SGOS 7.4.6.1
25086
16 October 2024
16 October 2024
October 15, 2024
To: Symantec Secure Web Gateway Customers Customers
From: The Broadcom SGOS and Advanced Secure Gateway Product Team
Subject: General Availability Announcement for SGOS and Advanced Secure Gateway
On behalf of Broadcom, we appreciate your business and the opportunity to provide you with high-quality, innovative software and services. As part of our ongoing commitment to customer success, we regularly release updated versions of our products. Today, we are pleased to announce that SGOS 7.4.6.1 is now available. This release also includes the first releases of SGAC 2.2.4 and Web VPM 2.2.4.
Manage SGAC and Web VPM Versions in the CLI
You can now use the command line to upgrade, downgrade, reset, and view information for the versions of the Admin Console and the Web VPM.
Use the #(config ui) sgac-update-path|vpm-update-path url command to set the download path for the UI images and the #load sgac-update|vpm-update [force] command to update the UI versions.
Use the #(config ui) reset sgac|vpm command to reset the UI versions to the version that came bundled withthe running system version. You can only reset images that have been updated. To check if a UI component has been updated, use the #(config ui) view command. You can tell if a version has been updated by the property next to theversion and build information:
(system): The UI version came bundled with the version of SGOS that is running. Versions with this status have notbeen updated.(forced): When the UI version was updated, the version checks were ignored.- No property listed: The UI version was updated.You can also view UI version information using the >show version or >show ui commands.
You can also view UI version information using the >show version or >show ui commands.
NOTE:
On upgrade (7.4.6.1 or higher), former obsolete UI files are removed. These files include any old (flash based) UI archives loaded earlier, as well as the unpacked contents on disk (from the update archives and system image). If SGOS is later downgraded to a version that supports these archives, since the system loads UI archive from the version that is bundled with the SGOS system, you will need to load any other specific UI archive you require.
More information:
- Edge SWG Admin Console Administration Guide
- #(config) ui
- # load
- > show version
- > show ui
- Upgrade/Downgrade Guide
Option to Disable Auto Socket Buffering
To help improve download performance, this release provides you with the ability to disable 'auto socket buffering' and use the specified window-size.
Auto socket buffering was introduced in 7.3.x, and unlike the socket buffering mechanism in 6.7.5.x, allocates only as much memory as is needed to hold outstanding socket data at any given time, up to the max window-size you have specified. It was previously not possible to turn this mechanism off.
To enable or disable 'auto socket buffering' (it is enabled by default), issue the new configuration command:
# (config) tcp-ip tcp-auto-buffer {enable | disable}
NOTE:
The default window-size in 6.7.5.x is 256K, whereas in 7.3.x it is 1MB. If you disable tcp-auto-buffer ,you should also reduce the window-size to avoid a potentially sharp increase in memory usage for packets.
More information:
Support for Class E IP Addresses
A new CLI command allows you to use Class E IP addresses for private subnets. These addresses range from 240.0.0.0 to 255.255.255.254.
To enable or disable class E IP support, issue the following command. The detault is disable.
# (config) tcp-ip class-e-ip-support {enable | disable}
More information:
DRTR and ICAP Debug Logs Added to Policy Diagnostic Probes
The policy diagnostic probes can now capture ICAP and DRTR debug logs to allow you to isolate transaction-based activity for those targets.
These new probe definition targets are added to the define probe definition.
Since these additional targets result in more logs stored in the transaction trace log buffer, the previous buffer size limit of 128KB can be configured up to 992KB. When the buffer is full, it is no longer truncated but is instead flushed into the trace log files that are defined by the probe.
More information:
Domain Fronting Detection Over HTTP
To support CPL that detects a difference in the GET request URL and the Host header when using HTTP non-encrypted connections, support for substitution variables is added on the right-hand side for request.header.Host.
Example:
define condition http_domain_match request.header.host="$(url.host)" url.port=80 request.header.host="$(url.host):80" url.port=80 request.header.host="$(url.host):$(url.port)"end
To deny any violating traffic, the policy rule would be:
condition=!http_domain_match deny ; deny any traffic that doesn't meet the domain fronting check condition
For backward compatibility, the current CPL support for match modifiers is still preserved if the right-hand side does not contain a substitution variable.
Track Policy Rules in the Access Log
An enhancement is made to the way that you can track the matching of policy rules in the access log. When the reference_id() action is invoked, the system maintains a list of reference_ids that were evaluated. The reference_ids are reported in the access log in the new field x-bluecoat-reference-ids.
The x-bluecoat-reference-ids field logs all of the policy rules that matched for a given transaction as a comma-delimited concatenated string. This allows you to perform a simple policy trace as well as profile the policy to remove rules that are no longer used.
