FireBrick Model: FB6000 | FB2500 | FB2700 | FB2900 | FB9000 | SoHo/Plus | FB105

OEM Version: FB   Change to: (default is FB)

Software Versions: Recent versions only | Factory releases | Factory and Beta | Factory, Beta & Alpha

Built 2011-01-17
Latest Alpha release
NOT WELL TESTED
2.02.647 (Thea+)

Release notes from Beta release 2.02.645 to Alpha release 2.02.647

ICMP error packets generated by the FB and sent out on a tunnel have source IP set to tunnel NAT IP (if set).

New tunnel port option is now available on bricks without bonding feature.

Built 2011-01-13
Latest Beta release
2.02.645 (Thea)

Release notes from Factory release 2.02.644 to Beta release 2.02.645

DHCP: Fixed problem where FB could incorrectly consider itself a backup server, and reply after a delay to some requests. Minor improvements/fixes to some DHCP log messages.

UI: Setup Log/Filter Options page did not redisplay after performing an email test.

Profiles: Ping profile now has an option to set the data length to be used in the ping packet - default is zero (as before).

Tunnels: Tunnels have a new option to set the UDP port number to be used for the tunnel envelope packets - default is 1 (as before). This enables tunnels to be used over some links with deep packet inspection which do not support UDP port 1.

Built 2009-09-07
Current factory release
2.02.644 (Sebastiana)

Release notes from Factory release 2.02.643 to Factory release 2.02.644

UI: Fix problem with clearing all Event actions in Log/Filter options.

Built 2009-02-12
Older factory release
2.02.643 (Rowena)

Release notes from Factory release 2.02.638 to Factory release 2.02.643

UI: The time at which the page was generated is now displayed on each page. Default filename for config save now includes Firebrick name and date/time. Setup Log/Filter options now correctly displays the default filter setting. Wizard should only display when user has enough access to make suggested change. Fix UI misbehaviour when clicking on Save Config after login has timed out.

Tunnels: Incorrect source IP could be used in some cases, causing a tunnel to fail to establish.

DHCP: Client was incorrectly setting an SNMP server in config on Firebrick without reporting feature. Server running as a backup was incorrectly adding "Offered" entries to DHCP table. Host name in "Offered" entries was sometimes incorrect. DHCP traffic to FireBrick is now allowed through the default filter, so no explicit filters are required for operation of DHCP.

ARP:ARP responses using ethernet 802 frame format are now accepted.

Routing: Session tracking of ICMP sessions (eg PING) improved.

Fix poor performance and lockup problems following reception of invalid length ether packets.
Built 2008-09-17
Older Beta release
2.02.641 (Quintijn)

Release notes from Factory release 2.02.638 to Beta release 2.02.641

UI: The time at which the page was generated is now displayed on each page. Default filename for config save now includes Firebrick name and date/time. Setup Log/Filter options now correctly displays the default filter setting. Wizard should only display when user has enough access to make suggested change. Fix UI misbehaviour when clicking on Save Config after login has timed out.

Tunnels: Incorrect source IP could be used in some cases, causing a tunnel to fail to establish.

DHCP: Client was incorrectly setting an SNMP server in config on Firebrick without reporting feature. Server running as a backup was incorrectly adding "Offered" entries to DHCP table. Host name in "Offered" entries was sometimes incorrect. DHCP traffic to FireBrick is now allowed through the default filter, so no explicit filters are required for operation of DHCP.

ARP:ARP responses using ethernet 802 frame format are now accepted.

Routing: Session tracking of ICMP sessions (eg PING) improved.

Built 2008-02-12
Older factory release
2.02.638 (Plonie)

Release notes from Factory release 2.02.637 to Factory release 2.02.638

Internal fix for compatibility with production labeller.
Built 2007-11-04
Older factory release
2.02.637 (Ottalie)

Release notes from Factory release 2.02.604 to Factory release 2.02.637

Introduction of new tunnel retiming code, which will be replacing the current tunnel reordering mechanism. The tunneling protocol version has been changed from V2 to V3 to include extra retiming information. If both ends of a tunnel are V3-capable, the Firebrick will automatically switch to V3 tunneling, and if tunnel bonding is in use, will retime the packets using the new information.
This release is fully compatible with the older V2 protocol, so can be safely used with FireBricks running pre-V3 software without the need for any configuration changes.
If desired, the old V2-style tunnel reordering can be forced even if both ends of the tunnel support V3.
Please note that this is work-in-progress, and further implementation changes are likely before this is fully released. Any feedback would be gratefully received. There is some new information shown on the tunnel set statistics page; this is primarily for diagnostics, and is not particularly useful for the end-user. The UI web pages have been extensively reviewed for this release. A few improvements to the UI have been incorporated, and several minor bugs fixed.
Changes include:
follows HTTP spec more closely;
HTML 4.01 strict compliance, with lower-case tags;
Fully customizable background colour;
improved login page (can now enter user CR password CR);
improved selection on session table page;
tidied Internet Explorer .png file transparency problem workaround (not needed for IE7);
failed login now logs out previous user;
handling of redirects and refreshed pages improved;
DNS servers can be cleared by saving blank entries;
Tooltips for icons and entry move options now displayed correctly in IE;

This release incorporates several enhancements, fixes and tidying up of the UI:

Throughput improvement:
A change made to the ethernet driver in the Folclinda release to improve tunnel performance had the unfortunate side-effect of reducing overall FireBrick throughput. The driver has been revamped yet again, and throughput and performance under load is now much improved.
An experimental option to allow the setting of a back-to-back packet transmit limit has been added on the setup ports page. The default setting (5) works well. Note that this option (and other CPU port settings on the setup ports page) are likely to be removed soon. Please check that you are using the defaults (input throttle off; pause disable off; back-to-back 5) unless you know what you are doing!

Tunnels:
Tunnel parameters are now forced to be consistent across a tunnel set.
Problems with a single tunnel (not in a set) and connecting to Linux tunnel implementation fixed.

Experimental (V3) bonded tunnel retiming:
The ethernet throughput improvements have resulted in improved behaviour of the original (V2) tunnel reordering mechanism, while the hoped-for improvements using the new V3 retiming have not yet materialised. Version 2 packet reordering is therefore now the default; version 3 must be explicitly selected. Note that users of Folclinda or Gemma beta releases should check their settings after upgrade, as the sense of the flag controlling V2/V3 reordering has been reversed.
There have been some V3 retiming changes: the thresholds controlling the latency adjustments are now parameterisable, and packets waiting to be sent now have their timing adjusted when a latency adjustment occurs.

UI changes:
Login mechanism improved - login returns to calling page after successful login, and when logged out with no access login page is displayed.
Introduction of use of POST method for UI actions causing FB state change. Style of the UI is consequently being changed to use forms/buttons rather than links for actions which have any effect on the brick operation or configuration.
Default custom user colour made a slightly lighter shade of grey.
Main page quick configure items are now left-aligned.
Fixed display of some blank table cells showing up with IE.
Improved UI for speed lane control and session display.
Fixed display of some pages with Opera browser (table cells lacking borders).
Saving the log in text form to a file now gives dialog box for file destination. Also it is now possible to save without clearing the log.

Miscellaneous:
Dynamic log display now detects TCP error/closure at remote end.
Very long log lines are no longer discarded.
Added extra LED setting options. These may be useful to enable a particular FireBrick situated with others to be identified.
Saved config file no longer has random data causing successive saves to differ.
Short ether packets padded with nulls rather than junk. [Solves a problem with a Juniper router, which was erroneously rejecting ping packets with non-null padding.]
DHCP bug fix (hopefully fixes occasional lease table corruption).
"VLAN 0" no longer appears in logging (it was causing some confusion).
Internal TCP stack improved - sessions to/from the brick terminate more cleanly, and out-of-order data arrival is supported making transfers faster when packets are dropped.
Port monitoring "Block normal traffic" option fixed (was not blocking traffic if the monitoring port belonged to an interface with one or more other ports).
Added connection timeout mechanism to TCP (mitigate UI loss due to faulty client or DoS attack).
ICMP destination unreachable error now distinguishes between host and network. Further UI improvements:
Conversion of status-changing links to use forms and POST completed. This has entailed the redesign of some parts of the UI.
The UI "look" has been adjusted to give near-identical presentation with Internet Explorer, FireFox and Opera.
Link to on-line documentation added to all pages.

Other changes:
DHCP bug fixes: lease table could get out of order, causing offering of wrong IP (subsequently retracted before being assigned); Correct IP source address on NAK packets.
Internal TCP stack closes connection cleanly, discarding unwanted input (previously could timeout and/or reset).
dologin and logt URLs repaired. Bug fixes:
A problem with ARPs on configurations using VLANs resulting in occasional dropped packets has been fixed.
A problem where routing of tunnel envelope traffic did not follow the routing parameters set in the tunnel configuration, and with tunnel UDP port 1 traffic sometimes appearing as two separate sessions in the session table has been fixed.
A problem in the internal TCP stack which could cause UI pages to display corrupted when a dropped packet caused a fast retransmit has been fixed.

Stealth changes:
New stealth pass-through options have been added for non-IP traffic and/or VLAN traffic, in addition to the IPv6 pass-through option. VLAN passthrough does not require the VLAN feature. Note that these settings are independent of the global stealth disable option.
A warning is displayed on the subnet page if a subnet is flagged as stealth but stealth is globally disabled.
With 5-port feature, a warning is displayed if stealth is enabled but the WAN and LAN interfaces are not both configured.

Other changes:
A setup delay time option has been added to ping-mode profiles. When set non-zero, the profile will not become active until an unbroken sequence of ping replies has been seen for the specified time.
A ping-mode profile that is also dependent on another profile will now not issue pings if replies would not affect the profile state. (i.e. a profile with an AND-dependency on another will not ping when the other profile is inactive, and one with an OR-dependency on another will not ping when the other is active.)
A UDP service has been added which will enable FireBrick throughput to be more easily measured. This needs to be used in combination with a client application which is not yet available.
The number of tunnel sets available with tunnel bonding has been increased to 15.
The Login and help links are no longer displayed on the login page.
Fixed a problem where ping profiles with timeout set to 1 second were erroneously timing out.

Previous fix to routing had broken some session matching - hopefully we've got it right this time! Please upgrade to this version if you have loaded Joost. UI:
The log can now be viewed (using an explicit URL .../log) during firmware upgrade when the FireBrick is requesting a new UI file.
The IPgroup and Portgroup pages have been improved, and now allow changes to be made as well as additions and deletions.
The Setup log/filter options page layout has been improved.
Wording on the features page when no contact can be established with the features server has been improved.
The ARP table now displays unknown MACs as blank, not 000000000000.
The MAC table display was sometimes reporting the wrong interface when port monitoring was in operation.
The "wizard" advisory warnings now warn if subnets have been configured but stealth is still enabled.
When a subnet shares the same interface, VLAN and IP range as an earlier subnet in the subnet table, it is now flagged as being an "extension" of the earlier subnet. [It is often useful to duplicate subnet entries in this way, eg to enable multiple DHCP allocation pools, IP aliases or alternative gateways to be specified.]

Routing:
Uplink bonding has been modified to allow bonding over two or more different interfaces (useful for 5-port configurations).
Up to 8 uplink bonding gateways may now be specified.
There has been some rearrangement of the internal router logic. This is unlikely to affect normal operation, but could affect unusual configurations.

DHCP:
Minor modifications have been made to DHCP. In particular, when a client requested renewal of an allocation, the reply was sometimes broadcast when it should have been unicast to the requesting client. This was upsetting some clients, causing them to repeatedly request renewal.

VRRP:
An implementation of VRRP (Virtual Router Redundancy Protocol) has been added. The Bonding feature is required in order to use this.

ARP:
Gratuitous ARPs are now sent whenever a change to a subnet which could affect the MAC address being used occurs, or whenever a subnet becomes live. A sequence of gratuitous ARPs over a few seconds are sent - this helps with devices (typically switches) where ports appear to become live a short while before the device actually begins to respond to traffic.
The same MAC is now used for all subnets sharing the same interface, VLAN and IP range (ie the first subnet and all its extensions - see UI changes above).
The common MAC and gratuitous ARP changes should help configurations with routers which do not regularly refresh their ARP tables. Unfortunately we know of at least one popular router which also ignores gratuitous ARPs, so in some cases a subnet change may still require routers to be rebooted.
A debug log entry is now made when MAC renewal of an active IP fails.

Other changes:
If an ICMP echo request (ping) has the Don't Fragment bit set, the reply will also be marked don't fragment.
When tunnel packets are sent on an interface which has multiple IPs, the destination IP used by remote end is now used by default as the source IP.
A problem which could cause a factory reset during startup if the brick rebooted unexpectedly has been fixed. This could have been the cause of the occasional loss of configuration seen after uploading new software.
Several efficiency improvements have been made, which should reduce CPU workload, and should improve stability and in some cases throughput.
A factory reset now disables debug logging. Fixed minor problem preventing deletion of filter table entries.
Added new tunnel bonding option to inhibit exclusion of first packet in a session from the bonding. The handling of packet fragments has been improved - they now participate fully in session tracking. This means they will be treated in the same way as unfragmented packets when filter, routing, mapping rules etc. are processed, so can be NATed or address mapped. This should improve performance, and also avoid problems with configurations using NATing where fragmentation cannot be avoided - eg VPNs. The distribution of traffic across bonded tunnel sets should also improve where there is significant fragmented data.

The checkbox for excluding the first packet of a bonded tunnelled session from special treatment which was added with Maraike has been fixed - it was not working correctly when a UI option setting other than "None" had been selected for number formatting.

The debug log output following an unexpected reboot now indicates which task was running at the time of failure. Fixes a problem with relaying DNS introduced with Norbart.
Built 2007-11-02
Older Beta release
2.02.636 (Norbart)

Release notes from Beta release 2.02.635 to Beta release 2.02.636

The handling of packet fragments has been improved - they now participate fully in session tracking. This means they will be treated in the same way as unfragmented packets when filter, routing, mapping rules etc. are processed, so can be NATed or address mapped. This should improve performance, and also avoid problems with configurations using NATing where fragmentation cannot be avoided - eg VPNs. The distribution of traffic across bonded tunnel sets should also improve where there is significant fragmented data.

