
Network Security Platform v5.1
Page 5
700-2014C00
Release Notes
For example: “layer2 forward vlan enable 5 10 interface 3A-3B” will enable layer2 forwarding on VLAN within the
range 5 to 10 on interface 3A-3B.
2 Issues resolved in this release
The following table contains issues resolved in this release of Network Security Platform 5.1.
2.1 Resolved Sensor software issues
Unless specified otherwise, the resolved Sensor software issues listed below are applicable to all M-series Sensor
models:
High severity Sensor software issues
ID # Issue
526430/
443201
In failover setups, there is a chance of pack
et drops on the sensor after running under high load for few
weeks.
525733 [M-8000] Incorrect ACL action with Permit and Ignore ACLs.
518534
There is a chance of a Sensor reboot when a certain rare sequence of TCP fragments is received at
the Sensor.
517919 [M-1250/M-1450] Sensors in a failover pair reboot occasionally because of an internal Sensor error.
516722 Excessive flapping of log channel and alert channel may cause the Sensor to reboot.
514787
Possibility of a Sensor to reboot when a lot of alert and packet logs are being sent to the Manager and
the user is trying to deinstall the Sensor.
507766
[M-4050] When ICMP packets with a certain pattern in the payload are received over a long period of
time, it can cause a traffic outage.
497799
If alert throttling is enabled, the Sensor sends packet logs for throttled alerts to the Manager after the
number of packet logs exceed 100,000. The additional packet logs could fill up the Manager database
and cause out-of-memory errors.
495544
While using the third-party NMS feature, if excessive SNMPv3 authentication failures occur, the
Sensor reboots due to the Sensor running out of memory.
483130
Some enhancements done to the SSH protocol (first released in signature sets 4.1.46.13/5.1.16.12),
exposed an error condition in the Sensor software that could cause performance/latency issues on the
Sensors when parsing certain types of SSH traffic.
460746 The show mem-usage command does not display the attack marker usage properly.
426570 Attack Markers Exhausted counters are getting incremented.
Medium severity Sensor software issues
ID # Issue
507854 [M-8000] ICMP timeouts are seen when fragments with jumbo packets are sent through the Sensor.
Commentaires sur ces manuels