Firewall Analyzer Release Notes

Listed here are the feature enhancements, bug fixes and limitations of each release update of Firewall Analyzer.

  • About Firewall Analyzer

    Firewall Analyzer is an easy-to-use, web-based tool that provides in-depth analysis of incoming and outgoing network activity through firewalls, VPNs, and proxy servers. Firewall Analyzer analyzes these logs and generates useful reports on bandwidth usage, user trends, detect anomalies, and firewall activity.

    Such information helps IT administrators manage their enterprise networks pro actively and also accelerates the troubleshooting process.

  • Release Overview
    1. 12.3 Build 123182

      Issue fixed:

      • When Alarm profile is exported, alarm profile created by other users is not available in the xml file. This issues is fixed to show all profiles.
      • When syslog is imported, the IP address of the device was updated with link-local IP. Now the device is added with local IP.
      • Device rule configured firewall is listed as first resource in drop down of configuration related reports. This issue is fixed.
      • In Policy Overview page, drill down on some of the services showed no data. This issue is fixed.
      • SMS Setting shows 'Not Configured', even after 'SMPP' or 'SMS Gateway (Clickatell)' is configured. This issue is fixed.
      • Unknown protocol report drill down showed sent and received as kilobytes (KB), where as it is in bytes. Changed the header to fix this issue.
      • When the Report Profile is edited, 'Run on Week Days' could not be selected. This issues is fixed.
      • If schedule for Search Report is created, it did not get added properly. The issue is fixed.
      • In the Device Detail page, executed report profile details are not displayed. The issue is fixed.
      • Support ID: 4594278 - Raw Search result page sorting not working. Fixed the issue.
      • When Working Hour is configured, ranges like 8-12,15-18,19,20,21 were not allowed. The issue is fixed.
      • Assigning Credential Profile without selecting a profile was not throwing any error. This issue is fixed.
      • If only Traffic Log is selected, raw search was not allowed. Fixed the issue.
      • In Standards > Edit Settings page, after editing when Save button is clicked, page refreshes and goes to different device. This is fixed.
      • In the Inventory snapshot page, device edit slide comes over user settings page.This issues is fixed.
      • 'All device' option for 'operator' user in Snapshot page has been removed.
      • In the Collector list page, if any action is performed, the page will be refreshed automatically.
      • In the Inventory > Users list page, 'username' search was not working. This issue is fixed.
      • In the Alarms page of Operator user, Close icon-title is not shown properly on hover. This issue is fixed.
      • Free license text is removed from the DE Alert image.
      • For 'Operator' user, Support page icon was not working. Fixed the issue.
    2. 12.3 Build 123177

      Enhancements :

      • Support - 4709829: Added SSH protocol to fetch WatchGuard firewall configuration.
      • In Anomaly alert criteria page, a help message 'CIDR and CSV formats are allowed' has been added to Source and Destination fields.
      • When Report Profiles are created, removed unnecessary API call to improve UI performance.
      • In Cloud Services page of Inventory, 'Add repository' option is provided.

      Issues fixed :

      • Support - 4669580: SNMP based Live Report of PaloAlto devices was not working properly. This issue is fixed.
      • Local File Inclusion vulnerability is fixed.
      • Device drill down from Policy Optimization page of Dashboard was not working. The issues is fixed and redirected to Optimization page.
      • In Firewall Live Traffic widget of Inventory page, when 'Gbps' is selected as unit, the values shown were not accurate. The issue is fixed to plot the graph with granular values.
      • Alarm Profile notification option 'Run As Script' didn't accept arguments. The issue is fixed.
      • Support - 4623647: In Import Log page, Local Schedule option was not shown even when the client can be accessed from localhost.
      • Support - 4697639: In Fortigate syslog, VPN close log has duplicate entry which led to incorrect data. Handled it to fix the issue.
      • Support - 4723997: Traffic Trend Report graph was not plotted in order. This issue is fixed
      • Support - 4732194: Syslog port details were not shown properly in Device Details Page of Settings tab. The issue is fixed
      • Support - 4566694 : When a PaloAlto Rule Name contains 'index' value, wrong unused rule list is displayed. The issue is fixed.
      • Support - 4707871: Checkpoint VPN log parsing issue is fixed.
      • In MSSQL setup, Yearly table drop was not proper. The issue is fixed.
      • When extra device license was applied in the product, the manage and unmanage actions couldn't be performed till user restarts the product. This issue is fixed.
      • Header of SMS notification in Alert Profile page changed from 'Send Email based SMS' to 'Send SMS' to avoid misunderstanding.
      • In the Report Profile Notification page, a message "Use comma ',' separator for multiple mail ids" has been added for clear understanding.
      • Edit and Save Report Profile action returned wrong status message. The issue is fixed to show proper status message.
      • While saving Compliance Report Schedule, there was no status message. This issue is fixed to show the status message.
    3. 12.3 Build 123169

      Issue fixed:

      • Security vulnerability: Cross site scripting(XSS) and arbitrary file read vulnerability in Fail Over has been fixed. [CVE-2018-12997, CVE-2018-12998]
    4. 12.3 Build 123164

      New device supported:

      • MikroTik

      New features:

      • Simulate firewall logs - You can simulate firewall logs for different vendors to check all the reports in Firewall Analyzer. Log simulation is available for Fortigate, PaloAlto, CheckPoint, Juniper SRX and Squid Proxy devices.

