Component: ipsec
514 changelog entries across 208 version(s)
Releases by channel (stacked)
- do not kill connection when peer's "name" or "comment" is changed;
- refresh peer's DNS only when phase 1 is down;
- fixed client certificate usage when certificate is renewed with SCEP;
- do not update peer endpoints for generated policy entries (introduced in v6.47);
- added SHA384 hash algorithm support for phase 1 (CLI only);
- do not update peer endpoints for generated policy entries (introduced in v6.47);
- fixed multiple warning message display for peers;
- inactivate peer's policy on disconnect;
- added "split-dns" parameter support for mode configuration;
- added "use-responder-dns" parameter support;
- allow specifying two peers for a single policy for failover;
- control CRL validation with global "use-crl" setting;
- do full certificate validation for identities with explicit certificate;
- fixed minor spelling mistake in logs;
- improved IPsec service stability when receiving bogus packets;
- place dynamically created IPsec policies by L2TP client at the begining of the table;
- added "split-dns" parameter support for mode configuration;
- added "use-responder-dns" parameter support;
- allow specifying two peers for a single policy for failover;
- place dynamically created IPsec policies at the begining of the table;
- improved system stability when handling fragmented packets;
- allow specifying two peers for a single policy for failover (CLI only);
- improved system stability when handling fragmented packets;
- improved system stability when handling fragmented packets;
- control CRL validation with global "use-crl" setting;
- do full certificate validation for identities with explicit certificate;
- added "use-responder-dns" parameter support (CLI only);
- added "split-dns" parameter support for mode configuration (CLI only);
- fixed minor spelling mistake in logs;
- improved IPsec service stability when receiving bogus packets;
- improved system stability when processing decrypted packet on unregistered interface;
- improved system stability when processing decrypted packet on unregistered interface;
- improved system stability when processing decrypted packet on unregistred interface;
- fixed action=none policies;
- added "error" topic for identity check failure logging messages;
- fixed DNS resolving when domain has only AAAA entries;
- fixed policy "sa-src-address" detection from "local-address" (introduced in v6.45);
- fixed IPsec policy checking on RB4011 (introduced in v6.46beta68);
- fixed policy "sa-src-address" detection from "local-address" (introduced in v6.45);
- allow inline "passphrase" parameter when importing keys;
- fixed minor spelling mistakes in logs;
- allow inline "passphrase" parameter when importing keys;
- fixed "eap-radius" authentication method (introduced in v6.45);
- fixed minor spelling mistakes in logs;
- fixed DNS resolving when domain has only AAAA entries;
- fixed "eap-radius" authentication method (introduced in v6.45);
- fixed minor spelling mistakes in logs;
- allow inline "passphrase" parameter when importing keys;
- added "error" topic for identity check failure logging messages;