The checkbox for excluding the first packet of a bonded tunnelled session from special treatment which was added with Maraike has been fixed - it was not working correctly when a UI option setting other than "None" had been selected for number formatting.

The debug log output following an unexpected reboot now indicates which task was running at the time of failure.
Built 2007-10-31
Older Beta release
2.02.635 (Maraike)

Release notes from Beta release 2.02.634 to Beta release 2.02.635

Fixed minor problem preventing deletion of filter table entries.
Added new tunnel bonding option to inhibit exclusion of first packet in a session from the bonding.
Built 2007-10-24
Older Beta release
2.02.634 (Leonie)

Release notes from Beta release 2.02.628 to Beta release 2.02.634

UI:
The log can now be viewed (using an explicit URL .../log) during firmware upgrade when the FireBrick is requesting a new UI file.
The IPgroup and Portgroup pages have been improved, and now allow changes to be made as well as additions and deletions.
The Setup log/filter options page layout has been improved.
Wording on the features page when no contact can be established with the features server has been improved.
The ARP table now displays unknown MACs as blank, not 000000000000.
The MAC table display was sometimes reporting the wrong interface when port monitoring was in operation.
The "wizard" advisory warnings now warn if subnets have been configured but stealth is still enabled.
When a subnet shares the same interface, VLAN and IP range as an earlier subnet in the subnet table, it is now flagged as being an "extension" of the earlier subnet. [It is often useful to duplicate subnet entries in this way, eg to enable multiple DHCP allocation pools, IP aliases or alternative gateways to be specified.]

Routing:
Uplink bonding has been modified to allow bonding over two or more different interfaces (useful for 5-port configurations).
Up to 8 uplink bonding gateways may now be specified.
There has been some rearrangement of the internal router logic. This is unlikely to affect normal operation, but could affect unusual configurations.

DHCP:
Minor modifications have been made to DHCP. In particular, when a client requested renewal of an allocation, the reply was sometimes broadcast when it should have been unicast to the requesting client. This was upsetting some clients, causing them to repeatedly request renewal.

VRRP:
An implementation of VRRP (Virtual Router Redundancy Protocol) has been added. The Bonding feature is required in order to use this.

ARP:
Gratuitous ARPs are now sent whenever a change to a subnet which could affect the MAC address being used occurs, or whenever a subnet becomes live. A sequence of gratuitous ARPs over a few seconds are sent - this helps with devices (typically switches) where ports appear to become live a short while before the device actually begins to respond to traffic.
The same MAC is now used for all subnets sharing the same interface, VLAN and IP range (ie the first subnet and all its extensions - see UI changes above).
The common MAC and gratuitous ARP changes should help configurations with routers which do not regularly refresh their ARP tables. Unfortunately we know of at least one popular router which also ignores gratuitous ARPs, so in some cases a subnet change may still require routers to be rebooted.
A debug log entry is now made when MAC renewal of an active IP fails.

Other changes:
If an ICMP echo request (ping) has the Don't Fragment bit set, the reply will also be marked don't fragment.
When tunnel packets are sent on an interface which has multiple IPs, the destination IP used by remote end is now used by default as the source IP.
A problem which could cause a factory reset during startup if the brick rebooted unexpectedly has been fixed. This could have been the cause of the occasional loss of configuration seen after uploading new software.
Several efficiency improvements have been made, which should reduce CPU workload, and should improve stability and in some cases throughput.
A factory reset now disables debug logging.
Built 2007-07-21
Older Beta release
2.02.628 (Koopje)

Release notes from Beta release 2.02.626 to Beta release 2.02.628

Bug fixes:
A problem with ARPs on configurations using VLANs resulting in occasional dropped packets has been fixed.
A problem where routing of tunnel envelope traffic did not follow the routing parameters set in the tunnel configuration, and with tunnel UDP port 1 traffic sometimes appearing as two separate sessions in the session table has been fixed.
A problem in the internal TCP stack which could cause UI pages to display corrupted when a dropped packet caused a fast retransmit has been fixed.

Stealth changes:
New stealth pass-through options have been added for non-IP traffic and/or VLAN traffic, in addition to the IPv6 pass-through option. VLAN passthrough does not require the VLAN feature. Note that these settings are independent of the global stealth disable option.
A warning is displayed on the subnet page if a subnet is flagged as stealth but stealth is globally disabled.
With 5-port feature, a warning is displayed if stealth is enabled but the WAN and LAN interfaces are not both configured.

Other changes:
A setup delay time option has been added to ping-mode profiles. When set non-zero, the profile will not become active until an unbroken sequence of ping replies has been seen for the specified time.
A ping-mode profile that is also dependent on another profile will now not issue pings if replies would not affect the profile state. (i.e. a profile with an AND-dependency on another will not ping when the other profile is inactive, and one with an OR-dependency on another will not ping when the other is active.)
A UDP service has been added which will enable FireBrick throughput to be more easily measured. This needs to be used in combination with a client application which is not yet available.
The number of tunnel sets available with tunnel bonding has been increased to 15.
The Login and help links are no longer displayed on the login page.
Fixed a problem where ping profiles with timeout set to 1 second were erroneously timing out.

Previous fix to routing had broken some session matching - hopefully we've got it right this time! Please upgrade to this version if you have loaded Joost.
Built 2007-07-20
Older Beta release
2.02.627 (Joost)
[Withdrawn]
This release has been withdrawn.

Release notes from Beta release 2.02.626 to Beta release 2.02.627

Bug fixes:
A problem with ARPs on configurations using VLANs resulting in occasional dropped packets has been fixed.
A problem where routing of tunnel envelope traffic did not follow the routing parameters set in the tunnel configuration, and with tunnel UDP port 1 traffic sometimes appearing as two separate sessions in the session table has been fixed.
A problem in the internal TCP stack which could cause UI pages to display corrupted when a dropped packet caused a fast retransmit has been fixed.

Stealth changes:
New stealth pass-through options have been added for non-IP traffic and/or VLAN traffic, in addition to the IPv6 pass-through option. VLAN passthrough does not require the VLAN feature. Note that these settings are independent of the global stealth disable option.
A warning is displayed on the subnet page if a subnet is flagged as stealth but stealth is globally disabled.
With 5-port feature, a warning is displayed if stealth is enabled but the WAN and LAN interfaces are not both configured.

Other changes:
A setup delay time option has been added to ping-mode profiles. When set non-zero, the profile will not become active until an unbroken sequence of ping replies has been seen for the specified time.
A ping-mode profile that is also dependent on another profile will now not issue pings if replies would not affect the profile state. (i.e. a profile with an AND-dependency on another will not ping when the other profile is inactive, and one with an OR-dependency on another will not ping when the other is active.)
A UDP service has been added which will enable FireBrick throughput to be more easily measured. This needs to be used in combination with a client application which is not yet available.
The number of tunnel sets available with tunnel bonding has been increased to 15.
The Login and help links are no longer displayed on the login page.
Built 2007-06-05
Older Beta release
2.02.626 (Irma)

Release notes from Beta release 2.02.625 to Beta release 2.02.626

Further UI improvements:
Conversion of status-changing links to use forms and POST completed. This has entailed the redesign of some parts of the UI.
The UI "look" has been adjusted to give near-identical presentation with Internet Explorer, FireFox and Opera.
Link to on-line documentation added to all pages.

Other changes:
DHCP bug fixes: lease table could get out of order, causing offering of wrong IP (subsequently retracted before being assigned); Correct IP source address on NAK packets.
Internal TCP stack closes connection cleanly, discarding unwanted input (previously could timeout and/or reset).
dologin and logt URLs repaired.
Built 2007-05-16
Older Beta release
2.02.625 (Harriet)

Release notes from Beta release 2.02.606 to Beta release 2.02.625

This release incorporates several enhancements, fixes and tidying up of the UI:

Throughput improvement:
A change made to the ethernet driver in the Folclinda release to improve tunnel performance had the unfortunate side-effect of reducing overall FireBrick throughput. The driver has been revamped yet again, and throughput and performance under load is now much improved.
An experimental option to allow the setting of a back-to-back packet transmit limit has been added on the setup ports page. The default setting (5) works well. Note that this option (and other CPU port settings on the setup ports page) are likely to be removed soon. Please check that you are using the defaults (input throttle off; pause disable off; back-to-back 5) unless you know what you are doing!

Tunnels:
Tunnel parameters are now forced to be consistent across a tunnel set.
Problems with a single tunnel (not in a set) and connecting to Linux tunnel implementation fixed.

Experimental (V3) bonded tunnel retiming:
The ethernet throughput improvements have resulted in improved behaviour of the original (V2) tunnel reordering mechanism, while the hoped-for improvements using the new V3 retiming have not yet materialised. Version 2 packet reordering is therefore now the default; version 3 must be explicitly selected. Note that users of Folclinda or Gemma beta releases should check their settings after upgrade, as the sense of the flag controlling V2/V3 reordering has been reversed.
There have been some V3 retiming changes: the thresholds controlling the latency adjustments are now parameterisable, and packets waiting to be sent now have their timing adjusted when a latency adjustment occurs.

UI changes:
Login mechanism improved - login returns to calling page after successful login, and when logged out with no access login page is displayed.
Introduction of use of POST method for UI actions causing FB state change. Style of the UI is consequently being changed to use forms/buttons rather than links for actions which have any effect on the brick operation or configuration.
Default custom user colour made a slightly lighter shade of grey.
Main page quick configure items are now left-aligned.
Fixed display of some blank table cells showing up with IE.
Improved UI for speed lane control and session display.
Fixed display of some pages with Opera browser (table cells lacking borders).
Saving the log in text form to a file now gives dialog box for file destination. Also it is now possible to save without clearing the log.

Miscellaneous:
Dynamic log display now detects TCP error/closure at remote end.
Very long log lines are no longer discarded.
Added extra LED setting options. These may be useful to enable a particular FireBrick situated with others to be identified.
Saved config file no longer has random data causing successive saves to differ.
Short ether packets padded with nulls rather than junk. [Solves a problem with a Juniper router, which was erroneously rejecting ping packets with non-null padding.]
DHCP bug fix (hopefully fixes occasional lease table corruption).
"VLAN 0" no longer appears in logging (it was causing some confusion).
Internal TCP stack improved - sessions to/from the brick terminate more cleanly, and out-of-order data arrival is supported making transfers faster when packets are dropped.
Port monitoring "Block normal traffic" option fixed (was not blocking traffic if the monitoring port belonged to an interface with one or more other ports).
Added connection timeout mechanism to TCP (mitigate UI loss due to faulty client or DoS attack).
ICMP destination unreachable error now distinguishes between host and network.
Built 2007-02-26
Older Beta release
2.02.606 (Gemma)

Release notes from Beta release 2.02.605 to Beta release 2.02.606

The UI web pages have been extensively reviewed for this release. A few improvements to the UI have been incorporated, and several minor bugs fixed.
Changes include:
follows HTTP spec more closely;
HTML 4.01 strict compliance, with lower-case tags;
Fully customizable background colour;
improved login page (can now enter user CR password CR);
improved selection on session table page;
tidied Internet Explorer .png file transparency problem workaround (not needed for IE7);
failed login now logs out previous user;
handling of redirects and refreshed pages improved;
DNS servers can be cleared by saving blank entries;
Tooltips for icons and entry move options now displayed correctly in IE;
Built 2007-01-31
Older Beta release
2.02.605 (Folclinda)

Release notes from Factory release 2.02.604 to Beta release 2.02.605

Introduction of new tunnel retiming code, which will be replacing the current tunnel reordering mechanism. The tunneling protocol version has been changed from V2 to V3 to include extra retiming information. If both ends of a tunnel are V3-capable, the Firebrick will automatically switch to V3 tunneling, and if tunnel bonding is in use, will retime the packets using the new information.
This release is fully compatible with the older V2 protocol, so can be safely used with FireBricks running pre-V3 software without the need for any configuration changes.
If desired, the old V2-style tunnel reordering can be forced even if both ends of the tunnel support V3.
Please note that this is work-in-progress, and further implementation changes are likely before this is fully released. Any feedback would be gratefully received. There is some new information shown on the tunnel set statistics page; this is primarily for diagnostics, and is not particularly useful for the end-user.
Built 2007-01-31
Older factory release
2.02.604 (Ester)

Release notes from Factory release 2.02.594 to Factory release 2.02.604

Fixed a problem where changes to setup security settings for the filters, users, tunnels, profiles and routes entries were ineffective. Improved checking of uploaded software and config files. Fixed problem preventing ports connected to certain makes of switch from re-establishing after parameter changes or a line test. Port Throttle and B/Limit options now work as intended. Corrected tunnel status checking, which was causing tunnels to appear to be up before keepalives had been exchanged in both directions. Added Date header to email messages. New "local information" feature allowing user-specifiable text and links to be displayed on the main menu page, configurable from setup page. Note that this is an experimental feature which may be changed or removed before the next factory release. Comments and suggestions are welcome.

Number of users increased to 25 (with extra features installed).
Advisory text displayed following factory reset, or on first use of brick, reinstated (had been accidentally removed in the 2005-10-08 Geertruid release).
Some warnings of possible config errors are now displayed in prominent text (red on white).
GRE protocol can now be selected on portmap page when using default user interface view of protocols.
Change to tunnel bonding to avoid mis-balanced tunnel output for a short period after a tunnel becomes active.
A timeout can now be set for ping-scanning profiles - default is ten seconds. Note that previously the timeout was five seconds and could not be altered.
Email made more resilient.
TCP/IP sessions to/from the fireBrick now correctly use MTU 576 to avoid possible packet fragmentation. New diagnostics flags added for development use only. One-minute packet count statistics no longer displayed to debug log. Moving a subnet which was set as the main default gateway or the subnet for routing syslog mesages now works correctly. Tunnel MTU is set back to default of 576 on erasing a tunnel. Tunnel state changes can be selected for logging on an individual tunnel basis. DHCP improvements: DHCP INFORM request is responded to; Interaction with ARP mechanism to check for in-use IP improved; A host with a single restricted entry for one IP can now swap from one MAC to another keeping the same IP even if old allocation is not released - this is useful when changing between wired and wireless connections.

