Sunteți pe pagina 1din 21

NIOS 5.

1r5-5 Release Notes


INTRODUCTION ...................................................................................................................... 2 NEW FEATURES...................................................................................................................... 4 NIOS 5.1r5-3 ...................................................................................................................... 4 NIOS 5.1r5 ........................................................................................................................ 4 NIOS 5.1r4-5 ...................................................................................................................... 5 NIOS 5.1r4-3 ...................................................................................................................... 5 NIOS 5.1r4 ........................................................................................................................ 5 NIOS 5.1r3-2 ...................................................................................................................... 6 NIOS 5.1r3 ........................................................................................................................ 6 NIOS 5.1r2 ........................................................................................................................ 7 NIOS 5.1r1 ........................................................................................................................ 8 ADDRESSED VULNERABILITIES .................................................................................................... 9 CHANGES TO DEFAULT BEHAVIOR ............................................................................................ 11 NIOS 5.1r2 ...................................................................................................................... 11 NIOS 5.1r1-1 .................................................................................................................... 11 NIOS 5.1r1 ...................................................................................................................... 11 NIOS 5.x ......................................................................................................................... 11 UPGRADE GUIDELINES ........................................................................................................... 12 Upgrading to NIOS 5.1r5 ..................................................................................................... 12 Upgrading to NIOS 5.1r2-1 .................................................................................................. 12 Upgrading to NIOS 5.x ........................................................................................................ 13 BEFORE YOU INSTALL ............................................................................................................ 15 ACCESSING GRID MANAGER ..................................................................................................... 16 RESOLVED ISSUES ................................................................................................................. 17 Fixed in 5.1r5-5 ............................................................................................................... 17 Fixed in 5.1r5-4 ............................................................................................................... 17 Fixed in 5.1r5-3 ............................................................................................................... 17 Fixed in 5.1r5-2 ............................................................................................................... 18 Fixed in 5.1r5-1 ............................................................................................................... 19 Fixed in 5.1r5-0 ............................................................................................................... 19 Severity Levels ................................................................................................................ 20 KNOWN GENERAL ISSUES ........................................................................................................ 21
2011 Infoblox Inc. All Rights Reserved. All registered trademarks are property of their respective owners. 400-0258-007 Rev. A Page 1 of 21 11/18/2011

NIOS 5.1r5-5 Release Notes


INTRODUCTION
Infoblox NIOS 5.1r5 software, coupled with Infoblox appliance platforms, enables customers to deploy large, robust, manageable and cost-effective Infoblox grids. This next-generation solution enables distributed delivery of core network services including DNS, DHCP, IPAM, TFTP, and FTP with the nonstop availability and realtime service management required for todays 24x7 advanced IP networks and applications. It also provides reporting capabilities in which you can export data in CSV (comma separated value) format, and then easily convert the file to PDF and other file formats. Please note the following: NIOS 5.1r5 does not support the IF-MAP service. You cannot upgrade Infoblox Orchestration Servers to NIOS 5.1r5. The IF-MAP service is supported in 5.1r2-IBOS-1, 6.0.0-IBOS-1, IBOS 2.1.0, IBOS 2.1.1 and later releases. For more information, visit the Infoblox Support web site at http://www.infoblox.com/en/support/support-center-login.html. This release has no new features. Supported Platforms Infoblox NIOS 5.x is supported on the following platforms: NIOS Appliances: Infoblox-250, -250-A, -550, -550-A, -1050, -1050-A, -1550, -1550-A, -1552, -1552-A, -1852-A, -2000, and -2000-A. Infoblox NIOS 5.x is not supported on the Infoblox-500, -1000, and -1200 appliances. Please see the section UPGRADING TO NIOS 5.x on page 13 if you are upgrading a grid that contains these appliances and for additional upgrade information. Note that the Infoblox-250 and -250-A appliances support all of the services of the larger Infoblox appliances, except for configuration as a grid master or grid master candidate. vNIOS for VMware on ESX/ESXi Servers: The Infoblox vNIOS on VMware software can run on ESX or ESXi servers that have DAS (Direct Attached Storage) or iSCSI (Internet Small Computer System Interface) SAN (Storage Area Network) attached. You can install the vNIOS software package on a host with VMware ESX or ESXi 4.x installed and configure it as an IB-VM-250, IB-VM-550, IB-VM-1050, IB-VM-1550, IB-VM-1850, or IB-VM-2000 virtual appliance. You can deploy the IB-VM-250, IB-VM-550, and IB-VM-1050 virtual appliances with either a 50 GB or 120 GB disk. You can configure the 50 GB vNIOS virtual appliances as grid members. They are not recommended as grid masters or grid master candidates. Note that the IB-VM-250 virtual appliance supports all the services provided by vNIOS virtual appliances, but it is not recommended as a grid master or grid master candidate.

2011 Infoblox Inc. All Rights Reserved. All registered trademarks are property of their respective owners. 400-0258-007 Rev. A

Page 2 of 21 11/18/2011

NIOS 5.1r5-5 Release Notes


The following table lists all the supported vNIOS virtual appliance models: Recommended as Grid Master and Grid Master Candidate (Yes/No) No

vNIOS Appliance

Disk (GB) 50

# of CPU Cores 1

Memory Allocation 512 MB

Virtual CPU Core Frequency 700 MHz

IB-BOB (supported on Cisco SRE-V only) IB-VM-250 IB-VM-250 IB-VM-550 IB-VM-550 IB-VM-1050 IB-VM-1050 IB-VM-1550 IB-VM-1850 IB-VM-2000

50 120 50 120 50 120 120 120 120

1 1 1 1 1 1 2 4 4

2 GB 2 GB 2 GB 2 GB 2 GB 2 GB 8 GB 8 GB 12 GB

700 MHz 700 MHz 1200 MHz 1200 MHz 2000 MHz 2000 MHz 5.5 GHz 10 GHz 12 GHz

No No No Yes No Yes Yes Yes Yes

vNIOS for VMware on Cisco UCS Express/SRE-V: The Infoblox vNIOS on VMware software can also run on Cisco SRE-V (Services Ready Engine Virtualization), which is part of the Cisco UCS (Unified Computing System) Express. Cisco SRE-V enables the VMware vSphere Hypervisor to be provisioned on Cisco SRE 700 and 900 Service Modules. The Cisco SRE Service Module can reside in the Cisco 2900 and 3900 series ISRs G2. The following table lists the supported vNIOS on VMware virtual appliances on SRE 700 and SRE 900:
vNIOS on VMware Virtual Appliances IB-BOB IB-VM-250 IB-VM-550 IB-VM-1050 Cisco SRE 700 Yes Yes Yes No Cisco SRE 900 Yes Yes Yes Yes

Note that all vNIOS on VMware virtual appliances running on Cisco SRE-V are not recommended as grid masters or grid master candidates. The IB-BOB virtual appliance only supports configuration as a grid member. For information about Cisco SRE-V, refer to the Cisco documentation.

