Release Notes Threat Management Services zl Module ST.1.2.110301
43
Software Fixes in Releases ST.1.0.090213 - ST.1.2.110301
Release ST.1.2.110301
Release ST.1.2.110301
The following problems were resolved in release ST.1.2.110301
Firewall
■ PR_65612 — Create a scenario where five hosts are getting NATted by a TMS zl Module
from Internal zone to External zone (source NAT). Three of five hosts can ping hosts on the
External zone.
Clear the connections using the no connections command on the TMS zl Module CLI.
After clearing connections, all hosts were able to ping for 2 seconds, then two of them (not always
the same as before) stopped pinging.
Captures on the External interface just show packets flowing from the External VLAN IP to the
target host.
Replace the TMS zl Module with an HP ProCurve 7203 router and enable NAT.
With Router, all hosts can ping the external host without interruptions.
High Availability
■ PR_64736 —In a high availability (HA) deployment, TMS zl Module memory usage builds
over time. Eventually, the HA master hangs, and the participant becomes the new master.
The new master does not recognize the previous master. Workaround: Reboot the previous
master TMS zl Module using service <slot-ID> reload. The module rejoins the HA cluster as a
participant.
VPN
■ PR_64254 — When a VPN connection using XAUTH and ProCurve VPN client is established,
a potential exists that when a new VPN user tries to login, the TMS zl Module will disconnect
the already connected user.