ARP mechhanism: Improved efficiency of VLAN and multiple subnet handling.

Internal TCP stack: Efficiency improvements - download of UI pages and upload/download of config and software images is faster. Tidier end to TCP sessions. Follows RFCs more closely in error situations.

Miscellaneous: Display of session and DHCP tables much faster; Tunnel reorder stats display improved; Minor improvements to the port line test facility - mostly in UI reporting.

New features: Experimental 8Mbit throttle for internal switch to CPU data path - this is to aid investigation of bonding issues, and may give improved performance in some situations; Port monitoring facility added - one or more of the five switch ports may be configured to monitor all traffic on other selected ports.

Bug fixes: Change of subnet now correctly restarts DHCP client; In pseudo-gateway bonding, a gateway specified using a subnet was incorrectly used when the subnet was disabled by profile; Tunnel reordering now correctly gives up after 100ms when waiting for late packet (previously could take from 100-200ms before packet was assumed lost); Unwanted cacheing in some browsers (particularly FireFox) causing confusing behaviour on some pages (particularly login) should no longer occur. This release has a redesigned ethernet driver which may improve performance in some scenarios where occasional packet drops occurred. It has not been extensively tested, so should be used with caution. The experimental internal CPU port input throttle option should no longer be necessary, and should be unchecked for best throughput.
A minor omission in the status counters display has been fixed. Note that this release will show a non-zero "in undersize" core count - this is expected, and not an error. Counters on status page now displays a consistent 1-second snapshot.
The LAN/WAN Reverse setting on the Port setup page was not working (on bricks without the 5-Port feature) - fixed.
A problem with TCP window sizes causing config saves to time out with Internet Explorer has been fixed.
Further ajustments to ethernet driver code.
The MAC provided by the FB when sending Proxy ARP replies is now the same one as used for the corresponding subnet (when the requestor matches a subnet). Fixed update problem with In/Out port traffic counts on status page.
Fixed problem with DHCP occasionally offering in-use IPs.
Disabling ports no longer prevents them from being used for factory reset.
Added "All" tick boxes for setting view and edit rights on user setup page.
DNS server setup now allows the setting of two DNS server IPs.
The Setup Special functions Factory Reset option now allows same selections as available with cable factory reset - DHCP and LAN/WAN swap.
For testing purposes - added ability to disable CPU pause flow control. Fixed portgroup edit page, which was showing new port ranges preset to start at 1 when using Internet Explorer.
Added diagnostics to check for correct operation of UI page generator.
Corrected error in user access checking when editing the security controls.
Fixed typo on features page. Avoid log corruption if FireBrick reboots while writing to the log.
Drop packets sent to incorrect FireBrick MAC (eg from routers with stale ARP caches).
Improve buffer handling to avoid FireBrick lockups/reboots if buffers become exhausted.
Factory Reset selecting DHCP and/or WAN/LAN reversal now sets Stealth operation off. (Note that we now recommend stealth off for all but the simplest of configurations).
Allow packets with protocol zero (previously could lose session slots).
Improve routing of ICMP error messages, and avoid making unnecessary sessions for them. This fixes some scenarios in which brick would continually reboot when sent an ICMP storm.
Error page (eg page not found message) now displayed using FireBrick page style.
Internal build changes: Introduce OEM CR variant. Minor improvement in efficiency of ARP table code. Fix spurious debug log message when viewing route table.
Internal fix - Factory init URL required by production labelling equipment reinstated. Added new logo for CR OEM variant.
Reduced size of WEN image files by removing unused icons.
Fixed crashing due to very long lines in log file.
DHCP client and server improvements - fixed minor deviations from RFC; improved detection of in-use IPs; reworded some log messages; fixed kill of DHCP lease when over 255 leases present.
Fixed non-detection of non-functional DNS server when both DNS servers specified.
Fixed minor cacheing pobblem when upgrading; also made style sheet cacheable.
Preserve user login info over software upgrade.
Built 2007-01-03
Older Beta release
2.02.603 (Derkje)

Release notes from Beta release 2.02.602 to Beta release 2.02.603

Fix spurious debug log message when viewing route table.
Internal fix - Factory init URL required by production labelling equipment reinstated.
Built 2006-12-06
Older Beta release
2.02.602 (Chinoek)

Release notes from Beta release 2.02.601 to Beta release 2.02.602

Avoid log corruption if FireBrick reboots while writing to the log.
Drop packets sent to incorrect FireBrick MAC (eg from routers with stale ARP caches).
Improve buffer handling to avoid FireBrick lockups/reboots if buffers become exhausted.
Factory Reset selecting DHCP and/or WAN/LAN reversal now sets Stealth operation off. (Note that we now recommend stealth off for all but the simplest of configurations).
Allow packets with protocol zero (previously could lose session slots).
Improve routing of ICMP error messages, and avoid making unnecessary sessions for them. This fixes some scenarios in which brick would continually reboot when sent an ICMP storm.
Error page (eg page not found message) now displayed using FireBrick page style.
Internal build changes: Introduce OEM CR variant. Minor improvement in efficiency of ARP table code.
Built 2006-11-15
Older Beta release
2.02.601 (Bente)

Release notes from Beta release 2.02.600 to Beta release 2.02.601

Fixed portgroup edit page, which was showing new port ranges preset to start at 1 when using Internet Explorer.
Added diagnostics to check for correct operation of UI page generator.
Corrected error in user access checking when editing the security controls.
Fixed typo on features page.
Built 2006-11-14
Older Beta release
2.02.600 (Adaja)

Release notes from Beta release 2.02.599 to Beta release 2.02.600

Fixed update problem with In/Out port traffic counts on status page.
Fixed problem with DHCP occasionally offering in-use IPs.
Disabling ports no longer prevents them from being used for factory reset.
Added "All" tick boxes for setting view and edit rights on user setup page.
DNS server setup now allows the setting of two DNS server IPs.
The Setup Special functions Factory Reset option now allows same selections as available with cable factory reset - DHCP and LAN/WAN swap.
For testing purposes - added ability to disable CPU pause flow control.
Built 2006-09-28
Older Beta release
2.02.599 (Zavia)

Release notes from Beta release 2.02.598 to Beta release 2.02.599

Counters on status page now displays a consistent 1-second snapshot.
The LAN/WAN Reverse setting on the Port setup page was not working (on bricks without the 5-Port feature) - fixed.
A problem with TCP window sizes causing config saves to time out with Internet Explorer has been fixed.
Further ajustments to ethernet driver code.
The MAC provided by the FB when sending Proxy ARP replies is now the same one as used for the corresponding subnet (when the requestor matches a subnet).
Built 2006-08-19
Older Beta release
2.02.598 (Yasmijn)

Release notes from Beta release 2.02.597 to Beta release 2.02.598

This release has a redesigned ethernet driver which may improve performance in some scenarios where occasional packet drops occurred. It has not been extensively tested, so should be used with caution. The experimental internal CPU port input throttle option should no longer be necessary, and should be unchecked for best throughput.
A minor omission in the status counters display has been fixed. Note that this release will show a non-zero "in undersize" core count - this is expected, and not an error.
Built 2006-08-08
Older Beta release
2.02.597 (Xenie)

Release notes from Beta release 2.02.596 to Beta release 2.02.597

DHCP improvements: DHCP INFORM request is responded to; Interaction with ARP mechanism to check for in-use IP improved; A host with a single restricted entry for one IP can now swap from one MAC to another keeping the same IP even if old allocation is not released - this is useful when changing between wired and wireless connections.

ARP mechhanism: Improved efficiency of VLAN and multiple subnet handling.

Internal TCP stack: Efficiency improvements - download of UI pages and upload/download of config and software images is faster. Tidier end to TCP sessions. Follows RFCs more closely in error situations.

Miscellaneous: Display of session and DHCP tables much faster; Tunnel reorder stats display improved; Minor improvements to the port line test facility - mostly in UI reporting.

New features: Experimental 8Mbit throttle for internal switch to CPU data path - this is to aid investigation of bonding issues, and may give improved performance in some situations; Port monitoring facility added - one or more of the five switch ports may be configured to monitor all traffic on other selected ports.

Bug fixes: Change of subnet now correctly restarts DHCP client; In pseudo-gateway bonding, a gateway specified using a subnet was incorrectly used when the subnet was disabled by profile; Tunnel reordering now correctly gives up after 100ms when waiting for late packet (previously could take from 100-200ms before packet was assumed lost); Unwanted cacheing in some browsers (particularly FireFox) causing confusing behaviour on some pages (particularly login) should no longer occur.
Built 2006-07-06
Older Beta release
2.02.596 (Wellemtje)

Release notes from Beta release 2.02.595 to Beta release 2.02.596

New "local information" feature allowing user-specifiable text and links to be displayed on the main menu page, configurable from setup page. Note that this is an experimental feature which may be changed or removed before the next factory release. Comments and suggestions are welcome.

Number of users increased to 25 (with extra features installed).
Advisory text displayed following factory reset, or on first use of brick, reinstated (had been accidentally removed in the 2005-10-08 Geertruid release).
Some warnings of possible config errors are now displayed in prominent text (red on white).
GRE protocol can now be selected on portmap page when using default user interface view of protocols.
Change to tunnel bonding to avoid mis-balanced tunnel output for a short period after a tunnel becomes active.
A timeout can now be set for ping-scanning profiles - default is ten seconds. Note that previously the timeout was five seconds and could not be altered.
Email made more resilient.
TCP/IP sessions to/from the fireBrick now correctly use MTU 576 to avoid possible packet fragmentation. New diagnostics flags added for development use only. One-minute packet count statistics no longer displayed to debug log. Moving a subnet which was set as the main default gateway or the subnet for routing syslog mesages now works correctly. Tunnel MTU is set back to default of 576 on erasing a tunnel. Tunnel state changes can be selected for logging on an individual tunnel basis.
Built 2006-06-21
Older Beta release
2.02.595 (Veronica)

Release notes from Factory release 2.02.594 to Beta release 2.02.595

Fixed a problem where changes to setup security settings for the filters, users, tunnels, profiles and routes entries were ineffective. Improved checking of uploaded software and config files. Fixed problem preventing ports connected to certain makes of switch from re-establishing after parameter changes or a line test. Port Throttle and B/Limit options now work as intended. Corrected tunnel status checking, which was causing tunnels to appear to be up before keepalives had been exchanged in both directions. Added Date header to email messages.
Built 2006-05-31
Older factory release
2.02.594 (Uriel)

Release notes from Factory release 2.02.588 to Factory release 2.02.594

Firebricks would answet ARPs for 0.0.0.0. Fixed.
Tidy of some DHCP error messages.
Layout change on subnet page to make subnet more clearly an general parameter and not specifically for DHCP
Added DHCP "additional field" allowing a string tag to be sent from the DHCP server, e.g. 17 for boot path.
New DHCP additional string not working correctly, sorry... Fixed.
Updated style sheet on XT UI issue.
Following change to prevent Plus/SoHo code being loaded, Plus/SoHo configuration loads were also being rejected. Fixed. DHCP ranges consisting of a single IP were in some situations being mishandled, and not offered to the client. Fixed. Fixed stack usage diagnostic following reboot/panic. Added counter for rx overruns to statistics. RoHS modification for production control. Fixed problem with shaping rule matching - source port setting was being ignored.
Built 2006-01-30
Older Beta release
2.02.593 (Teudsindis)

Release notes from Beta release 2.02.592 to Beta release 2.02.593

Following change to prevent Plus/SoHo code being loaded, Plus/SoHo configuration loads were also being rejected. Fixed. DHCP ranges consisting of a single IP were in some situations being mishandled, and not offered to the client. Fixed.
Built 2005-12-02
Older Beta release
2.02.592 (Sarieke)

Release notes from Beta release 2.02.591 to Beta release 2.02.592

Updated style sheet on XT UI issue.
Built 2005-11-25
Older Beta release
2.02.591 (Rebecca)

Release notes from Beta release 2.02.590 to Beta release 2.02.591

New DHCP additional string not working correctly, sorry... Fixed.
Built 2005-11-25
Older Beta release
2.02.590 (Quincent)

Release notes from Beta release 2.02.589 to Beta release 2.02.590

Tidy of some DHCP error messages.
Layout change on subnet page to make subnet more clearly an general parameter and not specifically for DHCP
Added DHCP "additional field" allowing a string tag to be sent from the DHCP server, e.g. 17 for boot path.
Built 2005-11-19
Older Beta release
2.02.589 (Popkje)

Release notes from Factory release 2.02.588 to Beta release 2.02.589

Firebricks would answet ARPs for 0.0.0.0. Fixed.
Built 2005-10-31
Older factory release
2.02.588 (Onno)

Release notes from Factory release 2.02.583 to Factory release 2.02.588

Corrected warning tune disable so that it does work when not disabled.
Slight tidy on labels on some buttons.
Added ALT tages to icons in addition to existing TITLE tags on the links.
Moving a subnet did not adjust subnets referenced in mapping rules, fixed.
Moving a subnet did not adjust subnets in new bonded uplink rules, fixed.
Fix to obscure error message in log when a user attempts access from an interface they are not allowed - applied to nobody user, or a logged in user if they lose access from the interface they are using. The error message was jibberish.
Changed to a login attempt with no user or password entered simply re-presents login screen and makes no log entry. previously it said bad login but did not log it.
Added IP6 WAN/LAN passthrough option to stealth settings.
It appears that the 105 would allow loading of the Plus and SoHo code, which then killed the brick. This has been fixed from this release. Do not attempt to load Plus or SoHo code in to a FireBrick 105.
Built 2005-10-20
Older Beta release
2.02.587 (Nijnke)

