Cisco Cisco Firepower Management Center 2000 Notas de publicación

Descargar
Página de 24
 
21
FireSIGHT System Release Notes
Version 5.3.1.1
  Known Issues
  •
Defense Center local configurations (
System > Local > Configuration
) are not synchronized between 
high availability peers. You must edit and apply the changes on all Defense Centers, not just the 
primary. (130612, 130652)
  •
In some cases, large system backups may fail if disk space usage exceeds the disk space threshold 
before the system begins pruning. (132501)
  •
In some cases, using the RunQuery tool to execute a 
SHOW TABLES
 command may cause the query to 
fail. To avoid query failure, only run this query interactively using the RunQuery application. 
(132685)
  •
If you delete a previously imported local intrusion rule, you cannot re-import the deleted rule. 
(132865)
  •
In rare cases, the system may not generate events for intrusion rules 141:7 or 142:7. (132973)
  •
In some cases, remote backups of managed devices include extraneous unified files, generating large 
backup files on your Defense Center. (133040)
  •
You must edit the maximum transmission unit (MTU) on a Defense Center or managed device using 
the appliance’s CLI or shell. You cannot edit MTUs via the user interface. (133802)
  •
If you create a URL object with an asterisk (
*
) in the URL, the system does not generate preempted 
rule warnings for access control policies containing rules that reference the object. Do not use 
asterisks (
*
) in URL object URLs. (134095, 134097)
  •
If you configure your intrusion policy to generate intrusion event syslog alerts, the syslog alert 
message for intrusion events generated by intrusion rules with preprocessor options enabled is 
Snort 
Alert
, not a customized message. (134270)
  •
If the secondary device in a stack generates an intrusion event, the system does not populate the table 
view of intrusion events with security zone data. (134402)
  •
If you configure an Nmap scan remediation with the 
Fast Port Scan
 option enabled, Nmap remediation 
fails. As a workaround, disable the 
Fast Port Scan
 option. (134499)
  •
If you generate a report containing connection event summary data based on a connection event table 
saved search, reports on that table populate with no data. (134541)
  •
Scheduling and running simultaneous system backup tasks negatively impacts system performance. 
As a workaround, stagger your scheduled tasks so only one backup runs at a time. (134575)
  •
If you edit a previously configured LDAP connection where user and group access control 
parameters are enabled, clicking 
Fetch Groups
 does not populate the Available Groups box. You must 
re-enter your password when editing an LDAP connection in order to fetch available groups. 
(134872)
  •
In some cases, if you enable 
Resolve IP Addresses
 in the 
Event Preferences
 section of the Event View 
Settings page, hostnames associated with IPv6 addresses may not resolve as expected in the 
dashboard or event views. (135182)
  •
You cannot enter more than 450 characters in the 
Base Filter
 field when creating an LDAP 
authentication object. (135314)
  •
In some cases, if you schedule a task while observing Daylight Saving Time (DST), the task does 
not run during periods when you are not observing DST. As a workaround, select 
Europe, London
 as 
your local time zone on the Time Zone Preference page (
Admin > User Preferences
) and recreate the 
task during a period when you are not observing DST. (135480)
  •
In some cases, the system may generate a false positive for the SSH preprocessor rule 128:1. 
(135567)