Artemis: Goddess of the hunt, wild things, and the moon. Protector of the young. [ Source: http://en.wikipedia.org/wiki/List_of_Greek_mythological_figures (2010-02-12) ]
| Item | Type | Details |
|---|---|---|
| Authentication | Enhancement | Updated wording on domain membership screens to make it clear domain membership is only required for NTLM authentication. |
| Advanced Interface Management | Fix | Previously it was not possible in some circumstances to change the role of some interfaces that should be configurable. This has been fixed. |
| SMTP Access Control | Enhancement | Handle the case when DNS isn't available when SPF updates are applied for allowed and/or denied hosts. |
| Windows BIC Agent | Fix | Previously if a remote site presented an exceptionally large SSL certificate that was to be SSL inspected, the SSL inspection module would drop the TCP connection, requiring the browser to reconnect. This has been addressed. |
| Item | Type | Details |
|---|---|---|
| Content Scanning | Enhancement | There is now a Time of Day criteria available in Content Scanning for SafeChat applications. This allows matching of rules based of the time of day the activity happens. For example, a rule can be created to allow chatting about a specific subject only during specific hours of the day, and blocked the rest of the time. |
| Content Scanning | Enhancement | Criteria can now be created for SafeChat applications that match based on a users group membership. This will be the same even if the user is using the BIC Agent, and they have no contact with the management Netbox. The BIC Agent will cache a users group membership until next time it can connect. |
| BIC Agent (Windows) | Enhancement | The Windows BIC Agent now better supports user switching for sites that have multiple users on a single PC. This can optionally be tied in with Internet Auth to have a user automatically log in or log out based on who is active at the terminal. |
| Local DNS Server | Enhancement | The internal Netbox DNS Server now supports names that violate RFC 952 (e.g.: names with an "_" in them). These can be added just as other names could be added previously. |
| Bridge Mode Interfaces | Enhancement | When a Netbox is configured as an Ethernet Bridge, there is now an option to hard set the Ethernet interface speeds. This is a requirement on some sites where the existing networking infrastructure does not follow accepted Ethernet speed negotiation standards. This should only be used if absolutely necessary as should the infrastructure be updated in the future, it may become hard to diagnose why things are not performing as expected. |
| Item | Type | Details |
|---|---|---|
| BIC Agent | Enhancement | It has been discovered that some home routers that run a DNS server do not conform to the standard and do not respond to TXT or SRV DNS requests. The BIC Agent uses these types of records for various services as they should be available as it is part of the very early specification. However due to these faulty devices the BIC Agent will now find work arounds for the network it is running in, including using alternative DNS servers if the currently configured OS ones are not working as they should. If the agent has had to fall back to alternative DNS servers, it will periodically check to see if the OS ones are working (e.g: if the user has changed networks), and if so, start using them again automatically to increase performance. |
| BIC Agent (Windows) | Enhancement | The BIC Agent now supports HTTP Pipelining used by some browsers to increase performance (generally it is off by default). This is now supported for both HTTP and HTTPS sites. |
| Content Scanning | Fix | Some emails that had an invalid encoding (typically spam), would cause text matching rules to not match. If an invalid encoding is detected, the Netbox will now fall back to using UTF-8 (which more closely matches what an email client does) for text searching. |
| Traffic Dump | Fix | The Traffic Dump tool under Administration > Network Tools will now work correctly when saving to a file with very few packets. Previously if the delay between packets was too large the web connection would time out. |
| Item | Type | Details |
|---|---|---|
| 802.1x Pass Through Authentication Integration | Enhancement | The Netbox can be configured to integrate with most 802.1x devices (including WiFi access points and managed wired switches) using RADIUS Accounts information. This provides the ability to have pass-through authentication with any device that supports 802.1x, including iOS and Android devices. This is also ideal for Bring Your Own Device (BYOD) sites who have a lot of users bringing their own devices onto the network, a user can use their normal directory server credentials and have any policies and reports applied to them as an individual. |