Release notes from Beta release 2.02.586 to Beta release 2.02.587

Fix to obscure error message in log when a user attempts access from an interface they are not allowed - applied to nobody user, or a logged in user if they lose access from the interface they are using. The error message was jibberish.
Changed to a login attempt with no user or password entered simply re-presents login screen and makes no log entry. previously it said bad login but did not log it.
Added IP6 WAN/LAN passthrough option to stealth settings.
Built 2005-10-17
Older Beta release
2.02.586 (Malin)

Release notes from Beta release 2.02.585 to Beta release 2.02.586

Moving a subnet did not adjust subnets referenced in mapping rules, fixed.
Moving a subnet did not adjust subnets in new bonded uplink rules, fixed.
Built 2005-10-15
Older Beta release
2.02.585 (Leena)

Release notes from Beta release 2.02.584 to Beta release 2.02.585

Added ALT tages to icons in addition to existing TITLE tags on the links.
Built 2005-10-13
Older Beta release
2.02.584 (Koris)

Release notes from Factory release 2.02.583 to Beta release 2.02.584

Corrected warning tune disable so that it does work when not disabled.
Slight tidy on labels on some buttons.
Built 2005-10-11
Older factory release
2.02.583 (Janneke)

Release notes from Factory release 2.02.570 to Factory release 2.02.583

Addition option to not reorder UDP packets sent on bonded tunnel set. This is because recoder can mean small delays (a few hundred ms) when packets are dropped, which can adversely affect some UDP traffic (e.g. VoIP).
Made the QOS option also remove the traffic from the reodering process.
Setting ping profiles down a tunnel with a dynamic far end point could cause the routing rules to take precidence on startup rather than fixing to route via the tunnel. Fixed.
Increased internal buffering.
Routing to an explicit subnet without saying an explicit gateway but where that subnet has a gateway defined now take priority over the default gateway which was previously applied if the same interface as the chosen subnet.
Further slight adjustment on gateway routing as the default gateway may set a subnet with no actual gateway (as set up by DHCP) and the move made in the last beta to change this caused it no longer to look up the subnet gateway - now it checks for this in using the default gateway.
Added GRE to "standard" protocol selection.
Test build - no significant changes - please ignore.
Change for IE users (MSIE 5.5 upwards) to allow correct viewing on icons.
Wizard removed as mostly out of date. May be reintroduced later
Fix to Latest beta - it was showing the "Update quick settings" button on IE even where there were none.
Option to disable the login error warning music - in setup/UI options.
Bonded uplink improved. Now allows 6 real gateways. Gateways have profiles to allow fallback. Gateways can reference subnets and use their defined gateway rather than having to be entered as an IP address (ideal for use with DHCP).
Prospective factory release.
Includes new XT OEM issue.
Revised default security level on factory reset for "config load/save" to level 1 not level 8
Factory note: if re-loading from Talorcan, manually factory init once s/w loaded as config security level changed.
Built 2005-10-11
Older Beta release
2.02.582 (Inkie)

Release notes from Beta release 2.02.581 to Beta release 2.02.582

Prospective factory release.
Includes new XT OEM issue.
Built 2005-10-08
Older Beta release
2.02.581 (Hannah)

Release notes from Beta release 2.02.580 to Beta release 2.02.581

Bonded uplink improved. Now allows 6 real gateways. Gateways have profiles to allow fallback. Gateways can reference subnets and use their defined gateway rather than having to be entered as an IP address (ideal for use with DHCP).
Built 2005-10-08
Older Beta release
2.02.580 (Geertruid)

Release notes from Beta release 2.02.579 to Beta release 2.02.580

Wizard removed as mostly out of date. May be reintroduced later
Fix to Latest beta - it was showing the "Update quick settings" button on IE even where there were none.
Option to disable the login error warning music - in setup/UI options.
Built 2005-10-05
Older Beta release
2.02.579 (Fick)

Release notes from Beta release 2.02.578 to Beta release 2.02.579

Change for IE users (MSIE 5.5 upwards) to allow correct viewing on icons.
Built 2005-09-30
Older Beta release
2.02.578 (Erika)

Release notes from Beta release 2.02.577 to Beta release 2.02.578

Test build - no significant changes - please ignore.
Built 2005-09-26
Older Beta release
2.02.577 (Dagarada)

Release notes from Beta release 2.02.576 to Beta release 2.02.577

Added GRE to "standard" protocol selection.
Built 2005-09-11
Older Beta release
2.02.576 (Catharijn)

Release notes from Beta release 2.02.575 to Beta release 2.02.576

Further slight adjustment on gateway routing as the default gateway may set a subnet with no actual gateway (as set up by DHCP) and the move made in the last beta to change this caused it no longer to look up the subnet gateway - now it checks for this in using the default gateway.
Built 2005-09-06
Older Beta release
2.02.575 (Barbelijn)

Release notes from Beta release 2.02.574 to Beta release 2.02.575

Routing to an explicit subnet without saying an explicit gateway but where that subnet has a gateway defined now take priority over the default gateway which was previously applied if the same interface as the chosen subnet.
Built 2005-08-30
Older Beta release
2.02.574 (Aalbertje)

Release notes from Beta release 2.02.572 to Beta release 2.02.574

Increased internal buffering.
Built 2005-08-25
Older Beta release
2.02.572 (Veldicca)

Release notes from Beta release 2.02.571 to Beta release 2.02.572

Setting ping profiles down a tunnel with a dynamic far end point could cause the routing rules to take precidence on startup rather than fixing to route via the tunnel. Fixed.
Built 2005-08-23
Older Beta release
2.02.571 (Uige)

Release notes from Factory release 2.02.570 to Beta release 2.02.571

Addition option to not reorder UDP packets sent on bonded tunnel set. This is because recoder can mean small delays (a few hundred ms) when packets are dropped, which can adversely affect some UDP traffic (e.g. VoIP).
Made the QOS option also remove the traffic from the reodering process.
Built 2005-08-12
Older factory release
2.02.570 (Talorcan)

Release notes from Factory release 2.02.543 to Factory release 2.02.570

Setting an explicit gateway in the tunnel target interface did not work, fixed
Change to ping profiles - now ping every second, and show "DOWN" after 5 seconds of no response. So much more responsive.
Adjusted tunnel keep alives when sending traffic so sent every second at least.
Changed ping timeout to 10 seconds before "Down".
Adjustment for routing to specific subnets in tunnels/ping/syslog packets so general routing rules for the same interface do not override per-subnet explicit gateways.
Explicit gateway on tunnels also correctly.
Changed ping no response time back down to 5 second.
Additional debugging information on ping profile logs.
Removed extra ping debug - seems to be working fine.
Change to ping/syslog when directed to specific tunnel - routing rules no longer override.
Fixed bug where an interface (w.g. LAN) was shown as up even when the only ports are disabled but have link.
New fallback option on ports - allows two ports to work as main and fallback to the same switch network.
Some ethernet port reconfiguration (enable/disable, b/w limit, throttle, long, fallback) no longer force a renegotiation on the port.
Ethernet port status now shows if port is disabled.
Profiles now have a No-Log optio which stops logging of change of state from pinging for that profile.
Moving subnets adjusts other config entries referring to interface specific subnets so that they remain correct, however this was not the case for the newer interface specific entries for tunnels, or syslog messages. Corrected.
Bug in explicit routing on tunnel/profile/syslog where sending to a specific subnet without gateway specified could cause traffic to be misrouted.
Timestamps logged on session table.
Better session tracking of changes to profile pings, tunnels and syslog.
Session table has option for TCP without any traffic to the firebrick port 80 - i.e. the firebrick admin pages themselves.
Adjusted case where change of MAC on unsolicited ARP "announce" can flush cache.
Allowed packet reordering on bonded tunnels even when no shaping feature on FireBrick. Should only be used with some form of shaping, either independant, or at least at the far end brick.
Session start time shown (after clock set) for sessions that started before the clock was set, rather than blank.
Subnet list now shows gateway as well, reflecting the greater importance of the subnet specific gateway in routing
Tunnel sets now sequencing packets even when only one active tunnel - allows tunnel sequence stats are receiving end, showing lost packet stats
Tunnel state change events now a separate logging control option, specifically to allow notification of tunnels going down.
Change to config for tunnels - easier options for keep alive sending, and option to authenticate only on keep alives.
Note that the new tunnel state logging does not get used for tunnels in "timeout" state, where the Up/Down is still logged to debug.
Added new option on profiles for monitoring tunnel state
Minor correction - profiles showed tunnel state option even when tunnels not installed!
Made it so that the time matrix on a profile affects when the manual controlled profiles are shown on the login page.
Memory initialisation correction - tunnel bonded set code with reordering could crash and even factory reset on start up in some cases.
Made default for tunnels to have "Fix" ticked.
Kill link on session (TCP exclude web admin) showed all TCP after killing session, fixed.
Fixed issue where pings to a generic interface with explicit gateway made a new session for each ping.
Case where first packet on a timeout keep alive tunnel where far end sends keep alives all the time could be unsigned when it needed to be, fixed.
Changed "auto" keep-alive on tunnels to "normal"
Changed so that logging to the tunnel state log rather than debug depends on whether far end indicates it is (old bricks) sending keep alives, or (new bricks) is in "master" or "auto with fixed IP far end". I.e. it logs if the tunnel state is expected to stay up all the time.
Made it easier to see if tunnel up/down by colour coding.
Changed timeouts on tunnel keep alives so that compatible with older tunnels that would send 10 second keep alives is some data if flowing. Now 5 seconds of no packets or 10 seconds of no keep alive packets before down.
Updated the inactivity timeout for tunnels on no traffic to 12 seconds not 10 - as pluses seem to be a bit slow.
Reordering on bonded tunnels was not working correctly and so giving slow performance as of betas from yesterday - fixed.
Extra tunneling debug stats.
Made bonded tunnel reorder buffers much larger - jitter on BT lines is more than expected - also added time limiting on reorder buffer to handle occasional dropped packets better.
Error in reordering logic for bonded tunnel sets meant some packets could be incorrectly delayed, affecting performance.
Added separate config security level setting so that upgrading software and saving/loading config can be different security settings. This makes it possible to have a user that can do s/w upgrades and save configs but not load configs or do anything else - ideal for remote scripts. For existing bricks config load/save is set to the same security level as s/w upgrade. The default for factory init for config is 8.
Bonded tunnel sets with one or more inactive tunnels could cause problems with reordering performance - fixed
Correction to extra debug.
Reduced number of tunnel sets to 10
Slight efficiency improvements
Change order of options on tunnel entry page, and slight change of wording.
CHanged tick box for the authentication only on keep alives to be "full authorisation" so all packets signed when ticked.
Work on reordered bonded tunnel sets now ready for use
Corrected typo in tunnel page
Improved debug stats
Factory note: Oisin changed config security level - build with Janneke or later and factory init before labelling.
Built 2005-08-11
Older Beta release
2.02.569 (Salorch)

Release notes from Beta release 2.02.568 to Beta release 2.02.569

Change order of options on tunnel entry page, and slight change of wording.
CHanged tick box for the authentication only on keep alives to be "full authorisation" so all packets signed when ticked.
Built 2005-08-11
Older Beta release
2.02.568 (Rhybrawst)

Release notes from Beta release 2.02.566 to Beta release 2.02.568

Reduced number of tunnel sets to 10
Slight efficiency improvements
Built 2005-08-10
Older Beta release
2.02.566 (Qodvoldeus)

Release notes from Beta release 2.02.565 to Beta release 2.02.566

Correction to extra debug.
Built 2005-08-10
Older Beta release
2.02.565 (Oisin)

Release notes from Beta release 2.02.564 to Beta release 2.02.565

Extra tunneling debug stats.
Made bonded tunnel reorder buffers much larger - jitter on BT lines is more than expected - also added time limiting on reorder buffer to handle occasional dropped packets better.
Error in reordering logic for bonded tunnel sets meant some packets could be incorrectly delayed, affecting performance.
Added separate config security level setting so that upgrading software and saving/loading config can be different security settings. This makes it possible to have a user that can do s/w upgrades and save configs but not load configs or do anything else - ideal for remote scripts. For existing bricks config load/save is set to the same security level as s/w upgrade. The default for factory init for config is 8.
Bonded tunnel sets with one or more inactive tunnels could cause problems with reordering performance - fixed
Built 2005-08-10
Older Beta release
2.02.564 (Natorus)

Release notes from Beta release 2.02.563 to Beta release 2.02.564

Reordering on bonded tunnels was not working correctly and so giving slow performance as of betas from yesterday - fixed.
Built 2005-08-09
Older Beta release
2.02.563 (Madan)

Release notes from Beta release 2.02.562 to Beta release 2.02.563

Updated the inactivity timeout for tunnels on no traffic to 12 seconds not 10 - as pluses seem to be a bit slow.
Built 2005-08-09
Older Beta release
2.02.562 (Lainbhui)

Release notes from Beta release 2.02.561 to Beta release 2.02.562

Changed timeouts on tunnel keep alives so that compatible with older tunnels that would send 10 second keep alives is some data if flowing. Now 5 seconds of no packets or 10 seconds of no keep alive packets before down.
Built 2005-08-09
Older Beta release
2.02.561 (Kinan)

Release notes from Beta release 2.02.559 to Beta release 2.02.561

Memory initialisation correction - tunnel bonded set code with reordering could crash and even factory reset on start up in some cases.
Made default for tunnels to have "Fix" ticked.
Kill link on session (TCP exclude web admin) showed all TCP after killing session, fixed.
Fixed issue where pings to a generic interface with explicit gateway made a new session for each ping.
Case where first packet on a timeout keep alive tunnel where far end sends keep alives all the time could be unsigned when it needed to be, fixed.
Changed "auto" keep-alive on tunnels to "normal"
Changed so that logging to the tunnel state log rather than debug depends on whether far end indicates it is (old bricks) sending keep alives, or (new bricks) is in "master" or "auto with fixed IP far end". I.e. it logs if the tunnel state is expected to stay up all the time.
Made it easier to see if tunnel up/down by colour coding.
Built 2005-08-08
Older Beta release
2.02.559 (Ilbrec)

Release notes from Beta release 2.02.558 to Beta release 2.02.559

Minor correction - profiles showed tunnel state option even when tunnels not installed!
Made it so that the time matrix on a profile affects when the manual controlled profiles are shown on the login page.
Built 2005-08-08
Older Beta release
2.02.558 (Huna)

