FireBrick

FireBrick - Firewalls, Bonding ADSL, Routers, Traffic Shaping...

FireBrick FB6000 series Software

As a matter of policy, FireBrick software upgrades are free to download for all FireBrick customers.

SOFTWARE UPGRADES ARE BEST DONE USING THE WEB CONTROL PAGES ON THE FIREBRICK ITSELF

If you are loading new software from this web page, please read the instructions first.

Factory, Beta or Alpha?

There are three categories of software releases available - Factory, Beta and Alpha.

These categories reflect the amount of testing done - releases normally start life as an alpha, then after initial alpha testing are converted to a beta. As a beta they are subjected to further testing, both by ourselves and by customers in the field. If, after beta testing, a release is stable, we will promote it to a factory release. If during testing we find a problem, we may choose to withdraw that release, or promote a later release.

Factory releases have been tested extensively, both by us and by test users, and have been stable for some time as a beta release. We recommend upgrading all FireBricks to the latest factory release when convenient. FB2500 and FB2700 models will automatically upgrade to the latest factory release, unless you change the default "sw-update" setting in the config.

Beta releases have been through alpha testing to eliminate obvious bugs, and are generally stable. They are available to all users, should you wish to try a new feature or bug-fix before it is available as a factory release, and are willing to take the risk. FireBrick dealer technical support may also ask you to try a new beta to fix a problem. However, when running a beta, we suggest you keep an eye on our software downloads page, in case the beta you are using is withdrawn, or a subsequent beta release with relevant bug fixes is made available. When a beta release has had sufficient testing, it is normally promoted to factory release, or withdrawn if any serious problems are found. Your FireBrick's upgrade page will normally offer the latest beta release, or you can manually download it from our website and upload it onto your FireBrick.

Alpha releases are only for use by designated alpha testers, who are members of staff or customers closely involved in developing and debugging new features. Alpha releases may have had little or no testing, so there is a significant risk of bugs. If you would like to get involved in alpha testing, please contact your dealer. To load an alpha release, your FireBrick must first have alpha upgrades enabled by us. Your FireBrick's upgrade page will then offer the latest alpha release, or you can manually download it from our website and upload it onto your FireBrick.

Remember that if any upgrade causes repeated crashes, your FireBrick automatically reverts to older code.

Upgrade Instructions

Upgrade using the FireBrick control pages

The FireBrick has a built-in software download and installation system which can be accessed from the web control pages. This provides a simple one-click download and install feature. Simply go to your FireBrick's Status page, and if there is an upgrade available it will display an upgrade link under the current software version. Click the upgrade link and it will show details of the latest release - once you have read the release notes and wish to proceed, simply click the Upgrade button and it will download that release, install it, and reboot (this causes a brief outage of a few seconds).

Manually downloading and installing an upgrade

To install new software manually you need to load the main product image file. You may also wish to update the bootloader; this is normally unnecessary unless indicated by the release notes. The XSD file corresponding to the software may also be downloaded; this does not need to be installed on the FireBrick, but is useful as a definitive reference for the XML configuration.

Log in to your FireBrick administration pages, select Upload, browse to the main or bootloader image, and click Send new code. The software will be saved to flash, which will take a few seconds, and will become operational the next time the FireBrick is rebooted. You can force an immediate reboot by ticking the checkbox before clicking Send New Code.

Breakpoint Releases

When upgrading manually, do not skip over breakpoint software releases (labelled [Breakpoint] under release version number), as these update your config for changes in format or syntax. If you have saved configs, always re-save a copy after upgrading to a breakpoint issue. If you have tools to update configs, check documentation to confirm they are up to date. We recommend using the upgrade button on the FireBrick web control pages as this will ensure you do not miss any steps. Automatic upgrades to the latest factory release are done by default on FB2500 and FB2700 models. More


FireBrick Model: FB6000 | FB2500 | FB2700 | SoHo/Plus | FB105

Model Variant: FB6202   Change to: (default is FB6202)

Software Versions: Older versions | Factory releases | Factory and Beta | Factory, Beta & Alpha

2012-01-24
Current factory release
1.10.001 (Katya)

Release notes from Factory release 1.08.001 to Factory release 1.10.001

BGP

  • Vendor specific SNMP for BGP status

CQM

  • Correct for rare race condition leading to multiple graphs of same name

DHCP

  • Clear DHCP command now allows range/prefix to clear multiple entries
  • Option to kill a DHCP allocation from web interface (DHCP status) now
  • Change handling of BOOTP to operate as a REQUEST not DISCOVER so causing allocation of lease

Flash

  • Avoid flash fragmentation by deleting old images if necessary before saving new image.