      Enhancements:

      • Added more than 3000 websites to the Cloud Repository.
      • Option to plot Dashboard Live traffic graph in 'Kbps/Mbps/Gbps' is available.
      • Support ID: 4598454 - Updated IP to Country database.
      • Support ID: 4573349 - When you import syslog, you can map the logs to the existing device.
      • Support ID: 4590527 - Export to CSV format option is available for expanded view of all 'Inventory' page widgets.
      • 'Admin Report' for PaloAlto available. It covers details of user login, log out, and commands executed.
      • Auto refresh option provide to 'Live Syslog Viewer' page.
      • Mail content format enhanced for scheduled 'Standards' report.
      • Additional tabs Bandwidth, Sites, Apps, and VPN are added in 'Device' inventory snapshot page for better access.
      • License count, number of managed devices and remaining devices count now available under ' License Management' page.
      • Now 'bps' value is formatted to readable format in Bandwidth Alert mail content.

      Issues fixed:

      • Support ID: 4588018 - While creating Alarm profile, configuring more than 50 criteria makes the page unresponsive. This issue is now fixed.
      • Refresh option in 'Dashboard Live Traffic' widget was not working. Now the issue is resolved.
      • AD User-IP Mapping had two entry for an user with Old and New IP. The duplication issue is rectified now.
      • Support ID: 4579510 - Incorrect Rule Name was shown for Zyxel firewall. This issue is now fixed.
      • Support ID: 4480507 - Invalid Byte Sequence Error while loading FirewallRecords table is fixed.
      • While parsing Sonicwall configuration, network objects with IP-range and IPv6 objects were not handled properly. It is fixed now.
      • Finding 'Unused Objects' from configuration file had discrepancy. Now it is rectified.
      • In Japanese Installation, when logs are imported, reports were generated for current time instead of log time. This issue is resolved.
      • 'Edit Interface' & 'Edit Interface Names' were not working, when edited for the second time. This issue is now fixed.
      • Occasionally, the 'Inventory' page became empty when 'Back' icon was clicked. This issue is now resolved.
      • Even after changing display name of Firewall, ' Resource Name' was displayed when user was added from User Management page. Now the issue is fixed to show the device list with display name while assigning device.
      • When Credential Profile was edited, the 'Email' field became empty. Now the issue is fixed to show the given Email Id in that field.
    5. 12.3 Build 123156
      • License Agreement has been updated.
      • Promotions related to ITOM Events will be displayed in the UI header after login.
    6. 12.3 Build 123151

      Bug Fixes:

      • In Group Chat Module, "Operator" user was not restricted from viewing the list of users, their User ID and Email addresses. This issue has been fixed.
      • EncryptPassword.bat has been removed due to DOS attack.
      • Path Traversal vulnerability in uploadMib API has been fixed (Reported by Pulse Security).
    7. 12.3 Build 123137

      New features:

      • Introduced 'Audit Report' for all add, delete, and update actions done by Firewall Analyzer user. All the user actions are logged.
      • Option to search personal information like Email, phone number and user name across the product and replace them with another user is available under 'Privacy Settings'

      Enhancements:

      • 'Security Audit Report' is now available in PDF format. You can export the report in PDF format from client.
      • Disclaimer added in exported PDF & CSV to convey availability of Personally Identifiable Information (PII) of GDPR.

      Issues fixed:

      • Option to add new Custom Report was not visible in UI. Now the issue is fixed.
    8. 12.3 Build 123129
      • Path Traversal vulnerability in uploadMib API has been fixed.
      • The RemodeCodeExecution(RCE) vulnerability occurring while testing scripts has been fixed.
      • The SQL injection vulnerability in "FailOverHelperServlet" for the operation 'standbyprobestatus' has been fixed.
      • The SQL injection vulnerability in "FailOverHelperServlet" for the operation 'getprobenetworkshare' has been fixed.
      • In Group Chat Module, "Operator" user was not restricted from viewing the list of users, their User ID and Email addresses. This issue has been fixed.
      • Previously, "Operator" user was not restricted from viewing the URL monitors in the Inventory Page. This issue has been fixed.
      • Previously, "Operator" user was not restricted from being able to modify the background color and the tile color in the 3D floor view page. This issue has been fixed.
    9. 12.3 Build 123126

      Admin Server

      • Enterprise edition for 12.3 version
      • Data Migration tool for enterprise edition 8.5 customers to upgrade to 12.3