Release notes from Beta release 2.02.557 to Beta release 2.02.558

Added new option on profiles for monitoring tunnel state
Built 2005-08-07
Older Beta release
2.02.557 (Garva)

Release notes from Beta release 2.02.556 to Beta release 2.02.557

Change to config for tunnels - easier options for keep alive sending, and option to authenticate only on keep alives.
Note that the new tunnel state logging does not get used for tunnels in "timeout" state, where the Up/Down is still logged to debug.
Built 2005-08-06
Older Beta release
2.02.556 (Febal)

Release notes from Beta release 2.02.555 to Beta release 2.02.556

Subnet list now shows gateway as well, reflecting the greater importance of the subnet specific gateway in routing
Tunnel sets now sequencing packets even when only one active tunnel - allows tunnel sequence stats are receiving end, showing lost packet stats
Tunnel state change events now a separate logging control option, specifically to allow notification of tunnels going down.
Built 2005-08-01
Older Beta release
2.02.555 (Eburos)

Release notes from Beta release 2.02.554 to Beta release 2.02.555

Session start time shown (after clock set) for sessions that started before the clock was set, rather than blank.
Built 2005-07-31
Older Beta release
2.02.554 (Dall)

Release notes from Beta release 2.02.553 to Beta release 2.02.554

Allowed packet reordering on bonded tunnels even when no shaping feature on FireBrick. Should only be used with some form of shaping, either independant, or at least at the far end brick.
Built 2005-07-29
Older Beta release
2.02.553 (Caibre)

Release notes from Beta release 2.02.552 to Beta release 2.02.553

Timestamps logged on session table.
Better session tracking of changes to profile pings, tunnels and syslog.
Session table has option for TCP without any traffic to the firebrick port 80 - i.e. the firebrick admin pages themselves.
Adjusted case where change of MAC on unsolicited ARP "announce" can flush cache.
Built 2005-07-29
Older Beta release
2.02.552 (Baithene)

Release notes from Beta release 2.02.551 to Beta release 2.02.552

Bug in explicit routing on tunnel/profile/syslog where sending to a specific subnet without gateway specified could cause traffic to be misrouted.
Built 2005-07-28
Older Beta release
2.02.551 (Adgennus)

Release notes from Beta release 2.02.550 to Beta release 2.02.551

Moving subnets adjusts other config entries referring to interface specific subnets so that they remain correct, however this was not the case for the newer interface specific entries for tunnels, or syslog messages. Corrected.
Built 2005-07-22
Older Beta release
2.02.550 (Vediacus)

Release notes from Beta release 2.02.549 to Beta release 2.02.550

Removed extra ping debug - seems to be working fine.
Change to ping/syslog when directed to specific tunnel - routing rules no longer override.
Fixed bug where an interface (w.g. LAN) was shown as up even when the only ports are disabled but have link.
New fallback option on ports - allows two ports to work as main and fallback to the same switch network.
Some ethernet port reconfiguration (enable/disable, b/w limit, throttle, long, fallback) no longer force a renegotiation on the port.
Ethernet port status now shows if port is disabled.
Profiles now have a No-Log optio which stops logging of change of state from pinging for that profile.
Built 2005-07-20
Older Beta release
2.02.549 (Uepogenus)

Release notes from Beta release 2.02.548 to Beta release 2.02.549

Additional debugging information on ping profile logs.
Built 2005-07-16
Older Beta release
2.02.548 (Taliesin)

Release notes from Beta release 2.02.547 to Beta release 2.02.548

Changed ping no response time back down to 5 second.
Built 2005-07-16
Older Beta release
2.02.547 (Salmhor)

Release notes from Beta release 2.02.546 to Beta release 2.02.547

Adjustment for routing to specific subnets in tunnels/ping/syslog packets so general routing rules for the same interface do not override per-subnet explicit gateways.
Explicit gateway on tunnels also correctly.
Built 2005-07-16
Older Beta release
2.02.546 (Rhyanidd)

Release notes from Beta release 2.02.545 to Beta release 2.02.546

Changed ping timeout to 10 seconds before "Down".
Built 2005-07-16
Older Beta release
2.02.545 (Pridfirth)

Release notes from Beta release 2.02.544 to Beta release 2.02.545

Change to ping profiles - now ping every second, and show "DOWN" after 5 seconds of no response. So much more responsive.
Adjusted tunnel keep alives when sending traffic so sent every second at least.
Built 2005-07-11
Older Beta release
2.02.544 (Oilioll)

Release notes from Factory release 2.02.543 to Beta release 2.02.544

Setting an explicit gateway in the tunnel target interface did not work, fixed
Built 2005-07-03
Older factory release
2.02.543 (Nathrach)

Release notes from Factory release 2.02.537 to Factory release 2.02.543

Added Expires, Date, and Last_modified headers to try and avoid caching issues.
Date option Full changed to Text, and Full added as option showing day of week as well.
ARP flush for announce - fixed, and tested
Change to handling of ARP announce. Only flushes if a change of MAC. Only logs of flushes. Checks VLAN/subnet match as well. Continues processing of packet (for stealth, etc).
Less debug logging for routing to tunnels that are currently down.
Added tunnel set bias
Tunnel fallback was causing some disruption when used with bonded sets and reordering - fixed
Ooops, previous beta you could not edit the tunnels. Fixed
Do not use this version with reordering on bonded tunnel sets.
List of mapping rules did not show which tunnel traffic was mapped to when mapping to specific tunnel. Display bug only, actual settings still applied. Fixed.
Make the tunnel set packet reorder option only available if Shaping feature also installed as trying to use reorder without shaping the external link is not sensible.
Built 2005-06-23
Older Beta release
2.02.542 (Madach)

Release notes from Beta release 2.02.541 to Beta release 2.02.542

Ooops, previous beta you could not edit the tunnels. Fixed
Built 2005-06-23
Older Beta release
2.02.541 (Laethrig)

Release notes from Beta release 2.02.540 to Beta release 2.02.541

Less debug logging for routing to tunnels that are currently down.
Added tunnel set bias
Tunnel fallback was causing some disruption when used with bonded sets and reordering - fixed
Built 2005-06-11
Older Beta release
2.02.540 (Kilian)

Release notes from Beta release 2.02.539 to Beta release 2.02.540

Change to handling of ARP announce. Only flushes if a change of MAC. Only logs of flushes. Checks VLAN/subnet match as well. Continues processing of packet (for stealth, etc).
Built 2005-06-10
Older Beta release
2.02.539 (Ilaunos)

Release notes from Beta release 2.02.538 to Beta release 2.02.539

ARP flush for announce - fixed, and tested
Built 2005-06-08
Older Beta release
2.02.538 (Huil)

Release notes from Factory release 2.02.537 to Beta release 2.02.538

Added Expires, Date, and Last_modified headers to try and avoid caching issues.
Date option Full changed to Text, and Full added as option showing day of week as well.
Built 2005-05-31
Older factory release
2.02.537 (Gartnait)

Release notes from Factory release 2.02.525 to Factory release 2.02.537

DHCP client does not accept itself as a gateway (D-Link DSL-300T routers send this for some reason) Minor cosmetic tidy to some of the config screens when accessed without write permissions.
Change to UI for tunnel bonding - now select a set number for all tunnels in same set - more intuitive. Do not downgrade below this s/w release after upgrading if you use bonded tunnels.
Change UI for tunnels now showing per tunnel in and out stats, as well as additional debug stats for packet reordering on tunnel sets
Change to pick up ARP announce broadcasts and flush the ARP cache (rather than use the broadcast which could be bogus). Good for use with VRRP.
Some tunnel optimisation.
Previous beta was not working on more than two tunnels bonded, fixed.
Updated tunnel packet reorder debug stats
Corrected repeated version names, sorry
Correction to some tunnel handling when tunnels down (introduced in latest beta releases)
Tidy of presentation of tunnel set packet reordering information
More packet re-order stats
More tunnel reorder work - reorder buffering not yet ready
Corrected bug whereby tunnels did not fall back cleanly on failure within sets (introduced in latest betas)
Tunnel set packet reordering option added (experimental)
Corrected bug in tunnel set reorder code causing fragmented tunnel packets to break slowing permformance.
Note that reordering is still experimental
Tunnel set reordering was actually fighting with traffic shaping as the outgoing sequence was set before shaping was applied. Fixed - now sequences after shaping applied.
Do not use this version with reordering on bonded tunnel sets.
A bonded tunnel going half down (Up/down) would not cause it to be removed from the bonded set hence causing packet loss (which would then fight the packet reordering causing delayed packets). Fixed.
Using bounce to answer pings was meant to delay the replies. It seems this was broken at some point and so ping replies were not delayed. Fixed.
Built 2005-05-28
Older Beta release
2.02.536 (Farinmail)

Release notes from Beta release 2.02.535 to Beta release 2.02.536

Tunnel set reordering was actually fighting with traffic shaping as the outgoing sequence was set before shaping was applied. Fixed - now sequences after shaping applied.
Built 2005-05-28
Older Beta release
2.02.535 (Eborius)

Release notes from Beta release 2.02.534 to Beta release 2.02.535

Corrected bug in tunnel set reorder code causing fragmented tunnel packets to break slowing permformance.
Note that reordering is still experimental
Built 2005-05-27
Older Beta release
2.02.534 (Dalbh)

Release notes from Beta release 2.02.533 to Beta release 2.02.534

Tunnel set packet reordering option added (experimental)
Built 2005-05-27
Older Beta release
2.02.533 (Caenneth)

Release notes from Beta release 2.02.532 to Beta release 2.02.533

More tunnel reorder work - reorder buffering not yet ready
Corrected bug whereby tunnels did not fall back cleanly on failure within sets (introduced in latest betas)
Built 2005-05-26
Older Beta release
2.02.532 (Baithen)

Release notes from Beta release 2.02.531 to Beta release 2.02.532

More packet re-order stats
Built 2005-05-26
Older Beta release
2.02.531 (Addedomarus)

Release notes from Beta release 2.02.530 to Beta release 2.02.531

Corrected repeated version names, sorry
Correction to some tunnel handling when tunnels down (introduced in latest beta releases)
Tidy of presentation of tunnel set packet reordering information
Built 2005-05-25
Older Beta release
2.02.530 (Dalbaech)

Release notes from Beta release 2.02.529 to Beta release 2.02.530

Updated tunnel packet reorder debug stats
Built 2005-05-25
Older Beta release
2.02.529 (Caelur)

Release notes from Beta release 2.02.528 to Beta release 2.02.529

Some tunnel optimisation.
Previous beta was not working on more than two tunnels bonded, fixed.
Built 2005-05-25
Older Beta release
2.02.528 (Baithan)

Release notes from Beta release 2.02.527 to Beta release 2.02.528

Minor cosmetic tidy to some of the config screens when accessed without write permissions.
Change to UI for tunnel bonding - now select a set number for all tunnels in same set - more intuitive. Do not downgrade below this s/w release after upgrading if you use bonded tunnels.
Change UI for tunnels now showing per tunnel in and out stats, as well as additional debug stats for packet reordering on tunnel sets
Change to pick up ARP announce broadcasts and flush the ARP cache (rather than use the broadcast which could be bogus). Good for use with VRRP.
Built 2005-05-13
Older Beta release
2.02.527 (Adcoprovatus)

Release notes from Factory release 2.02.525 to Beta release 2.02.527

DHCP client does not accept itself as a gateway (D-Link DSL-300T routers send this for some reason)
Built 2005-04-28
Older factory release
2.02.525 (Veda)

Release notes from Factory release 2.02.516 to Factory release 2.02.525

Added new option for tunnels so that the source address used for NAT or FireBrick originated traffic can be defined. If undefined then the NAT will use an IP from the far end FireBrick.
Modified DHCP server to allow arbitrary range if used with /32 subnet (normally range is constrained to subnet).
. Minor tidy of tunnel control UI
Minor change to "DHCP invalid" comment on subnet control page when used with /31 or /32 subnets
Minor change to subnet control page
Changed page heading on tables to be left aligned rather than a centred caption (helps with wide IPgroup tables for example)
Changed display of ip/port group lists so table does not get stupidly wide - stops at 20 entries so you select to see the full list.
Added DHCP response UDP checksum as some devices were not happy with non checksum UDP even though valid (notably the WFT-E1 on EOS-1DsMkII), same for UDP time response.
Change to tunnels so that (like ping and syslog) the target interface and gateway IP can be specified if required
Made wording of target interface, source IP, and gateway consistent on syslog, profiles and tunnels
If an explicit route (in routing rules, or set in syslog, profiles, tunnels) is to a specific subnet with no gateway set and the subnet has a DHCP gatewayt defined, then that gateway is used. This is tested just before application of the default gateway.
Note that a DHCP client allocated a gateway will already set the DHCP gateway for that subnet, so can be used with above rule to allow routing to a DHCP client interface without knowing the gateway it will use.
Minor change that the system wide default gateway IP is not set if setting to a DHCP subnet as the gateway from the subnet itself can be implicitely used.
Correction that if the DHCP client is a different interface from the default gateway it is not changed, unless it has no gateway IP defined and it references a general ethernet interface or references an ethernet subnet which has no gateway defined.
Change in config on setup as setting gateway to blank rather than typing "none" did not set gateway!
Change so that DHCP requests are issued as soon as first port on an interface becomes active
Made I/f column on subnets indicate (red/green) if the interface is active (any ports connected)
Made the use of a subnet specific gateway after checking the default gateway, so default gateway can be to a subnet without specifying a gateway itself.
Built 2005-04-28
Older Beta release
2.02.524 (Ueda)
[Withdrawn]
This release has been withdrawn.

