SonicOS/X 7.0.1 Release Notes

Version 7.0.1-5100 March 2023

March 2023

This version of SonicOS 7.0.1 (7.0.1-5100) is a maintenance release for currently shipping NSsp 15700 platforms and resolves issues found in previous releases.

Supported Platforms

This release applies only to the NSsp 15700 platform.

For information about the latest release related to other platforms, please see Version 7.0.1-5111 April 2023.

Resolved Issues

Issue ID Issue Description
GEN7-28170 Appflow Reports displays the incorrect number of threats for GAV, Anti-Spyware, Intrusion Prevention, and Applications.
GEN7-31592 Opening up a new tab by right-clicking on an existing browser tab showing Interfaces and then clicking Duplicatemay display the error Invalid authentication: SN and EPAID do not match.
GEN7-32232 The VPN tunnel interface may periodically become inactive with IKE response packets dropped due to IKE packets from the stack not allowed in Policy Mode.
GEN7-32518 Slow transfer rates may be experienced when using TFTP.
GEN7-32882 Slow web traffic over IPSec VPN may be experienced with ESP packets dropped by the remote firewall because of an error in the checksum when the tunnel VPN is established on the slave blade of the device when management traffic is being used.
GEN7-33499 Application Security Policies may not function correctly when App Group indexes are not set correctly when objects are first created after registration.
GEN7-33612 A Guest account may be able to access the internet after the account session time has been expired
GEN7-33643 When editing the administration privilege of local users, the updates are not displayed on Local Users page.
GEN7-33748 When Virtual MAC is enabled, during transition from primary to backup in a High Availability configuration, the standby appliance uses the shared IP to generate ARP broadcasts.
GEN7-33848 SlowTFTP traffic may be experienced when traversing the firewall. Option ACK messages are dropped by the firewall when received on different blades than the Read Request Forward blade.
GEN7-34183 In a High Availability environment, the default routes for the directly connected interfaces are not synchronized to the secondary device.
GEN7-34397 SNMP packets are dropped with the error NAT policy generate unique remap port failed due to incorrect multi-blade traffic handling for SNMP traffic.
GEN7-34773 DPI-SSL may intermittently not be enforced.
GEN7-34774 The Don't redirect unauthenticated users to log in setting in the Action Profile object does not function as expected. Unauthenticated users are not bypassed from user-specific policies.
GEN7-35294 Security Policy Block Page for Website Category blocking for authenticated user displays different Security Policies instead of the higher- priority Security Policy for Authenticated User Group.
GEN7-35491 The firewall may not initiate Single Sign-on (SSO) consistently on denied websites when the Zone- based SSO is set to Enforced.
GEN7-35786 The sorted order of items is incorrect when sorting NAT policies by Name, Created, or Updated.
GEN7-35966 Single Sign-on (SSO) was not triggered for SSO enforcement before detecting that it is needed by the policies.
GEN7-36684 A design change now allows special management (no user policy required) only using the MGMT port on appliances that do not have a management port. For the appliances that have a management port, the user will need to add an explicit management rule to allow management service on a non-management port. Administrators must create an allow rule to allow management services using non-management ports (such as X0 and X1) and enable the corresponding management service on each of the interfaces.
GEN7-36980 ICMP traffic fails over a numbered tunnel interface when the packets are larger than 1472 because the remote firewall receives an incorrect checksum.
GEN7-37018 When an LDAP user without administration privileges attempts to log in from a LAN, the error message Unknown error is displayed instead of a more specific reason, such as not enough privilege.
GEN7-37069 Cannot export Security Policies to a CSV file.
GEN7-37070 Sorting NAT Policies by Hits and other new columns does not function as expected.
GEN7-37134 Under some conditions, Content Filtering Service (CFS) DNS reply handling and request time out ,which can trigger conflicts in the handling of cache timers and cause an unexpected restart of the appliance.
GEN7-37633 Connections fail over SSL-VPN with users using Two-Factor authentication in addition to RADIUS authentication.
GEN7-38154 SonicOS Stack-based Buffer Overflow Vulnerability. For more information, refer to CVE-2023-0656.

Additional References

The following additional resolved issues in this release are listed here for reference:

GEN7-24931, GEN7-27414, GEN7-28768, GEN7-29045, GEN7-29907, GEN7-31205, GEN7-31255, GEN7-31307, GEN7-31354, GEN7-31779, GEN7-32451, GEN7-32452, GEN7-32577, GEN7-33185, GEN7-33349, GEN7-33505, GEN7-33628, GEN7-33637, GEN7-33697, GEN7-33878, GEN7-34011, GEN7-34168, GEN7-34186, GEN7-34209, GEN7-34263, GEN7-34488, GEN7-34824, GEN7-34842, GEN7-34884, GEN7-34967, GEN7-35037, GEN7-35162, GEN7-35174, GEN7-35499, GEN7-35565, GEN7-35609, GEN7-35621, GEN7-35646, GEN7-35648, GEN7-35801, GEN7-35826, GEN7-35967

Known Issues

Issue ID Issue Description
GEN7-31899 The configuration on the DOS Policy page cannot be edited.
GEN7-32261 OSPFv3/RIPng]OSPFv3/RIPng cannot be established over trunked VLAN or sub-VLAN interfaces.
GEN7-34690 The Resolved Address is not displayed when the domain is resolved when using a IPv6 DNS server.
GEN7-35781 Adding an ECMP route with Tunnel VPN as the last interface fails when the Gateway Number is either 3 or 4.
GEN7-36708

Unable to load a build or export a file when performing out-of-band management using the MGMT port.

Used a different port for out-of-band management or the system being used needs to be on the same subnet as the MGMT port.

GEN7-37532 The active unit in a High Availability configuration shows the same MGMT IP for both the Primary and Secondary appliances.

Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

  • Hidden
  • Hidden

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.
  • Hidden
  • Hidden