      Standalone/Collector Server

      • Compliance reports and Policy/Rule Management support for WatchGuard device
      • Compliance reports and Policy/Rule Management support for SonicWALL device.
      • Policy/Rule re-order report for PaloAlto device
    10. 12.3 Build 123092

      Enhancements

      • Default reports enhanced with drill down option to second and third level. Particularly for 'Unknown Protocols', you can drill down up to raw log level.
      • 'End User' feature moved to 'Firewall Inventory' tab. You can get 'End User' details from 'Users' Tab.
      • 'Rule Management' and 'Compliance Reports' files stored in Firewall Analyzer server directory are encrypted now.
      • User information is encrypted at the database storage.
      • 'CSV Export' option is available for 'Rule Management' reports.
      • 'Scheduled Report' mail format is enhanced to show properly aligned mail content.
      • Support - 4458020: In 'Change Management' report, new column has been added to show the IP address of user from which he did configuration changes.
      • Support - 4429668: 'Admin' report is available for Huawei Firewall. You can view user login, logout and command executed reports.

      Issues Fixed

      • Support - 4477638: Fixed the issue of incorrect data shown in 'Policy Optimization reports' for some PaloAlto devices.
      • Support - 4519337: Fixed the issue of not fetching configuration files from SonicWALL firewalls due to incorrect SCP command.
      • Support - 4497009: Fixed issues in 'Denied Events' and URL log parsing for Juniper SRX devices.
      • Support - 4510780: Fixed the issue of wrong time period shown in i-Filter reports data, due to non-processing of time stamp available in the logs.
      • Support - 4496764: Fixed the issue of mismatch in rules count of unused rules and total rules displayed for some PaloAlto firewalls.
      • Issue - 126991: In PaloAlto firewall 'Policy Overview' page, no data was displayed when clicked on some source and destination objects. This issue is fixed.
      • Fixed the issue of no data display in 'Total Bytes' column in Trend Micro device reports, due to non-processing of byte value available in the logs.
    11. 12.3 Build 123083

      Enhancements

      • Dashboard loading has been revamped and optimized for better performance.
      • In the Login page, iPhone/Android and iPad application download links have been included.
      • License expiry information in header had a few alignment issues. This has now been fixed.
      • User Icon with product details and about information has been moved to right top corner.
      • In the Inventory page, product based tabs have been moved horizontally.
      • Sign out option has been moved from Quick links to User details menu.
      • Support icon has been added for (Mail, Apply license, phone number, SIF, User guide, Videos, Service pack, ThreadDump, DB Query & view Logs) links.
      • In support page, the Query page under DB Query will be opened in a new window without ember.
    12. 12.3 Build 123070

      Vulnerability Fix

      • SQL injection vulnerabilities in Servlet's API has been fixed.
    13. 12.3 Build 123064

      Enhancements

      • Provision to configure each device in the Inventory itself. For a single device, you can configure Report, Alert, Device Rule, and SNMP in one place.
      • Ad-hoc reports are listed in the drill down page of 'Device' under Inventory.
      • 'Device' summary widget under Inventory, is enhanced to show more device configuration options.
      • Cloud Control Repository updated and new services added.
      • 'No Data' message will be displayed in widget header, if a widget has no data to display. If the widget has data, total number of rows will be displayed.
      • Reduced the 'Inventory' page loading time.
      • By default, indexing enabled for Security Logs.
      • Support Id: 4400799 - New widget added under drill down page of 'Cloud Control'. The widget shows all source IP addresses, who accessed the corresponding 'Cloud' service.

      Issue Fixes

      • Support Id: 4223153 - Bandwidth Alert profiles created with criteria 'mbps' were not working. This issue is fixed.
      • Support Id: 4223153 - URL report, date and priority parsing issues of pfSense firewall is fixed.
      • Support Id: 4275699 - When one Juniper SRX device was added it was displayed as two devices. This was due to absence of firewall name in some syslogs. This issue is fixed to show it as a one device.
      • Issue Id: 124479 - Earlier user couldn't edit the report filter while creating 'Report Profile'. Now 'Edit' option provided for the report filters to fix the issue.
      • Issue Id:126112 - After selecting custom time period in 'Inventory' drill down page, the end time was not shown properly. This issue is fixed.
      • Issue Id:126077 - In 'Add Credential Profile' page, 'Device Type' option is moved up near 'Protocol' for better accessibility.
      • Issue Id:126332 - In 'Device Rule' list page, sorting of any column, removed 'Fetch Rules' and 'Security Audit Report' icons. This issue is fixed.
    14. 12.3 Build 123057

      Vulnerability Fixes:

      • DDI-VRT-2018-02 – Unauthenticated Blind SQL Injection via /servlets/RegisterAgent
      • DDI-VRT-2018-03 – Unauthenticated Blind SQL Injection via /servlets/StatusUpdateServlet and /servlets/AgentActionServlet
      • DDI-VRT-2018-04 – Multiple Unauthenticated Blind SQL Injections via /embedWidget
      • DDI-VRT-2018-05 – Unauthenticated XML External Entity Injection via /SNMPDiscoveryURL
      • DDI-VRT-2018-06 – Unauthenticated Blind SQL Injection via /unauthenticatedservlets/ELARequestHandler and /unauthenticatedservlets/NPMRequestHandler
      • DDI-VRT-2018-07 – User Enumeration via /servlets/ConfServlet
    15. 12.3 Build 123045

      New device/log format support

      • Support Id: 4385377 - i-Filter Version10 device logs support

      Enhancements

      • System settings (General and logging) page added for Firewall Analyzer module to enhance the customization
      • Drill-down, from graph, for all reports along with table values
      • Labels for the reports graph for X and Y axis are shown
      • Custom time period has been shown properly in Inventory, Reports, Standards and End-Users reports based on earlier time selection
      • Inventory snapshot start-time and end-time shown for all time periods under clock icon
      • Filter option provided for source in live Syslog viewer

      Issues fixed

      • Issue Id: 122137 - Missed internationalization keys in Compliance Standard Reports fixed.
      • Issue Id: 123950 - Non-internationalized Total & other key are internationalized in Firewall reports.
      • Issue Id: 125439 - Disabling VDOM in User Config option deletes all device rules configured.
      • Issue Id: 125440 - Newly supported 'Device Rule Vendor' list added in Credential Profile page.
      • Issue Id: 121670 - Log Level debug settings for logger-name not handled.
      • Issue Id: 125070 - Graph Unit is not internationalized in snapshot widget header.
      • Issue Id: 123955 - 'No Data' string in some graph is not internationalized.
      • Issue Id: 123859 - Live Report drill-down didn't pass proper time-range.
      • Issue Id: 125582 - While sorting the column in table data leads to table empty in Traffic Trend report.
      • Issue Id: 125598 - Getting 'NullPointerException' in weekly trend comparison reports page.
      • Issue Id: 125456 - Getting 'NullPointerException' while parsing SonicWall logs.
      • Support Id: 4343907 - Data movement to data tables isn't working due to large duration value in few Syslogs in SonicWALL device.
    16. 12.3 Build 123027

      Enhancements

      • The 'Automatic/On-click/No lookup' options of Resolve DNS in global settings synchronized for all widgets.
      • Two more SMS service Clickatell and AppSMS supported to send SMS notifications for 'Alarms, Configuration changes, and Availability Alerts'

      Issues fixed

      • 123396 - If dashboard data is with '\', in its drilldown page data is shown without '\' . The issue is resolved to display it properly.
      • 121669 - When Traffic Conversation Table in Interface drilldown page is expanded, it was displaying only top 10 rows. Issue fixed to display complete data.
      • 123760 - In CCTV view, Operator can view unauthorized device's Live Traffic. Issue is fixed by hiding it.
      • 122774 - In one of the 'Proxy Reports', when Search icon is clicked, empty page was displayed. Issue fixed to display appropriate page.
      • 123955 - 'No Data' message not internationalized in some graphs, issue fixed by internationalizing it.
      • 122298 - In dashboard traffic and security statistics report, when Search icon is clicked, empty page was displayed. Issue fixed to display appropriate page.
      • 124212 - 'In' & 'Out' legends in Device Summary graph were not internationalized, issue fixed by internationalizing it.
      • 121712 - Fixed memory handling issue, during user association and manual IP mapping when device is deleted.
      • 123826 - Fixed an issue in reimport option of manual IP mapping.
      • 120736 - Fixed issues in FWA Availability alert page UI and Disable notification link in the alert notification mail
      • 122140 - Fixed an issue in script error handling, when a schedule is added for Compliance report without selecting any type of standards.
      • 125095 - In standard compliance reports, if clicked to drill down the report, the table values are not displayed. Fixed the issue for table value display.
      • 125093 - User with '\' character could not be added, for 'End Users' reports. Fixed the issue to add user.
      • 123942 - There was an UI alignment issue in NetFlow widget populated in OpManager's End Users report. Fixed the issue to align the UI.
      • 122493 - In the dashboard, snapshot view of Cloud Users report, fixed the issue of missing 'Expand View' icon.
      • 124899 - Fixed the issue in Disable notification option of the change management alert notification mail.
      • 124613 - When TLS option was configured in Mail Server settings, mail notifications for alerts were not sent. Fixed the issue to send mails.
      • 124090 - Fixed the misalignment issue in Policy Overview report table. This was for MS SQL database.
      • 122970 - When a new report type is added with the existing name, 'Success' message is displayed. Fixed the issue to display 'Failed' message.
      • 125067 - Fixed the issue to populate rule details of SRX devices, when the configuration file is not having network object details.
      • 125059 - In the 'Unused Rules' report of 'Rule Management', the resource criteria is not applied properly. Fixed the issue to apply the resource criteria properly.
      • 4245966 - In FWA, log entries for unsuccessful console login attempt on Cisco ASA devices are not there. Fixed the issue to get entries.
      • 4206352 - Issue, in SonicWALL log parsing for protocol, is fixed.
      • 4086698 - All the IPs are not getting resolved into names, when 'Resolve DNS' is set to 'Automatic'. Fixed the issue to resolve all IPs.
      • 4250080 - When scheduled PDF report page count is more than 100, the total page count in PDF footer was not proper. Fixed the issue for proper page count.
      • 4300246 - Fixed the out of memory error generated when change management report was accessed.
    17. 12.3 Build 123008