Release notes from Beta release 2.02.523 to Beta release 2.02.524

Minor change that the system wide default gateway IP is not set if setting to a DHCP subnet as the gateway from the subnet itself can be implicitely used.
Correction that if the DHCP client is a different interface from the default gateway it is not changed, unless it has no gateway IP defined and it references a general ethernet interface or references an ethernet subnet which has no gateway defined.
Built 2005-04-27
Older Beta release
2.02.523 (Talchimen)

Release notes from Beta release 2.02.522 to Beta release 2.02.523

Change to tunnels so that (like ping and syslog) the target interface and gateway IP can be specified if required
Made wording of target interface, source IP, and gateway consistent on syslog, profiles and tunnels
If an explicit route (in routing rules, or set in syslog, profiles, tunnels) is to a specific subnet with no gateway set and the subnet has a DHCP gatewayt defined, then that gateway is used. This is tested just before application of the default gateway.
Note that a DHCP client allocated a gateway will already set the DHCP gateway for that subnet, so can be used with above rule to allow routing to a DHCP client interface without knowing the gateway it will use.
Built 2005-03-18
Older Beta release
2.02.522 (Sal)

Release notes from Beta release 2.02.521 to Beta release 2.02.522

Added DHCP response UDP checksum as some devices were not happy with non checksum UDP even though valid (notably the WFT-E1 on EOS-1DsMkII), same for UDP time response.
Built 2005-03-14
Older Beta release
2.02.521 (Rhiada)

Release notes from Beta release 2.02.520 to Beta release 2.02.521

Changed display of ip/port group lists so table does not get stupidly wide - stops at 20 entries so you select to see the full list.
Built 2005-03-09
Older Beta release
2.02.520 (Reo-Derg)

Release notes from Beta release 2.02.519 to Beta release 2.02.520

Minor change to subnet control page
Changed page heading on tables to be left aligned rather than a centred caption (helps with wide IPgroup tables for example)
Built 2005-03-09
Older Beta release
2.02.519 (Prasutagus)

Release notes from Beta release 2.02.518 to Beta release 2.02.519

Minor tidy of tunnel control UI
Minor change to "DHCP invalid" comment on subnet control page when used with /31 or /32 subnets
Built 2005-03-09
Older Beta release
2.02.518 (Ogmios)

Release notes from Beta release 2.02.517 to Beta release 2.02.518

Modified DHCP server to allow arbitrary range if used with /32 subnet (normally range is constrained to subnet).
.
Built 2005-03-08
Older Beta release
2.02.517 (Natanleod)

Release notes from Factory release 2.02.516 to Beta release 2.02.517

Added new option for tunnels so that the source address used for NAT or FireBrick originated traffic can be defined. If undefined then the NAT will use an IP from the far end FireBrick.
Built 2005-02-24
Older factory release
2.02.516 (Macnia)

Release notes from Factory release 2.02.472 to Factory release 2.02.516

One more route in non-extras release making 5 plus subnets and default gateway.
One more profile in extras release making 100 plus fixed profiles.
Moved factory default top make subnets the first routing rule.
Correction to help text
Bug in LED cycling lights - not always change to/from this to showing port state.
Session list now has separate "kill" link at end rather than clicking on protocol.
Session list now also shows gateway in each direction, if any.
Session list now shows "Stealth" rather than S/R.
DHCP list now has separate "kill" link rather than clicking on interface.
DHCP list now has headings on table.
Ping profiles to an explicit ethernet subnet sets the source IP to that of the subnet before running through routing rules.
Ping profiles now have an option source IP setting.
Some internal changes for ATE.
Minor changes to load shared routes to correct an anomoly when routing to multiple tunnels
Added a debug message for DHCP client mode
Packet counter diagnostic stats added, 1 minute interval
Tunnel stats only applicable when tunnel feature installed
Added new options for setting routing and source address for syslog messages
Minor adjustments to diagnostic packet stats
Removed panic code 4D
Withdrawn Dropped internal diagnostic for ethernet loopback as giving misleading results
Changes in some debug messages, and fix of obscure issue with certain unexpected ping replies being misrouted.
Update that should fix tunnel lock up issue. OK, really fixing the tunnels this time...
Built 2005-02-24
Older Beta release
2.02.515 (Laery)

Release notes from Beta release 2.02.514 to Beta release 2.02.515

Update that should fix tunnel lock up issue.
Built 2005-02-05
Older Beta release
2.02.514 (Kian)

Release notes from Beta release 2.02.513 to Beta release 2.02.514

Changes in some debug messages, and fix of obscure issue with certain unexpected ping replies being misrouted.
Built 2005-02-01
Older Beta release
2.02.513 (Ilar)

Release notes from Beta release 2.02.510 to Beta release 2.02.513

Removed panic code 4D
Withdrawn Dropped internal diagnostic for ethernet loopback as giving misleading results
Built 2005-01-31
Older Beta release
2.02.512 (Huctia)
[Withdrawn]
This release has been withdrawn.

Release notes from Beta release 2.02.510 to Beta release 2.02.512

Removed panic code 4D
Withdrawn
Built 2005-01-28
Older Beta release
2.02.510 (Farinmagil)

Release notes from Beta release 2.02.509 to Beta release 2.02.510

Minor adjustments to diagnostic packet stats
Built 2005-01-28
Older Beta release
2.02.509 (Ebicatos)

Release notes from Beta release 2.02.508 to Beta release 2.02.509

Added new options for setting routing and source address for syslog messages
Built 2005-01-28
Older Beta release
2.02.508 (Dalbaech)

Release notes from Beta release 2.02.505 to Beta release 2.02.508

Packet counter diagnostic stats added, 1 minute interval
Tunnel stats only applicable when tunnel feature installed
Built 2005-01-07
Older Beta release
2.02.505 (Caelur)

Release notes from Beta release 2.02.502 to Beta release 2.02.505

Added a debug message for DHCP client mode
Built 2005-01-04
Older Beta release
2.02.502 (Baithan)

Release notes from Beta release 2.02.499 to Beta release 2.02.502

Minor changes to load shared routes to correct an anomoly when routing to multiple tunnels
Built 2004-12-12
Older Beta release
2.02.499 (Adcoprovatus)

Release notes from Beta release 2.02.485 to Beta release 2.02.499

Session list now has separate "kill" link at end rather than clicking on protocol.
Session list now also shows gateway in each direction, if any.
Session list now shows "Stealth" rather than S/R.
DHCP list now has separate "kill" link rather than clicking on interface.
DHCP list now has headings on table.
Ping profiles to an explicit ethernet subnet sets the source IP to that of the subnet before running through routing rules.
Ping profiles now have an option source IP setting.
Some internal changes for ATE.
Built 2004-11-25
Older Beta release
2.02.485 (Vatiaucus)

Release notes from Beta release 2.02.480 to Beta release 2.02.485

Bug in LED cycling lights - not always change to/from this to showing port state.
Built 2004-11-07
Older Beta release
2.02.480 (Uchtdealb)

Release notes from Beta release 2.02.479 to Beta release 2.02.480

Correction to help text
Built 2004-11-02
Older Beta release
2.02.479 (Taistellach)

Release notes from Factory release 2.02.472 to Beta release 2.02.479

One more route in non-extras release making 5 plus subnets and default gateway.
One more profile in extras release making 100 plus fixed profiles.
Moved factory default top make subnets the first routing rule.
Built 2004-10-05
Older factory release
2.02.472 (Saidhe)

Release notes from Factory release 2.02.430 to Factory release 2.02.472

Fixed speed lane selection so as not to try and show the extra interface names for 5 PORT or Tunnel when not installed.
Updated IP Wizard to set DHCP client on WAN side correctly.
Some internal changes related to some feature key handling.
Fix display on port map which was showing a range when it should not be.
Internal changes to TCP stack - no impact on normal usage. (RST packets sent with odd sequence numbers)
Internal change to self test on ethernet interface.
Minor change to config upload when uploading WAN/LAN reversed config.
Installing 5 port would sometimes create incorerct port assignments until rebooted.
Changes to re-route on profiles.
  • Will now force re-route of pings from the firebrick (which may make no difference if explicit interface specified in ping profile).
  • Will reroute traffic destined for tunnels (non NAT)
Tunnel bonding will now send the initial packet for any new session via the specified tunnel in the routing and not pick an alternative (unless the initial tunnel is down). Subsequent packets then bond. This helps with return traffic if far end is not bonding in the same way. Load balance routing can be used to spread initial packets.
Tunnel bonding will pick an alternative tunnel, even for start of session or QOS selected packets if the tunnel picked is down and alternatives exist.
Fixed case where routed traffic to broadcast destinations (directed broadcast) could generate ICMP errors if rejected by filters, which is invalid.
Changed login sequence to better work with firefox
Added "special" link in setup for factoryinit, reboot, etc.
Changed some links to work with lynx
Tunnel list shows near end IP now if set.
Factory reset link fixed
DHCP list on 5 port when less than 5 ports configured did not show all interfaces allocaing DHCP addresses
Added facicon
INternal change - better checking on UDP packet headers for traffic to the FireBrick
Saving a log while tracking it could cause the log output to be corrupted
Built 2004-10-01
Older Beta release
2.02.471 (Reoda)

Release notes from Beta release 2.02.470 to Beta release 2.02.471

INternal change - better checking on UDP packet headers for traffic to the FireBrick
Built 2004-09-27
Older Beta release
2.02.470 (Potomarus)

Release notes from Beta release 2.02.461 to Beta release 2.02.470

Factory reset link fixed
DHCP list on 5 port when less than 5 ports configured did not show all interfaces allocaing DHCP addresses
Added facicon
Built 2004-09-11
Older Beta release
2.02.461 (Ogma)

Release notes from Beta release 2.02.450 to Beta release 2.02.461

Minor change to config upload when uploading WAN/LAN reversed config.
Installing 5 port would sometimes create incorerct port assignments until rebooted.
Changes to re-route on profiles.
  • Will now force re-route of pings from the firebrick (which may make no difference if explicit interface specified in ping profile).
  • Will reroute traffic destined for tunnels (non NAT)
Tunnel bonding will now send the initial packet for any new session via the specified tunnel in the routing and not pick an alternative (unless the initial tunnel is down). Subsequent packets then bond. This helps with return traffic if far end is not bonding in the same way. Load balance routing can be used to spread initial packets.
Tunnel bonding will pick an alternative tunnel, even for start of session or QOS selected packets if the tunnel picked is down and alternatives exist.
Fixed case where routed traffic to broadcast destinations (directed broadcast) could generate ICMP errors if rejected by filters, which is invalid.
Changed login sequence to better work with firefox
Added "special" link in setup for factoryinit, reboot, etc.
Changed some links to work with lynx
Tunnel list shows near end IP now if set.
Built 2004-08-21
Older Beta release
2.02.450 (Narlos)

Release notes from Beta release 2.02.449 to Beta release 2.02.450

Internal change to self test on ethernet interface.
Built 2004-08-16
Older Beta release
2.02.449 (Kenulphus)

Release notes from Beta release 2.02.442 to Beta release 2.02.449

Internal changes to TCP stack - no impact on normal usage. (RST packets sent with odd sequence numbers)
Built 2004-07-05
Older Beta release
2.02.442 (Igerna)

Release notes from Beta release 2.02.439 to Beta release 2.02.442

Fix display on port map which was showing a range when it should not be.
Built 2004-06-30
Older Beta release
2.02.439 (Hlao)

Release notes from Beta release 2.02.438 to Beta release 2.02.439

Some internal changes related to some feature key handling.
Built 2004-06-30
Older Beta release
2.02.438 (Gargeolain)

Release notes from Beta release 2.02.437 to Beta release 2.02.438

Updated IP Wizard to set DHCP client on WAN side correctly.
Built 2004-06-24
Older Beta release
2.02.437 (Faolan)

Release notes from Factory release 2.02.430 to Beta release 2.02.437

Fixed speed lane selection so as not to try and show the extra interface names for 5 PORT or Tunnel when not installed.
Built 2004-06-16
Older factory release
2.02.430 (Eber)
This is the first release for this platform.
Built 2004-06-02
Older Beta release
2.02.412 (Daire)

Release notes from Beta release 2.02.404 to Beta release 2.02.412

Slight change to DHCP server to set sname to text version of bootp address if used, and send as option 66 (SNAME) [may be removed later, not sure].
Built 2004-05-11
Older Beta release
2.02.404 (Cael)

Release notes from Beta release 2.02.403 to Beta release 2.02.404

Further fix to port mapping display as was not showing a range when a range of target ports was selected.
Built 2004-05-11
Older Beta release
2.02.403 (Baiscne)

Release notes from Beta release 2.02.398 to Beta release 2.02.403

If more than 10 lines selected for paging on user then showed an ipgroup and port group No. 11 by mistake. Fixed.
Showing "lane" column on sessions even shaping not installed.
On mappings, if target IP range, then was showing range of mapped to port instead of single port.
Built 2004-04-21
Older Beta release
2.02.398 (Acco)

Release notes from Beta release 2.02.393 to Beta release 2.02.398

The quick setup screen was showing a red not green background on "allowed in" filters that were selected, in some cases. The check box was correct though. Fixed.
Built 2004-04-11
Older Beta release
2.02.393 (Vassedo)

Release notes from Beta release 2.02.390 to Beta release 2.02.393

Internal adjustment to ethernet flow control timing
Built 2004-04-06
Older Beta release
2.02.390 (Uchtain)

Release notes from Beta release 2.02.385 to Beta release 2.02.390

Added new option to specific TOS value considered to be priority for QOS controls in traffic shaping and bonded tunnels. (set in log/filter options)
Changed name of protocol 41 to Encap/IP6
Changing ip/port groups causes speed lanes to be re-evaluated
Editing filters caused change to general TOS value in 2.02.389 and not setting the filter tos value. Usually this severely affected VoIP as it made TOS 0 the setting for QO. 2.02.389 withdrawn.
Built 2004-04-03
Older Beta release
2.02.389 (Taileach)
[Withdrawn]
This release has been withdrawn.

