# Firewall Analyzer - Readme ## Release Overview ### Build No - 12.9.119 - July 22, 2026 **New Features & Enhancements:** 1. Firewall: Enhanced support for syslog-dependent Rule Management and Compliance reports in high-syslog firewall environments by setting a System property. Firewall Analyzer now provides improved report generation for syslog-dependent reports, including Unused Rules, Rule Suggestion, Policy Fine-Tuning, Objects Usage, and Unused Objects. 2. Firewall: SupportID: 13069487 — Introduced enhancements for Cisco FMC using API mode Firepower device rule support. ### Build No 12.9.118 - July 20, 2026 **New Features & Enhancements:** 1. The Ember.js version used for the Custom Reports, Syslog Reports, Proxy Reports, and Country Reports pages has been upgraded to 6.4. 2. The Ember.js version used for the Search and VPN tabs has been upgraded to 6.4. **Security Fixes:** 1. Firewall: Previously, path traversal issue identified during export report. This issue has been fixed. (Reported by Tuannq. Refer ZVE-2026-4565) ### Build No 12.9.117 - July 09, 2026 **Security Fixes:** 1. Previously, sensitive information was exposed on the Inventory interface list page. This issue has now been fixed. (Reported by ch4r0n. Refer ZVE-2026-4285) ### Build No 12.9.106 - July 03, 2026 **Issues Fixed:** 1. Previously, firewall names detected from syslog could cause a stored XSS vulnerability. This issue has now been fixed. (Reported by NGOC HIEU) 2. Previously, an SQL injection vulnerability was identified in Rule Management Search Reports. This issue has now been fixed. (Reported by NGOC HIEU) ### Build No 12.9.102 - June 18, 2026 **New Features & Enhancements:** 1. Support ID: 13005925 - Added an option to create an "Event Report" based Anomaly Alert. 2. Support ID: 13074591 - For PaloAlto and Sophos XG firewall devices, handled the following NAT fields from syslog to display the respective values in the RAW Search report: NAT Source IP, NAT Destination IP, NAT Source Port, NAT Destination Port. 3. Introduced OpenAI as a third-party GenAI integration, allowing users to connect via an API key and leverage AI-powered summarization features. 4. Introduced Ollama as a third-party GenAI integration, allowing users to connect locally hosted LLMs using a Base URL and leverage AI-powered summarization features. 5. Introduced DeepSeek as a third-party GenAI integration, allowing users to connect via an API key and leverage AI-powered summarization features. 6. Added support for selecting a default GenAI provider while adding or editing an integration, with priority-based fallback to OpenAI, DeepSeek, and Ollama when the configured default provider is reset or removed. 7. Firewall Analyzer now introduces the AI-guided Zia chatbot within the product UI to enhance user assistance and support. 8. Added support for forwarding alarms to Log360 On-Premises using Notification Templates. **Issues Fixed:** 1. Support ID: 12906520 - Username—IP Mapping was not working for Cisco firewall devices. Fixed. 2. Support ID: 12778312, 12755846 - Duplicate device addition issue for Sophos XG syslogs from multiple IPs resolved with custom mapping option. 3. Support ID: 12908952 - Fixed VPN disconnection syslog parsing issue for Sophos XG. 4. Support ID: 13065822, 13116373 - Fixed CountryCode table population failure in MSSQL. 5. Support ID: 11646671 - Fixed associated rules display issue for Juniper SRX Duplicate Objects Report. 6. Support ID: 11474096 - Fixed FortiGate Device Rule parsing issues. 7. Support ID: 12307333 - Improved REST API-based configuration fetching by handling API error responses gracefully. ### Build No 12.9.100 - June 04, 2026 **New Features & Enhancements:** 1. Firewall: SupportID: 12292991 - Introduced Security Rating, Baseline Rating, and Regulatory Rating scores in the [Executive Summary Report and Policy Overview](https://www.manageengine.com/products/firewall/help/device-score.html?fwa_readme). 2. Firewall: SupportID: 12729995, 13218270 - Added support for capturing URL Categories and Profiles configured in PaloAlto Security Rules. **Issues Fixed:** 1. Firewall: SupportID: 12521452 - Incorrect logging status for Check Point inline layers fixed. 2. Firewall: SupportID: 12816704 - Frequent socket timeout exceptions in API mode resolved. 