      Issue fixes

      1. Device rule configuration using SCP protocol was not functioning in build 12300. Now this issue is fixed.
      2. Sometimes, SRX marked as unsupported device, if Firewall Analyzer receives unsupported log as the very first record. Now, wait time is added to check more received logs to avoid unparsed error.
      3. System performance and custom dashboard view were missing when logged in for the first time. Now the issue is fixed and the user can view both.
      4. Editing widget "Top N Hosts by Traffic" and selecting Protocol under category makes the widget to show data of protocol-group by traffic. Now, the issue is fixed by showing Protocol-Group instead of Protocol in dashboard widget - edit section.
      5. 'Live Syslog Viewer' status shown as 'undefined' when we do continuous refresh. Now the status message handling issue is fixed in the server side to show proper status in the UI for continuous refresh.
      6. Increased the data dumb volume from base table 'Firewall Records' to next level data table for database performance increase.
      7. Inventory Interface snapshot traffic conversation report's last row was not shown properly in UI. Now the issue is fixed and the report loads the data properly.
      8. Graph units option provided in the Inventory LiveReports page was not in proper sequence. This is issue is fixed and the units are now shown in proper order like kbps,mbps and gbps.
      9. When the user selects all predefined reports while creating a report profile, received PDF shows all the reports name in the home page without proper alignment. Now, Alert Message added for Report Profile reports selection

      New Features

      1. Previously, there was no option to view the selected time-period of each dashboard widgets. Now, sub-header details will be shown in each widgets with device information along with time-period applied.
    18. 12.3 Build 12300

      New Devices/Log Formats Supported

      1. Trend Micro IWSVA 6.5
      2. Palo Alto VPN logs
      3. FortiGate Management logs
      4. Juniper SRX Management logs
      5. SonicWall IPSec VPN logs
      6. New easy to use revamped web client

      New Features

      1. 'Insider Threat' reports to track internal user's cloud application usage
      2. Drill down for all dashboard reports
      3. Exclude IP/IP range/network from reporting
      4. URL and VPN reports for Inventory report user drill down
      5. Live report for Proxy servers
      6. Live report drill down for device and interfaces from Inventory
      7. Interface Live Traffic widgets in Custom Dashboard
      8. End User widgets in Custom Dashboard
      9. Anomaly Alerts based on Country
      10. User specific reports for Proxy servers
      11. Option to export report as CSV on demand
      12. Option to use Management IP address to fetch device configuration
      13. Option to configure 'Row Count' for on-demand PDF/CSV report export
      14. More reports for Rules in Device snapshot

      Bug Fixes

      1. SRX policy parsing issue for Compliance & PolicyOverview report
      2. Live Report out-traffic spike based on SNMP fixed
      3. Fortigate 5.2.4 Device rule ssh connection issue fixed
      4. VPN Usage Trend report issue fixed
      5. PDF issue in non English client side language issue fixed
      6. Export to PDF issue fixed for Rule-Reorder recommendation report
      7. SNMP V3 configuration issue without community fixed
      8. Drill-down issue for Usernames which contains slash in it.
      9. Squid proxy log user name parsing issue
      10. Fortigate VPN log parsing issue
      11. Issue in Paloalto country name parsing
      12. Issue in Checkpoint denied status when value is 'drop' in syslog
    19. 12.2 Build 12200

      For 8500 upgrade

      New Features

      • Firewall Analyzer is integrated with OpManager
      • New easy to use revamped web client

      New Device/Logs/Reports

      • WebMarshal Proxy Server
      • Juniper-SRX - VDOM logs support
      • McAfee - SideWinder Firewall
      • i-Filter Proxy Server
      • PfSense open source firewall
      • Cisco-Meraki (Proxy) and FireSight module support

      For 12000 & 12100 upgrade

      New Features:

      1. SNMP based reports
        • Live Report
        • Bandwidth Alert
      2. Unassigned protocol grouping
      3. Live Syslog Viewer
      4. Packet-Count / Flow-rate / Syslogs server details page
      5. "View Report" option from 'Import Log' list page
      6. Import/Export option for Report,Alert and Protocol-Groups
      7. On-demand pdf/csv export option in Policy Tab
      8. Active VPN connection trend report
      9. User Configuration/Raw Configuration pages
      10. Device grouping
      11. Compliance:
        • Policy Overview/Optimization - schedule option
        • Unused rules - Calendar option
      12. 'Total & Others' row for all default reports table data
      13. Filter option for all default reports
      14. "Firewall Log Level" settings page for debugging
      15. PDF export for Inventory page Widgets
      16. Server/Client side PDF export option for Scheduled reports