Release notes from Beta release 2.02.385 to Beta release 2.02.389

Added new option to specific TOS value considered to be priority for QOS controls in traffic shaping and bonded tunnels. (set in log/filter options)
Changed name of protocol 41 to Encap/IP6
Changing ip/port groups causes speed lanes to be re-evaluated
Built 2004-03-29
Older Beta release
2.02.385 (Saenu)

Release notes from Beta release 2.02.383 to Beta release 2.02.385

Also now showing stealth on the subnet list when selected with 5 port option
Incorrect rate (min) shown in speed lane list, fixed.
Built 2004-03-26
Older Beta release
2.02.383 (Reoda)

Release notes from Beta release 2.02.381 to Beta release 2.02.383

Same minor routing change made to default gateway
Returned stealth tick box on subnets for 5 port option
Built 2004-03-21
Older Beta release
2.02.381 (Regol)

Release notes from Beta release 2.02.379 to Beta release 2.02.381

Subtle change in routing rules so that return routes to general interfaces work subnet based on subnet not originating subnet.
Built 2004-03-21
Older Beta release
2.02.379 (Potitus)

Release notes from Beta release 2.02.375 to Beta release 2.02.379

Allows default route to be set to tunnel with no IP address (as there is no need on a tunnel)
Some minor typos fixed
Change to description of Fast TOS. Now labeled QOS. Same action to set priority for traffic with TOS bits 7 or 4 set, typically for VoIP.
Add QOS option to tunnels when bonding un use. If set then packets with TOS bits 7 or 4 set are not reordered (forced down same tunnel).
Built 2004-03-14
Older Beta release
2.02.375 (Ogarmach)

Release notes from Beta release 2.02.355 to Beta release 2.02.375

Speed lanes were not allowing edit of flags for fast, fast ack, fast tos, fixed
Added Display of min and max rate on speed lanes
Lots more testing with VoIP over ADSL and speed lanes
Changed ifName in SNMP reporting to be "eth0", etc., as per MIB spec.
Changed ifDesc in SNMP reporting to return description as per MIB spec, with option to send just a number like hp switches do.
Built 2004-03-08
Older Beta release
2.02.355 (Naoise)

Release notes from Beta release 2.02.341 to Beta release 2.02.355

Change to lane give/take feature - see manuals for more details
Basically simplified. Each lane/direction now has a min and a max setting and any spare capacity unused by the master to added to the currently used capacity on each subordinate lane. Setting the max to the same as the min stops this on any lane.
Older configs which did not have "take" specified on a lane will automatically have the "max" setting set to the same as the "min" to operate in the same way.
Slight change on maximum queue latency controls. TCP 500ms as before, but other protocols now 1s.
Conversion from old configs before 2.02.352 was not quite right.
Further tidy of conversion from old configs.
Speed icon displayed interface now defaults to the interface selected as the default gateway interface.
Factory default example speed lanes for ADSL now set max as well as min
Built 2004-03-07
Older Beta release
2.02.353 (Machar)
[Withdrawn]
This release has been withdrawn.

Release notes from Beta release 2.02.341 to Beta release 2.02.353

Change to lane give/take feature - see manuals for more details
Basically simplified. Each lane/direction now has a min and a max setting and any spare capacity unused by the master to added to the currently used capacity on each subordinate lane. Setting the max to the same as the min stops this on any lane.
Older configs which did not have "take" specified on a lane will automatically have the "max" setting set to the same as the "min" to operate in the same way.
Slight change on maximum queue latency controls. TCP 500ms as before, but other protocols now 1s.
Conversion from old configs before 2.02.352 was not quite right.
Built 2004-03-07
Older Beta release
2.02.352 (Laegaire)
[Withdrawn]
This release has been withdrawn.

Release notes from Beta release 2.02.341 to Beta release 2.02.352

Change to lane give/take feature - see manuals for more details
Basically simplified. Each lane/direction now has a min and a max setting and any spare capacity unused by the master to added to the currently used capacity on each subordinate lane. Setting the max to the same as the min stops this on any lane.
Older configs which did not have "take" specified on a lane will automatically have the "max" setting set to the same as the "min" to operate in the same way.
Slight change on maximum queue latency controls. TCP 500ms as before, but other protocols now 1s.
Built 2004-03-06
Older Beta release
2.02.341 (Kentigern)

Release notes from Beta release 2.02.333 to Beta release 2.02.341

SNMP reports oper status as down on a filter that is marked suspended - avoids seeing stupid numbers of operational interfaces.
SNMP reports oper status as down on all lanes for to/from interfaces which are not in use - again, cuts down number of operational interaces.
SNMP reports admin status as down on all lanes for to/from interfaces which are not valid (feature not present).
OK, the SNMP oper status for filters was messed up. Fixed.
Built 2004-03-06
Older Beta release
2.02.338 (Igalram)
[Withdrawn]
This release has been withdrawn.

Release notes from Beta release 2.02.333 to Beta release 2.02.338

SNMP reports oper status as down on a filter that is marked suspended - avoids seeing stupid numbers of operational interfaces.
SNMP reports oper status as down on all lanes for to/from interfaces which are not in use - again, cuts down number of operational interaces.
SNMP reports admin status as down on all lanes for to/from interfaces which are not valid (feature not present).
Built 2004-03-06
Older Beta release
2.02.333 (Heremon)

Release notes from Beta release 2.02.297 to Beta release 2.02.333

SNMP walking no longer includes various fields we did not have data for.
New SNMP interface numbering. 1-5 is physical ports, 6 is core. 101-200 is filters. 201-250 is shaping to/from WAN. 301-350 is shaping to/from LAN ... up to 701-750 shaping to/from tunnel.
Corrected bug in SNMP where values 128 to 255 were returned incorrectly.
Added extended interface stats for interfaces 1-6 including in/out discards/errors/unicast, ifName and ifAlias.
Built 2004-03-05
Older Beta release
2.02.297 (Garbhcronan)

Release notes from Beta release 2.02.276 to Beta release 2.02.297

Speed lanes now specified in Kbits/s not Kbytes/s. Existing configs scales by 8 automatically.
As per normal use for communications links, K in traffic rates now 1000 not 1024
Internal changes to speed lanes to make the control more accurate (previously higher speeds were somewhat approximate)
Speed figures on master speed lane now includes all subordinate speed lane traffic as well
Note that historical statistics (today, yesterday, this month, last month) on speed lanes will be reset on upgrade to this software
Speed lanes now allow control of rate TO and rate FROM each interface. For any traffic the src and destination interface speeds are both applied (effectely limiting to the lower speed).
Speed lanes now record usage of rate TO and rate FROM each interface.
Speed lane configuration page now operates on one selectable interface at a time (would be 2 cluttered with 12 separate entries per lane, and most people only want to control to/from WAN anyway).
Corrected factory default on speed lanes to by right values in Kbits/s
Further minor changes to speed lane controls after testing
Built 2004-03-05
Older Beta release
2.02.291 (Eathfaigh)
[Withdrawn]
This release has been withdrawn.

Release notes from Beta release 2.02.276 to Beta release 2.02.291

Speed lanes now specified in Kbits/s not Kbytes/s. Existing configs scales by 8 automatically.
As per normal use for communications links, K in traffic rates now 1000 not 1024
Internal changes to speed lanes to make the control more accurate (previously higher speeds were somewhat approximate)
Speed figures on master speed lane now includes all subordinate speed lane traffic as well
Note that historical statistics (today, yesterday, this month, last month) on speed lanes will be reset on upgrade to this software
Speed lanes now allow control of rate TO and rate FROM each interface. For any traffic the src and destination interface speeds are both applied (effectely limiting to the lower speed).
Speed lanes now record usage of rate TO and rate FROM each interface.
Speed lane configuration page now operates on one selectable interface at a time (would be 2 cluttered with 12 separate entries per lane, and most people only want to control to/from WAN anyway).
Built 2004-03-04
Older Beta release
2.02.276 (Daigre)

Release notes from Beta release 2.02.269 to Beta release 2.02.276

Added option to allow speeds to be shown in Kbits/s rather than Kbytes/s
Built 2004-03-04
Older Beta release
2.02.269 (Caedmac)

Release notes from Beta release 2.02.160 to Beta release 2.02.269

Killing a session with session number over 999 and commas in the UI options would not work, fixed
Support for /31 subnets (both IPs valid and not broadcast), RFC3021
Without extras, only 9 profiles where available, now 10 as per manuals
Ranges of IPs are displayed more clearly in some cases, e.g. 172.16-31.X.X with UI option to show ranges in full instead
UI Option to show ranges of IPs using netmask/CIDR notation where possible
UI Option to show netmasks in non CIDR notation
Default IP group RFC1918 block was incorrect, was 172.16.255.255-172.31.255.255 not 172.16-31.X.X
Change to default filters to remove general outgoing ICMP and add an incoming "Ping" specific filter
Factory reset as DHCP server on LAN was not working, fixed
Factory reset as WAN/LAN reverse on 5 port now does reverse WAN/LAN with LAN as port 1
DHCP client is quicker to pick up an address at startup now
Port mappings now have option of percentage chance (part of bonding feature) like routing does
In 5 port mode, where some interfaces were not being used, shaping rules listed wrong interfaces
Speed lanes now allow control of "To Tunnel" traffic. The tunnelled traffic (UDP port 1) is not affected by speed lanes, but does count in usage.
White, Black and Purple options added to user colour controls
Important change to weighted rule handling - see Manuals
IP wizard was removing routes to subnets, as well as not making all settings correctly.
Added some colour to log display
Deleting a user will immediately log them out.
Much faster tunnel handling - to accomodate 3 x 2Mb ADSL bonded line handling
Firebrick web configuration pages now faster especially over remote links
General optimisations, and fix of packet delay issue when rejecting traffic
Current in/out KB/s per port now shown on status page
Counters on ports now show per second values as well
Was not able to set flags (fast ACK, etc) on "To tunnel" in speed lane controls
Renamed "monitoring" feature to "reporting" as people confused with ping scanning (profiles)
New improved purple
Change to login screen when uploading UI
Changed factory default filters to be Any->LAN and LAN->Any rather than WAN->LAN and LAN->WAN
Corrected error introduced in 2.02.200 which causes tunnels not to work in some cases. If you are running 2.02.200 or 2.02.260 and use tunnels you should upgrade.
Built 2004-03-01
Older Beta release
2.02.260 (Baethbarr)
[Withdrawn]
This release has been withdrawn.

Release notes from Beta release 2.02.160 to Beta release 2.02.260

Killing a session with session number over 999 and commas in the UI options would not work, fixed
Support for /31 subnets (both IPs valid and not broadcast), RFC3021
Without extras, only 9 profiles where available, now 10 as per manuals
Ranges of IPs are displayed more clearly in some cases, e.g. 172.16-31.X.X with UI option to show ranges in full instead
UI Option to show ranges of IPs using netmask/CIDR notation where possible
UI Option to show netmasks in non CIDR notation
Default IP group RFC1918 block was incorrect, was 172.16.255.255-172.31.255.255 not 172.16-31.X.X
Change to default filters to remove general outgoing ICMP and add an incoming "Ping" specific filter
Factory reset as DHCP server on LAN was not working, fixed
Factory reset as WAN/LAN reverse on 5 port now does reverse WAN/LAN with LAN as port 1
DHCP client is quicker to pick up an address at startup now
Port mappings now have option of percentage chance (part of bonding feature) like routing does
In 5 port mode, where some interfaces were not being used, shaping rules listed wrong interfaces
Speed lanes now allow control of "To Tunnel" traffic. The tunnelled traffic (UDP port 1) is not affected by speed lanes, but does count in usage.
White, Black and Purple options added to user colour controls
Important change to weighted rule handling - see Manuals
IP wizard was removing routes to subnets, as well as not making all settings correctly.
Added some colour to log display
Deleting a user will immediately log them out.
Much faster tunnel handling - to accomodate 3 x 2Mb ADSL bonded line handling
Firebrick web configuration pages now faster especially over remote links
General optimisations, and fix of packet delay issue when rejecting traffic
Current in/out KB/s per port now shown on status page
Counters on ports now show per second values as well
Was not able to set flags (fast ACK, etc) on "To tunnel" in speed lane controls
Renamed "monitoring" feature to "reporting" as people confused with ping scanning (profiles)
New improved purple
Built 2004-02-24
Older Beta release
2.02.200 (Vallaunius)
[Withdrawn]
This release has been withdrawn.

