Cisco Cisco Web Security Appliance S670 Release Notes

Page of 76
C I S C O   I R O N P O R T   A S Y N C O S   6 . 3 . 8   F O R   W E B   R E L E A S E   N O T E S
 
21
Fixed: Cannot access some HTTPS servers with decryption enabled
Previously, users could not access some HTTPS servers intermittently when decryption was 
enabled. This no longer occurs. [Defect ID: 69793] 
Fixed: Web Proxy generates a core file accessing some websites
Previously, the Web Proxy generated a core file due to leaked memory when accessing some 
websites. This no longer occurs. [Defect ID: 69902] 
Fixed: Web Proxy restarts and generates a core file when serving a range of PDF content 
from the web cache
Previously, the Web Proxy restarted and generated a core file when serving a range of PDF 
content from the web cache. This no longer occurs. [Defect ID: 70142] 
Fixed: Web Proxy restarts and generates a core file with decryption enabled in some 
cases
Previously, the Web Proxy restarted and generated a core file when decryption was enabled 
and the HTTPS server returned a 503 Service Unavailable response. This no longer occurs. 
[Defect ID: 70182] 
Fixed: Web Proxy generates a core file when downloading large files in some cases
Previously, the Web Proxy generated a core file when downloading large files from servers 
that served data faster than the client application could read it. This no longer occurs. [Defect 
ID: 54894] 
Fixed: CPU usage can get very high with a very large number of authentication groups
Previously, the Web Proxy downloaded the entire list of authentication groups, and when the 
number of groups was very large, such as over 250,000 groups, the CPU usage was close to 
100%. This no longer occurs. Now, the Web Proxy limits downloads up to 500 authentication 
groups at a time. [Defect ID: 54929] 
Fixed: Web Proxy does not query all LDAP groups in some cases
Previously, the Web Proxy did not query all LDAP groups, causing some requests to 
erroneously fall into the Global Access Policy. This no longer occurs. [Defect ID: 65977] 
Fixed: FTP Proxy does not spoof the IP address of the FTP server for active mode 
connections
Previously, the FTP Proxy did not spoof the IP address of the FTP server for active mode 
connections. This no longer occurs. Now, the FTP Proxy spoofs the IP address of FTP servers 
for both active and passive mode connections. [Defect ID: 66458]