Release Notes

Version 5.2.0.2 Sourcefire 3D System Release Notes 22
Issues Resolved in Version 5.2.0.2
Resolved an issue where the intrusion policy comparison view stalled if the
option to update the base policy with intrusion rule updates was disabled in
the base intrusion policy. (123739)
Resolved an issue where, in some cases, adding two or more detection
patterns to an application protocol detector drained system resources.
(123767)
Resolved a firmware issue where NAT, access control, or system policy
apply could fail on 3D7010, 3D7020, or 3D7030 managed devices
configured with NAT policies. (123920)
Resolved an issue where you could not break clusters or stacks from the
command line interface (CLI) on the primary device if the managing
Defense Center was unavailable. (123932)
Improved the accuracy of the FireSIGHT host limit count. (124091)
The Product Updates widget now displays the correct geolocation update
version running on the Defense Center. (124616)
Improved the reliability of the Context Explorer when accessed from the
dashboard. (124638)
Resolved an issue where, after completing the update to Version 5.2, Snort
did not load if an intrusion policy contained invalid local rules. (124935)
Resolved an issue where, in some cases, configuration backups failed after
the system included extraneous geolocation and Security Intelligence
statistics. (125131)
Resolved an issue where Snort did not load on managed devices if an
intrusion policy contained a network object used as a variable value and an
SRU or custom rule file was installed. (125139, 125910)
Version 5.2
The command line interface (CLI) command show traffic-statistics
now displays statistics for virtual as well as physical interfaces. (102347)
Resolved an issue where clicking the evaluate icon to evaluate an
application detector with a packet capture prevented you from activating the
detector. (102464)
Added, modified, and removed numerous preprocessor rules. (102633,
104588, 111941, 113970, 118178, 118500, 118553, 122038)
Resolved an issue where the intrusion event views incorrectly displayed
XFF data. (102655, 110873, 113369)
Improved the use of colors throughout the user interface. (104562, 112517)
Report text now supports the ASCII code 8217 quotation mark. (105857)