3. Firewall: SupportID: 12983378 - Fixed NAT IP Pool parsing issue for Juniper SRX. 4. Firewall: SupportID: 13033390 - Fixed PaloAlto configuration parsing issue. --- ### Build No 12.8.732 - May 8, 2026 **New Features & Enhancements:** 1. Support IDs: 12441121, 12151443, 10077088 - Introduced [Custom Risk Profile](https://www.manageengine.com/products/firewall/help/custom-risk-profile.html?fwa_readme). 2. Updated terminology in Enterprise Edition from “Admin/Collector” to “Central/Probe”. **Issues Fixed:** 1. Support ID: 12708266 - Fixed SNMP credential application issue. 2. Support ID: 10726120 - Devices sorted by license status by default. --- ### Build No 12.8.718 - April 09, 2026 **New Features & Enhancements:** 1. SupportID 12292991 — Introduced [Advanced Filter](https://www.manageengine.com/products/firewall/help/advanced-filter.html?fwa_readme). 2. SupportID 12610494 — Added VPN sections to Security Audit report. **Issues Fixed:** Multiple parsing, performance, memory, and reporting issues across FortiGate, Check Point, Firepower, MSSQL setups, FQDN handling, anomaly detection, scheduled reports, and more. --- ### Build No 12.8.707 - April 03, 2026 **New Features & Enhancements:** 1. Added support for [ManageEngine Log360 integration](https://www.manageengine.com/products/firewall/help/integrate-log360.html?fwa_readme). --- ### Build No 12.8.704 - March 20, 2026 **New Features & Enhancements:** 1. Support for Peplink SDX Pro devices. 2. New syslog format for Checkpoint Embedded GAIA OS. 3. Enhanced Cloud Service drilldown reports. 4. Rule Risk Report support for Netfilter firewalls. **Issues Fixed:** Multiple VPN parsing, export, SNMP, configuration parsing, schedule display, and MSSQL exception issues resolved. --- ### Build No 12.8.691 - February 27, 2026 **New Features & Enhancements:** 1. Introduced [High Availability (HA) monitoring](https://www.manageengine.com/products/firewall/help/high-availability-monitoring.html?fwa_readme). 2. SSH key-based authentication support for CLI mode. 3. Cisco FMC with FTD mapping for Change Management. **Issues Fixed:** Resolved Deny URL report, VPN login parsing, and session duration issues. --- ### Build No 12.8.665 - January 09, 2026 **New Features & Enhancements:** 1. Parallel configuration fetching optimization. 2. MGuard extended-style configuration support. 3. Push notifications in mobile app. 4. Rule-Expiry enhancements (Excel/CSV support, N-days view, email details). 5. Multi-rule policy fine-tuning export options. **Issues Fixed:** Multiple rule parsing, change management, VPN parsing, report export, scheduling, login handling, and memory optimization fixes. --- ### Build No 12.8.626 - September 24, 2025 **New Features & Enhancements:** 1. Syslog-based traffic reports for H3C firewalls. 2. Optimized syslog-dependent Rule Management reports. 3. Extended NAT Rules report support for multiple vendors. **Issues Fixed:** Resolved live traffic, NAT population, drilldown, protocol parsing, and VPN duration issues. --- ### Build No 12.8.611 - August 25, 2025 **New Features & Enhancements:** 1. Customizable Security Audit Reports. 2. Application column support in audit reports. 3. New VPN tab with overview widgets. **Issues Fixed:** Resolved Mikrotik parsing, Fortigate VDOM issues, Palo Alto VSYS fetch logic, MSSQL offset issue, and alert notification problems. --- ### Build No 12.8.582 - June 30, 2025 **New Features & Enhancements:** 1. NAT Rules support for CheckPoint. 2. Splunk and generic SIEM integration via UDP. 3. PagerDuty integration. **Issues Fixed:** Resolved Check Point rule parsing affecting Rule Suggestion and Policy Fine-Tuning. --- ### Build No 12.8.568 - May 30, 2025 **New Features & Enhancements:** 1. Bulk Device-Rule configuration. 2. Virtual device addition. 3. New device support (mGuard 8.2.2, A10 Proxy). 4. Check Point enhancements (nested groups, rule numbering, VPN column). 5. Availability Alert edit option. **Issues Fixed:** Multiple device rule parsing, configuration fetch, duplicate rule, API access, and MSSQL query issues resolved. --- ### Build No 12.8.552 - April 16, 2025 **New Features & Enhancements:** 1. NIS 2 Compliance support. 2. Virtual Firewall Mapping enhancements. 3. Inventory export filtering. 4. RAW Search save page improvements. 5. Custom data storage periods. 6. Enterprise security improvements. 7. Lazy loading in Rule Impact Report. 8. SRX log parsing enhancements. **Issues Fixed:** Resolved parsing issues for Cisco Meraki, Firepower, Squid Proxy, Fortigate logs, device list loading in Japanese, and dashboard redirection. --- ### Build No 12.8.511 - January 30, 2025 **New Features & Enhancements:** 1. CLI support for Barracuda, F5, mGuard. 