| Data Browse Screens (Network Monitoring, and Denied Activity) | Enhancement | Real time interactive reporting and scheduled reports can now optionally select users based on group membership. This is ideal for example to add just one specific group/department to a report that is automatically sent to the department head on a regular basis, while still sending the full report to the IT manager and organisation board. All relevant data browsing screens have this available as another criteria type. |
| Users and Groups | Enhancement | Groups now can be named with purely numbers. This allows matching against external authentication providers that may have groups that are only numbers. (Please note: group uploads with only numbers are not supported as this is ambiguous as to if it is referring to a group name or a group ID). |
| SMTP Split Delivery | Enhancement | For sites who have multiple mail servers each with different users for the same domain, the Netbox can now intelligently deliver messages to the correct server. For example at a school site, there may be a different server for the teachers vs the students. The Netbox (using RAV) will ask each server who is responsible for a specific email address, and deliver to the correct server. This requires no uploading of user accounts or directory lists to the Netbox, it is completely automatic. |
| Item | Type | Details |
|---|---|---|
| Internet Authentication | Enhancement | For systems that have not yet authenticated with the Netbox the attempts to authenticate them using pass-through authentication are rate limited. The minimises load on internal authentication servers which can get overwhelmed if to many devices are constantly trying to access the internet, but are always failing. |
| Definition Updates | Enhancement | Definitions (for AV, spam and other services) are now updated using a variety of channels, including HTTPS over an upstream CONNECT proxy. This will mean that sites that are behind very locked down upstream firewalls and proxies will be far more likely to stay up to date in real time. |
| Management Tunnel | Enhancement | The tunnel that the Netbox establishes when running behind a firewall now tries additional methods to avoid getting blocked, including working over an upstream CONNECT proxy. Additionally it will also try more regularly to make updates come through more rapidly. |
| SMTP Server | Enhancement | The Netbox SMTP server can now be configured to trust hosts based on their SPF records (rather than using host names or IP's). This is ideal for external mail servers that need to relay mail via the Netbox, but can not use authentication, and do have SPF records published for their relevant IP addresses. |
| Proxy Authentication Whitelist | Fix | Previously when an entry was added to the direct proxy authentication whitelist, it would also be excluded from filtering. Now all URL's are filtered, even if there is no attached user name. For sites with a default block configuration, this may require a URL filtering policy to be created for these specific URL's to be allowed out. |
| Item | Type | Details |
|---|---|---|
| Lotus Connections | Enhancement | SafeChat now supports Lotus Connections forums, for both hosted (Lotus Live) and internally hosted sites. |
| Proxy Statistics | Enhancement | There is now a new page accessible under Administration > Proxy Stats that provides live information on the proxy performance, and where bottle necks may be. This includes ratio of cache hits to misses, external authentication providers (e.g.: NTLM) and a grouping by response times. |
| BIC Agent | Enhancement | The services the BIC agent runs are now named to better match their function (on both Mac and Windows). |
| Item | Type | Details |
|---|---|---|
| SafeChat custom base URLs | Enhancement | It is now possible to manually enter additional base URL's for specific SafeChat applications. For applications that can be hosted on internal servers, (e.g. Lotus Connections), the custom site URL can be entered here. This also applies to external applications with a custom external URL (e.g.: Google Apps). |
| Category Web Filtering | Enhancement | The internal services have been optimised even further to further improve performance and minimise memory utilisation. |
| BIC Agent (Mac and Windows) | Enhancement | Further hardening against tampering. Additional alerts are also produced if tampering is detected on either Mac or Windows. |
| Item | Type | Details |
