Release Notes PN 93000693_E3 Digi ConnectPort WAN VPN (Verizon) 82001350_E3 EOS August 9, 2007 INTRODUCTION This is a production release of firmware for the Digi ConnectPort WAN VPN. The ConnectPort WAN VPN is a hardened, upgradeable 3G cellular router that provides secure high speed wireless connectivity to remote sites and devices. It can be used for primary wireless broadband network connectivity to equipment at remote locations, as well as for a backup to existing landline communications. The ConnectPort WAN VPN is ideal for use where wired networks (e.g., leased line/frame relay, ISDN, DSL) are not feasible, or where alternative network connections are required. SUPPORTED PRODUCTS Digi ConnectPort WAN VPN SUPPORTED AIR INTERFACES Sierra Wireless MC5720 Sierra Wireless MC5725 ENHANCEMENTS Add support for ERI-specific roaming codes, first seen as a 0x40 roaming code on the Verizon network. Implement an updated algorithm for Verizon Data Call Retry back-off. Improve handling when a call is dropped from the Verizon network and the Digi device redials, resulting in a mobile session mismatch: the redial logic is modified such that the MC5720 or MC5725 module is not reset between every call, to avoid the session mismatch. BUG FIXES Fix problem in VPN settings that did not support the hyphen character as a valid part of a domain name. When used in an identity string, the error for "invalid" content was not being displayed in the web UI, but failed to be saved in the settings. (23415) Handle multiple proposals in Phase 2 IPSec VPN requests. (22534) Fix problem for the MC5720 and MC5720 modules, in which the illuminated signal strength LEDs differ from the number of "bars" shown in the web UI (Mobile System Information page) or CLI ("display mobile" command output). (23706) Fix a NAT problem where a non-ICMP trigger’s time-to-live (TTL) was incorrectly reset when an ICMP error was received, thereby interfering with the proper NAT management of the associated trigger (rule). KNOWN ISSUES On some IPSec VPNs, SA lifetime is not negotiated correctly. To work around this issue, configure the SA lifetime on the Digi ConnectPort WAN VPN to be less than that configured on the VPN concentrator. For IPSec VPN tunnels using AES encryption, multiple key lengths (128-, 192- and 256-bit) are supported for ISAKMP/IKE phase 1 encryption proposals. For ISAKMP/IKE phase 2 proposals, currently only 256-bit keys are supported for AES encryption. DOCUMENTATION ERRATA None. ADDITIONAL INFORMATION It is recommended that you perform a backup of your device's settings prior to upgrading your firmware. If you should need to revert back to a previous version of firmware, this will ensure that you will be able to restore your device to its previous settings in the event that some settings are not restored properly after downgrading the firmware. To backup your device settings, follow this simple procedure: 1) Open the web user interface and navigate to the "Administration" section and select "Backup/Restore". 2) Click the "Backup" button and select the location to where you want to save your backup file. To restore: 1) Navigate to the same section within the web UI. 2) Click the "Browse" button to select the backup file you saved in the previous steps. 3) Click the "Restore" button to upload the configuration settings contained in your backup file. On initial boot of this device, it will generate some encryption key material: an RSA key for SSL/TLS operations, and a DSA key for SSH operations. This process can take as long as 40 minutes to complete. Until the corresponding key is generated, the device will be unable to initiate or accept that type of encrypted connection. It will also report itself as 100% busy but, since key generation takes place at a low priority, the device will still function normally. On subsequent reboots, the device will use its existing keys and will not need to generate another unless a reset to factory defaults is done, which will cause a new key to be generated on the next reboot. HISTORY 82001350_E3 - August 9, 2007 See ENHANCEMENTS and BUG FIXES information above. 82001350_E2 - June 25, 2007 ENHANCEMENTS Add "display techsupport" CLI command. This reports a wide variety of settings ans status information that is helpful for technical support purposes. Enhance NAT to support multiple instances rather than just one instance. BUG FIXES Fix problem with conversion of version 1 VPN settings to version 2 format, which caused VPN thread to lock up and settings to be lost. (22437) Modify NAT behavior so it will not send untranslated IP datagrams. This avoids a problem in cases where the mobile provider does not accept IP datagrams whose source IP address is not the mobile IP address, and it takes the action of resetting the mobile PPP connection, which disrupts network services over the mobile connection. Modify IP pass-through behavior to better filter the IP datagrams sent to the mobile network (this is similar to the NAT change above). This avoids a problem in cases where the mobile provider does not accept IP datagrams whose source IP address is not the mobile IP address, and it takes the action of resetting the mobile PPP connection, which disrupts network services over the mobile connection. Filter nonprintable characters