|
50 Minuteman Rd. Andover, MA 01810 (978) 684-1000
CUSTOMER RELEASE NOTES
|
When updates have been obtained using the NetSight Atlas Web Update feature, the Addendum section at the end of these release notes will contain the updated release information.
The most recent version of these release notes can also be found on the NetSight Documentation web page: http://www.enterasys.com/support/manuals/netsight.html.
| NOTE: | When this topic is opened from the CD-ROM, the links from this topic to other help topics will not work (404 - not found). Links within the topic will work and once you've installed NetSight Atlas Automated Security Manager, you can launch the help system and access help for all topics.
|
|---|
| It is recommended that you thoroughly review these release notes prior to the installation or upgrade of this product. |
| Corrected a problem that caused events to be displayed in the wrong tab. |
| (Linux only) The problem of re-processing Syslog/Trap information that had already been processed when Console is relaunched has been corrected. |
Problems with the Search Scope Rules have been corrected.
|
| Corrected a problem that caused events to be displayed in the wrong tab. |
| (Solaris and Linux only) The problem with executing Custom Undo scripts has been corrected. |
| Incident numbers now appear correctly in the Automated Security Manager tab in Console's Events View. |
Devices/Firmware that support Static Policies:
| Product Family | Firmware Version | |||
| Matrix C1 | 1.01.xx 2.00.xx |
|||
| Matrix E1 | 3.00.xx 3.01.xx 3.02.xx |
|||
| Matrix E6/E7 (2nd/3rd Generation) |
5.06.xx 5.07.xx 5.08.xx |
|||
| Matrix N3/N7 Platinum |
3.00.xx 4.00.xx 4.05.xx 4.11.xx |
|||
| Matrix N3/N7 Gold |
3.10.xx 4.05.xx 4.11.xx |
|||
| RoamAbout R2
|
5.03.xx |
Devices/Firmware that do not support Static Policies:
| Product Family | Firmware Version |
| Matrix E5 | 3.00.xx |
| Matrix V2 | 2.03.xx 2.04.xx |
|
Vertical Horizon VH-2402S VH-2402-L3 VH-4802 VH-8TX1UM/MF |
2.05.19 1.00.16 2.05.05 2.04.07.08 |
| RoamAbout Access Point 3000 | 1.00.xx |
| Matrix C2 | 1.00.20 |
Use NetSight Atlas Console's CDP Status FlexView to disable CDP on downstream devices.
For example:
From Console:
Devices/Firmware that do not support CDP
| Product Family | Firmware Version |
| Matrix C2 | 1.00.20 |
|
Vertical Horizon VH-2402S VH-2402-L3 VH-4802 VH-8TX1UM |
2.05.19 1.00.16 2.05.05 2.04.07.08 |
Devices/Firmware that support "Optimized" Node/Alias:
| Product Family | Firmware Version |
| Matrix E1 | 3.00.xx 3.01.xx 3.02.xx |
| Matrix E6/E7 (2nd/3rd Generation) | 5.06.xx 5.07.xx 5.08.xx |
|
Matrix N3/N7 Platinum and Gold |
3.00.xx 4.00.xx 4.05.xx 4.11.xx |
| Matrix V2 | 2.03.xx 2.04.xx |
| NOTES: |
Support for Optimized Node/Alias -- The Automated Security Manager
Incident Detail view (right-click an entry in the Activity Monitor and select
View Details) indicates whether a device
supports the optimized Node/Alias table or not:
-- Matrix C1 -- Matrix C2 -- Matrix E5 -- Matrix E1 (1G6xx-xx) -- Vertical Horizon These devices do not support any form of Node/Alias. For these devices, the Automated Security Manager search resolves the searched IP address to the corresponding MAC address and does a MAC-based search to locate the physical port. Routers must be included in the search scope in order to provide access to the routers' ARP cache. In addition, you must select the ipRouteTable and ipCIDRRouteTable MIBs in the Automated Security Manager Options MIB Selection panel. Disable Node/Alias Learning -- It's important to make sure that inter-switch links are not learning Node/Alias information, as it would slow down searches and give inaccurate results. Enabling CDP on inter-switch links disables Node/Alias learning. You can also disable Node/Alias learning on a switch port by setting the maximum number of entries per interface (ctAliasConfigurationInterfaceMaxEntries) to 0 on that port, using the Node Alias Control FlexView in Console. |
|---|
The following table provides Automated Security Manager search time comparisons between optimized and not optimized Node/Alias implementations.
