SonicOS/X 7.0.1 Release Notes

Version 7.0.1-5083 September 2022

September 2022

This version of SonicOS 7.0.1 (7.0.1-5083) is a maintenance release for currently shipping NSsp 15700 platforms and resolves issues found in previous releases.

Supported Platforms

This release applies only to the NSsp 15700 platform.

For information about the release related to other platforms, please see Version 7.0.1-5080 September 2022.

Resolved Issues

Issue ID Issue Description
GEN7-29975 The ESP packet is dropped by the remote firewall because of an error in the checksum when the tunnel VPN is established on the slave blade of the device when management traffic is being used.
GEN7-30535 Changing the setting of the Enable checkbox for a Syslog Server entry may cause a full preference synchronization to the backup unit in an High Availability environment.
GEN7-30559 The firewall may automatically restart when importing a large number of LDAP users.
GEN7-30710 If an SSH session goes into configuration mode, and performs a commit for another configuration while a prior SSH session configuration commit is still in process, a deadlock state may occur.
GEN7-30858 When selecting an interface to reserve for multi-instance, the error message Command 'reserve interface Xnn' does not match where nn = interface you want to reserve. may be displayed. Subsequent attempts to select the interface succeed without producing the error.
GEN7-31091 SSO via Capture Client using Endpoint Security Enforcement login is not working when SSO login via Endpoint Security is enabled. The user login authentication page is displayed when accessing any website. The status of the User login session is shown as Inactive with SSO/Endpoint Security.
GEN7-31119 On the Packet Monitor and Connection Monitor pages, some of the initiator and responder routes are swapped in the display.
GEN7-31487 Synchronization of OSPF route updates from master to slave blades may fail.
GEN7-31807 Default address objects cannot be deleted for interfaces that are not assigned.
GEN7-31855 Changing the OSPF timer interval changes the authentication password and causes OSPF to stop operating.
GEN7-31911 Connectivity issues may be experienced due to inconsistencies in the OSPF route blade synchronization.
GEN7-31919 Using the boot current firmware with a local backup configuration may fail in a High Availability environment. After the firewalls restart, the configuration has not been updated.
GEN7-32062 SNMPv2 packets are being dropped as IP Spoof, but SNMPv3 packets are not.
GEN7-32096 Information sent to Analytics is reporting only one-fourth of the Active Connections and App Bandwidth than what is displayed directly in the System Monitor data for the firewall.
GEN7-32102 The Capture ATP scan History may intermittently disappear on a firewall in High Availability environment.
GEN7-32117 Connections may be dropped in a High Availability environment due to dynamic route blade and High Availability synchronization issues.
GEN7-32118 After failover in a High Availability environment, the secondary unit is not able to maintain OSPF adjacency with its peers and all routing entries may be lost.
GEN7-32129 After disabling source port remap under NAT, a firewall may drop traffic with the error NAT policy generate unique remap port failed. Traffic originating from the X0 interface works correctly for TCP, but drops with the same error for ICMP. Traffic from other interfaces or VPN do not work for TCP or ICMP. (The option was removed from multibladed platforms.)
GEN7-32197 OSPF remains in an inactive state and the Designated Router fails to initiate link-state advertisement (LSA) after failover in a High Availability environment.
GEN7-32244 Some OSPF routing entries persist even after relevant OSPF neighbor has been inactive for a period of time.
GEN7-32253 Connectivity issues may be experienced due to inconsistencies in the OSPF route blade synchronization.
GEN7-32324 Adding a chassis secondary IP on a Secondary firewall produces the error message Chassis IP and Secondary Chassis IP overlap ,
GEN7-32661 In a High Availabilty environment when performing Failover/Failback, that OSPF Originate Default Route may stop working.
GEN7-32691 Scheduling a backup for FTP settings may cause a file to be generated with 0 Bytes.
GEN7-32779 Configuring a static IPv6 WAN interface produces the error message Error: Command 'dns primary 2002:4860::8888' does not match. A condition is missing to disable the DNS fields for static WAN interfaces.
GEN7-33236 Sending TSR/Settings by FTP via Mixed Schedule did not trigger the transfer if the one-time schedule was not matched.
GEN7-33365 Nine-digit Common Vulnerabilities and Exposures (CVEs) are missing or invalid under Object -> Profile Objects -> Intrusion Prevention -> Intrusion Prevention Objects.
GEN7-33371 The Factory Default Configuration button does not function.
GEN7-33473 The CFS Confirm/Passhrass action does not redirect for websites that use a custom HTTP/ HTTPS port.
GEN7-33559 Information sent to Analytics is reporting only one-fourth of the Active Connections and App Bandwidth than what is displayed directly in the System Monitor data for the firewall.
GEN7-33630 Adding a new Security Policy fails to synchronize between the Active firewall and Standby firewall in a High Availability environment because the index value was not being returned.
GEN7-34409 NAT Lookup fails after SonicOS restarts for NAT Policy when the NAT LB probe is in a failed state because it tries to create its own Network Monitor (default) policy, but its name conflicts with an existing NetMon policy. When this occurs, the NetMon policy creation fails, causing the NAT Policy to become invalid.
GEN7-35041 The last character of syslog messages and log messages is missing.

Additional References

The following additional resolved issues in this release are listed here for reference:

GEN7-29143, GEN7-30911, GEN7-31421, GEN7-32097, GEN7-32874, GEN7-35723

Known Issues

Issue ID Issue Description
GEN7-34690 The Resolved Address is not displayed even though the domain is resolved when using IPv6 DNS server.
GEN7-35600 When logging in with limited, read-only, or guest administrator user credentials, an error is displayed when accessing the Local User and Groups page.
GEN7-35640 Traffic is not distributed as expected after a failover when using source and destination IP address binding in Round Robin-based WAN Load Balancing.
GEN7-35769 DNS Diagnostic does not use static DNS Proxy Cache entries when DNS Proxy is enabled when Enforce DNS Proxy For All DNS Requests is enabled.
GEN7-35781 Adding an ECMP route with Tunnel VPN as the last interface fails when the Gateway Number is set to 3 or 4.

Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

  • Hidden
  • Hidden

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.
  • Hidden
  • Hidden