      Issue Fixes:

      1. Inventory - Device drill down - Top 10 widgets - Fixed missing scroll down option
      2. Bundled check-point device dll & opsec.exe.
      3. Fixed the missing "View All" option missed in all default Reports.
      4. Fixed URL Report parsing issue for Palo-Alto
      5. Cisco-Meraki (Proxy) and FireSight device support
      6. Administrator/ Operator specific page view issues fixed
      7. Fixed showing two scroll-bar in Security Audit page.
    20. 12.0 Build 12000

      GA release of Firewall Analyzer Distributed Edition.

      New Features - Admin Server

      There are no new features available for Admin Server in this release

      New Features - Collector Server

      All the features available in this release of Firewall Analyzer Standalone Edition (see below) is available for Collector Server of Distributed Edition

      12.0 - Build 12000 - Standalone Edition

      The general features available in this release are:

      New Features

      • Firewall Analyzer is integrated with OpManager
      • New easy to use revamped web client.
    21. 8.5 Build 8500

      GA release of Firewall Analyzer Distributed Edition.

      New Features - Admin Server

      There are no new features available for Admin Server in this release

      New Features - Collector Server

      All the features available in this release of Firewall Analyzer Standalone Edition (see below) is available for Collector Server of Distributed Edition

      8.5 - Build 8500 - Standalone Edition

      The general features available in this release are:

      New Features

      • 'Cloud Control Reports' feature
      • Rule reorder and recommendation
      • AD User vs IP address mapping for reports
      • Change management, security audit and unused rules reports for WatchGuard firewall
      • Industry standard compliance reports and policy optimization for PaloAlto firewall

      New Device/Logs/Report

      • WebMarshal Proxy Server
      • Juniper-SRX - VDOM logs support
      • McAfee - SideWinder Firewall

      Issue Fixes

      • Fixed XSS Vulnerability identified in-house, all forms, all URL parameters, and login page
      • Instead of first device quick report is shown for all devices in dashboard. Fixed this issue
      • TLS issue in Email configuration is fixed
      • Custom Reports not getting generated with MS SQL database. Fixed the issue
      • Cisco VPN log parsing issue, for log id - 722051, is fixed
      • In SonicWALL device reports, 'Duration' value is displayed as '0'. This issue is fixed
      • Issue in PaloAlto log parsing, if the URL field contains comma, is fixed
      • In 'Report' tab, if we click 'View Report' link of 'VPN Trend Report', no data is displayed. Fixed the issue
      • In Professional edition of the product, there are no 'Save', 'Cancel' buttons in 'Firewall Availability Alert' page. Fixed the issue
      • If Juniper SRX syslog contains kernel logs, the logs get overwritten while parsing. Fixed the issue
    22. 8.3 Build 8300

      8.3 - Build 8300 - Distributed Edition

      GA release of Firewall Analyzer Distributed Edition.

      New Features - Admin Server

      There are no new features available for Admin Server in this release

      New Features - Collector Server

      All the features available in this release of Firewall Analyzer Standalone Edition (see below) is available for Collector Server of Distributed Edition

      8.3 - Build 8300 -Standalone Edition

      The general features available in this release are:

      New Features

      • Policy/Rule Optimization
        • Anomaly Rules Reports (Correlation, Generalization, Shadowed, and Redundant Rules)
        • Rule Grouping Recommendation
        • Rule Cleanup Recommendation
      • Options provided in the Device Rule UI:
        • Fetch Policy, Configuration based on TFTP, SCP protocols
        • Login banner support
      • Change management and Unused rules reports for Palo Alto firewalls
      • Industry Standard Compliance reports (PCI-DSS, SANS, NIST, ISO, NERC-CIP) for Juniper-SRX device
      • Indexing Traffic logs along with security logs for fine grained advanced search results
      • Performance improvement to support more logs/sec
      • Alert and Search based on Country, Application
      • Application and Security reports for Juniper-SRX device
      • Security Reports for Microsoft-ISA
      • 'Denied Login Users' report for NetScreen

      New Device/Logs/Reports

      • iPrism
      • Huawei
      • BlueCoat Proxy SGOS 6.4.5.2
      • Juniper-SRX - Security and Application logs
      • Watchguard XTM version 11.9

      Issue Fixes

      • Issue in, populating URL length > 2500 characters, is fixed
      • Support extended for User Group information of Squid proxy server
      • Issue in, populating the URL information for Cisco, is fixed
      • Fixed issue in scheduled fetch of user details from Active Directory.
      • Wrong listing of Cisco denied URLs issue is fixed
      • Zywall log format change issue fixed
    23. 8.1 Build 8110

      8.1 - Build 8110 - Distributed Edition

      GA release of Firewall Analyzer Distributed Edition.