2. Auto-generation of Risk and Standard reports. 3. Bulk Device Add with CSV: https://www.manageengine.com/products/firewall/help/add-bulk-device.html?fwa_readme 4. Export to PDF option in Inventory. 5. Lucene upgraded to 9.12. **Issues Fixed:** Resolved Unassigned Objects inaccuracies and device rule failures. --- ### Build No 12.7.260 - December 11, 2023 **Security Issue Fixed:** 1. Path traversal vulnerability in MIB browser fixed. CVE-2023-47211: https://nvd.nist.gov/vuln/detail/CVE-2023-47211 --- ### Build No 12.6.118 - July 27, 2022 **Security Issue Fixed:** 1. CVE-2022-36923 fixed. https://nvd.nist.gov/vuln/detail/CVE-2022-36923 --- ### Build No 12.6.101 - June 23, 2022 **Security Issue Fixed:** 1. CVE-2022-35404 fixed. https://nvd.nist.gov/vuln/detail/CVE-2022-35404 --- ### Build No 12.5.606 - August 04, 2022 **Security Issue Fixed:** 1. CVE-2022-36923 fixed. https://nvd.nist.gov/vuln/detail/CVE-2022-36923 2. CVE-2022-37024 fixed. https://nvd.nist.gov/vuln/detail/CVE-2022-37024 3. CVE-2022-38772 fixed. https://nvd.nist.gov/vuln/detail/CVE-2022-38772 --- ### Build No 12.5.125 - April 29, 2020 **Security Issue Fixed:** 1. CVE-2020-12116 fixed. --- ### Build No 12.5.120 - April 16, 2020 **Security Issue Fixed:** 1. CVE-2020-11946 fixed. --- ### Build No 12.4.181 **Vulnerability Issue Fixed:** 1. Arbitrary file read vulnerability fixed. --- ### Build No 12.3.239 **Security Issues Fixed:** 1. CVE-2018-20338 fixed. https://nvd.nist.gov/vuln/detail/CVE-2018-20338 2. CVE-2018-20339 fixed. https://nvd.nist.gov/vuln/detail/CVE-2018-20339 --- ### Build No 12.3.224 **Security Issues Fixed:** 1. CVE-2019-11677 fixed. https://nvd.nist.gov/vuln/detail/CVE-2019-11677 2. CVE-2019-11676 fixed. https://nvd.nist.gov/vuln/detail/CVE-2019-11676 --- ### Build No 12.3.222 **Security Issue Fixed:** 1. CVE-2018-18949 fixed. https://nvd.nist.gov/vuln/detail/CVE-2018-18949 --- ### Build No 12.3.231 **Security Issues Fixed:** 1. CVE-2018-19403 fixed. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19403 --- ### Build No 12.3.218 **Security Issue Fixed:** 1. CVE-2019-11678 fixed. https://nvd.nist.gov/vuln/detail/CVE-2019-11678 --- ### Build No 12.3.169 **Security Issues Fixed:** 1. CVE-2018-12997 fixed. https://nvd.nist.gov/vuln/detail/CVE-2018-12997 2. CVE-2018-12998 fixed. https://nvd.nist.gov/vuln/detail/CVE-2018-12998 --- ### Build No 12.3.164 **New Features & Enhancements:** 1. Added Audit Report for tracking all user actions. 2. Privacy Settings for managing personal information. --- ### Build No 12.3.137 **New Features:** 1. Audit Report for user actions. 2. Privacy Settings for personal data management. --- ### Build No 12.3.129 **Security Fixes:** 1. SQL Injection vulnerabilities fixed. 2. Remote Code Execution vulnerabilities fixed. 3. User access restrictions enhanced. --- ### Build No 12.3.126 **Enterprise Edition Enhancements:** 1. Data Migration tool for 8.5 customers. 2. Compliance and Rule Management support for WatchGuard and SonicWALL. --- ### Build No 12.3.092 **Enhancements:** 1. Drill-down support for default reports. 2. Encrypted storage for rule management files. 3. CSV export for Rule Management reports. --- ### Build No 12.3.083 **Enhancements:** 1. Revamped Dashboard performance. 2. Improved UI alignment and navigation. --- ### Build No 12.3.064 **Enhancements:** 1. System settings customization page. 2. Drill-down enhancements. 3. Improved Live Syslog Viewer filtering. --- ### Build No 12.3.052 **Security Fix:** 1. ConfServlet vulnerability fixed. --- ### Build No 12.3.045 **New Features:** 1. Insider Threat reports. 2. Drill-down for dashboard reports. 3. Exclude IP/IP range from reporting. 4. CSV export option. --- ### Build No 12.3.027 **Enhancements:** 1. Global Resolve DNS synchronization. 2. Additional SMS services supported. --- ### Build No 12.3.008 **New Features:** 1. Sub-header details for dashboard widgets. 2. Improved rule fetching and inventory behavior. --- ### Build No 12.3.000 **New Devices & Features:** 1. Trend Micro IWSVA 6.5 2. Palo Alto VPN logs 3. FortiGate and Juniper Management logs 4. Revamped web client 5. Insider Threat reporting 6. Rule management improvements 7. VPN usage enhancements --- ### Build No 12.2.12200 **New Features:** 1. Integration with OpManager 2. Revamped web client 3. Scheduled Interface Live reports **New Devices Supported:** 1. WebMarshal Proxy 2. Juniper SRX VDOM 3. McAfee SideWinder 4. i-Filter Proxy 5. pfSense Firewall