|---|---|---|
| CONNECT Proxy | Enhancement | It is now possible to exclude remote sites from SSL inspection, while still using the upstream CONNECT proxy. Previously white listing one would white list the other. |
| Item | Type | Details |
|---|---|---|
| Kernel | Enhancement | Additions to the operating kernel to support additional hardware in selected regions. |
| Malformed Email Parsing | Enhancement | Improve the handling of malformed emails so the Netbox better detects spam messages. |
| Definition Downloads | Enhancement | When running behind an upstream CONNECT proxy, downloads will be attempted from both HTTP and HTTPS sites to prevent filtering by the upstream proxy. |
| Traffic Shaping | Fix | Matching traffic in some configurations did not work correctly previously, this has been addressed. |
| Item | Type | Details |
|---|---|---|
| IDS/IPS | Fix | Prevent duplicate entries on the IPS signature configuration screen for languages other than English. |
| CONNECT Proxy | Fix | In some configurations of the CONNECT proxy HTTPS inspection would not work correctly for unauthenticated users. |
| SSL Inspection | Enhancement | Automatically update SSL inspection certificates if they are about to expire or are invalid for the site. |
| Item | Type | Details |
|---|---|---|
| User Interface | Enhancement | Updates to user interface for languages other than English. |
| Item | Type | Details |
|---|---|---|
| Proxy User Interface | Enhancement | Added a new Proxy Statistics page under the Administration section of the user interface. This page shows statistics about recent usage and performance of the proxy server. This can help pin-point performance issues. |
| Mac OS X BIC Agent | Enhancement | The BIC Agent on OS X will update certificates if required on the host at boot time, instead of just on installation. This will reduce complexity in some deployments where the installer isn't used to deploy the BIC Agent or new users are regularly added to the system. |
| Upstream Proxy | Enhancement | The CONNECT proxy is now supported when the Netbox is deployed in Ethernet bridge mode. |
| Upstream Proxy | Enhancement | There is a new configuration option under the upstream CONNECT proxy to allow the selection of the ports to redirect to the upstream CONNECT proxy. Previously only network could be excluded. This is ideal for situations where the upstream proxy only supports limited ports (eg: port 80 and 443). |
| URL Filtering Test Page | Fix | The Test URL page no longer fails for IP-based policies if only some of the sample criteria are entered (it did work as expected when all criteria were entered). |
| Item | Type | Details |
|---|---|---|
| BIC Agent | Enhancement | When the BIC Agent is used on home networks where a consumer gateway device does not respond correctly to TXT and SRV DNS requests, the BIC Agent will disregard the router's DNS server and will go directly to public internet DNS servers. (We encourage any users who are aware they have a router with a faulty DNS server to report it to their provider.) |
| Category Web Filtering | Enhancement | The Category Web Filtering database has been upgraded to use a newer, more efficient, method of categorisation. This should bring both efficiency and speed increases. Please note that this will require a new complete download of the database after the update of the Netbox. |
| Upstream CONNECT Proxy | Enhancement | The CONNECT Proxy may now take a username and password to use to authenticate with an upstream proxy server. |
| Logging and Reporting | Enhancement | Fixed a corner case where, in some rare situations, the wrong policy (Default URL filtering policy) was being reported in the block logs (the correct policy was applied however). |
| Item | Type | Details |
|---|---|---|
| Proxy | Enhancement | The proxy now has the option to, when configured under Configuration > Web Proxy > Record full URL in proxy logs, provide all GET parameters in the proxy logs visible under Administration > View Logs > Web Proxy. This remains off by default as it may have privacy and legal implications is some jurisdictions. |
| URL Filtering | Enhancement | Added the ability to see which Policy will be matched with any combination of URL, Group and IP. This allows for very easy testing of policies right from the user interface. |
| SafeChat | Enhancement | Facebook private messages with attachments can now be filtered. |
| URL Filtering | Enhancement | Performance and efficiency enhancements for group matching have been implemented in URL Filtering. |
| Item | Type | Details |
|---|---|---|
