.bat file. As already mentioned, you can also make use of the tray-icon option Shutdown Server

    Starting in Linux

    1. Navigate to the <Firewall Analyzer Home>/bin directory and execute the file to start the Firewall Analyzer server.
    2. >
    3. Once the server has successfully started, open a web browser and type the URL, http://<hostname>:8500 (replace <hostname> with the name of the machine on which Firewall Analyzer is installed, and 8500 with the web server port specified during installation)

    Shutting down from Linux

    1. Navigate to the <Firewall Analyzer Home>/bin directory, and execute the file to shut down the server.
  • Document Set

    The documentation set for this product includes:

    • This README.html - version enhancements, basic installation, known issues, release notes Online
    • Help - Context-sensitive help screens that provide guidance for performing a task
    • User Guide - Includes a product overview, and sections such as frequently asked questions, troubleshooting tips, etc.
  • Contact Information

    Technical Support:
    Web site: |
    Toll-free: +1 888 720 9500

    Firewall Analyzer licenses usually include the right to patches, service packs, and minor upgrades apart from technical support for one (1) year from the date of purchase. After the first year, Maintenance must be renewed on an annual basis.

  • About ZOHO Corp®

    Enabling Management Your WayTM

    ZOHO Corp. provides affordable software in the areas of network applications and database tools. With a broad product portfolio and an active customer base ranging from enterprises, equipment vendors and service providers, ZOHO Corp. has emerged as a very affordable and high-quality alternative to expensive software that is common in the industry. ZOHO Corp. is headquartered in Pleasanton, CA with offices in NJ, MA, India, UK, China and Japan and has a well-trained partner base around the globe.

    Visit us at

    Copyright © 2018, ZOHO Corp. All rights reserved.

    ZOHO Corp., ManageEngine, Enabling Management Your Way are trademarks of ZOHO Corp. All other trademarks are the property of their respective owners.

  • License Agreement


    1. Your Acceptance of the Terms of Sale

    Thank you for visiting the Zoho Corporation Private Limited ("we" or "Zoho") website, (the "Website"). This document ("Terms of Sale") is a legal agreement between you or the entity that you represent ("you") and Zoho, and governs your download and purchase of ManageEngine software products from the Website.


    2. Purpose:

    The purpose and intent of this Website is to provide information on software products (the "Software") that we make available for download and purchase through the Website.

    3. Download of Evaluation Version:

    We offer the Software for download on a free trial basis pursuant to an Evaluation License as set out in our End-User License Agreement set forth below ("EULA"). Your use of the copy of the evaluation version of the Software is subject to the applicable terms and conditions of the EULA.

    4. Purchase of Commercial Licenses:

    After the expiration of the evaluation period, you may obtain through the Website a Commercial License of the Software pursuant to the Annual Subscription, Perpetual, or if applicable, the Free Edition, as set out in the EULA. Your use of the copy of the Software is subject to the applicable terms and conditions of the EULA.

    Our authorized U.S. reseller, Zoho Corporation ("Distributor"), is responsible for sales of Commercial Licenses within the U.S. region. Your purchase of a Commercial License within the U.S. region is subject to any pricing or any special terms of sale that may be agreed between you and Distributor. You are responsible for providing Distributor with a valid credit card number or other acceptable means of payment to secure payment. Distributor reserves the right to cancel any order if the credit card number you provide is not valid.


    THE following terms constitute a binding agreement between you and Zoho with respect to use of ManageEngine Firewall Analyzer ("Licensed Software")


    Zoho Corporation Private Limited ("Zoho") grants to you a non-exclusive, non-transferable, Evaluation License for trial and evaluation of the Licensed software, in binary object code form, for a period of thirty (30) days from the date of download or installation. This License begins upon downloading or installing the Licensed Software and ends thirty (30) days thereafter ("Evaluation Period").