2011 Infoblox Inc. All Rights Reserved. All registered trademarks are property of their respective owners. 400-0258-007 Rev. A

Page 3 of 21 11/18/2011

NIOS 5.1r5-5 Release Notes


vNIOS on Cisco Application eXtension Platform (AXP) 1.6 service modules in Integrated Services Routers (ISRs): The Infoblox vNIOS software package for Cisco can run on the following NME (Network Module Enhanced) AXP service modules installed in the 2800 and 3800 series ISRs (or using a hardware adapter, in the 2900 and 3900 series ISRs): NME-302, NME-522, and NME-502. It also can run on the SRE 700 and SRE 900 service modules in the 2900 and 3900 series ISRs. For additional information, refer to the Quick Start Guide for Installing vNIOS Software on Cisco Application eXtension Platforms. vNIOS on Riverbed Steelhead appliances: Infoblox has certified the vNIOS software with RiOS (Riverbed Optimization System) v6.1.x and v5.5.x and RSP (Riverbed Services Platform) service v6.0.1 and v5.5.0 on Riverbed Steelhead models 520, 550, 1020, 1050, 1520, 2020, and 2050. For additional information, refer to the Quick Start Guide for Installing vNIOS Software on Riverbed Service Platforms.

NEW FEATURES NIOS 5.1r5-3


Member DNS/DHCP Permissions You can now separate DNS and DHCP administration on different grid members by applying specific DNS and DHCP permissions to admin groups and roles. For example, you can create an admin group or role that can only create, modify, and delete DHCP ranges in a specific network on a specific member in the Grid. This admin group or role is restricted to the specified tasks on the selected Grid member. It cannot perform other DNS or DHCP tasks on this member, and it cannot perform the specified tasks on other grid members. You can also control whether admins can modify member DNS and DHCP properties. For more information about this feature, refer to the Infoblox NIOS Administrator Guide.

NIOS 5.1r5
Scheduling Full Upgrades With NIOS 5.1r5, you can schedule a full upgrade that allows for member-to-master data replication. A full upgrade occurs when there are database schema changes between the existing and upgrade software versions. Scheduling an upgrade for a grid can minimize network and operational outages, especially when you have grid members that are in different time zones. Depending on the configuration of your grid and the software version that is currently running in the grid, you can schedule your upgrades for different members or upgrade groups over a period of nine days. For more information about scheduling full upgrades, refer to the Infoblox NIOS Administrator Guide. To schedule a full upgrade, you must first upgrade to NIOS 5.1r4-6, and then to NIOS 5.1r5. GUI Enhancements This release includes the following enhancements to Grid Manager and System Manager: The vertical scroll bar in the Add Content panel of the Dashboard enhances the usability of the Dashboard. In the DNS, DHCP, and Grid tabs, accordions are replaced with sub tabs to improve navigation through different views. System messages, including information, warnings, and errors, are now displayed in specific tabs, panels, and tables in which specific tasks are being performed. GUI performance improvements in the following: tab navigation, login process, and drill downs.

2011 Infoblox Inc. All Rights Reserved. All registered trademarks are property of their respective owners. 400-0258-007 Rev. A

Page 4 of 21 11/18/2011

NIOS 5.1r5-5 Release Notes


NIOS 5.1r4-5
Support of 50 GB Disks on vNIOS Virtual Appliances With this release, you can deploy the IB-VM-250, IB-VM-550, and IB-VM-1050 vNIOS on VMware virtual appliances with either a 50 GB or 120 GB disk. You can configure the 50 GB vNIOS virtual appliances as grid members. They are not recommended as grid masters or grid master candidates. For information about the supported vNIOS on VMware appliance models, see Supported Platforms on page 1. Support of vSphere vMotion With this release, you can use vSphere vMotion to migrate vNIOS virtual appliances from one ESX or ESXi server to another with minimal service downtime. The migration preserves the database, hardware IDs, and licenses of the virtual appliances. For information about how to migrate vNIOS appliances, refer to the Installation Guide for vNIOS Software on VMware.

NIOS 5.1r4-3
API Enhancement With this release, you can use the Infoblox::DHCP::Network functionality to enable searching for networks within a network container.

NIOS 5.1r4
License Transfer for vNIOS on VMware With this release, you can transfer the valid licenses of a vNIOS virtual appliance from one ESX/ESXi 4.x server to another without going through the RMA (returned materials authorization) process. For more information, refer to the Infoblox Installation Guide for vNIOS Software on VMware. New Platforms for vNIOS on ESX/ESXi Servers Infoblox now supports the following additional vNIOS for VMware appliances on ESX/ESXi servers: IB-VM-550 and IB-VM-1850. For information about the new platforms, refer to the Infoblox Installation Guide for vNIOS Software on VMware. vNIOS for VMware on Cisco UCS Express/SRE-V You can now install the vNIOS for VMware software on Cisco SRE-V, which is part of the Cisco UCS Express. Infoblox supports the following vNIOS for VMware virtual appliances on Cisco SRE-V: IB-BOB, IB-VM-250, IB-VM-550, and IB-VM-1050. For more information about the supported virtual appliances, see the section Supported Platforms on page 2. For information about Cisco SRE-V, refer to the Cisco documentation. Lease Scavenging You can enable member DHCP servers to automatically delete free and backup leases that remain in the database beyond a specified period of time. When you enable this feature, the appliance permanently deletes the free and backup leases, and you can no longer view or retrieve the lease information. Synchronization with Microsoft Servers With this release, there is an option to create a Microsoft user account that does not require Administrator Group rights to synchronize Microsoft servers. IPv6 Support for NIC Redundancy This release supports both IPv4 and IPv6 addresses for NIC (Network Interface Controller) redundancy using the LAN2 port.

2011 Infoblox Inc. All Rights Reserved. All registered trademarks are property of their respective owners. 400-0258-007 Rev. A

Page 5 of 21 11/18/2011

NIOS 5.1r5-5 Release Notes


Support for Google Chrome Frame Plug-in This release includes support for the Google Chrome Frame plug-in for Internet Explorer. To enhance performance on Internet Explorer 7.x and 8.x browsers, Infoblox recommends that you install the Google Chrome Frame plug-in. For additional information, refer to the Knowledgebase Article 15953 on the Infoblox Support website at http://support.infoblox.com.

NIOS 5.1r3-2
CLI Command for Upgrade Compatibility Starting with this release, you can use the CLI command show upgrade_compatible on a grid master to verify whether your grid or appliance can be upgraded to NIOS 6.x and later. For information about this command, refer to the Infoblox CLI Guide.