| AV Content Scanning | Enhancement | It is now possible to remove expired licenses for specific AV products. As licenses would not replace existing licenses, expired licenses would remain accessible without this fix. |
| Item | Type | Details |
|---|---|---|
| Categroy Web Filtering | Enhancement | Minor enhancements to the cloud lookup process to allow more simultaneous lookups. |
| Item | Type | Details |
|---|---|---|
| Categroy Web Filtering | Enhancement | When using the local database with category web filtering, if a URL is not available in the local database and the lookup goes to the cloud, the filtering service now waits for the response rather than queuing it in the background and immediately returning "uncategorised" for a few seconds. Now if a URL is already classified in the cloud, the category will be returned before the page loads allowing access if appropriate. There have also been additional performance improvements as part of this upgrade. |
| Item | Type | Details |
|---|---|---|
| Mac OS X BIC Agent | Enhancement | The Mac OS X BIC Agent now has full SafeChat support for HTTP(S) supported sites directly in the agent. |
| SafeChat | Enhancement | The $username field is now supported in alerts triggered by SafeChat/Content Scanning. This means that an alert can be configured to go to "$username @example.com". This is ideal for situations where you want to alert on email irrespective of the application actually in use. |
| User Interface | Enhancement | When "hovering" over rows in data tables, the entire row will highlight making it easier to look across at the action buttons for an item on a data row. This is especially helpful when using the interface on a large monitor. |
| DNS Boundary Redirection | Enhancement | Previously when internet authentication was on, traffic to external DNS servers was blocked until the PC was authenticated. With this change, if DBR is on, DNS traffic is allowed, allowing for automatic redirection to the captured portal. |
| BIC Agent | Enhancement | When using the local cache (to allow for use of the agent when the master Netbox is unreachable), the local cache is now fully encrypted. |
| Traffic Shaping | Fix | Some configurations of Traffic Shaping with port ranges would result in information being incorrect or not displayed in the web interface when configuring rules, this is now fixed. |
| Item | Type | Details |
|---|---|---|
| URL Overrides | Feature | URL Filtering now has the option for an overrides page which makes it simple for non-administration users to add temporary overrides to the URL Filtering policies. This feature must be enabled and a user group given permission to have access to the override screen. |
| SSH Pass Through Authentication | Enhancement | SSH Pass Through is now supported for most authentication plug-in's. This allows, for example, to have Mac's have pass though authentication when on an Active Directory domain (previously this was only supported on an Apple Open Directory domain server). |
| User Interface | Enhancement | When "hovering" over rows in data tables, the entire row will highlight making it easier to look across at the action buttons for an item on a data row. This is especially helpful when using the interface on a large monitor. |
| Low Disk Space Alerts | Enhancement | The alert threshold has been adjusted to take into account additional factors, and will alert if less than 10% of free space is available. |
| SafeChat | Fix | AJAX block pages are now more robust on Facebook when a message is blocked. |
| Item | Type | Details |
|---|---|---|
| ESET Gateway Security | Enhancement | The ESET Gateway Security product is now an option for HTTP and HTTPS virus and malware scanning. This requires a separate license from ESET for this feature. |
| Automatic BIC Agent Updates | Enhancement | For new sites the option of automatic BIC Agent updates now defaults to "on". |
| Network Monitoring & Email Monitoring | Enhancement | When viewing network monitoring and email monitoring interactive reports, the time columns no longer show milliseconds or seconds saving column width making it easier to use on smaller monitors. |
| Item | Type | Details |
|---|---|---|
| Proxy | Fix | For specific combinations of direct proxy only with no transparent proxy enabled the proxy service would not start. This has been addressed. |
| Item | Type | Details |
|---|---|---|
| Mac OS X Agent | Enhancement | The Mac agent can now automatically update binaries directly from the Netbox (unless this is disabled in the configuration on the Netbox). |