    If you are not willing to use the Licensed Software, either the Free Edition or the Professional/Premium/Distributed Edition, after the Evaluation Period, delete all the copies installed in your computer with immediate effect. You are forbidden from using the Licensed Software for any other use or otherwise offering it for resale under the terms of this Section 1. Zoho retains all rights not specifically granted to you herein.


    Annual Subscription License: As part of your choosing annual subscription license, Zoho grants you a fee-bearing, nonexclusive, non-transferable, world-wide license to Use the Licensed Software including user documentation, updates and upgrades to which you are entitled as well as any plug-ins provided to you during the period of your subscription, provided that such access and Use of the Licensed Software is in accordance with the Single Installation License granted by Zoho. Under the Subscription License, the Licensed Software is licensed only for a subscription period of one year. You must renew your license at least 10 days before the expiry of the subscription period in order to continue using the Licensed Software. If you do not renew the license, you agree to stop using the Licensed Software after end of the subscription period and remove the Licensed Software from your systems

    Perpetual License: As part of your choosing perpetual license, Zoho grants you a fee-bearing, nonexclusive, non-transferable, perpetual, world-wide license to Use the Licensed Software including user documentation, updates and upgrades to which you are entitled as well as any plug-ins provided to you, provided that such access and Use of the Licensed Software is in accordance with the Single Installation License granted by Zoho.

    "Use" means storing, locating, installing, executing or displaying the Licensed Software according to the license procured by you.

    "Single Installation License" means that the license key provided shall not be used for more than one concurrent Use of the Licensed Software.


    The Licensed Software may contain software which originated with third party vendors and without limiting the general applicability of the other provisions of this Agreement, you agree that (a) the title to any third party software incorporated in the Licensed Software shall remain with the third party which supplied the same; and (b) you will not distribute any such third party software available with the Licensed Software, in any manner.


    In addition to all other terms and conditions of this Agreement, you shall not: (i) install one copy of the Licensed Software on more than one CPU; (ii) remove any copyright, trademark or other proprietary notices from the Licensed Software or its copies; (iii) make any copies except for one back-up or archival copy, for temporary emergency purpose; (iv) rent, lease, license, sublicense or distribute the Licensed Software or any portions of it on a standalone basis or as part of your application; (v) modify or enhance the Licensed Software; (vi) use the Licensed Software in a computer-based services business or publicly display visual output of the Licensed Software or use the Licensed Software for the benefit of any other person or entity; (vii) reverse engineer, decompile or disassemble the Licensed Software; or (viii) allow any third parties to access, use or support the Licensed Software.


    As part of subscription license, Zoho provides support that includes email support for problem reporting, product updates, upgrades and online access to product documentation at no additional cost for the period of subscription. Technical Support is not included as part of perpetual license. You may purchase technical support services for perpetual license by paying the then current maintenance and support fee.


    ZOHO collects details pertaining to your usage of the Licensed Software such as the license details, type of installation, configuration of database, configuration of data storage, configuration of the system in which the Licensed Software is installed, statistics pertaining to the total number of devices and total number of events handled, top pages visited, and frequency of use of the various features of the Licensed Software. ZOHO agrees to furnish the data collected regarding your usage of the Licensed Software upon request by you. You understand and acknowledge that collection of Usage Details is enabled by default and that it needs to be disabled through the Licensed Software's user interface if you do not wish to allow ZOHO to collect Usage Details.


    Zoho owns all right, title and interest in and to the Licensed Software. Zoho expressly reserves all rights not granted to you herein, notwithstanding the right to discontinue or not to release any Licensed Software and to alter prices, features, specifications, capabilities, functions, licensing terms, release dates, general availability or characteristics of the Licensed Software. The Licensed Software is only licensed and not sold to you by Zoho.

    8. AUDIT:

    Zoho has the right to audit your Use of the Licensed Software by providing at least seven (7) days prior written notice of its intention to conduct such an audit at your facilities during normal business hours.