NIOS 5.1r3
Authenticated DHCP Infoblox now offers a feature that requires unknown users to register their client devices using a captive web portal, before the DHCP server issues a lease. The captive portal can be configured to support authenticated access using either RADIUS or Active Directory, Guest access, or both. An administrator can define multiple ranges per network to handle authenticated, guest and quarantine clients. Each range uses a MAC address filter to determine which clients are registered. Depending on whether a user completes successful authentication, fails authentication, or requests guest access, the DHCP server issues an address from the appropriate range and inserts the MAC address of the client device into the appropriate MAC filter. A grid can support one or more captive portals for redundancy, and each captive portal can be configured with customized graphics, acceptable use policies, and guest registration fields. Option 82 Fixed Address Support Infoblox has enhanced the DHCP fixed address to support DHCP relay agent information (option 82) in addition to the MAC address and DHCP Client Identifier. You can now specify either the circuit ID or remote ID as the host identifier in a fixed address. This will allow the client to receive a consistent IP address based upon the option 82 value. Support for Intermediate Certificates Infoblox now supports the use of intermediate certificates to complete the chain of trust from the server certificate to a trusted root CA. If required, you can upload intermediate certificates in addition to a server certificate. This will eliminate intermediate certificate security warnings that appear when you open a web browser and try to connect to an Infoblox appliance. Enhanced IB-PLATFORMONE-MIB The IB-PLATFORMONE-MIB now provides objects that report status information about software services (e.g., DNS and DHCP), the operating system, and hardware services (e.g., Fan status and CPU temperature). GUI Enhancements This release includes the following enhancements to Grid Manager and System Manager: The Override/Inherit option was added to the DDNS Domain Name and DDNS TTL fields in the DHCP Network, Network Template, DHCP Range, DHCP Range Template, Fixed Address, Roaming Host and Shared Network editors.

2011 Infoblox Inc. All Rights Reserved. All registered trademarks are property of their respective owners. 400-0258-007 Rev. A

Page 6 of 21 11/18/2011

NIOS 5.1r5-5 Release Notes


The Update DNS on DHCP Lease Renewal option can now be set in the DDNS tab of the Member DHCP Properties, DHCP Network, Shared Network, DHCP Range, Network Template and DHCP Range Template editors, in addition to the Grid DHCP Properties editor. The DDNS tab of the Roaming Host editor provides the option to "Override client provided hostname with roaming host name". Disabled DHCP ranges and fixed addresses are displayed with a grey background. API Enhancements This release includes the following enhancements to the API: You can search host objects for a particular alias. The search for host objects now returns all objects. In past releases, the API returned a maximum of 20,000 objects. bloxTools Enhancements bloxTools was enhanced as follows: You can restart the bloxTools Environment web service from both inside the bloxTools Environment and remotely When you access bloxTools for the first time, it displays a page that provides instructions on how to proceed. Note: Infoblox updates the bloxTools environment from time to time. Infoblox recommends that developers test their snapins for compatibility in every version.

NIOS 5.1r2
Management for Microsoft DHCP Servers You can configure grid members to manage Microsoft DHCP servers. Grid members can synchronize DHCP data with Microsoft DHCP servers, enabling administrators to use Grid Manager to view and manage DHCP data served by the Microsoft servers. A Microsoft Management license is required to use this feature. vNIOS on VMware Platforms This release supports the VM-35 and VM-55 virtual NIOS appliances, in addition to the VM-5 and VM-25 virtual NIOS appliances introduced in NIOS 5.1r1. You can install the vNIOS software package on a host with VMware ESX or ESXi 4.x installed and configure it as a VM-5, VM-25, VM-35 or VM-55 virtual appliance. VM-25, VM-35 and VM-55 virtual appliances can be configured as virtual grid masters and grid master candidates, as well as grid members or independent appliances. A VM-5 virtual appliance supports all the services provided by vNIOS virtual appliances, but it is not recommended as a grid master or grid master candidate. For information on supported features and how to install vNIOS software on VMware platforms, refer to the Quick Start Guide for Installing vNIOS Software on VMware Platforms. Sophos NAC Integration You can configure Infoblox DHCP servers to work with Sophos NAC Advanced servers to form a DHCP-based endpoint compliance system. The DHCP servers can send authentication requests to Sophos NAC Advanced servers, and then grant or deny leases based on NAC filters that match the authentication results. DNSSEC Enhancements The appliance supports the SHA-2 (256-bit and 512-bit) cryptographic hash algorithms in DNSKEY and RRSIG resource records, and in Key-Signing Keys (KSKs) and Zone-Signing Keys (ZSKs). Also in this release, signed zones can accept dynamic DNS updates, and users can add a trust anchor for the root zone.

2011 Infoblox Inc. All Rights Reserved. All registered trademarks are property of their respective owners. 400-0258-007 Rev. A

Page 7 of 21 11/18/2011

NIOS 5.1r5-5 Release Notes


NAPTR Records Infoblox DNS servers now support NAPTR (Name Authority Pointer) records, which specify rules that use substitution expressions to rewrite strings into domain names or URIs (Uniform Resource Identifiers). NAPTR records are usually used to map E.164 numbers to URIs or IP addresses, allowing us to use telephone numbers to reach devices, such as fax machines and VoIP phones, on the Internet. VM Discovery Infoblox network discovery can now discover and retrieve information about active virtual machines on specified VMware ESX and ESXi servers. You can use this new functionality to obtain and manage IP address and other vSphere-specific information about your virtual machines. GUI Enhancements This release includes the following enhancements to Grid Manager and System Manager: The Dashboard provides the following new widgets for monitoring your grid or appliance: DHCP Statistics, DDNS Statistics, System Activity Monitor, and Active WebUI Users. You can delete a network container and either retain its contents, such as other network containers and leaf networks, or delete them as well. API Enhancements This release includes the following enhancement to the API: The NetworkContainer and IPv6 NetworkContainer objects include a new method, "remove_subnets", where you can specify whether to retain or delete the contents of the objects when deleting the object. Added new objects, DNS::Nameserver::Address and DNS::Record::NS, for adding and managing NS records. The DHCP Network object now has a new search attribute "contains_address" which can be used to retrieve the smallest network that contains the given address. CLI Enhancement This release includes the following new CLI commands: set bloxtools reset all: Clears bloxTools data, as well as the root file system set bloxtools reset data: Clears bloxTools user data.