L2TP

  • Internal change to RADIUS handling to reduce risk of watchdog under heavy load
  • Updated RADIUS to abort authentication request if session closed to reduce load if slow auth replies
  • Better "clear l2tp all", depending on speed of RADIUS accounting
  • Vendor specific SNMP for L2TP status
  • Added min-retry as a minimum session time before retrying an outgoing L2TP connection (default 10 seconds)
  • New platform RADIUS logic

Shaping

  • Fix incorrect handling of (legacy) tx-interval on shaper

SNMP

  • SNMP now has extra logical interfaces which are all named shapers in order, including relevant stats for a shaper.
2012-01-18
Previous factory release
1.09.001 (Jacynth)
[Withdrawn]
This release has been withdrawn.

Release notes from Factory release 1.08.001 to Factory release 1.09.001

BGP

  • Vendor specific SNMP for BGP status

DHCP

  • Clear DHCP command now allows range/prefix to clear multiple entries
  • Option to kill a DHCP allocation from web interface (DHCP status) now
  • Change handling of BOOTP to operate as a REQUEST not DISCOVER so causing allocation of lease

L2TP

  • Internal change to RADIUS handling to reduce risk of watchdog under heavy load
  • Updated RADIUS to abort authentication request if session closed to reduce load if slow auth replies
  • Better "clear l2tp all", depending on speed of RADIUS accounting
  • Vendor specific SNMP for L2TP status

SNMP

  • SNMP now has extra logical interfaces which are all named shapers in order, including relevant stats for a shaper.
2012-01-09
Previous factory release
1.08.001 (Isadora)
[Breakpoint]

Release notes from Factory release 1.07.001 to Factory release 1.08.001

  • Auto upgrade software not done if new software already in flash, stops a crash causing a loop.
  • Better error message on ip group name syntax check
  • Added link to upload new config on factory reset screen
  • Added link to upload new config on soft factory recovery screen

CLI

  • Changed show [bgp] route command to list where each route is directed.
  • Allow abort by pressing a key on the show routes command.
  • Tidied show dhcp command

CQM

  • CQM graphs now in alphabetic order
  • Shaper sharing system
  • Hourly rate line on CQM graphs

DHCP

  • Internal change to handling of DHCP server when searching for a suitable IP

FB105-config

  • Convertor making more sensible names for things like "24-7"

Firewall

  • Improved traceroute through mapped IPs

L2TP

  • Increased negotiation sessions to 4096
  • Made payload-table consistent - now defaults to 0 not (in some cases) "same as table"
  • Faster session clearing when using clear all
  • IP over LCP sending as RADIUS controlled flag (filter C)
  • Not picking L2TP endpoint as our IP if cross table tunnel - picks any IP from a subnet on same table
  • Added return of Proxy-State in platform RADIUS response
  • Added Tunnel-Medium-Type (IPv4/6) in platform RADIUS response
  • Added optional Juniper Context-Name response in platform RADIUS response (for BT 20CN session steering)
  • Added username hash based Tunnel-Preference in platform RADIUS response
  • Recognise BT specific "Subscriber provisioning failed" error and send clear cause 15 on RADIUS
  • More options for ordering the response on platform RADIUS
  • Faster LCP conf req on l2tp connect with no LCP
  • Additional debug added in L2TP/RADIUS code

PPP

  • IP over LCP rx handling added. I.e. LCP with code 4X or 6X assumed to be IP.

