New in Version 12.1.8-ADS [ Feb 21 2016]
========================================
* New Features and Improvements *
- Updated the Web proxy software to the latest version. This provides performance gains and improvements in URL filtering of HTTPS sites.
- Updated the pattern matching software.
- Added a new email filering engine to detect and block the newest zero-hour Email Spam attacks.
* Fixes *
- Fixed a possible bypass of Web URL filtering when using the Safari browser.
New in Version 12.1.7-ADS [ Feb 16 2016]
========================================
* New Features and Improvements *
- Updated the Anti-Virus scanner to check for zero-day macros in documents.
- Added a Network Traffic Analyser. This listens on any network interface and displays a table of current bandwidth usage by pairs of hosts, showing any network hogs. The analyser can be run concurrently on more than one Interface, to show a view of traffic on the LAN and the WAN interface at the same time.
- Added more choices to the options for the File server Shadow Copy feature.
- Updated the network traffic monitor with the latest software version.
- Updated the caching, recursive DNS server software to the latest version.
- Added an option to the General Email configuration to enable/disable TLS encryption on incoming SMTP connections. Previously, only the client ( outgoing) TLS encryption was affected.
- Increased the performance of the Web Proxy server. Asynchronous disk access is now used, reducing contention.
- Several improvements to the Web Configuration Interface.
- Modified Horde IMAP groupware configuration to send emails to the SMTP network port.
* Fixes *
- During first-time provisioning of the Active Directory Server, the DNS server is now changed to the internal BIND DNS server. Previously, the AD Server would not provision properly.
- Created a new, default, self-signed RSA certificate for the Web Server.
- Many other bugs squashed.
New in Version 12.1.6-ADS [ Jan 29 2016]
========================================
* New Features and Improvements *
- Security – Installed RSA certificates for the IMAP and POP email servers.
- Security – Updated the SASL authentication libraries to the latest version.
- IPSec – Added a connection monitor for IPSec connections. If a ping to a remote IP address fails, then, the IPSec SA is restarted for that connection.
- IPSec – New program and kernel module installed.
- IPSec – Allow insecure DH group 1 and single DES for some Vigor routers and others.
- Web proxy – Updated the server software and re-configured it to speed-up traffic flow.
- Mail Server – Allow the Igaware mail server to transmit data to SMTP relay servers in 7 bit mode.
* Fixes *
- Local Master Browser tick box for standalone file server server – the setting wasn’t saved.
- Networking – Interface script fixed. This now calls ipsec restart correctly. Previously ipsec down was not called and blocked the shutdown of the ppp device.
- Email server – Force file ownership permissions for the SMFS recipient verification server.
- Email Server – Relaying of unlnown local users to an SMTP server was not working correctly when the server was specified with a domain name.
- Fixed several bugs in the Web configuration interface.
New in Version 12.1.5-ADS [ Jan 11 2016]
========================================
* New Features and Improvements *
- Security – Plain text passwords (LOGIN/PLAIN auth mech) are disabled for eMail server SMTP authentication.
- Web Interface – Added an option to allow LOGIN/PLAIN clear-text passwords for SMTP authentication.
- Security – Added X-FRAME-OPTIONS to Web server response headers.
- Security – Prevent possiblity of XSS ( cross-site scripting) in Web
configuration interface.
— New in Version 12.1.2-ADS [ Dec 22 2015]
========================================
- Anti-Spam – added some rules to get rid of current invoice spam.
- Securtiy – Added CRAM authentication for IMAP – cram-md5.pwd
- Security – Installed RSA certs for IMAP server. This allows secure TLS connections.
- Security – Added an option to block email that contains Microsoft OLE documents with Macros to the Anti-Virus page – off by default.
- Security – Secured incoming IMAP and POP3 connections with CRAM encryption during login and TLS for the connection.
- Security – Secured incoming IMAP and POP3 connections with TLS encryption.
- Many other small improvements.
* Fixes *
- Backup – When mounting a cifs share as a backup destination, the username is tried both with and without the workgroup name. Newer kernel require the WORKGROUP/user format.
- Routing – Fixed some routing tables that had multiple rule entries – table-iproute now deletes a rule before adding it again.
- Backup – Exclude the $RECYCLE.BIN folder when backuping up ISCSI sources.
- Networking – Allow DH group 1 for IPSEC VPN.
- DHCP Server – Set the zone domain properly from the correct LAN domain, if we are using the BIND DNS Server.
- Web Interface – Don’t cache the image of the Email Traffic graph, so that the new one displays correctly.