NIOS 5.1r1
Management for Microsoft DNS Servers You can configure grid members to manage Microsoft DNS servers. Grid members can synchronize DNS data with Microsoft DNS servers, enabling administrators to use Grid Manager to view and manage the DNS zones and resource records served by the Microsoft servers. A Microsoft Management license is required to use this feature. vNIOS on VMware Platforms You can install the vNIOS software package on a host with VMware ESX or ESXi 4.x installed and configure it as either a VM-5 or VM-25 virtual NIOS appliance. NIOS virtual appliances are virtual grid members that include a full suite of core network servicesDNS, DHCP, IPAM, FTP, TFTP, HTTP, and NTP. Distributed organizations obtain the cost benefits of consolidation and the simplicity of centrally managed Infoblox NIOS virtual appliances.

2011 Infoblox Inc. All Rights Reserved. All registered trademarks are property of their respective owners. 400-0258-007 Rev. A

Page 8 of 21 11/18/2011

NIOS 5.1r5-5 Release Notes


The joint Infoblox-VMware solution supports hybrid environments that include a mix of physical Infoblox appliances and NIOS virtual appliances depending on branch office requirements. Each NIOS virtual appliance appears to the grid as a grid member, with all of the benefits of distributed services and centralized management. This includes centralized backup and restoration of user data, DHCP failover capabilities, onetouch software upgrades, DNS with low latency, and many other benefits of the Infoblox solution. For information on supported features and how to install vNIOS software on VMware platforms, refer to the Quick Start Guide for Installing vNIOS Software on VMware Platforms. GUI Enhancements This release includes the following enhancements to Grid Manager and System Manager: In the Dashboard, you can turn on the auto refresh feature to periodically refresh the contents of all widgets. This feature is turned off by default. Global Search results now include the IP addresses of matching objects, if applicable. You can click the address links to view detailed information about the IP addresses. In all selectors, you can now locate an object quickly by using the autocomplete feature. Enter the first few characters of an object name in the Go to field and select the object from a list of possible matches. You can now ping individual IP addresses from the IP List tab. In earlier releases, you could ping IP addresses only from the IP Map tab. When you perform a network discovery, the discovered data now includes information about DHCP leases that do not associate with any objects, such as host records or fixed addresses. You can also configure the appliance to append newly discovered data to existing data before starting a discovery. You can now use discovered data, such as conflicts, unmanaged data, and last discovered timestamps as filter criteria for creating smart folders. You can now use the Active Directory wizard to configure zones to accept dynamic DNS updates from domain controllers. You can now select a lease from the DHCP Range list, IP Map, or IP List and view detailed information. SNMP Enhancements Some objects in the Infoblox MIBs were updated to comply with RFC 2578. ibDDNSUpdateSucess and ibDDNSUpdateFailure were changed from Counter64 to scalar types in compliance with RFC 2578. To obtain the latest Infoblox MIB files, log in to Grid Manager and navigate to the Data Management tab, select the Grid tab, and then select the Grid Manager tab. Expand the Toolbar and select Download -> SNMP MIBs.

ADDRESSED VULNERABILITIES
This section lists security vulnerabilities that were addressed in this and earlier NIOS releases. For additional information about these vulnerabilities, including their severities, please refer to the National Vulnerability Database (NVD) at http://nvd.nist.gov/. The Infoblox Support website at http://support.infoblox.com also provides more information, including vulnerabilities that do not affect Infoblox appliances. CERT VULNERABILITY NOTE CVE-2011-4313 After a recursive name server caches an invalid record, subsequent queries for that record could crash the resolver with an assertion failure and the following error message: "INSIST(! dns_rdataset_isassociated(sigrdataset))"

2011 Infoblox Inc. All Rights Reserved. All registered trademarks are property of their respective owners. 400-0258-007 Rev. A

Page 9 of 21 11/18/2011

NIOS 5.1r5-5 Release Notes


CERT VULNERABILITY NOTE CVE-2011-3192 The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 could allow remote attackers to cause a denial of service CERT VULNERABILITY NOTE CVE-2011-2748 | CVE-2011-2749 DHCP: A remote attacker could cause the "dhcpd" process to exit using a specially crafted packet. CERT VULNERABILITY NOTE VU#142646 (CVE-2011-2464) BIND 9: Denial-of-service vulnerability in recursive and authoritative DNS servers in which a specially crafted packet sent to the servers could cause the named process to fail. CERT VULNERABILITY NOTE VU# 795694 (CVE-2011-1910) BIND 9: Very large DNSSEC RRSIG RRsets in a negative cache could trigger an assertion failure that could cause the named daemon to fail. CERT VULNERABILITY NOTE CVE-2011-0419: Denial-of-service vulnerability in which a carefully crafted HTTP request could cause excessive CPU usage under some circumstances. This issue affected NIOS 4.3r3-0 and later releases. CERT VULNERABILITY NOTE CVE-2011-0014: Incorrectly formatted ClientHello handshake messages could cause parsing issues in OpenSSL CERT VULNERABILITY NOTE VU#3706148 (CVE-2010-3613): BIND 9: Cache incorrectly allows a ncache entry and a rrsig for the same type CERT VULNERABILITY NOTE VU#837744 (CVE-2010-3614): BIND 9: Key algorithm rollover bug CERT VULNERABILITY NOTE VU#360341 (CVE-2010-0097): BIND 9 DNSSEC validation code could cause fake NXDOMAIN responses CERT VULNERABILITY NOTE CVE-2010-4008: IF-MAP service security vulnerability CERT VULNERABILITY NOTE VU#418861 (BIND 9.6.1-P2) (CVE-2009-4022): Cache Update from Additional Section CERT VULNERABILITY NOTE VU#568372 (CVE-2009-3563): NTP denial-of-service vulnerability CERT VULNERABILITY NOTE VU#120541 (CVE-2009-3555): TLS renegotiation MITM attacks CERT VULNERABILITY NOTE CVE-2009-3111: Denial-of-service condition from malformed Tunnel-Password attribute CERT VULNERABILITY NOTE VU#725188 (CVE-2009-0696): Denial-of-service condition when processing a specially-crafted dynamic DNS update packet.

2011 Infoblox Inc. All Rights Reserved. All registered trademarks are property of their respective owners. 400-0258-007 Rev. A

Page 10 of 21 11/18/2011

NIOS 5.1r5-5 Release Notes


CERT VULNERABILITY NOTE VU#723308 (CVE-2008-4609): State vulnerabilities triggered by sockstress

CHANGES TO DEFAULT BEHAVIOR NIOS 5.1r2


In the first step of the network, DHCP range and fixed address wizards, you can choose to create an object from scratch or use a template. NSEC3 hash iteration parameters were changed to conform to NIST guidelines. In previous releases, if you enabled DDNS updates, the DNS server could accept DDNS updates from a DHCP client even if the server was not allowed to receive DNS queries from that client. In this release, the DNS server no longer accepts DDNS updates from such DHCP clients.