| Connect Proxy | Enhancement | If the Netbox is installed behind an upstream proxy server (and outbound access is restricted by the firewall), there is now the ability to configure it so all TCP connections are transformed to CONNECT requests against the upstream proxy. This includes all traffic that is attempting to access the internet via the Netbox (including devices that traditionally don't work well with proxies such as iPads). |
| Email scanning | Fix | Fixed an issue handling some poorly encoded ISO-2022-JP encoded attachments. |
| Network Monitoring | Enhancement | Recording of a users internet usage is now done once when using the Laptop Protector on the LAN and going out via the Netbox. Previously data could be counted twice in some configurations. |
| SafeChat | Fix | AJAX block pages are now more robust on Facebook when a message is blocked. |
| Item | Type | Details |
|---|---|---|
| Mac OS X Agent | Enhancement | The Mac OS X agent is now ready for production use for filtering web access as per the organisational policies configured on the Netbox. This is in addition to the Windows agent. |
| User Quota Uploads | Change | When uploading quotas that have a time based quota, the units are now seconds rather than days. This is ideal for situations where usage is extremely high cost. |
| Time Quotas | Fix | When applying time based quotas, these are now enforced correctly in a timely manner. |
| Item | Type | Details |
|---|---|---|
| Mac OS X Agent | Enhancement | There is now a Mac OS X agent for use on laptops when outside the organisational network. This is an initial preview release. |
| Item | Type | Details |
|---|---|---|
| Authentication | Enhancement | The Netbox now has support for Apple Open Directory - including support for passthrough authentication and email address resolution. |
| SSL Inspection | Enhancement | It is now possible to turn SSL Inspection on and off independently for transparent and direct proxy connections. |
| Item | Type | Details |
|---|---|---|
| Safechat | Enhancement | When blocking content on web based pages, display the block in a more user friendly manner that integrates with the site more closely. |
| Safechat Facebook Chat | Enhancement | Minor updates to support small changes in the chat protocol. |
| Network Tools | Enhancement | New Traffic Dump tool under Administration > Network Tools. This allows for capturing raw packets from an interface and viewing them on screen or downloading them to file for later processing by tools such as WireShark. |
| Port Forwarding | Enhancement | Port forwarding configuration under Advanced Firewall > Port Forwarding now has a checkbox to enable or disable individual rules and a comment field for each rule. |
| URL Filtering Block Messages | Fix | Policy names are correctly escaped for HTML tags when shown in block pages and the user interface. Some HTML combinations were not displayed correctly previously. |
| Item | Type | Details |
|---|---|---|
| Back-end Database Upgrade | Enhancement | A major back-end database upgrade is included in this release. This provides for future enhancements to reporting and logging capabilities. Please note that during the database upgrade process some data may be temporarily unavailable until the upgrade is complete (normally within 1-4 hours). |
| Item | Type | Details |
|---|---|---|
| BIC Agent | Fix | The BIC Agent did not upgrade sometimes on unstable connections. This has now been changed so that it is much more reliable during upgrades. |
| RAID Firmware | Enhancement | RAID firmware for some models of the Netbox appliance have been updated to the latest version. |
| Item | Type | Details |
|---|---|---|
| Protection of long lived proxy connections | Enhancement | When making minor changes to the Netbox URL filtering rules the Netbox will only apply those rules to new connections. Existing connections will stay active with the old policy applied, rather than getting reset so the new policy will apply right away. This is useful in environments that use the proxy for non-web traffic that requires a long lived connection. |
| Item | Type | Details |
| BIC Agent running without Active Directory | Enhancement | The BIC Agent can now run on computers and networks that are not managed by an Active Directory server. |
| Network Tools | Enhancement | Under Administration > Network Tools > Traceroute there is now an option to do traceroutes via TCP (in addition to UDP and ICMP). This can assist in diagnosing firewalling, path-MTU and routing issues. TCP traceroute is very useful when there is a problem with a specific application (eg: SMTP on port 25). |
| Facebook Image Posts | Enhancement | SafeChat now supports scanning of images posted in a status or to a user's wall. |