Profiles

  • initial state of profile with set="..." now uses that setting not initial="..." value

RADIUS

  • Fix platform radius proxy state return issue affecting relayed platform radius

Web control pages

  • Added reboot link to web pages, in "status" section for ADMIN level or higher
  • Added VRRP masters count to pre-shutdown message for reboot and s/w updates
  • Added new form for pcap dumping to file from browser (/pcap/)

XML

  • XML checking recognises that an empty list is not valid on a mandatory attribute
  • XML checking no longer reports issues with schemaLocation - they are now ignored
2011-11-15
Previous factory release
1.07.001 (Hermia)

Release notes from Factory release 1.06.004 to Factory release 1.07.001

  • Does not auto update and reboot if in factory reset recovery state

CLI

  • New show routes command not BGP specific
  • Show dhcp command layout fix

DHCP

  • DHCP client sets /32 routes for DNS servers provided

L2TP

  • Pressing a key on telnet command "clear l2tp all" stops clearing lines.
  • Increased L2TP neg slots to 1024
  • Support for RADIUS Framed-IP-Netmask mapped to L2TP PPP IPCP NETMASK (144)
  • L2TP client mode asks for DNS on PPP
  • Config change was unnecessarily restarting some L2TP sessions
  • L2TP failed tunnel timout reduced from 5 minutes to 1 minute
  • L2TP error response on duplicate tunnel ID to try and manage restart case better
  • Better logging of unexpected L2TP SCCRQ
  • Issue with L2TP clients when no hostname and no local system name configured

Web control pages

  • Using web interface diagnostics/routing could cause a crash
  • Showing associated routes on subnets, dongles, PPPoE, etc.
2011-11-03
Previous factory release
1.06.004 (Gemini)

Release notes from Factory release 1.05.001 to Factory release 1.06.004

  • Added memory usage to one second stats
  • Possible obscure issue with DHCP server code fixed - probably only when default dhcp server user (i.e. ip not set)
  • Added new show status command on telnet, and reformatted web status page
  • Ethernet port status shown on FB6000 now

CQM

  • Bug if graphs trying to scale to just under 4Gb/s, showed scaled at bottom end in error. Fixed.
  • Not including old (off screen) rate changes in max scale on graphs

DHCP

  • Additional options in DHCP client
  • Changed DHCP server to serve bricks IP as DNS server allowing it to relay, unless explicit servers set in config

Ethernet

  • Changed autoneg setting on ethernet ports to default to false if manually setting speed or duplex and not 1G

L2TP

  • Changed L2TP logging so relay sessions have same logging as incoming session at the time
  • L2TP config change was clearing tunnels if not using a hostname setting
  • Changed logic for logging L2TP to try and ensure relayed sessions log correctly
  • L2TP relay was dropping first packets exchanged
  • Periodic RADIUS accounting was incorrectly showing timestamp less any current dropped packets which could cause a slight discrepancy
  • Change of field name (username) not preserving old field (user-name) in l2tp-relay, fixed

Logging

  • Log email sending retry logic changed
  • Added much more debug for log-debug for logging email sending

Ping

  • Ping graphs can now use a host name

PPPoE

  • Default if no route= set to also set /32s to DNS servers as well as default route

RADIUS

  • L2TP RADIUS for PAP was using cleartext password as message auth (16 byte), changed to random.

Syslog

  • Added additional information to emailed logs

VRRP

  • Deleting an interface which VRRP master caused a crash

Web control pages

  • Improved lists of objects with sub objects present in config editor
  • General change to css, layout and menus, and new options for menu/banner controls
  • Extra information on DHCP client status page (subnets)
  • Change to allow you to stay logged in when clock first sets
  • Home page shows if system name is not set is this really should always be set, but is not actually a mandatory field
2011-11-02
Previous factory release
1.06.001 (Gemini)
[Withdrawn]
This release has been withdrawn.