NIOS 5.1r1-1
In previous releases, when you defined an option filter to match the vendor class value in a vendor option space, the matching value was automatically returned through option 60 (vendor class identifier). In this release, the appliance does not automatically return a matching vendor class value in a vendor option space through option 60. You can now specify any vendor class value to be returned through option 60. For example, for PXE clients that require option 60 to be returned with values starting with PXEClient, you must configure this DHCP option at the option filter level or at other appropriate levels.

NIOS 5.1r1
The Infoblox GUI and API display text in a TXT record exactly as it was entered, except in the following cases: If you enter a text string with multiple spaces between each word and the string is not enclosed in double quotes, the GUI and API display the text string with a single space between each word. If you enter one word enclosed in double quotes, the GUI and API display the word without the quotes.

NIOS 5.x
The Workflow Scheduling feature was changed as follows: Grid Manager does not display a warning when tasks are scheduled for the same date/time. There is no restriction on entering seconds for the scheduled time. There is no restriction on the number of tasks that can be scheduled. In previous releases, a maximum of 500 tasks could be scheduled. Scheduled tasks survive a master promotion and revert. Changed default value for CLI-accessible scheduled task restarts from 4 to 60 Removed the ability to enable/disable the scheduling feature at the global level (in GUI and PAPI). This feature is enabled by default. An Infoblox DHCP server that was also a DHCP IF-MAP client sent packets to the IF-MAP server from its LAN port, even when the client was an HA member. The DHCP server now sends the packets from the VIP of the HA pair. Therefore, you must configure the IF-MAP server to accept packets from the VIP.

2011 Infoblox Inc. All Rights Reserved. All registered trademarks are property of their respective owners. 400-0258-007 Rev. A

Page 11 of 21 11/18/2011

NIOS 5.1r5-5 Release Notes


In previous releases, a DHCP custom option list defined at the member level overrode all options defined at the grid level. In this release, it will override individual custom options, instead of the complete list. In this release, a GSS-TSIG key is required when you override the grid setting and enable GSS-TSIG in the DDNS tab of the DHCP Members editor.

UPGRADE GUIDELINES Upgrading to NIOS 5.1r5


Review the following guidelines before upgrading to NIOS 5.1r5: If you are upgrading from a NIOS 4.3rx release and the NAC Foundation module was configured, you must disable the RADIUS and DHCP Authentication services before the upgrade. After the upgrade, most of the features that were configured for the NAC Foundation module are preserved, including the configured RADIUS and AD servers; the MAC address filters and their corresponding prefixes; the quarantine, guest and authorized DHCP ranges; leases; user information registered through the captive portal; and the associations between the ranges and MAC address filters. If you would like to use the DHCP authentication feature introduced in NIOS 5.1r3, you must do the following after the upgrade: Configure the captive portal, including its IP address. Select the authentication server group and associate it with the captive portal server. Associate the DHCP server with the captive portal server. When you upgrade a VM-5, VM-25, VM-35, or VM-55 virtual appliance to NIOS 5.1r4 or later, you must deploy the appliance with at least 120GB of disk space. The vNIOS licenses that contain the old vNIOS model numbers are preserved after an upgrade. The display names of the vNIOS on VMware models however, change based on the following: VM-5 to IB-VM-250 VM-25 to IB-VM-550 VM-35 to IB-VM-1050 VM-55 to IB-VM-2000 For information about the supported vNIOS on VMware models, refer to the Infoblox Installation Guide for vNIOS Software on VMware.

Upgrading to NIOS 5.1r2-1


Review the following guideline before upgrading to NIOS 5.1r2-1: NIOS 5.1r2-1 does not support records with duplicate IP addresses in the same network view. For example: Two host records, configured for DHCP, with the same IP address in the same network view A host record and a fixed address record with the same IP address in the same network view During the upgrade, if the DHCP configuration is the same for the host addresses or for the host address and fixed address, the appliance will remove the DHCP configuration from one host address and will log a warning message in syslog. If the DHCP configuration is different, then the appliance will log an error message in syslog and fail the upgrade.

2011 Infoblox Inc. All Rights Reserved. All registered trademarks are property of their respective owners. 400-0258-007 Rev. A

Page 12 of 21 11/18/2011

NIOS 5.1r5-5 Release Notes


Infoblox recommends that you run the upgrade test, so you can resolve any potential data migration issues before the upgrade.

Upgrading to NIOS 5.x


If you are upgrading from a NIOS 4.x release, Infoblox recommends that you review these guidelines before upgrading appliances from a NIOS 4.x release to a NIOS 5.x release. You can run an upgrade test before performing the actual upgrade. Infoblox recommends that you run the upgrade test, so you can resolve any potential data migration issues before the upgrade. NIOS 5.x is not supported on the Infoblox-500, -1000, and -1200 appliances. Though a grid member that is running an earlier release (4.x) on unsupported hardware will be able to join a grid running NIOS 5.x, Grid Manager will display a warning every time a user logs in after the grid member joins the grid. Following are guidelines for upgrading a grid that contains Infoblox-500, -1000, and -1200 appliances: The upgrade will fail if the grid master is running on one of the unsupported appliances. An upgrade test will report this when you run the test prior to the actual upgrade. The upgrade will succeed if the grid master or a grid member has an expired license. After the upgrade, Grid Manager will display a warning every time a user logs in. If an appliance is running a NIOS version that is earlier than 4.2r4-0, you must upgrade it to 4.2r4-0 or later before upgrading it to a NIOS 5.x release. NIOS 5.x does not support the following features: RADIUS VitalQIP IPAM WinConnect These features will not be supported when you upgrade to NIOS 5.x. Note that these features will continue to be supported in 4.x. For more information, please see your Infoblox representative. During the upgrade, if the admin Group "ALL USERS" contains some administrators, it will be converted to a group called Default Group with the same administrators. Default Group will also be created if "ALL USERS" is used in the Remote Authentication policy. The permissions that are attached to "ALL USERS" will be moved to a role called Default Role that applies to all groups in the system. If "ALL USERS" has no permission, Default Role will not be created during the upgrade. In this release, the maximum length of the following fields is 256 bytes: Failover association name MAC filter name Option filter name Relay agent filter name Range, fixed address, and network template names Option definition name Option space name The upgrade and upgrade test will fail if any of these values exceed 256 bytes. The maximum length of the relay agent filter circuit ID and remote ID values is 255 bytes. The upgrade will fail if any of these values exceed 255 bytes. The minimum expiration time for MAC filters is 60 seconds. During an upgrade, NIOS sets expiration times to 60 seconds if they are less.
2011 Infoblox Inc. All Rights Reserved. All registered trademarks are property of their respective owners. 400-0258-007 Rev. A Page 13 of 21 11/18/2011