Search Time Comparisons:
| Number of Devices | Node/Alias Optimized 4000 entries |
Node/Alias Not Optimized 4000 entries |
Node/Alias Optimized 200 entries |
Node/Alias Not Optimized 200 entries |
|---|---|---|---|---|
| 25 | 3 sec | 1 min 40 sec | 3 sec | 7 sec |
| 100 | 9 sec | 5 min 50 sec | 9 sec | 25 sec |
| 200 | 20 sec | 11 min 10 sec | 20 sec | 47 sec |
| 300 | 25 sec | 16 min 52 sec | 25 sec | 1 min 13 sec |
| 800 | 1 min 3 sec | 58 min 46 sec | 1 min 3 sec | 3 min 13 sec |
The NetSight Atlas Installer (InstallAnywhere® by Zero G Software, Inc.) leads you through a series of windows that ask you for all the information required in order to install NetSight Atlas Automated Security Manager. When you finish with the series of windows, NetSight Atlas Automated Security Manager is installed according to your specification. For complete installation information and instructions, refer to the Installation help topic, and the instructions available on the web site: www.enterasys.com/netsight/.
The Precedence values for the Default Event Categories in ASM 1.1 are:
If you are upgrading from a prior version of NetSight Atlas Console, your upgrade includes an evaluation copy of Automated Security Manager that you can try for 30 days. If you decide to convert an evaluation copy of Automated Security Manager at the end of the evaluation period, you should contact your Enterasys Networks Representative to purchase the software and receive a License Key.
Evaluation periods for Console and Automated Security Manager (ASM) are activated separately. The evaluation period for Console starts when it is launched for the first time and expires 30 days later. The evaluation period for ASM starts the first time ASM is launched from Console's Applications menu and expires either 30 days later or with the expiration of the Console evaluation period, whichever occurs first.
To convert from an evaluation copy of NetSight Atlas Console or NetSight Atlas Console with Automated Security Manager to a purchased copy, contact your Enterasys Networks Representative to purchase the software and receive a License Key. You will not need to reinstall the software to perform the conversion from an evaluation copy to a fully licensed version of the software.
| (Windows 2000/XP/Server 2003 only) An evaluation of your system is not automatically performed during the installation. If system requirements are not met, the install will take place, but results will be unpredictable. | |
| Solution: | Verify that all Windows 2000/XP system requirements are met prior to installing NetSight Atlas Automated Security Manager. |
| (Solaris only) In the Select Destination window of the Installer, if you click Browse and then double click to select a directory, the OK button doesn't work. | |
| Solution: | You must select the directory using a single click instead of a double click. |
| (Solaris only) The Installer does not come up due to path problems. | |
| Solution: | Ensure that /usr/usb does not precede /bin in your path. To do this, in a Unix window, type which chown. If the result is /usr/ucb/chown, replace /usr/ucb with /bin in your path. If the result is /bin/chown, the path is not the problem. |
| (Solaris only) When the Installer is started, the following message is reported:
Warning: Cannot convert string "-monotype-arial-regular-r-normal--*-140-*-*-p-*-iso8859-1" to type FontStruct. |
|
| Solution: | No action is required. The Installer will use a default font. |
| (Solaris only) The NetSight Atlas Uninstall program cannot warn you that the Automated Security Manager is running when you attempt to uninstall. When this happens, some components are not removed and subsequent installation and operation is unspecified. | |
| Solution: | Exit from the NetSight Atlas Automated Security Manager and stop all services prior to starting Uninstall on Solaris workstations. |
| During installation, the license information will be unreadable if your display settings are set for a black background (e.g., High Contrast#1, High Contrast #2, or High Contrast Black). | |
| Solution: | Set your display Properties > Appearance > Color Scheme to something other than a black background during installation. |
|
|
When there is insufficient space in the selected install area, the installer reports the situation and lets you select an alternate location. If the alternate location does not provide the required space, the installer again reports the shortfall, but instead of showing the alternate path, it incorrectly shows the path to the original install area. The space provided by the alternate path is analyzed correctly; only the path that is reported is wrong. |
| Solution: | Select an install area that provides the required disk space. Refer to System Requirements for more information. |
|
|
(Linux Enterprise v3 ES only) During install, the installation program reports the obsolete use of an option for the tail command and an inability to check for available disk space: For example:
Preparing to install... |
| Solution: | This is a problem with the install program and the messages can be ignored. |