      New Features - Admin Server

      There are no new features available for Admin Server in this release

      New Features - Collector Server

      All the features available in this release of Firewall Analyzer Standalone Edition (see below) is available for Collector Server of Distributed Edition

      8.1 - Build 8110 -Standalone Edition

      The general features available in this release are:

      New Features
      • Industry Standard Compliance reports for Cisco and Fortigate devices,
        • PCI-DSS
        • ISO-27001 (2013)
        • NERC-CIP
        • NIST
        • SANS

      New Device/Logs/Reports

      • SonicWALL SSL-VPN appliance
      • 'Application Report' supported for D-Link, Clavister and WatchGuard firewalls
      • 'Category Report' supported for D-Link and Palo-Alto firewalls
      • 'VPN & Interface Reports' supported for Cyberoam devices

      Issue Fixes

      • Optimized D-Link device log parser to handle the heavy log flow rate
      • Issue, while handling Banner for CLI SSH, is fixed
      • Alert generated for wrong bandwidth % criteria. This issue is fixed
      • In the 'URL Report' for Fortigate devices, the URL column displayed 'Destination IP Address' instead of 'Destination Name'. The issue is fixed
      • If the Cisco device, while fetching the rules, it was throwing timeout if the 'enable' mode in the device is kept enabled. This issue is fixed
    24. 8.0 Build 8000

      8.0 - Build 8000 - Distributed Edition

      GA release of Firewall Analyzer Distributed Edition.

      New Features - Admin Server

      There are no new features available for Admin Server in this release

      New Features - Collector Server

      The general features available in this release include,

      • Collector Server contains all the features of Firewall Analyzer Standalone Edition (see below)

      8.0 - Build 8000 -Standalone Edition

      The general features available in this release are:

      New Features

      1. New Devices supported:
        • Opzoon firewall device
        • Stonesoft firewall device
        • Barracuda device
        • McAfee Firewall Enterprise (Sidewinder (S4016)) logs
        • SonciWALL device - Management, Application control and SSL-VPN logs
        • Palo Alto (PANOS 4.1.0) logs
        • FortiOS 5.x VPN logs
      2. New user interface
      3. Policy/Rule overview reports for Cisco and Fortigate firewalls with real-time and export options
      4. On-demand fetching of complete (raw) device configuration in file
      5. Country/Geo-location reports with export and schedule options
      6. Trend report for VPN connection
      7. Option to view/export Live Reports in Mbps or Gbps
      8. Zoom In/Out option for Live Bandwidth reports of device and interfaces
      9. Export/Import option for Protocol Groups page
      10. 'Rebranding' support for alert notification E-mails
    25. 7.6 Build 7600

      7.6 - Build 7600 - Distributed Edition

      GA release of Firewall Analyzer Distributed Edition.

      New Features - Admin Server

      There are no new features available for Admin Server in this release

      New Features - Collector Server

      The general features available in this release include,
      • Collector Server contains all the features of Firewall Analyzer Standalone Edition (see below)

      7.6 - Build 7600 -Standalone Edition

      The general features available in this release are:

      New Features

      1. New Devices supported:
        • FortiGate - FortiOS 5.x logs supported
        • NetASQ
        • PaloAlto - Application reports
        • Bluecoat - Virus reports
      2. Option to identify non standard protocols (Unknown Protocol) detail in your network.
      3. Email alert notification when Firewall Analyzer fails to write the logs in archive
      4. SFTP/SSH protocol support to import logs from remote machines
      5. Optionally, traffic logs can be indexed and searched
      6. Advanced Search can now be used to find the exact Port/Protocol details
      7. Showing the conversation (source/destination/protocol) details for anomaly alert in mail
      8. Troubleshooting tool to apply License file in case of product license expiry
      9. Users with 'Guest' privilege can now access the'Compliance' tab
      10. Firewall Analyzer will henceforth be using PostgreSQL database (applies to fresh install of full build only)

      Bug Fix

      1. Wrong alert message showing double the number of managed devices compared to the License count has been fixed
      2. Fixed the Windows Authentication issue in Admin server MS SQL setup
      3. SonicWALL device interface name parsing issue is fixed
      4. Fixed the issue to retain the Y-axis value as integer in Time Series graph in PDF export
      5. Allowed URL reports will now be populated for Palo Alto devices
      6. Parsing issue of Juniper SSL logs fixed
      7. Native OS (German and French) Installation issue fixed
      8. 'DisplayName' of the device will be shown now in Change Management alerts, Anomaly alerts and Compliance reports instead of 'ResourceName'
    26. 7.4 Build 7400

      7.4 - Build 7400 - Distributed Edition

      GA release of Firewall Analyzer Distributed Edition.