NIOS 5.1r5-5 Release Notes

If you configured the NIOS appliance to authenticate administrators using RADIUS or Active Directory servers, and configured static routes from the MGMT port of the appliance to any of those servers, the appliance will ignore those static routes after the upgrade to NIOS 5.x. To enable remote authentication using the MGMT port to connect to a RADIUS or AD server after the upgrade, navigate to the Administration tab, select the Administrators tab, and then select Remote Authentication. In the RADIUS Service or Active Directory Services tab, click the Add icon to add a server and select the Connect through MGMT Interface option. API Upgrade Guidelines All the deprecated IPAM device type and custom fields were removed from the API. The API does not support RADIUS. For example, the uca_group() method was removed from the DHCP::Range object as it was only used with the NAC Foundation feature. The behavior of bootfile(), bootserver() and nextserver() has changed. Each of these methods has its own override. Setting the override for one enables the override for that method to True. Object types affected by this change are: Grid::Member::DHCP DHCP::Range DHCP::SharedNetwork DHCP::Network DHCP::FixedAddress DHCP::NetworkTemplate DHCP::FixedAddressTemplate DHCP::RangeTemplate DHCP::Host Changes to the "range_templates" and "fixed_address_templates" methods of the NetworkTemplate object. You can no longer specify just the name of the child template when assigning a range and fixed address template to a network template. Instead, you must specify a DHCP::Template object that contains optional "offset" and "count". Following is an example: my $rtemp = Infoblox::DHCP::Template->new( name => "range template", offset => 10, # OPTIONAL, if not provided use from template count => 10, # OPTIONAL, if not provided use from template ); my $fatemp = Infoblox::DHCP::Template->new( name => "fa template", offset => 10, # OPTIONAL, if not provided use from template count => 10, # OPTIONAL, if not provided use from template ); $network_template->range_templates([ $rtemp ]); $network_template->fixed_address_templates([ $fatemp ]); In the Infoblox::DNS::View object, the match_clients and match_tsig_clients fields were replaced by the mixed-type match_clients field.

2011 Infoblox Inc. All Rights Reserved. All registered trademarks are property of their respective owners. 400-0258-007 Rev. A

Page 14 of 21 11/18/2011

NIOS 5.1r5-5 Release Notes


In the Infoblox::Grid::DNS and Infoblox::Grid::Member::DNS objects, the allow_query and allow_recursive_query fields were replaced by mixed-type allow_query and allow_recursive_query fields respectively. The allow_transfer and transfer_keys fields, and allow_update and update_keys fields were replaced by mixed-type allow_transfer and allow_update fields. In the Infoblox::DNS::Zone object, the allow_query and allow_transfer fields were replaced by mixedtype allow_query and allow_transfer fields. The allow_update, transfer_keys and update_keys fields were replaced by the mixed-type allow_update field. There is a new object Infoblox::Grid::NTPAccess for specifying the access list for the NTP service. The Session method restart() no longer supports the following parameters: when, time_zone, and cancel. Instead, use the parameter scheduled_at. In the Infoblox::Grid::ScheduledTask::ChangedObject, the expected values for action() are now: INSERT -> Add UPDATE -> Modify DELETE -> Delete The FixedAddress and RoamingHost objects are now two separate objects.

BEFORE YOU INSTALL


Infoblox recommends that administrators planning to perform an upgrade from a previous release create and archive a backup of the Infoblox appliance configuration and data before upgrading. You can run an upgrade test for a full upgrade before performing the actual upgrade. Infoblox recommends that you run the upgrade test, so you can resolve any potential data migration issues before the upgrade. You can also schedule a full upgrade that allows for member-to-master data replication. Following is the NIOS release from which you can schedule a full upgrade: 5.1r5-4, 5.1r5-3, 5.1r5-2, 5.1r5-1, 5.1r5-0, 5.1r4-6, 5.1r4-7 Following is a list of upgrade and revert paths that are supported and believed to be working: 5.1r5-4, 5.1r5-3, 5.1r5-2, 5.1r5-1, 5.1r5-0 5.1r4-8, 5.1r4-7, 5.1r4-6, 5.1r4-5, 5.1r4-4, 5.1r4-3, 5.1r4-2, 5.1r4-1, 5.1r4-0 5.1r3-11, 5.1r3-10, 5.1r3-9, 5.1r3-8, 5.1r3-7, 5.1r3-6, 5.1r3-5, 5.1r3-4, 5.1r3-3, 5.1r3-2, 5.1r3-1, 5.1r3-0 5.1r2-6, 5.1r2-5, 5.1r2-4, 5.1r2-3, 5.1r2-2, 5.1r2-1, 5.1r2-0 5.1r1-7, 5.1r1-6, 5.1r1-5, 5.1r1-4, 5.1r1-3, 5.1r1-2, 5.1r1-1, 5.1r1-0 5.0r1-8, 5.0r1-7, 5.0r1-6, 5.0r1-5, 5.0r1-4, 5.0r1-3, 5.0r1-2, 5.0r1-1, 5.0r1-0 4.3r8-5, 4.3r8-4, 4.3r8-3, 4.3r8-2, 4.3r8-1, 4.3r8-0 4.3r7-4, 4.3r7-3, 4.3r7-2, 4.3r7-1, 4.3r7-0 4.3r6-6, 4.3r6-5, 4.3r6-4, 4.3r6-3, 4.3r6-2, 4.3r6-1, 4.3r6-0 4.3r5-6, 4.3r5-5, 4.3r5-4, 4.3r5-3, 4.3r5-2, 4.3r5-1, 4.3r5-0 4.3r4-6, 4.3r4-5, 4.3r4-4, 4.3r4-3, 4.3r4-2, 4.3r4-1, 4.3r4-0 4.3r3-2, 4.3r3-1, 4.3r3-0 4.3r2-9, 4.3r2-8, 4.3r2-7, 4.3r2-6, 4.3r2-5, 4.3r2-4, 4.3r2-3, 4.3r2-2, 4.3r2-1, 4.3r2-0, 4.3r2-200, 4.3r2-TTL-0 4.3r1-3, 4.3r1-2, 4.3r1-1, 4.3r1-0 4.2r5-7, 4.2r5-6, 4.2r5-5, 4.2r5-4, 4.2r5-3, 4.2r5-2, 4.2r5-1, 4.2r5-0 4.2r4-3, 4.2r4-2, 4.2r4-1-sp1, 4.2r4-1, 4.2r4-0

2011 Infoblox Inc. All Rights Reserved. All registered trademarks are property of their respective owners. 400-0258-007 Rev. A

