HP VPN Server Appliance sa3110/sa3150/sa3400/sa3450 and sa3000 Series VPN Manager - Release 6.8.2 Release Notes

24
Hewlett-Packard VPN Server Appliance SA3110/SA3150/SA3400/SA3450
Net-Include and Static Route Shortfalls
Overcome by SAs for IPSec Tunnels
Reference Number 185DF
When you want to route subnet traffic to a destination that
is within the tunnel destination, use a Security Association
(SA) to define the tunnel end-points. SAs override net-
includes and static routing statements.
Frame Relay Sprint Certification Testing
Release 6.8.2 passed all Frame Relay Sprint certification
testing except for one suite of tests that was not run. Since
congestion management is not fully supported currently in
the Frame Relay module, the Congestion Control
certification test was not run.
56-Bit DES and 168-Bit 3DES Versions
There are two versions of the software. One version
provides 56-Bit DES encryption, while the other version
provides 168-Bit 3DES encryption.
As a result of certain countries' import and export
restrictions on security technology, use of encryption
encapsulation algorithms that exceed 56 bits may be
limited. If you are using the software in one of these
countries, please disregard instructions concerning
encryption greater than 56 bits in the online Help file as
both software versions include the same online Help file.
Tunnel Negotiation Attempted After
Interface Shut Down
Reference Number 114DF
As a result its architecture, the VPN device tries to bring up
tunnels even though the interface is shut down. This
happens for SST, as well as IPSec, tunnels.
No packets are sent on the physical media as a result of
this internal behavior.