Release notes from Factory release 1.05.001 to Factory release 1.06.001

  • Added memory usage to one second stats
  • Possible obscure issue with DHCP server code fixed - probably only when default dhcp server user (i.e. ip not set)
  • Added new show status command on telnet, and reformatted web status page
  • Ethernet port status shown on FB6000 now

CQM

  • Bug if graphs trying to scale to just under 4Gb/s, showed scaled at bottom end in error. Fixed.
  • Not including old (off screen) rate changes in max scale on graphs

DHCP

  • Additional options in DHCP client
  • Changed DHCP server to serve bricks IP as DNS server allowing it to relay, unless explicit servers set in config

Ethernet

  • Changed autoneg setting on ethernet ports to default to false if manually setting speed or duplex and not 1G

L2TP

  • Changed L2TP logging so relay sessions have same logging as incoming session at the time
  • L2TP config change was clearing tunnels if not using a hostname setting
  • Changed logic for logging L2TP to try and ensure relayed sessions log correctly
  • L2TP relay was dropping first packets exchanged
  • Periodic RADIUS accounting was incorrectly showing timestamp less any current dropped packets which could cause a slight discrepancy

Logging

  • Log email sending retry logic changed
  • Added much more debug for log-debug for logging email sending

Ping

  • Ping graphs can now use a host name

PPPoE

  • Default if no route= set to also set /32s to DNS servers as well as default route

RADIUS

  • L2TP RADIUS for PAP was using cleartext password as message auth (16 byte), changed to random.

Syslog

  • Added additional information to emailed logs

VRRP

  • Deleting an interface which VRRP master caused a crash

Web control pages

  • Improved lists of objects with sub objects present in config editor
  • General change to css, layout and menus, and new options for menu/banner controls
  • Extra information on DHCP client status page (subnets)
  • Change to allow you to stay logged in when clock first sets
  • Home page shows if system name is not set is this really should always be set, but is not actually a mandatory field
2011-09-22
Previous factory release
1.05.001 (Filippa)

Release notes from Factory release 1.03.001 to Factory release 1.05.001

ARP

  • Internal adjustment to queued packets waiting on ARP

BGP

  • Stopped announce of FE80::/10 when subnet has bgp="true"
  • No longer logging full BGP packet when discarded due to !allow-own-as or allow-only-their-as
  • Added additional per peer counters for ignored and filtered incoming updates

CLI

  • The show flash log command is now available to admin users
  • Added new command line to clear data pages in flash

Diagnostics

  • Tidy up the traceroute command to allow more than one attempt per hop, and some bug fixes
  • Access list check (command and web UI)

Documentation

  • Started work on addition information on config documenation

Factory default

  • Made factory default have local-only set true on http access

FB105-config

  • Various corrections to config convertor for latest releases
  • Improved fb105 config conversion for VLAN handling

Logging

  • Possible fix to issue causing occasional unexplained crashes
  • Bug where viewing logs on web pages could cause crash, fixed
  • Removed hex dump debug log of DHCPv6 - as cluttred interface debug logs and better done using pcap

PPPoE

  • Additional logging of PPPoE PAP/CHAP response message even if failed

Services

  • Added new access check for local-only on services. IMPORTANT - defaults to true for telnet, dns, timed, so you will need to set to false if you want remote access to these

SNMP

  • snmp was not access locked to routing table, fixed

Web control pages

  • Removed WebSite link as caused confusion, and made footer have link to FB website
  • Added configurable links on home page and fb105 conversion
  • Added optional CSS URL allowing customisation of control pages
  • Added ping/traceroute on web interface
  • Ping and traceroute now separate diagnostics
  • Show route now on web diagnostics menu
  • Web config edit has more information shown now, and change to some spacing.
  • Missing titles on lists of blackhole and nowhere routes
2011-09-09
Previous factory release
1.03.001 (Dimity)

Release notes from Factory release 1.01.002 to Factory release 1.03.001

  • TCP floods (e.g. http) could cause crash, fixed

Config

  • Changed default config - using LAN and WAN as interface and port group names and added more comments

L2TP

  • Changed to not debug log PAP passwords at all, but showing length of data sent (so length of password)

Logging

  • Documentation updated, and console log off/on commands now TROFF and TRON
  • log-starts logs start and stop of stats logging
  • Occasional crash in logging when lots of information is logged.