      New Features - Admin Server

      The general features available in this release include,
      • Dedicated compliance section for device rules configurations, firewall rules monitoring, change management reports and alerts for each collector server

      New Features - Collector Server

      The general features available in this release include,
      • Collector Server contains all the features of Firewall Analyzer Standalone Edition

      7.4 - Build 7400 -Standalone Edition

      The general features available in this release are:

      New Features

      1. Supports 'IPFIX with extensions' based flows (for SonicOS 5.8) - reports include top URLs, applications, users, viruses, attacks, intrusions, spyware, etc.
      2. Dedicated compliance section for device rules configurations, firewall rules monitoring, change management reports and alerts
      3. Detailed reports for applications accessed through Check Point and SonicWALL devices
      4. Consolidated VPN traffic reports for user-groups
      5. 'Exclude criteria' option now allows users to generate configuration change management reports that excludes certain specific lines or text
      6. Importing 'Local Host' log directory is now supported
      7. 'Intranet Settings' can now be configured for multiple devices
      8. For FTP log import from remote hosts, in addition to specifying time interval users can now specify 'Schedule Start Time'
      9. 'Scheduled Reports' can be now saved in the machine running Firewall Analyzer
      10. Active Directory or RADIUS can be set as default authentication for Firewall Analyzer login
      11. Active Directory Users can now be imported at the Organizational Unit level, Group level and Individual User level

      Bug Fix

      1. Fixed indexing of Juniper IDP attack logs
      2. Increased the default value of row count of reports in PDF format from 10 to 100
      3. Fixed the usability issue in Scheduling Device Rule
      4. Fixed the Parser Rule issue for Cisco Message Id 713119
      5. Fixed Change Management Alert issue when difference in configuration content has dollar symbol in it
      6. Fixed the 'device credentials test button' issue
      7. Fixed issue in detecting dynamic file name changes, during scheduled import
      8. The issue with 'SNMP community string with special characters' to access the interface is fixed
      9. The issue in parsing unused ACEs of Cisco firewall is fixed
    27. 7.2 Build 7021

      GA release of Firewall Analyzer.

      7.2 - Build 7021 - Standalone Edition

      The general features available in this release are:

      Bug Fix

      • Optimized the connection between Firewall and Firewall Analyzer, to fetch rules
    28. 7.2 Build 7020

      GA release of Firewall Analyzer.

      7.2 - Build 7020 - Distributed Edition

      GA release of Firewall Analyzer Distributed Edition.

      New Features - Collector Server

      • Collector Server contains all the features of Firewall Analyzer Standalone Edition

      7.2 - Build 7020 - Standalone Edition

      The general features available in this release are:

      New Features and Enhancements

      1. New Device/Log Format supported
        • Palo-Alto Firewall
        • Juniper SSLVPN 6500
        • Check Point VSX firewalls
        • FortiGate WebFilter, DLP, IPS modules and IPSec support
      2. Application reports for Fortigate firewalls based on Application Control service
      3. Support for Virtual Firewalls of Cisco, Fortigate, and Check Point devices. By default, each context/vdom is displayed as separate device
      4. Alerts based on bandwidth utilization of a specific interfaces
      5. Client UI and email notification for Firewall Status Alerts for the following conditions:
        • Lack of disk space
        • Syslog server down
      6. View unused ACEs details of ACLs, for Cisco devices available in Unused Rules report
      7. Real-time Syslog collection from Squid proxy server supported
      8. Complete time duration details of the VPN user sessions available in 'VPN User Session Details' reports under VPN Reports
      9. Option to export 'VPN User Session Details' report to other formats, while clicking 'View All' link
      10. Zone based and interface specific Live reports using SNMP for Netscreen devices
      11. Change Management Report for Juniper SRX device available
      12. Option to fetch Rules and Configurations for any CLI supported device to get Unused Rules, Compliance and Change Management reports
      13. New format for Email alert to cater for context based Configuration Changes
      14. Optional privilege available to 'Guest' user to view the generated alerts for the assigned device(s)
      15. Optional privilege available to 'Guest' user to view the Report Profile(s) assigned by Administrators

      Bug Fixes

      1. Identifying Device IP address from the logs imported from Blue Coat proxy server
      2. Collecting intermittent logs of VPN sessions support for SonicWALL, Cisco, Checkpoint and Netscreen Firewall devices
      3. Added page navigation component in 'Raw Log Search' result page
      4. Importing log files with non-English names/folders from remote machines using FTP is supported
      5. Allowed special characters in SNMP Community string to fetch SNMP data from devices
      6. Issue in Diagnose Connections when the interface name had special characters

      Known Issue

      • You can not use Active Directory or RADIUS Server Authenticated Admin user credentials for Data Collection in Admin Server (i.e., from Edit Collector Details page of Collector Settings)
  • For further information please contact Firewall Analyzer Support.

A single platter for comprehensive Network Security Device Management