from display in web UI, which could result in a device lockup Fix problem in which the DHCP server did not properly use the DHCP client's requested lease time. Fix problem in which the alarms configuration could possibly be corrupted from the web UI. (21977) Fix problem in which authenticationFailure traps were being sent for login failures. (22026) Fix network stack problem for IP datagram fragment reassembly. (20481) Fix problem in which data buffer is not cleared when UDP serial settings are changed. (19786) Fix problem in which autoconnect fails if it is configured to connect on data, and the serial buffer becomes full, resulting in no subsequent connection attempts. (22333) Fix the "set pppoutbound port=5 ipcp=off" command to correctly turn off DNS IP address acquisition on Verizon firmware. (22851) Fix problem in which some mobile statistics were displaying as negative values when the bytes transferred count became large. (22844) Fix problem in which the host list restore from backup would fail. (22779) Changed the web server, for dynamic pages, to return: cache-control: no-cache,no-store (used to only be no-cache) to prevent clients from storing dynamically generated content. In particular, the java 1.6 plugin was caching camera images that it should not. The java plug in now caches all network resources that do no specify no-store, so we now will return no-store on all dynamic content. 82001350_E1 - April 23, 2007 ENHANCEMENTS: None. BUG FIXES: Remove a 2MB file size limitation in the Connectware management protocol to allow upgrading to future EOS images that may be larger than 2MB. 82001350_E - April 4, 2007 ENHANCEMENTS: Add support for X.509 certificates. This feature is available to the SSH, SSL and IPSec VPN services. Add event logging capabilities for critical system events. Add Virtual Host VPN capabilities to allow common Ethernet network configuration on multiple units connecting into the same VPN concentrator. Add support for Digi DialServ, providing connectivity to legacy devices and peripherals that are only capable of connecting to a PSTN. Add DNS Host List for use with Digi DialServ and auto-connect services. Add SNMP MIBs providing support for cellular statistics and traps. Enhance VPN tunnel configuration to allow all traffic, destined for any subnet (0.0.0.0/0), through the VPN tunnel. Add check box to VPN IKE settings to support functionality with Nortel VPN appliances. o Suppress SA lifetime during IKE phase 1 BUG FIXES: None. 82001350_D - January 31, 2007 ENHANCEMENTS: Change default time interval for SureLink mobile link integrity test to 2 hours for the Verizon Network. BUG FIXES: Remove capability to enable LCP echos for the Verizon Network. 82001350_C - October 17, 2006 ENHANCEMENTS: Add "ping" pinhole for IP pass-through mode of operation. Increase to five the number of concurrent VPN tunnels. Add more mobile status information items including network speed, service type, frame erasure rate, noise and others. Add LCP echo support in web UI for Movistar Panama. Add PPP option to enable/disable IPCP acquisition of DNS IP addresses, enabled by default to preserve prior behavior. For NAT: o Add port range support for port forwarding rules. o Increase the maximum number of triggers to 1024 (was 512). o Add maximum number of triggers configuration field to web UI. o Reduce TCP trigger idle lifetime to free associated resources: new idle lifetime is 122 minutes rather than 24 hour). For SureLink (tm) link integrity monitoring "ping" test: o Change ping data size to minimum of 4 bytes (was 56), to reduce data usage for cellular network connections. o Increase ping "wait for reply" interval to 5 seconds (was 3) to reduce the likelihood of unnecessary retries and hence reduce data usage for cellular network connections. Add the use of the "nonadministrative reset" statistic for PPP, to count occasions when the cellular network disconnects the PPP session by means of an LCP Terminate message (versus dropping the call). Add a new item to indicate the reason/type of the last PPP connection reset. BUG FIXES: IPSec updates (fixes specific to IKE). Fix a possible lockup condition in the processing of network stack timers. For NAT: o Fix a bug in which NAT would forward an untranslated packet to a public network when the maximum trigger limit was reached. (19552) o Fix a bug in which a NATed FTP session could become nonresponsive and eventually that session would abort. Fix various pmodem issues. (19206, 19226) Improve "revert" help. (17161) Fix a timing problem when reading the phone number from the SIM via an AT command sent to the Siemens MC75 module. Fix a problem in IP pass-through mode in which some services may not be accessible from the Ethernet side, if a pinhole was configured for that service. (19487) Improve the resolution of the TCP idle/keepalive timer to comply better with configured keepalive settings. (19546) Fix stack size problem for simple password daemon. (19659) 82001350_B - August 30, 2006 ENHANCEMENTS: Add IP Pass-through mode (optional): IP Pass-through (bridged) mode specifies that IP packets received by the Digi device server will be bridged transparently between the Ethernet and mobile data links. This is useful for interoperability with third-party routers. Effectively, the