Page 15 of 21 11/18/2011

NIOS 5.1r5-5 Release Notes


Technical Support Infoblox technical support contact information: Telephone: 1-888-463-6259 (toll-free, U.S. and Canada); +1-408-625-4200, ext. 1 E-mail: support@infoblox.com Web: http://www.infoblox.com/en/support/support-center-login.html GUI Requirements Grid Manager supports the following operating systems and browsers. You must install and enable Javascript for Grid Manager to function properly. Grid Manager supports only SSL version 3 and TLS version 1 connections. Infoblox recommends that you use a computer that has a 2 GHz CPU and at least 1 GB of RAM. Infoblox supports the following browsers for Grid Manager: OS Microsoft Windows 7 Microsoft Windows XP (SP2+) Red Hat Enterprise Linux 6.x Red Hat Enterprise Linux 5.x Apple Mac OS X 10.6.x Browser Microsoft Internet Explorer 8.x and 9.x Mozilla Firefox 3.6.x and 4.x Google Chrome 7.x and 10.x Microsoft Internet Explorer 7.x and 8.x Mozilla Firefox 3.6.x and 4.x Google Chrome 10.x Mozilla Firefox 3.6.x and 4.x Google Chrome 7.x and 10.x Mozilla Firefox 3.6.x and 4.x Google Chrome 10.x Safari 5.x Mozilla Firefox 3.6.x and 4.x Google Chrome 10.x

Infoblox recommends using the latest release of the supported versions of Mozilla Firefox or Google Chrome for best performance. When viewing Grid Manager, set the screen resolution of your monitor as follows: Minimum resolution: 1024x768 Recommended resolution: 1280x800 or better Documentation You can download the Infoblox Administrator Guide from the appliance. From Grid Manager, expand the Help panel, and then click Documentation -> Admin Guide. Training Training information is available at http://www.infoblox.com/en/training/training-center.html.

ACCESSING GRID MANAGER


Before you log in to Grid Manager, ensure that you have installed your NIOS appliance, as described in the installation guide or user guide that shipped with your product, and configured it accordingly. To log in to Grid Manager: 1. Open an Internet browser window and enter https://<IP address or hostname of your NIOS appliance>. The Grid Manager login page appears. 2. Enter your user name and password, and then click Login or press Enter. The default user name is admin and password is infoblox.
2011 Infoblox Inc. All Rights Reserved. All registered trademarks are property of their respective owners. 400-0258-007 Rev. A Page 16 of 21 11/18/2011

NIOS 5.1r5-5 Release Notes


3. Read the Infoblox End-User License Agreement and click I Accept to proceed. Grid Manager displays the Dashboard, your home page in Grid Manager.

RESOLVED ISSUES
This section lists the issues that were fixed in the NIOS 5.1r5 release. The resolved issues are listed by severity. For a description of the severity levels, refer to Severity Levels on page 20. Note: Infoblox now uses a new numbering scheme to track issue IDs. Numbers in parenthesis are legacy IDs. The new numbering scheme is in the format: NIOS-xxxxx or DIW-xxxxx.

Fixed in 5.1r5-5
ID Severity Summary After upgrading, grid members could not boot until a "reset database" was performed on all grid members, which had to rejoin the grid.

NIOS-33194 Critical NIOS-32871

Fixed in 5.1r5-4
ID Severity Summary This release addresses CVE-2011-4313: After a recursive name server caches an invalid record, subsequent queries for that record could crash the resolver with an assertion failure and the following error message: "INSIST(! dns_rdataset_isassociated(sigrdataset))"

NIOS-33433 Major

Fixed in 5.1r5-3
ID Severity Summary After an HTTPD process failure, the appliance generated core files and restarted. Users were able to view additional information when they used the autocomplete feature to enter CLI commands. The vertical toolbar and the Logout button became unresponsive. A descriptor leakage caused the monitor process to generate core files after it exceeded the descriptor threshold for a process. When using the Add Admin Group wizard to create an admin group, the Role Selector dialog did not display user-defined roles. When a client attempted to use an incorrect encryption method during a GSS-TSIG transaction, the appliance sent a SERFAIL error message instead of indicating that there was a decryption failure. After upgrading to NIOS 5.1r4-4, users were unable to access the Administration tab in Grid Manager.

NIOS-32148 Major NIOS-32134 Major NIOS-31867 Major NIOS-31783 Major NIOS-31696 Major NIOS-31542 Major

NIOS-31535 Major

2011 Infoblox Inc. All Rights Reserved. All registered trademarks are property of their respective owners. 400-0258-007 Rev. A

Page 17 of 21 11/18/2011

NIOS 5.1r5-5 Release Notes


NIOS-31159 Major NIOS-30744 Major NIOS-30491 Major NIOS-30425 Major NIOS-30326 Major NIOS-30303 Major NIOS-30293 Major NIOS-29988 Major On some occasions, users encountered an error when they tried to access the Dashboard in Grid Manager. DHCP service restart took longer than expected due to a large number of inactive and outdated leases in the database. Users could not create a delegation in a DNS zone in certain configurations that involved a Microsoft read-only primary server. Grid members were disconnected from the Grid Master due to a product restart caused by an httpd process failure. Modifying information in name server groups took longer than expected. Users could not create a sub zone if the parent zone was managed by a read-only Microsoft server. The appliance did not send the HA replication online/offline SNMP traps after an HA failover. The appliance did not return any data when users filtered the syslog using Server = TFTP or Server = HTTP, even though there were syslog messages related to TFTP and HTTP. Limited-access users could not assign an IP address when they used the Next Available IP feature. Updated the documentation to clarify how the system migrates bulk hosts when you upgrade to NIOS 4.3r3 or earlier releases Users could not remove Microsoft DNS/DHCP data after they removed a Microsoft server that was in read-only mode. Multiple vendor options with the same option name and code defined in different options spaces overwrote one another. The help file of the DNSSEC tab of the Member DNS Properties editor contained an incorrect field label. Grid Manager erroneously sorted the global Smart Folders by creation date rather than in alphabetical order. Fixed a typo in the error message displayed by the Add Extensible Attribute wizard when users did not enter a maximum value for an extensible attribute. When using Google Chrome browser to access Grid Manager, it would sometimes hang. An RFC 2317 prefix could not be modified if the zone had a Grid Secondary or External Secondary defined.

NIOS-29429 Major NIOS-29345 Major NIOS-28189 Major (49936) NIOS-26649 Major (47567) NIOS-32108 Minor NIOS-31996 Minor NIO-31748 Minor

NIOS-31683 Minor NIOS-31579 Minor

Fixed in 5.1r5-2
ID Severity Summary clusterd could consume increasing amounts of memory.

NIOS-32094 Critical

2011 Infoblox Inc. All Rights Reserved. All registered trademarks are property of their respective owners. 400-0258-007 Rev. A

Page 18 of 21 11/18/2011

NIOS 5.1r5-5 Release Notes


Fixed in 5.1r5-1
ID Severity Summary Addresses CVE-2011-3192: The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 could allow remote attackers to cause a denial of service. Grid Manager reported 100% CPU utilization and became unusable due to numerous, concurrent queries for Smart Folders that contained large amounts of data. Improved recycle bin and global search processes that caused CPU utilization to significantly increase. Recursive queries failed until the cache was flushed. API: Deleting thousands of records using the API took longer than expected and caused CPU usage to significantly increase.