The maximum character size limit for the x-bluecoat-reference-ids field is 50,000 characters. The last reference_id string (and subsequent ones) beyond the 50,000 character limit are replaced by an ellipsis to indicate the overflow.
To support the x-bluecoat-reference-ids field, restrictions are placed on the syntax of the reference_id().
More information:
ProxySG Admin Console 2.2.4
This release includes the following new features and enhancements:
Manage SGAC and Web VPM Versions in the SGAC
You can now use the Edge SWG Admin Console to upgrade, downgrade, reset, and view information for the versions of the Admin Console and the Web VPM. In the Admin Console, click Administration > System > Software Images and view the information in User Interface Images. From this screen, you can also update the UI versions and reset them to the version that came bundled with the running SGOS system image. You can only reset images that have been updated. You can tell if a version has been updated by the property next to the version and the build information:
- (system): The UI version came bundled with the version of SGOS that is running. Versions with this status have not been updated.
- (forced): The UI version was force updated, meaning that the version checks were ignored. If you downgraded the version, you had to have used the force update.
- No property listed: The UI version was updated.
To view information on what version of the Admin Console the appliance is running, see the banner from any page in the Admin Console. For more information on the SGAC and Web VPM versions, see the Identification screen (Administration > General > Identification).
NOTE:
If you use Management Center to launch SGAC or Web VPM, the version that is running is the version that you selected in Management Center.
NOTE:
If Edge SWG is hosted on a Symantec Integrated Secure Gateway (ISG) device, the Software Images page is not currently available in SGAC. However, you can manage the versions of the Admin Console and the Web VPM using the new Edge SWG CLI commands.
More information:
- Edge SWG Admin Console Administration Guide
- #(config) ui
- # load
- > show version
- > show ui
- Upgrade/Downgrade Guide
Changes to Network Adapters
To make configuring network adapter settings easier (Configuration > Network > Adapters), the tables of the interface, aggregate interface, and bridge settings of the Network Adapters page have been streamlined.
More information:
Web VPM 2.2.4
This release includes the following new features and enhancements:
Manage Web VPM Versions in the Admin Console
You can now use the Edge SWG Admin Console to upgrade, downgrade, reset, and view information for the versions of the Web VPM. In the Admin Console, click Administration > System > Software Images and view the information in User Interface Images. From this screen, you can also update the Web VPM version and reset them to the version that came bundled with the running SGOS system image. You can only reset images that have been updated. You can tell if a version has been updated by the property next to the version and the build information:
- (system): The UI version came bundled with the version of SGOS that is running. Versions with this status have not been updated.
- (forced): The UI version was force updated, meaning that the version checks were ignored. If you downgraded the version, you had to have used the force update.
- No property listed: The UI version was updated.
To view information on what version of the Web VPM the appliance is running, in the Edge SWG Admin Console (SGAC 2.2.4 and later), see the Identification screen (Administration > General > Identification).
NOTE:
If you use Management Center to launch the Web VPM, the version of Web VPM that is running is the version that you selected in Management Center.
NOTE:
If Edge SWG is hosted on a Symantec Integrated Secure Gateway (ISG) device, the Software Images page is not currently available in SGAC. However, you can manage the versions of the Web VPM using the new Edge SWG CLI commands.
More information:
- Edge SWG Admin Console Administration Guide
- #(config) ui
- # load
- > show version
- > show ui
- Upgrade/Downgrade Guide
New Client IP Address/Subnet List Object
The policy object Client IP Address/Subnet List has been added to the Source column. Use this object to specify a list of the following items:
- IPv4 or IPv6 addresses
- IPv4 addresses with one or more wildcards
- Ranges of IP addresses in a network
- Optional subnet mask (for IPv4) or prefix length (for IPv6)
More information:
To download this release and review Release Notes, visit the Symantec Enterprise Security portal at https://support.broadcom.com/security. A MyBroadcom login is required. See https://knowledge.broadcom.com/external/article/151364/download-the-latest-version-of-symantec.html for details.
If you have any questions or require assistance please contact Broadcom Customer Care online at https://www.broadcom.com/support/software/contact where you can submit an online request using the Customer Care web form: https://ca-broadcom.wolkenservicedesk.com/web-form?_ga=2.205828371.1432263889.1590607313-713014253.1588711301 . You can also call Broadcom Customer Care at +1-800-225-5224 in North America or see https://www.broadcom.com/support/software/contact for the local number in your country.
Should you need any assistance, our Broadcom Services experts can help. For more information on Broadcom Services and how you can leverage our experience, please visit https://www.broadcom.com/support/ca/services-support/ca-services.
Your success is very important to us, and we look forward to continuing our successful partnership with you.
To review Broadcom Support lifecycle policies, please review the Broadcom Support Policy and Terms located at: https://support.broadcom.com/.
Thank you again for your business.