Release notes from Beta release 2.02.160 to Beta release 2.02.200

Killing a session with session number over 999 and commas in the UI options would not work, fixed
Support for /31 subnets (both IPs valid and not broadcast), RFC3021
Without extras, only 9 profiles where available, now 10 as per manuals
Ranges of IPs are displayed more clearly in some cases, e.g. 172.16-31.X.X with UI option to show ranges in full instead
UI Option to show ranges of IPs using netmask/CIDR notation where possible
UI Option to show netmasks in non CIDR notation
Default IP group RFC1918 block was incorrect, was 172.16.255.255-172.31.255.255 not 172.16-31.X.X
Change to default filters to remove general outgoing ICMP and add an incoming "Ping" specific filter
Factory reset as DHCP server on LAN was not working, fixed
Factory reset as WAN/LAN reverse on 5 port now does reverse WAN/LAN with LAN as port 1
DHCP client is quicker to pick up an address at startup now
Port mappings now have option of percentage chance (part of bonding feature) like routing does
In 5 port mode, where some interfaces were not being used, shaping rules listed wrong interfaces
Speed lanes now allow control of "To Tunnel" traffic. The tunnelled traffic (UDP port 1) is not affected by speed lanes, but does count in usage.
White, Black and Purple options added to user colour controls
Important change to weighted rule handling - see Manuals
IP wizard was removing routes to subnets, as well as not making all settings correctly.
Added some colour to log display
Deleting a user will immediately log them out.
Built 2004-02-10
Older Beta release
2.02.160 (Uccus)

Release notes from Beta release 2.02.128 to Beta release 2.02.160

New option on tunnels, MSS Fixup, which adjusts TCP MSS (if specified) on SYNs to the appropriate value for the specified MTU to avoid segmenting packets.
New feature on tunnels when bonding available to allow multiple tunnels to be bonded
Slight re-ordering of fields in Tunnel config pages
Change to subnet DHCP restrict feature allowing different restriction prefix from subnet name
Change to subnet DHCP restrict to also match MAC (hex) as well as name against prefix
Log output (and syslog, etc) for drop/accept/etc and end session now has more information in interface name (subnet/tunnel name)
End session log has additional information on NAT address/ports applied
Log/filter options controlling debug were not working correctly.
A configuration with no speed limit but "Take" set to take capacity from another speed lane could be limited in speed sometimes. Such a config was not sensbile anyway. Fixed
On end of routes the gateway route was badly laid out, fixed
Some DHCP debug logs were badly formatted - tidied up
Built 2004-01-30
Older Beta release
2.02.128 (Tailc)

Release notes from Beta release 2.02.127 to Beta release 2.02.128

IP Wizard to create bonded uplink was broken (backup routes were none->WAN not any->WAN), fixed
Speed lanes have new latency adding option for simulation of high latency links (e.g. satellite)
Built 2004-01-26
Older Beta release
2.02.127 (Saenius)

Release notes from Beta release 2.02.098 to Beta release 2.02.127

Internal changes for load handling and monitoring on ethernet device drivers, and added counters on diagnostics pages.
In some cases shortly after first getting a DHCP address a power cycle would lose the config, fixed
Added diagnostic log entries for connection/disconnection of ports
Built 2004-01-08
Older Beta release
2.02.098 (Rascua)

Release notes from Beta release 2.02.097 to Beta release 2.02.098

Speed lanes were not re-allocated when time profiles changed unless "re-route" also ticked on profile. Fixed
Built 2004-01-02
Older Beta release
2.02.097 (Pisear)

Release notes from Beta release 2.02.094 to Beta release 2.02.097

Changes "reroute" on profiles not to affect traffic destined for a tunnel, but obviously affects the UDP port 1 tunnel traffic itself still.
Minor change for ARPs when ARP on WAN stealth
Built 2003-12-18
Older Beta release
2.02.094 (Odras)

Release notes from Beta release 2.02.091 to Beta release 2.02.094

Slight change in TCP stack for RST response handling
Built 2003-12-12
Older Beta release
2.02.091 (Nantua)

Release notes from Beta release 2.02.084 to Beta release 2.02.091

Minor change to ARP stealth on units with 5port option
Fixed bug in ARP cache which could affect large sites
Log for "restored contact" showing junk if profile was 20 character name, fixed
DHCP client could get confused with replies to other firebricks on same LAN, fixed
Fixed diagnostic MAC report when using multiple interfaces (5 port option)
Built 2003-11-24
Older Beta release
2.02.084 (Macer)

Release notes from Beta release 2.02.082 to Beta release 2.02.084

Loading an old firebrick config would sometimes get the allowed interface list wrong on User settings. Fixed
Loading an old firebrick config could show misleading interface directions for subnets in the routing table. Fixed
IP Wizard was not setting ping profiles to ping 24/7. Fixed
Slight change to wording for ping profile lost/restored contact so truncated subnet shows currently if email->SMS.
Internal ATE change
Built 2003-11-15
Older Beta release
2.02.082 (Keir)

Release notes from Beta release 2.02.074 to Beta release 2.02.082

When editing any filter/route/etc which used the "IP of logged in user" IP group, this was not selected, so a save would then use "Any" IP.
Error in debug log message report for invalid VLANs tags, fixed
Built 2003-11-08
Older Beta release
2.02.074 (Iehmarc)

Release notes from Beta release 2.02.070 to Beta release 2.02.074

Changed speed lane operation so that master speed lane is selectable per speed lane
Changed factory default speed lanes
Added tool tips to lane setup
Mapping listing page had new ip/port mixed up - fixed
Built 2003-11-07
Older Beta release
2.02.070 (Heber)

Release notes from Beta release 2.02.016 to Beta release 2.02.070

Corrected summer time / winter time change to be 01:00 UTC, was 01:00 BST
Improved log to not say install key "expired" if actually "up to date"
Changed log to say "Install key" not "Auth" to be consistent
Link from speed lanes to sessions was broken
Setting Full duplex mode was not showing as set when going back to ports page
Status now shows DHCP allocations on LAN2/3/4 as well (e.g. 5 port mode)
Possible MAC cache problem with WAN/LAN reversal mode, corrected
Tidied up option to name interfaces - now available without 5 port option
5port option allows complete flexability of which ports are what interfaces Check config after upgrade
Stealth now operates between WAN and LAN even in 5 port mode (providing WAN and LAN both have ports defined)
Factory reset for 5 port sets 5 separate interfaces, and stealth enabled
Corrected factory reset which set the gateway interface incorrectly by default
Change to try and ensure a logged in user stays logged in when loading new code or UI
Added warning if users change two interfaces to be the same name
IP wizard on new unit now wards that not all options may be listed until features are set up
Built 2003-10-23
Older Beta release
2.02.016 (Garad)

Release notes from Beta release 2.02.000 to Beta release 2.02.016

If number formatting set to use commas, then some flags in subnet settings operated incorrectly.
After WAN/LAN reversal, a second power cycle was sometimes necessary.
Internal change to slightly improve efficiency of routed traffic.
Built 2003-10-18
Older Beta release
2.02.000 (Fais)

Release notes from Beta release 2.01.812 to Beta release 2.02.000

First factory release of FireBrick 105
Built 2003-10-18
Older Beta release
2.01.812 (Easal)

Release notes from Beta release 2.01.810 to Beta release 2.01.812

Further internal changes
Release candidcate
Built 2003-10-17
Older Beta release
2.01.810 (Daighre)

Release notes from Beta release 2.01.808 to Beta release 2.01.810

Internal changes for port initialisation
Release candidate
Built 2003-10-16
Older Beta release
2.01.808 (Cadwan)

Release notes from Beta release 2.01.807 to Beta release 2.01.808

Still a broken link
Built 2003-10-16
Older Beta release
2.01.807 (Badvoc)

Release notes from Beta release 2.01.806 to Beta release 2.01.807

Broken link in wizard prompts
Built 2003-10-15
Older Beta release
2.01.806 (Ablach)

Release notes from Beta release 2.01.801 to Beta release 2.01.806

Further internal changes
Built 2003-10-14
Older Beta release
2.01.801 (Weonard)

Release notes from Beta release 2.01.788 to Beta release 2.01.801

Icons now match manual
Internal changes for ATE/labeling
The login/title section no longer shows the serial number and version unless you have status view access
Built 2003-10-09
Older Beta release
2.01.788 (Vainche)

Release notes from Beta release 2.01.785 to Beta release 2.01.788

Last release actually broke the IP wizard - new spells formulated
Internal change to startup code
Groups were actory reset security 3 and are now security 2
Additiona OEM releases
Built 2003-10-07
Older Beta release
2.01.785 (Uar)

Release notes from Beta release 2.01.760 to Beta release 2.01.785

IP/port groups default security level 2
Config loading was causing a factory reset
Added extra "magic" IP group for IP of any logged in user
Added default IP group for "RFC1918 Private IPs"
Added default Port Group "FB Tunnel Traffic"
Fixed wizard to order subnets Inside first
More typos
Built 2003-10-06
Older Beta release
2.01.760 (Tah-Nu)

Release notes from Beta release 2.01.753 to Beta release 2.01.760

Better handling of a reload on setup page after auto-logout.
Various typos
Loading old configs screwed up mapping interfaces
Mapping was not saving target source/target ports
Page handling on various screens was messed up
Traffic shaping was not right and was matching inactive and incorrect shaping rules
Built 2003-10-04
Older Beta release
2.01.753 (Saccius)

Release notes from Beta release 2.01.749 to Beta release 2.01.753

Icons re-done and new IP/Port grp icons - on non red backgrounds they look much prettier in mozilla than IE
Name and security on IP/port groups now saved when you click "Add"
Removed "Blank" wording - looks silly. Fixed empty table cells not showing in IE
Built 2003-10-03
Older Beta release
2.01.749 (Rascua)

Release notes from Beta release 2.01.716 to Beta release 2.01.749

IP groups working (under setup menu at present, may have icon soon)
Port/protocol groups working (under setup menu at present, may have icon soon)
Where no name for an item it now shows Blank
Portmaps now also allow specific subnet selection on mapped interface
Re-wording of feature installation screens on FireBrick and web site to be more consistent
Changed icon/title from "Ports" to "Mapping"
Background colours now colour behind icons at top - image files need a bit of tidying up
Built 2003-10-02
Older Beta release
2.01.716 (Raigre)

Release notes from Beta release 2.01.696 to Beta release 2.01.716

Added specific subnet/tunnel for default gateway and for ping destination
Tidy up of Setup menu
Tidy subnet menu with VLAN subnets
Major change to ARp handling for VLAN subnets
Built 2003-10-01
Older Beta release
2.01.696 (Pesrut)

Release notes from Beta release 2.01.690 to Beta release 2.01.696

Token/key input now one field not three to allow cut and paste.
Added MAC cache list loaded from switch
Built 2003-10-01
Older Beta release
2.01.690 (Odhrain)

Release notes from Beta release 2.01.638 to Beta release 2.01.690

Changes feature update requests
Changed name to "FireBrick 105"
Filter edit was not listing some check boxes correctly
Subtle internal error in tunnels fixed - could drop some tunnel packets incorrectly.
Better handling of tunnels restarting when from DHCP subnets.
Note that stealth is not available with 5Port feature, although the LAN1 stealth address still works on LAN1.
Port controls (Speed, duplex, MDI/X, etc)
Built 2003-09-28
Older Beta release
2.01.638 (Mac-Da-Tho)

Release notes from Beta release 2.01.584 to Beta release 2.01.638

Shapes & lane were not listing or editing correctly
Some UI fixes - subnets would not save, filters would not erase, etc.
Wizard prompts improved
IP wizard added - comments please
Left hand factory reset now makes DHCP client on WAN and LAN as well as server
on LAN. If LAN gets an address it stops being a server.
DHCP server can have manual override on gateway issued
Routing should now allow subnets to be moved even without EXTRAs pack -
subnets inserted at route 5 by default.
Updates feature setup pages. Nearly ready for online feature installation.
Built 2003-09-27
Older Beta release
2.01.584 (Lachlan)

Release notes from Beta release 2.01.448 to Beta release 2.01.584

link to firebrick software web site goes to 1740 software not 1730
IMPORTANT NOTE - BETA TEST CUSTOMERS MUST CONTACT SUPPORT BEFORE LOADING THIS VERSION

Lots of changes in ATE support, etc.
New options for log display
Corrected spelling or authorize
Auto reload on cable test function
Switched time profiles show colour based on active or not, as possible to be switched on but inactive if conditional on another profile.
Updated UI for 5 port option
Started adding tool-tips to input boxes and links. All input boxes should eventually have them but IE does not show on selection boxes. Comments welcome.
Made port ranges on main screen check boxes a tool tip to reduce confusion and space taken.
Increased number of router/subnet/user when none EXTRAs to allow some of the other features to work.
Added ports and protocol to routing
Change to UI style for configuration/forms - making UI more consistent to allow for future features - comments please
This issue is an interim issue - some work still to be done on IP wizard, etc

Built 2003-08-31
Older Beta release
2.01.448 (Keelta)

Release notes from Beta release 2.01.424 to Beta release 2.01.448

Added more debug messages to tunnels
Corrected broken tunnel operation
Stealth operation was not working correctly
Built 2003-08-29
Older Beta release
2.01.424 (Kea)

Release notes from Beta release 2.01.420 to Beta release 2.01.424

Internal change to improve performance
It appears that moving filters, or routes, etc, left the firebrick in a state where a reboot would lose the config.
Built 2003-08-21
Older Beta release
2.01.420 (Iduthin)

Release notes from Beta release 2.01.416 to Beta release 2.01.420

Subnet VLAN support on DHCP server and client
Fixed tunnel name on session list
Added subnet name on session list
Fixed conversion from old (1730) configs for time profiles using "Not ...". Reload old config after updating to this version.
Built 2003-08-21
Older Beta release
2.01.416 (Hanno)

Release notes from Beta release 2.01.413 to Beta release 2.01.416

Loading old config was not correcting interfaces on PortMaps, and so they would be messed up. Reload old config after upgrading to this version.
Built 2003-08-19
Older Beta release
2.01.413 (Gamal)

Release notes from Beta release 2.01.398 to Beta release 2.01.413

ARP for subnet VLANs in place - there is no filtering on VLA - some more to do stillNs
Routes can now be optionally directed to specific subnets (affects MAC and VLAN)
Built 2003-08-17
Older Beta release
2.01.398 (Fail-Inis)

Release notes from Beta release 2.01.381 to Beta release 2.01.398

Feature table in setup screen. Note, not all features are available yet.
Low level discard of 802.3 ethernet headers as per old firebrick.
Transparrent 802.3ac tag handling of packets routed through the brick.
Cable tester in setup / port setup
Built 2003-08-16
Older Beta release
2.01.381 (Eala)

Release notes from Beta release 2.01.365 to Beta release 2.01.381

DHCP mirror. A DHCP client which gets a gateway will find the next later subnet in mirror mode on a different interface and update it.
Changed status - now uses text to describe interface type of connected ports
New counters page shows all stats from built in switch with per port counters
SNMP working for basic stats per port - not full RMON stats yet
Added MAC to status
Added ability to move subnets about.
Changed DHCP mirror so subnet to bne mirrored is set explicitely
Built 2003-08-16
Older Beta release
2.01.365 (Daich)

Release notes from Beta release 2.01.337 to Beta release 2.01.365

Tidy up ARP handling with multiple MACs
DHCP client and server now using multiple MAC (DHCP mirror disabled for now)
100 routes
100 tunnels
100 portmaps
50 speed lanes
1000 ARP entries
Built 2003-08-15
Older Beta release
2.01.337 (Cacumattus)

Release notes from Beta release 2.01.284 to Beta release 2.01.337

Config upload now works
Serial number now reported correctly
24/7 checkbox on profile time setting
Increased to 100 profiles
Increased number of DHCP server addresses to 1024
Increased number of sessions to 10000
Built 2003-08-14
Older Beta release
2.01.284 (Abhean)
This is the first release for this platform.

Recent versions only | Factory releases | Factory and Beta | Factory, Beta & Alpha