NIOS-31866 Major

NIOS-30723 Major NIOS-30035 Major NIOS-26708 NIOS-29951 Major NIOS-31567 Minor

Fixed in 5.1r5-0
ID Severity Summary Upgrading to NIOS to 5.1r4-3 failed due to a named daemon monitoring failure when zones had a TSIG key defined to allow updates. This issue affected NIOS 5.1r4-3, 6.0.4, and 6.1.0.

NIOS-31310 Critical

ID

Severity

Summary This release addresses the following vulnerability: DHCP: A remote attacker could cause the "dhcpd" process to exit using a specially crafted packet. (CVE-2011-2748 | CVE-2011-2749) This issue affected NIOS 4.2r4 and later releases. Adding zone associations to DHCP networks impacted GUI performance. After a grid master candidate was promoted to grid master, the DNS views that contained DNSSEC zones were not associated with the newly promoted grid master. The appliance could not restore a backup file due to a data translation issue in a TXT record. Adding zone associations to DHCP networks impacted GUI performance. DNS queries on the UDP port encountered frequent timeouts due to a buffer issue in the burst traffic. When a zone was assigned to a Microsoft server, users could not create a delegation to this zone if the grid master is a Microsoft primary server in a read-only mode. Users could not create a sub zone if the parent zone was managed by a Microsoft primary server in a read-only mode.

NIOS-31455 Major

NIOS-31296 Major (51108) NIOS-31177 Major NIOS-31172 Major NIOS-31111 Major NIOS-30972 Major (47645) NIOS-30806 Major NIOS-30802 Major

2011 Infoblox Inc. All Rights Reserved. All registered trademarks are property of their respective owners. 400-0258-007 Rev. A

Page 19 of 21 11/18/2011

NIOS 5.1r5-5 Release Notes


NIOS-29937 Major (49025) NIOS-29896 Major NIOS-29893 Major NIOS-29883 Major (52803) NIOS-29874 Major (47658) NIOS-29849 Major NIOS-29834 Major (52623) NIOS-29830 Major (53081) NIOS-31108 Minor (48748) NIOS-31106 Minor (50729) NIOS-30933 Minor (52894) NIOS-30930 Minor NIOS-30823 Minor (48353) Comments added to a network were not synchronized with a Microsoft DHCP server. Adding a new view, and then viewing Smart Folders caused the CPU usage to significantly increase. Updated the documentation to indicate that changing the VPN port, time zone, date and time of a Grid requires a product restart. Changing the value of an extensible attribute in a host record took longer than expected. Creating smart folders with certain conditions caused the CPU usage to significantly increase. Under certain circumstances, some DHCP options and scopes were missing or corrupted after users restarted the DHCP service on a Microsoft server. NIOS did not synchronize correctly when a Microsoft secondary server was added before the Microsoft primary server. The mssyncd process constantly restarted after a software downgrade because the Microsoft cache was not probably cleaned up during the downgrade. Scheduled SCP backups were logged as error even when they were successful. The CLI command show cpu returned unnecessary information in the last column. Users could not remove a Microsoft server that was associated with a Microsoft readonly zone. Improved some ambiguous error messages in the MS Management log. When a user's page size was greater than the number of rows that could be displayed, and the user tried to use "Go to" to find an item, Grid Manager jumped to the correct page of the table but did not reposition the scrollbar so that the matching item was visible. Updated the documentation to clarify the password for the RADIUS test users. The options in the DNS Blackhole tab were changed from Allow and Deny to Include and Exclude to better describe the actions.

NIOS-30154 Minor NIOS-29846 Minor (50830)

Severity Levels
Severity Critical Major Moderate Minor Enhance Description Core network services are significantly impacted. Network services are impacted, but there is an available workaround. Some loss of secondary services or configuration abilities. Minor functional or UI issue. An enhancement to the product.

2011 Infoblox Inc. All Rights Reserved. All registered trademarks are property of their respective owners. 400-0258-007 Rev. A

Page 20 of 21 11/18/2011

NIOS 5.1r5-5 Release Notes


KNOWN GENERAL ISSUES
ID NIOS-25064 (45488) Summary If you configured a member DHCP server to authenticate DHCP clients with a RADIUS authentication server group and RADIUS is disabled (the server group is disabled, all RADIUS servers in the group are disabled, or the member DHCP server was not assigned an authentication server group), NAC filters with does not equal rules will always match. Workaround: Do not disable RADIUS. When you use the "Order DHCP Ranges" button to change the order of thousands of DHCP ranges in a network, the GUI may hang and the appliance logs an error message to infoblox.log. When you run a discovery on a network served by Microsoft servers, and Grid Manager discovers a MAC address that does not match any of the fixed addresses associated with an IP address, it reports a conflict and lists the associated fixed address objects in the Related Objects table. You cannot select which fixed address to resolve in the Related Objects table. You can only resolve the conflict for the first address. If a virtual NIOS member does not start up due to a license violation, Grid Manager displays the status of the vNIOS member as online/running even though the member is not online. When you stop the DNS service of an independent appliance with temporary DNS and DHCP licenses, Grid Manager displays the Restart Services panel regardless of which function you select. An admin cannot display DNS views created by other admins during the same browser session. To display the DNS views created by other admins, you must log out and log in again. Grid Manager does not display an error when you move a DNS view to a network view that contains a host record that has the same MAC address as a host record in the DNS view that is being moved. Grid Manager does not sort columns correctly in the IPAM and Network list panels when the columns contain UTF-8 data. The appliance allows users with read-only permission to A records to view DNSSEC resource records as well. A NIOS virtual appliance running vNIOS for Cisco cannot join a grid after the grid reverts to an earlier version of NIOS. Workaround: Use the CLI command set nogrid to remove the NIOS virtual appliance from the grid, and then use the set membership command to join the NIOS virtual appliance to the grid. Syslog messages generated during a TFTP file transfer display the incorrect time zone. Adding, updating, or deleting reverse zones could fail due to unsupported PTR records in the root zone.

NIOS-24953 (45379) NIOS-24820 (45296)

VNIOS-36 (41215) NIOS-21512 (39917) NIOS-21499 (38968) NIOS-19853 (31668) NIOS-19144 (30208) NIOS-18163 (27831) NIOS-18009 (27385)

NIOS-17636 (26233) NIOS-17513 (26080)

2011 Infoblox Inc. All Rights Reserved. All registered trademarks are property of their respective owners. 400-0258-007 Rev. A

Page 21 of 21 11/18/2011

S-ar putea să vă placă și