UpgradesRelease notice for Ingate Firewall® 6.2.2 and Ingate SIParator® 6.2.2
Release name: |
Ingate Firewall® 6.2.2
Ingate SIParator® 6.2.2 |
The new version can be found here
Release notice for Ingate SIParator(R)/Firewall(R) 6.2.2
Release name: Ingate SIParator(R)/Firewall(R) 6.2.2
Release date: July 17, 2019
The new version and documentation can be found at:
https://account.ingate.com/
This is a bug fix release with important stability and security improvements.
We recommend everyone to upgrade.
* SIP related issues **************************************************
*** Fixed TLS domain check on DNS Override.
If DNS Override was used with Modify RURI set to No,
the RURI domain portion was not matched against the certificate CN/sAN.
*** Fixed TLS domain check on fall-back.
On fall-back to successive targets (e.g. multiple DNS targets),
the RURI domain portion was not matched against the certificate CN/sAN.
*** No longer attempt fall back to UDP for Remote NAT Traversal TLS
connections when UA does not respond via TLS.
Only related to "Remote SIP Connectivity."
*** Fixed a crash in B2BUA CANCEL scenario.
*** Fixed a crash in Media Encryption handling.
*** Fixed the "Require TLS" setting together with the B2BUA.
*** Fixed Media Encryption with B2BUA and INVITEs without SDP.
*** Fixed Media Encryption "Multi Profile" together with the B2BUA.
*** Fixed SDP crypto lifetime parsing.
Allow lifetimes of up to 2^48.
*** Fixed a memory leak in Media Proxy if it failed to set up media streams.
*** Fixed a memory leak in sipfw if media port allocation failed.
*** Fixed "Reuse port numbers" together with the B2BUA.
*** Fixed parsing of Call-ID headers containing double quotes.
*** Only fall back in DNS Override on 5xx class responses.
*** Allow other UA to update SRTP keys in re-INVITES when
sipfw does SRTP transcoding.
*** Use UPDATE method instead of re-INVITE for session refreshes initiated
by the B2BUA if the other UA supports it.
*** Support configurable response from the dial plan.
"Forward To": ;respond="503"?Retry-After=1800
See document "How To use Generic Header Manipulation".
* Other issues ********************************************************
*** Improved network performance on IG-953 and IG-970.
*** Show DHCPv6 client ID (DUID) on Interface Status page when DHCPv6 is used.
*** Set correct DUID type in DHCPv6 client.
Use 'LL' for units with flash storage and the default 'LLT' on other unit
types.
*** Disregard IPv6 in PPPoE route checker.
*** Make add/delete of received 'IPv6 SLAAC next hop' more stable.
*** Add support for hardware 410 (S42) and 450 (S82).
*** Handle SIP Trunk and session licenses via HTTP REST API.
* GUI *****************************************************************
*** Fixed a possible unit hang when downloading a Support Report.
*** Fixed an error when taking a support report on units without SIP Trunks.
*** Fixed a traceback on the IDS/IPS status page.
The page could not be shown under certain conditions.
*** Improved "Restart SIP Module" under the restart tab.
The SIP module didn't restart under certain conditions.
|