Component: ipsec
511 changelog entries across 207 version(s)
Releases by channel (stacked)
- fixed client certificate usage when certificate is renewed with SCEP;
- do not update peer endpoints for generated policy entries (introduced in v6.47);
- added SHA384 hash algorithm support for phase 1 (CLI only);
- do not update peer endpoints for generated policy entries (introduced in v6.47);
- fixed multiple warning message display for peers;
- inactivate peer's policy on disconnect;
- added "split-dns" parameter support for mode configuration;
- added "use-responder-dns" parameter support;
- allow specifying two peers for a single policy for failover;
- control CRL validation with global "use-crl" setting;
- do full certificate validation for identities with explicit certificate;
- fixed minor spelling mistake in logs;
- improved IPsec service stability when receiving bogus packets;
- place dynamically created IPsec policies by L2TP client at the begining of the table;
- added "split-dns" parameter support for mode configuration;
- added "use-responder-dns" parameter support;
- allow specifying two peers for a single policy for failover;
- place dynamically created IPsec policies at the begining of the table;
- improved system stability when handling fragmented packets;
- allow specifying two peers for a single policy for failover (CLI only);
- improved system stability when handling fragmented packets;
- improved system stability when handling fragmented packets;
- control CRL validation with global "use-crl" setting;
- do full certificate validation for identities with explicit certificate;
- added "use-responder-dns" parameter support (CLI only);
- added "split-dns" parameter support for mode configuration (CLI only);
- fixed minor spelling mistake in logs;
- improved IPsec service stability when receiving bogus packets;
- improved system stability when processing decrypted packet on unregistered interface;
- improved system stability when processing decrypted packet on unregistered interface;
- improved system stability when processing decrypted packet on unregistred interface;
- fixed action=none policies;
- added "error" topic for identity check failure logging messages;
- fixed DNS resolving when domain has only AAAA entries;
- fixed policy "sa-src-address" detection from "local-address" (introduced in v6.45);
- fixed IPsec policy checking on RB4011 (introduced in v6.46beta68);
- fixed policy "sa-src-address" detection from "local-address" (introduced in v6.45);
- allow inline "passphrase" parameter when importing keys;
- fixed minor spelling mistakes in logs;
- allow inline "passphrase" parameter when importing keys;
- fixed "eap-radius" authentication method (introduced in v6.45);
- fixed minor spelling mistakes in logs;
- fixed DNS resolving when domain has only AAAA entries;
- fixed "eap-radius" authentication method (introduced in v6.45);
- fixed minor spelling mistakes in logs;
- allow inline "passphrase" parameter when importing keys;
- added "error" topic for identity check failure logging messages;
- added "connection-mark" parameter for mode-config initiator;
- allow peer argument only for "encrypt" policies (introduced in v6.45);
- fixed peer configuration migration from versions older than v6.43 (introduced in v6.45);
- improved stability for peer initialization (introduced in v6.45);
- show warning for policies with "unknown" peer;