Profiles

  • Changed wording on logs for inverted profiles

Routing

  • Possible issue with watchdog failure being addressed

Web control pages

  • Heading on web logs saying which log report shown
  • Subnets listed in order
  • Icons redrawn
  • Changed page title to list name before serial
  • Manual s/w upgrade looks nicer now
  • Graph names as text on graphs list to allow searching in browser
  • Corrected icons for rule-set
  • Tweak factory reset menu
  • Additional per second stats for http access counts
  • Adjust timing on status check to try and ensure we see new s/w first time
2011-09-04
Previous factory release
1.01.002 (Bryony)

Release notes from Factory release 1.00.001 to Factory release 1.01.002

Config

  • Increase internal storage for config by 33%
  • Password now mandatory on user field, and error if blank and not using OTP
  • Added extra notes on localpref to explain highest value wins
  • Minor change to wording on web config
  • Added <blackhole.../> and <nowhere.../> as explicit routing objects rather than using <route.../> with no gateway.
  • as-path only on network object as was not in fact functional on route object
  • IPv6 addresses use lower case when output as a config view.

DHCPv6

  • Rebind handling corrected (was being ignored)

Documentation

  • Corrected description of interface object

FB105-config

  • Timezone fixes on config convertor

L2TP

  • Fixed DHCPv6 issue on L2TP which was only working on session numbers below 4096
  • Incorrect logging of LCP Init Rx, Last Rx, and Last Tx, fixed
  • Improved logging where incorrect length proxy challenge or response received on L2TP connect
  • Added extra checking on L2TP packets where hidden fields could encode invalid length
  • Made error for bad hidden field length non fatal - investigating how this is happening
  • Hidden fields stopped working on L2TP tunnels after two config changes after tunnel was established, fixed
  • Some internal rework of L2TP code, and answering ICMPV6 router solicitations over L2TP
  • Adjusted IPv6 RA for L2TP - now send periodically if IPv6 router solicitation previously received
  • Logging of CHAP accept/reject showed wrong length (correct length was being sent)

Logging

  • Adjusted email log sending to use CR+LF on all contents lines as per RFC2821, rather than just LF as is convention on linux system
  • Fix for rare case causing crash after emailing a log.
  • Email has boot date/time in text at top now
  • Emailed logs were re-sent on every config change, fixed
  • Changed syslog to use UDP non encrypted RFC5424 logging with microsecond precision. Affects all log lines as module name added
  • Added option to specify source IP for syslog messages

pcap

  • Added more useful error messages for malformed pcap requests
  • Can now use pcap to log l2tp session from the start based on calling line id, see documentation for details
  • PCAP giving better error messages

Ping

  • Ping setting on interface was not always starting the pings, and not stopped when config removed. Fixed

Profiles

  • Changed logic so "or" profile with no other settings and none of the "or" profiles match will fail not pass.
  • Corrected timeout/recovery logic
  • Added initial-state option on profiles
  • Profiles tracking ppp did not spot if a PPP went off because it was itself turned off by profile config
  • Changed logging for profiles so "still active" and "still inactive" logs are log-debug now

Routing

  • Correctly sending ICMP errors for dead end routes
  • Routing loop detection improvements
  • Minor change to internal routing/ARP cache functions to test a specific bug report.

TCP

  • TCP test port (4242) removed
  • Increased number of active TCP sessions

VRRP

  • VRRP use-vmac default changed to true

Web control pages

  • Changed headings on config edit boxes
  • Changed the sequence when downloading new code
  • Automatically redirects to status page after a short delay when new s/w loaded
  • Less margins on web pages
  • Changed breadcrumbs in UI to use :: not : as spacing, consistent with website
  • Slight changes to layout of software upgrade pages
  • Made breadcrumbs larger and easier to read
2011-08-01
Previous factory release
1.00.001 (Yves)

Release notes from Factory release 0.11.002 to Factory release 1.00.001

  • Launch release

Authentication

  • Users can now be restricted to a routing table.

Config

  • Subnet mtu states default based on interface.
  • Max portdef now 2, not 5.

Documentation

  • Alphabetic order for documentation of config.