| IM Inspection Exclusions | Enhancement | Users may now choose to exclude local and remote hosts, networks and domains from instant messaging inspection in SafeChat. |
| SafeChat on Laptop Protector | Enhancement | SafeChat now runs on the Laptop Protector. |
| Item | Type | Details |
|---|---|---|
| Gmail Attachments | Enhancement | SafeChat now supports scanning of Gmail email attachments sent through the predominant upload method (Flash-based upload applet). |
| Security | Enhancement | Add limiting on the LAN access to the HTTP interface to stop infected PCs from being able to denial of service the authentication interface of the Netbox. |
| Internet Connection | Enhancement | When PPPoE connections hang during initialisation due to authentication problems with ISP, now be more aggressive with retries and don't timeout waiting for the ISP to terminate the attempted connection. |
| Google Search in SafeChat | Enhancement | SafeChat now supports alerting and blocking of Google searches (for most Google services) based on the terms entered. |
| Always Replace in Content Scanning | Defect | If a rule has 'Always Replace' and a filtered item can't be replaced, ensure we block it instead. |
| Item | Type | Details |
|---|---|---|
| Alert if BIC Agent not installed | Enhancement | An administrator can now configure the Netbox to alert if the BIC Agent is not installed on users computers. This allows for early warning if a user is tampering with their computer, or a computer has not had the BIC Agent when it should have. |
| Quota exceeded in proxy logs | Enhancement | If a user exceeds quota when using the direct proxy, when they are denied access as they try to visit a page, the proxy logs now specifically state they have exceed quota (rather than a policy violation). |
| Direct proxy NTLM prompts | Fix | Occasionally if a user was regularly refreshing a page for over 30 seconds, and their browser was using a HTTP Proxy-Keep-Alive connection with direct proxy and NTLM authentication, the user would be randomly prompted for a user name and password. This has been addressed and the users current windows credentials are correctly used. |
| Item | Type | Details |
|---|---|---|
| Facebook friend requests | Enhancement | Improved support for SafeChat decoding of Facebook friend requests. SafeChat now processes the sending and accepting of friend requests through the Facebook web site. |
| HTTPS Inspection Warnings | Enhancement | The web interface now adds warning icons to rules if HTTPS inspection is not enabled and some of the rule's websites require it to ensure all content is scanned. |
| Content filtering | Enhancement | The BIC Agent can categorise IP addresses and block them when the protocol is not HTTP. In order to allow administrators to whitelist or blacklist IP addresses you may now add IP addresses to the URL Domain List that will match on IP connections from the BIC Agent. If you have a URL Regex List, you may match the IP if you use a pattern that matches a string like " ip://123.123.123.123:123/". |
| Item | Type | Details |
|---|---|---|
| ESET Virus Scanner | Enhancement | The site administrator will receive alerts when the ESET NOD32 scanner is first installed approximately every hour if a valid license has not been uploaded. This should be done right away under Content Scanning > General if this module in installed. |
| SafeChat Summaries | Enhancement | New substitution tokens are now available; $summary and $body. These can be used in Alert sub-action and Forward sub-action fields. |
| Test IP Authentication | Fix | The IP test under Test Authentication will now behave as expected and do a real time lookup when doing a test by IP address. Previously only the cache was used that may have missed some lookups which otherwise would have been valid. |
| Item | Type | Details |
|---|---|---|
| ESET Virus Scanner | Enhancement | The ESET NOD32 AV scanner has been updated to the latest version 4. |
| Internet Auth | Fix | An issue with non-standard characters in usernames has been addressed for authentiction when using internet auth with an external authentication server. |
| Item | Type | Details |
|---|---|---|
| SafeChat | Enhancement | Filtering and reporting based on the content of messages sent via social networking websites such as MySpace and Facebook. |
| Performance | Enhancement | Various improvements to the performance of the system under load. |
| Item | Type | Details |
|---|---|---|
| BIC Agent | Enhancement | Initial release of the BIC Agent (previously known as the Laptop Protector). This is a Windows based agent that integrates with the Netbox to enforce organisational policy even when the laptop or workstation is outside of the network. |