![]() |
|
HyperIP Release 5.4 (September 2005)OPERATIONAL/PROCEDURAL IMPACT1) CRITICAL SECURITY UPDATE - Network Executive Software strongly recommends this upgrade as it contains closure of a critical security issue dealing with Apache, SSH, SSL, and SNMP packages. 5) Utility user 'admin' has been changed to 'hipadmin'. The default password is set to the HyperIP serial number. If you are installing on a previously configured HyperIP, the password remains as set. 6) ntp (network time protocol) 'passive mode' is now disallowed. Default setting is 'nontp'. FEATURES/ENHANCEMENTS1) Rate Limit Scheduling based on Day, Time of Day, or Date. Up to 31 rules are allowed.2) Lockdown by default more services on management and data ports to increase security. DOCUMENTATION UPDATES
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Problems/Issues fixed in 5.4 |
#714: Performance lower than expected with large variances in measured round-trip times. |
#717: With many active TCP connections, status display may be truncated. |
#784: Displayed connection byte counts can go negative. |
#798: NetBackup using iSCSI proxy mode does not connect via HyperIP. |
#805: Multiple TCP connections can be established using the same port. |
#806, 807, 825: Problems reconnecting after failover: No active routes, invalid ARP table entries, with Spanning Tree protocol. |
1) CRITICAL SECURITY UPDATE - Network Executive Software, Inc. strongly recommends thisupgrade as it contains closure of a critical security issue dealing with the admin password. Special characters allowed access to the admin user when entered in the password. admin password should be changed prior to downloading this update. The following special characters cannot be used in a password: apostrophe, back-tic, back-slash, double-quote
None
None
Problems/Issues fixed in 5.3.18 |
#621: Data is not accelerated over HyperIP. Message in HyperIP log like: "Received non-dynpam msg to DREF 0Xf0f4b595 from DREF 0X7f". |
#698: Certain special characters in the admin password always allow access. |
1) Performing a 'restart force' may take up to an additional 30 seconds to complete.
2) A reboot is now required after a new code release install. The installer issues reminder messages at the end of its process.
None
None
Problems/Issues fixed in 5.3.12 |
#???: Gateway disable doesn’t work via the dialog Workaround: Use Web interface. |
#670: Restart Force may cause HyperIP to freeze Workaround: reboot. |
#671: HyperIP MIB not available via SNMP Get and Graphing may not initialize Workaround: reboot. |
#666: HyperIP state may show ‘stopped’ when HyperIP is running Workaround: 'Restart Force' or reboot. |
#643: Traceroute to HyperIP’s virtual IP address is blocked by firewall Workaround: Traceroute to the real IP address |
#688: Web interface allows modification of management access even when using only the data port - may lock out access from the web and/or telnet. Workaround: Don't disable mgmt access if not using a separate mgmt port. |
#635: Unconnected TCP connect control blocks are left around for long periods of time, consuming HyperIP resources and cluttering the HyperIP status display. Workaround: 'Restart Force' or reboot. |
None
None
None
This new release of HyperIP software includes the following features:
Problem 5a: The HyperIP boot sequence may take 1-2 minutes longer with this release. Cause: If the NTP service is configured as ‘active’ HyperIP will wait up to a minute for the network interfaces to become functional, and up to a minute to contact an NTP server, in order to avoid an unnecessary switch of the AHS role. Fix or Workaround: Connect the network interfaces or configure them onboot=no, configure NTP to passive or none or use NTP server(s) that respond, or just wait a minute or two. Problem 5b: In an AHS configuration, both the primary & backup HyperIPs can assume the Master role simultaneously. This can stop data transfers between the HyperIPs. Cause: If a routing protocol such as Spanning Tree or something else causes a disruption of communication between the Master/Backup HyperIPs for an extended period (>12 seconds) on the HyperIP subnet, the AHS role becomes ambiguous, the remote Master HyperIP drops its active route,and a code bug prevents proper resyncing. Workaround: To correct the situation