L2TP

  • L2TP stack adjust
  • Possible bug with DHCPv6 on L2TP fixed

PPPoE

  • LCP negotiation now logged as log-debug
  • Did not do multiple PPP sessions on different ports if same session ID was being used, fixed

Profiles

  • Tidy wording on profile changes for new invert feature
  • Selecting fb105, ppp, route, and, or, vrrp, that have no entries now gives an error
  • Did not work checking vrrp state
  • Ping via explicit gateway now bypasses session tracking

VRRP

  • VRRP now has a default ID (42)
  • Now accepts DNS requests to VRRP address
  • DHCP now giving VRRP address as default DNS server not specified and not resolvers defined and VRRP is in use.
  • VRRP now has default VRID and the field is now optional

Web control pages

  • Changed "Subnet" icon to "Interface"
  • Timeout while editing config on web pages now fixed
  • Updated the link/message for s/w upgrades on status pages
  • Minor typos/changes on upgrade web page
  • Explains that routes with no gateway are blackhole routes.
  • Layout of share on rules tidied and comment field added.
  • route-override layout tidied.
  • List headings tidied.
  • Layout of DHCP server settings improved.
  • Platform RADIUS config tidied.
  • Subnet ttl now a hidden field.
  • Added some colour to lists of things in UI to make columns clearer.
  • Some help text improved.
  • Help link on config edit.
  • Tool tip on protocol says 1=ICMP, 6=TCP, 17=UDP
  • Add and Edit only on lists where order matters, else just Add at end.
  • Confirmed help link working in Web config edit
  • Profile link was not showing on status
  • Web config: Save and Cancel buttons.
  • Lots of tweaks, mosting UI web config improvements and IE9 support
  • Fix profile layout - was not showing all fields
  • Fix profile layout - was not showing all fields.
  • Static route tidy
  • Not showing bgp attribute by default as not usually relevant
  • Moved PPPoE settings under "Interface" and titled "PPPoE settings"
  • Move Ethernet and Port groups under "Interface"
  • Tidy up of config fields and web config edit
  • Typo in PPPoE status corrected
2011-07-19
Previous factory release
0.11.002 (Xavier)

Release notes from Factory release 0.09.002 to Factory release 0.11.002

  • External logging was stopping after a change of profile state, fixed

VRRP

  • VRRP3 implementation for IPv6 and sub second timing
  • New VRRP3 (IPv4/IPv6) and some bug fixes
  • Some more bug fixes, new web UI in place now, and VRRP3 working.
2011-07-18
Previous factory release
0.09.002 (Ulysses)
[Breakpoint]

Release notes from Factory release 0.08.049 to Factory release 0.09.002

  • test release, extra debug
  • Logs were restarting on config change
  • Odd error messages on reboot which could lead to issues upgrading - fixed

VRRP

  • VRRP logging using new logging system

Web control pages

  • UI updates - including a keep-alive to stay logged in while editing config
  • Change to CSS and layout of tables for comments
  • Major UI edit changes and re-styling
  • Various web UI changed, cache control improvements, not logging out while XML editing
  • Major improvements to web based config edit, and various minor enhancements
2011-07-08
Previous factory release
0.08.049 (Sherlock)
[Breakpoint]

Release notes from Factory release 0.08.001 to Factory release 0.08.049

  • Test low level changes to ethernet PHY communications timeout management to handle possible race conditions
  • Fixed DHCP issue which stopped reuse of expired allocations
  • New logging system started - not finished yet
  • new logging systeme started - some more work needed
  • New logging started
  • New logging system now handling email, more work to do but should be a safe build to try
  • New logging doing email better now
  • Corrected picking up MX 0 for emailed logs
  • Logging changes, and slight adjustment to BGP origin
  • Test build - may not be totally safe
  • Test build
  • Improved session logging
  • Various improvements since last beta

L2TP

  • Error on hidden fields over 30 characters on L2TP messages, fixed
  • Corrected M bit on some sent L2TP AVPs for relayed L2TP
  • Source filtering control mon RADIUS for L2TP
2011-06-07
Previous factory release
0.08.001 (Randolph)
[Breakpoint]