mobile IP address of the Digi device server is given to a host on the Ethernet side of that Digi device server. Please consult with your mobile plan provider to obtain addresses to use (IP, DNS), and that your plan supports static address assignment. Optional "pinholes" can be configured such that a user can still access specific services of the Digi device server from the mobile network side, even when it is operating in IP Pass-through mode. For example, one can configure a pinhole that permits a user to telnet to the Digi device server over the mobile network connection. Add Socket Tunnel feature: A Socket Tunnel can be used to connect two network devices - one on the Digi device server's local network and the other on the remote network. This is especially useful for providing SSL data protection when the local devices do not support the SSL protocol. One of the endpoint devices is configured to initiate the socket tunnel. The tunnel is initiated when that device opens a TCP socket to the Digi device server on the configured port number. The Digi device server then opens a separate connection to the specified destination host. Once the tunnel is established, the Digi device server acts as a proxy for the data between the remote network socket and the local network socket, regardless of which end initiated the tunnel. Support additional wireless carriers: o Cellular South (CDMA) o Movistar Colombia (CDMA) o Movistar Panama (CDMA) o Movistar Peru (CDMA) o Verizon Puerto Rico (CDMA) Improve cellular module provisioning (web UI and CLI). Add SureLink (tm) statistics and additional mobile information to the Mobile System Information web page. Connectware Manager (Remote Management): o Add Server-Initiated Connection support for Connectware Manager, allowing the server to connect to the device (on demand) as a configurable option. Includes Last Known Address (LKA) updates to the Connectware Manager when the mobile IP address changes. o Decrease the amount of data exchanged over a cellular connection when connecting to the Connectware Manager server. o Simplify Remote Management Configuration web pages for an improved user experience. o Add support to disconnect from the Connectware Manager when the connection to the server is idle for a configurable interval. DHCP Server: o Add configurable conflict detection, whereby the DHCP Server pings an IP address to verify its availability, before offering it to a client for a new lease. Conflict detection is disabled by default. o Improve information on web page for DHCP Server Management. o Improve web UI help information. Add RealPort (tm) "exclusive" mode option: Exclusive mode provides the ability for the Digi device to close an existing RealPort connection and establish a new one immediately upon a new connection request from the same IP address. This mode is useful when using RealPort over wide area networks that can be unstable and where you are charged by the byte (such as cellular or satellite) and do not wish to incur costs for keep-alive traffic. Exclusive mode will allow your application to retain continuity when temporary, unexpected interruptions in network connectivity occur. This configuration is available via the command line. Syntax: set realport exclusive=on|off Add support for new air interface cards: o Sierra Wireless MC8755 (GSM/GPRS/HSDPA/UMTS) - European frequency o Sierra Wireless MC8765 (GSM/GPRS/HSDPA/UMTS) - North American frequency Operate with newer Sierra Wireless AirCard 850 with SIM PINs enabled. BUG FIXES: Fixed an issue in which some of the cached DHCP Server configuration information may be corrupt after a button reset. (18483) Fixed an issue in which a network endpoint (UDP socket) could become blocked because of an empty packet being sent to it. (18626) Invalid alarm subject when configuring an snmp trap alarm. (17656) In Network Services Settings page, ADDP UDP port may no longer be configured by the user. (16811) Added mobile phone number of cellular modem to Mobile System Information page in web UI. (17752) Fixed an issue in which telnet breaks were not being sent on a serial port. (17568) Fixed memory leaks. (17730, 18440) Fixed a failure to detect in a timely manner the end of a session in SSL/TLS, particularly during the handshake phase. (19068) Removed unneeded or invalid groups from the RCI reply. This eliminates confusion and significantly reduces the size of the generated output. (18880) Corrected duplicate and elements in the group. (19052) Added multiple AES key lengths (128, 192 and 256 bit) to ISAKMP/IKE phase 1 encryption proposals. Clarified encryption proposals for ISAKMP/IKE phase 2 proposals, which currently support only 256-bit keys. Removed the other key length selections from the UI for phase 2, until we support a configurable AES key length. (18824) 82001350_A - April 26, 2006 Initial release. - SureLink (tm) link integrity monitor. - DynDNS.org dynamic DNS support. - GSM data-only SIM/plan support. - Mobile data throughput enhancements. - Support for newer AirCard 860 firmware (1.1.29). - An issue was corrected which may have prevented negotation of PAP over the mobile link. - An issue was corrected where, under certain conditions, it was possible for the Digi Connect to be unaware of the dropped mobile link.