if it should occur, Identify the Master HyperIP with no active route, i.e. messages in the HyperIP log of the form: hyperip: ic_input:(Lcl:0),Active route not found in fogroup,5001:TPSNOROUT:Route id not found hyperip: readNetThread(23087,-2144665584:-1,6): send connect request ic_input() returned with xc->status=5001, and restart that HyperIP. Fix or Workaround: Fixed in release 5.1.3. Problem 5c: TCP connections do not complete between certain servers. Cause: A HyperIP bug may compute an incorrect IP message checksum for some IP address combinations. Fix or Workaround: Fixed in release 5.1.5. Problem 5d: Netex and HyperIP logs are unreadable from the browser or dialog user interface. Cause: HyperIP appliances shipped from the factory with code version 5.1 have incorrect permissions on these files. Fix or Workaround: Fixed in release 5.1.7. Problem 5e: During a HyperIP fail-over, TCP applications which do automatic timeout and restart may get connected before HyperIP has re-enabled its intercepts, resulting in a non-accelerated session. Cause: IP forwarding allows the connection to be completed ‘around’ HyperIP while it is initializing. Fix or Workaround: For release 5.3, controls are in place to allow or disallow IP forwarding by default, and to allow the connection to be re-broken & re-established if this should occur. In the interim, there are 3 update files on our ftp site which provide this capability: EnableForwarding.nex, DisableForwarding.nex, QueryForwarding.nex They can be downloaded as normal code updates, and applied when the functions are needed. Problem 5f: HyperIP operator interface hang – no response to web or dialog commands after a HyperIP restart. Cause: Occasionally a HyperIP restart can fail to bring all processes down completely, so the processes can’t restart. Fix or Workaround: Reboot the appliance. Fixed in release 5.3 Problem 5g: Configuration file corrupted after HyperIP config change. No HyperIP sessions are configured. Cause: A bug causes the file to be rebuilt incorrectly if changes are made but the basic topology is the same (AHS or not) Fix or Workaround: The configuration topology can be changed temporarily from AHS to non-AHS or vice-versa, then back to force the configuration to be rebuilt correctly. Fixed in release 5.3. Problem 5h: TCP connections established but hung with no peer on the other end and zero bytes transferred to/from local (in HyperIP State display). Cause: Attempting to start a large number of concurrent active connections (about 120 in this release). Fix or Workaround: Restart HyperIP or reboot. Fixed in release 5.1.7 Problem 5i: Traps to mailhub address may not be delivered. Cause: If the mailhub is configured with an IP address instead of a DNS hostname, it is accepted but fails to function. Fix or Workaround: Reconfigure mailhub address as a hostname. Fixed in release 5.3. If this has caused many emails to be generated but nor delivered, they will all come in a rush once the configuration is fixed. To first purge all the old queued emails, we have an update file on our ftp server: delete-email-queue.nex Download this to your HyperIP appliance(s) and install as an Update. Problem 5j: Trap messages may not be sent to SNMP trap server. Cause: HyperIP cannot resolve its own hostname if it is not in a configured DNS server. Fix or Workaround: Add HyperIP names/addresses to DNS. Fixed in release 5.3. Problem 5k: Only the first DNS server configured is used for name lookups. Cause: Config file is not written correctly. Fix or Workaround: Fixed in release 5.3. |
Problems/Fixes in Release 5.1 Problem 4e: If the dialog program running on the serial port is terminated with CTL-c rather than the dialog exit sequence, it can hang in an endless loop. You can see this is occurring with ‘Display Processor Usage’ from the web ‘Maint’ page. Cause: Bug in 3rd party dialog software on a serial port. Fix or Workaround: Fixed in release 5.1 Problem 4f: HyperIP loops after many days of continuous operation. Cause: Bug in HyperIP block number wrap at > 2**31 blocks (c. 2 billion). Fix or Workaround: Fixed in Release 5.1 Problem 4g: Target performance rate drops after a long period of low activity. Cause: Bug introduced by code to slow down when receiving naks. Fix or Workaround: Fixed in Release 5.1.1 |