Release notes from Factory release 0.06.001 to Factory release 0.08.001

  • Factory release
  • Testing change to LCP echo timeout in case of major issues
  • Change for possible issue with fragments crashing session tracking code
  • More detailed controls of LCP echo rate and timeout per session. slow-poll deprecated
  • LCP rate and timeout per session in seconds, and change the timestamp on RADIUS stop to be last LCP response
  • Sending tunnel incoming name as Tunnel-Client-End in RADIUS access request and accounting to help track connections
  • Test build of NAT checksum changes
  • New CHAP-Password RADIUS response for tunnel relay password override
  • Corrected web/cli stats for outgoing sessions
  • Minor changes, and some experimental extra interface counters on SNMP.
  • Added SNMP (unwalkable) extra interface stats of IPv4 and IPv6 specific data. .410 and .610 for IPv4/Ipv6 of .10, and same for .11, .16 and .17
  • tidied up multiple request SNMP
  • Corrected LNS damping issue
  • Fix for remote-ip in matching rules on l2tp
  • Fix config bug, and wrap up recent l2tp match relay syntax changes
  • Test build, correcting some documentation
  • Minor changes to l2tp commands
  • Test build for Ben
  • Candidate factory release
  • Canditate factory release

L2TP

  • Extra L2TP NSN conditional setting for GGSN use
  • L2TP status on web interface
  • New local auth options for L2TP, untested
  • Local auth on L2TP tested, added extra debug
  • L2TP Proxy PAP handling
  • L2TP Proxy PAP handling (incoming and relayed)
  • L2TP congestion management (damping) bug fix
  • Shaper updates (mainly for L2TP usage)
  • Changed L2TP match to make relay clearer and local pref allow remote-ip
  • New PPPoE server / BRAS mode for L2TP, and various minor config tweaks
  • Fixes on L2TP command line and addition session and tunnel specific XML http requests for L2TP status
  • L2TP XML http tweak
  • Tidied the URL coding for L2TP http xml requests
  • Additional checks on L2TP status commands
2011-03-11
Previous factory release
0.06.001 (Marmaduke)

Release notes from Factory release 0.02.001 to Factory release 0.06.001

  • Factory release
  • PPP DHCPv6 prefix delegation for initial testing (no DNS yet)
  • Faster reboot time
  • Sending DHCPv6 DNS responses as well
  • config load crashing if FB105 routes on dead tunnel
  • fb105 config causing config edit problem
  • DHCP server error recently introduced now fixed
  • Fixed DHCP client, and reqworked some ARP/ND code
  • Slight changes on IPv6 ND timeouts when no response, and also on IPv6 RA options for M and O bits
  • Corrected ARP issue introduced in previous version
  • Some significant internal changes, but main impact is subtle changes to subnets are now picked up correctly, and you can set gateway=' on a dhcp client to not pick up a gateway now
  • Minor tweaks on DHCP server side
  • Changed config main page layout, tweak to hopefully fix CQM average latency, additional debug added
  • New status reports on web admin pages, more to come
  • minor tidy of new status pages
  • Issue with handling of some reply packets fixed, e.g. DNS resolver function
  • Changes to IPv6 ND handling for FE80::/10 LL addresses, was affecting windows machines
  • Session tracking on web interface
  • Changed source to source-ip in profiles for pinging. Some prototype web config not finished let. Added profiles to FB6202.
  • Minor changes to screen layout and graphics
  • Added new experimental web config editor (for users set to level DEBUG) for testing/feedback
  • Web config initial release
  • IE6 fix for checkboxes
  • Candidate factory release. Also, IPv6CP timeout on PPP.
  • Factory release candidate - new web config
  • Web config not working on all variants, fixed
  • Tidy up of some web config and added profiles to subnets
  • Slight alteration for session tracking and firwalling to an interface where there is no route to host, should mean fewer lingering sessions. Also added special interfaces to web config.
  • Slight alteration for session tracking and firwalling to an interface where there is no route to host, should mean fewer lingering sessions. Also added special interfaces to web config
  • Factory release candidate
  • Test

Authentication

  • OATH/OTP login feature added
  • OATH/OTP update - lockout after failed attempts, etc

L2TP

  • Minor update to tunnel MTU on relayed L2TP
  • Checking fixed on DHCP via L2TP/PPP interface, caused fatal error before
  • Minor change to an L2TP parameter for GGSN use

VRRP

  • Change to handle unexpected VRRP packet via no ethernet interfaces

Web control pages

  • New web based status functions started, subnet list is only one so far
  • Various minor UI changes
2011-01-23
Previous factory release
0.02.001 (Inigo)

No changes reported for this release note.