    The Licensed Software contains proprietary information of Zoho that are protected by the laws of the United States and you hereby agree to take all reasonable efforts to maintain the confidentiality of the Licensed Software. You agree to reasonably communicate the terms and conditions of this Agreement to those persons employed by you who come into contact with or access the Licensed Software, and to use reasonable efforts to ensure their compliance with such terms and conditions, including but not limited to, not knowingly permitting such persons to use any portion of the Licensed Software for a purpose that is not allowed under this Agreement.


    Zoho does not warrant that the Licensed Software will be error-free. Except as provided herein, the Licensed Software is furnished "as is" without warranty of any kind, including the warranties of merchantability and fitness for a particular purpose and without warranty as to the performance or results you may obtain by using the Licensed Software. You are solely responsible for determining the appropriateness of using the Licensed Software and assume all risks associated with the use of it, including but not limited to the risks of program errors, damage to or loss of data, programs or equipment, and unavailability or interruption of operations.


    In no event will Zoho be liable to you or any third party for any special, incidental, indirect, punitive or exemplary or consequential damages, or damages for loss of business, loss of profits, business interruption, or loss of business information arising out of the use or inability to use the program or for any claim by any other party even if Zoho has been advised of the possibility of such damages. Zoho's entire liability with respect to its obligations under this agreement or otherwise with respect to the Licensed Software shall not exceed the amount of the license fee paid by you for the Licensed Software.


    Zoho agree to indemnify and defend you from and against any and all claims, actions or proceedings, arising out of any claim that the Licensed Software infringes or violates any valid U.S. patent, copyright or trade secret right of any third party; so long as you provide; (i) prompt written notice to Zoho of such claim; (ii) cooperate with Zoho in the defense and/or settlement thereof, at Zoho's expense; and, (iii) allow Zoho to control the defense and all related settlement negotiations. The above is Zoho's sole obligation to you and shall be your sole and exclusive remedy pursuant to this Agreement for intellectual property infringement.

    Zoho shall have no indemnity obligation for claims of infringement to the extent resulting or alleged to result from (i) any combination, operation, or use of the Licensed software with any programs or equipment not supplied by Zoho; (ii) any modification of the Licensed Software by a party other than Zoho; and (iii) your failure, within a reasonable time frame, to implement any replacement or modification of Licensed Software provided by Zoho.


    This Agreement is effective until terminated by either party. You may terminate this Agreement at any time by destroying or returning to Zoho all copies of the Licensed Software in your possession. Zoho may terminate this Agreement for any reason, including but not limited to your breach of any of the terms of this Agreement. Upon termination, you shall destroy or return to Zoho all copies of the Licensed Software and certify in writing that all know copies have been destroyed. All provisions relating to confidentiality, proprietary rights, non-disclosure, and limitation of liability shall survive the termination of this Agreement.

    14. GENERAL:

    If you are a resident of the United States or Canada, this Agreement shall be governed by and interpreted in all respects by the laws of the State of California, without reference to conflict of laws' principles, as such laws are applied to agreements entered into and to be performed entirely within California between California residents. If you are a resident of any other country, this Agreement shall be governed by and interpreted in all respects by the laws of the Republic of India without reference to conflict of laws' principles, as such laws are applied to agreements entered into and to be performed entirely within the Republic of India between residents of the Republic of India. If you are a resident of the United States or Canada, you agree to submit to the personal jurisdiction of the courts in the Northern District of California. If you are a resident of any other country, you agree to submit to the personal jurisdiction of the courts in Chennai, India. This Agreement constitutes the entire agreement between the parties, and supersedes all prior communications, understandings or agreements between the parties. Any waiver or modification of this Agreement shall only be effective if it is in writing and signed by both parties hereto. If any part of this Agreement is found invalid or unenforceable, the remainder shall be interpreted so as to reasonable effect the intention of the parties. You shall not export the Licensed Software or your application containing the Licensed Software except in compliance with United States export regulations and applicable laws and regulations.


A single platter for comprehensive Network Security Device Management