| When upgrading to ASM 1.1, you must install ASM 1.1 directly over ASM 1.0. In other words, do NOT uninstall ASM 1.0 first and then install ASM 1.1. (When you install ASM 1.1, it will automatically uninstall ASM 1.0.) Otherwise, the snmptrapd.conf file won't be saved. | |
| Solution: | If you have already uninstalled ASM 1.0 first and then installed ASM 1.1, you must re-configure the snmptrapd.conf file and then restart the SNMPTrap deamon process. |
| (Linux and UNIX only) You cannot specify a range of pages when printing from tables on UNIX or Linux systems. If you select Print from the Table Tools popup menus, the resulting print settings window does not open to a sufficient size (and cannot be resized) to allow access to the page range fields. | |
| Solution: | For these systems, the only option is to print the entire table. |
|
|
(Linux only) Linux remembers if a window was previously maximized, and if the help window is maximized prior to being dismissed, the next time it is opened, the information does not completely fill the maximized window. |
| Solution: | Resize the window to restore a normal presentation. |
|
|
If an action has been taken on a port and a timer has been set to Undo the action, if another trap comes in that implicates the same port, the second action will be taken. At this point, the first action cannot be Undone because the settings have changed so when the first timer expires, the Undo will fail. |
| Solution: | If multiple actions are taken on the same ports, they must be undone in reverse order so that the port can be successfully returned the its original state. Note that in this case, the rules should be evaluated to insure this is the desired behavior for the Automated Security Management system. |
|
|
The SNMPTrap Service synchronizes its timestamp with your system's clock when the service is launched, but does not recognize changing to or from Daylight Savings Time while running. This causes a one hour discrepancy in the timestamps for Traps and Informs that appear in Console and Automated Security Manager after making the change. |
| Solution: | Stop and Restart the SNMPTrap Service when changing to or from Daylight Savings Time. |
|
|
In the Activity Monitor, if several threats are received with the same Sender ID, Sender Name, and Threat IP, and they are Filtered because a Search for that Threat IP is already in progress, the Status of the incident sometimes stays at Search in Progress, even though the Search has completed. |
| Solution: | Set the ASM Operation Mode to Disable, which will force all Searches in Progress (Searches Pending) to be cancelled. Set the ASM Operation Mode to "Search Only" or "Search And Respond" and subsequent threats received will generate new Incidents in the Activity Monitor. The entries for the cancelled searches can be deleted, as desired. |
| Links to topics selected in the Contents will not work correctly following a search operation. If you use the JavaHelp search to find a term, then return to the Contents and navigate to a topic, the viewer may take you to the wrong place in the topic. If the topic you select contains the term just sought using the search, the viewer will take you to the term instead of the topic you chose from the Contents. | |
| Solution: | Return to the Search tab, clear the entry and click Search. Go back to the Contents and the navigation will work correctly. |
| Scrolling rapidly (using the arrow keys) through the Contents panel in the help and, less frequently, scrolling within a topic (right panel) will cause a Java Exception. This is related to a JavaHelp bug. | |
| Solution: | Use the scroll bar in the help topics or use mouse clicks to navigate in the Contents panel. |
| Printing help files from the Automated Security Manager Help viewer may cause the application to hang. | |
| Windows users should use Task Manager to end the
Automated Security Manager Help task. Solaris users should kill the Automated Security Manager Help process.
Print help files from a browser by accessing the NetSight Documentation Web page at
|
|
|
|
(Linux only) Linux remembers if a window was previously maximized, and if the help window is maximized prior to being dismissed, the next time it is opened, the information does not completely fill the maximized window. |
| Solution: | Resize the window to restore a normal presentation. |
Any other problems than those listed above should be reported to our Technical Support Staff.
Click here for a list of the IETF and Private Enterprise MIBs supported by NetSight Atlas Automated Security Manager as of its initial release. For information regarding the latest software available, recent release note revisions and changes to the supported MIBs, visit the NetSight Atlas Automated Security Manager section at the following Web site:
http://www.enterasys.com/support/manuals/netsight.html.
Additional (indexed) MIB documentation is also available at the following Web site:
http://www.enterasys.com/support/mibs
For information regarding the latest software available, recent release note revisions, or if you require additional assistance, please visit the Enterasys Support web site.
http://www.enterasys.com/support