Watchguard XTM 1050, XTM 2050, XTM 2 Series, XTM 3 Series, XTM 5 Series, XTM 8 Series – Fireware XTM OS 11.7 Build # 359571
New features in Fireware XTM v11.7 Build # 359571
- With Policy Grouping, you can create and apply tags to policies and then use the tags to easily filter the list of policies and streamline the number of policies in the policy list at one time. This is particularly helpful for users who have complicated device configuration files with many policies to manage. Policy tags are not available for devices running older versions of Fireware XTM OS (pre-v11.7) or for configuration files created for pre-v11.7 devices.
- You can now group your XTM device physical interfaces together to work as a single logical interface. With link aggregation, you can increase the cumulative throughput of your XTM device beyond the capacity of a single physical interface, and provide redundancy if there is a physical link failure.
WebBlocker Cloud Option with Websense
- New support for the Websense URL database in the cloud. Now, you can use the Websense cloud, with over 100 content categories and many new categories, as your WebBlocker Server. Or, if you prefer, you can continue to use a WebBlocker Server with the SurfControl database and 54 content categories. For new WebBlocker activations, the Websense cloud configuration is the default setting. When you upgrade to Fireware XTM v11.7, WebBlocker continues to use the previously configured WebBlocker server. After you upgrade, you can update the WebBlocker configuration to use the Websense cloud for WebBlocker lookups. When you switch between WebBlocker server options, the management software can automatically convert the currently blocked categories to similar categories in the other database.
WatchGuard Mobile VPN App for iOS and Android
- New apps make it easy for end users to build a VPN connection from iOS and Android devices. The administrator of the XTM appliance can securely email a file with the required configuration details, which the user can simply click to install the VPN profile after the app is installed. For Android, we now provide a WatchGuard client for Mobile VPN with IPSec. The WatchGuard VPN app for iOS operates with both Mobile VPN with IPSec and Mobile VPN with L2TP connections. The iOS app will be available in the Apple store later this month. The Android app will be available in the Google Play app store later this month as well.
Mobile VPN with L2TP
- Support for a new type of Mobile VPN connection – L2TP (Layer 2 Tunneling Protocol) v2, as described in RFC 2661.
IPS and Application Control Support in the HTTPS Proxy
- IPS and Application Control security subscriptions are now fully supported by the HTTPS proxy to allow the XTM device to scan for IPS and Application Control signatures on the decrypted HTTPS content stream.
Other new features include:
- New web interface for CA Manager – The CA Manager Web UI has moved to the Log and Report Manager Web UI. The combined web interface has been renamed to WebCenter.
- New web UI to manage quarantined email messages – New look and feel for the Web UI that email recipients use to see and manage their quarantined email messages.
- Support for more than four external interfaces on your XTM device
- Hardware Health Monitoring – Your XTM device now self-monitors the health of specific hardware areas and sends an email notification if it detects a problem in those areas.
- FireCluster support with wireless devices – You can now configure FireCluster for XTM 2 Series Models 25 and 26 Wireless and XTM 33 Wireless. Only active/passive mode is supported for wireless devices.
- New DHCP options for VoIP support – You can now configure your XTM device to support DHCP options 66, 67 and 150.
- Per user/group and concurrent login support – You can now set the number of concurrent, authenticated sessions you want to allow, and you can control this on a per user or per group basis.
- Wireless Hotspot external authentication support – You can optionally configure the wireless hotspot on the XTM device to redirect hotspot users to an external web server before they connect to the wireless network.
- IPv6 enhancements – We add support for IPv6 stateful firewalling for these networking and security features:
1.1. IPv6 host/network/address ranges in From and To lists in policies
1.2. IPv6 addresses in blocked sites and blocked site exceptions
1.3. Blocked ports applies to both IPv6 and IPv4 traffic
1.4. TCP SYN checking applies to both IPv6 and IPv4 traffic
- Branch office VPN failover to modem – If you have enabled serial modem failover on your XTM 25, 26, 3 Series, or 5 Series device, you can configure the branch office VPN to fail over to a modem if all external interfaces cannot connect.
- Stream packet capture data to a file – A new advanced option to stream packet capture data to a file.
- Global Dynamic NAT enhancements – When you configure a global dynamic NAT rule, you can now set the source IP address to use
- IPS Scan mode – You can now select between two scan modes, Fast Scan and Full Scan. The default setting is Full Scan, which directs IPS to scan all packets. To improve performance, you can select Fast Scan, which directs IPS to scan fewer packets. Fast Scan mode greatly improves throughput for scanned traffic, with a slight drop in IPS effectiveness.
- New Management Tunnels – New support for remote XTM devices behind a NAT gateway
Resolved Issues in Fireware XTM v11.7 Build # 359571
- WFS firmware component files and management applications are no longer bundled with WatchGuard System Manager 
- A problem that caused the XTM 1050 10 Gigabit Fiber ports to fail has been resolved 
- This release resolves a problem that caused a kernel crash when a reset packet is sent out through the 10 Gigabit Fiber ports on the XTM 1050 and XTM 2050 [70384, 70296]
- When an IP address is added to the Temporary Blocked Site list by the administrator through the Firebox System Manager > Blocked Sites tab, the expiration time is no longer reset when traffic is received from the IP address 
Proxies and Subscription Services
- File downloads no longer stall when you use an HTTP packet filter policy with IPS 
- The SIP ALG now supports REFER method for call transfers 
- The IPS deny message contents have been improved 
- We have improved the scand daemon so that it restarts faster in the event of a crash
Logging and Reporting
- You can now show more than 5000 lines of log messages in Firebox System Manager 
- The contents of the XTM Configuration Report have been localized for both viewing and printing into all languages supported by the Fireware XTM Web UI 
- The behavior of the Report Server Maximum Database Size setting now matches that of the Log Server, and prevents the Report Server database from filling the disk partition 
- Log collector no longer crashes when it reaches the 2GB virtual size limit on 32-bit Windows systems 
- If you manually created dynamic routing policies in Fireware XTM v11.5.x or earlier, the To and From lists in these policies are no longer cleared when you upgrade to v11.6 or v11.7 
- The SNMP process is now automatically restarted if it becomes stuck in a dormant state 
- The IGMP_Max_Membership setting for OSPF has been increased to support a large number of VLANs with dynamic routing 
- This release resolves a problem that caused the master in an XTM 2050 FireCluster to go into an idle state when you added a new interface 
- The Terminal Services TO Agent now works correctly when used in an active/passive FireCluster [70098, 69944]
- The 5GHz Wireless band now works correctly with channels 36, 40, 149 or 165 
Branch Office VPN
- Managed BOVPN tunnels now include support for optional 1-to-1 NAT 
- The amount of time it takes to fail over from a leased line to a branch office VPN with OSPF or BGP has been reduced 
- Frequent mobile VPN client log in/log out events no longer cause a low memory condition on the XTM device 
- When you use a native Cisco IPsec iOS client for Mobile VPN with IPSec, the client no longer disconnects after three minutes of idle time 
- If you set the diagnostic log level for Mobile VPN with SSL traffic to “debug” level, log messages now correctly display in Firebox System Manager > Traffic Manager 
- You can now correctly establish a Mobile VPN with SSL connection from a Windows-based computer when the Windows system account is Chinese 
- A continuous FTP session over a Mobile VPN with IPSec connection is no longer terminated if an IPSec rekey occurs during the FTP transfer 
You can download 11.7 Build # 359571 from Watchguard Support Portal by logging in to your account.Follow @aid_in_it