SurfControl Web Filter 5.5.0.504 Readme
February 2007
|
Welcome to SurfControl Web Filter 5.5.0.504.
This release contains the enhancements and fixes listed below. SurfControl
Technical Support can be contacted
by phone or e-mail.
Search engine results contain lots of content that may be inappropriate. For instance, in image search thumbnails or cached versions of search pages. Web Filter v5.5 now categorizes and blocks search engine results based on the ‘real’ site’s category.
Pause to Real Time Monitor
Now you can optionally pause the Real Time Monitor to examine violations or activity before it scrolls off the screen.
SurfControl Report Central 2.5 Improvements
There
are a host of new reports and options for reporting, including:
•
Report
showing ‘Who went where, when and for how long’
•
Report
on workstation IP range
•
Naming
on custom reports
•
Page
numbers on reports
•
IP Range Reporting
•
Duration Field in User Activity Report
New Company & Intranet category
During the install you can automatically identify
internal IP addresses and company domains and mark them for inclusion in the
“Company and Intranet” category for more accurate reporting and monitoring.
“What” tab in Rules
Administrator
This new tab logically groups controls for what
the user does in the rules creation process.
The list of applications, ports, protocols, file types and extensions,
etc. is also expanded in this tab.
Other Enhancements:
· Optional, anonymous daily submission of customer’s top 100 uncategorized sites for categorization
· “None” sites renamed to “Uncategorized”
· Database Architectural Improvements
· Databases can be shared amongst all instances of Web Filter v5.5 for Windows, Web Filter for Microsoft ISA Server, Mobile Filter and Web Filter for Citrix Presentation Server
· Support for SQL 2005/ 2005 Express
· Streamlined installation process
Instant Message Filtering
Identifies and optionally blocks IM traffic by protocol signature, not port. Protects against most widely used protocols:
Peer to Peer Filtering
Identifies and optionally blocks P2P traffic by protocol signature, not port. Protects against most widely used protocols:
•
eDonkey
•
BitTorrent
•
FastTrack
•
Gnutella
Alternative
This alternative tool
is based on the domain Login/Logoff script and
captures Login, Logoff and any IP address changes in between, without having to
install anything on the desktop or the domain controller.
Antivirus Filtering at the Gateway
Sold as an add-on and
powered by McAfee, this feature now provides antivirus filtering at the
gateway, and in the same layer as Web Filter.
Extended Protocol Protection
Now you can monitor and block all ports, not just HTTP + FTP, which provides
increased visibility into EVERYTHING users are doing on the web. This can also integrate to ISA as an
Application Filter.
Antivirus reporting in Report Central
New report in Report Central provides detailed activity on when and
where web viruses were detected and blocked.
Other Enhancements
·
Support for Microsoft ISA Server 2006 both
Standard and
·
ISA Alerts
·
Option to ignore 404 unreachable web sites
SurfControl Mobile Filter provides user
name-level monitoring, reporting, and blocking of all Internet activity of
remote workers, no matter how they access the Internet. Mobile Filter helps you
increase employee productivity, optimize network bandwidth, increase security,
and limit the legal liability that occurs when remote employees are given local
Internet access. SurfControl Mobile Filter gives you:
·
Secure
LDAP communication between Mobile Filter and the domain controller.
·
The
ability to configure the port between the client and Mobile Filter server.
·
Network
installation of clients via group policy.
·
The
ability to make the client invisible to the user.
·
Secure
communication between the client and the server.
·
Increased
client deployment security.
Web Filter 5.5.0.504 contains the
following bug fixes:
|
Description |
Issue Number |
|
Defects
Fixed in 5.5.0.504 |
|
|
Real-Time
Monitor hangs when opening the General Settings dialog under load |
13230 |
|
Dr Watson
occurs on starting the Web Filter service if the rank values for categories
in table _Category_A do not form a sequential list. |
13376 |
|
STNT -
v5.0 ScUserAgent failing with Dr. Watson |
13921 |
|
GetRuleDenyPage
Dr. Watson caused by duplicate categories |
14028 |
|
Override
page does not display category for "None sites" |
14109 |
|
Category names in Where Lists are not upgraded correctly |
14200 |
|
Crash
when running dbupdate |
14651 |
|
Rules containing
Active Directory Groups with no members apply to Anybody |
14973 |
|
Database creation error when using SQL 2005 |
15039 |
|
Rules Administrator is unable to display Active Directory
child domains that have the same subdomain name |
15335 |
|
Firewall service doesn't
restart after SWF has been removed |
15490 |
|
Problems with the SWF
service and other SWF apps crashing |
15510 |
|
Block until categorized
feature causes the hostname cache in the driver to fill up too quickly |
16157 |
|
Changes to purge scripts so
that they do not deadlock while flat file imports are occurring |
16814 |
|
Category name change to
"Company & Intranet" |
16942 |
|
Mobile Filter - Dr Watson
during the transfer of log files from the client to the server |
17969 |
|
Web Filter service crashing
unexpectedly |
19343 |
|
Novell Netware NLM not
seeing usernames |
19913 |
|
Installing the Client on a
Domain Controller causes severe problems |
20618 |
|
Mobile Filter - Windows Server
2003 doesn't allow ISAPI extensions to run by default and thus no clients can
be installed |
11483 |
|
VPN Access with a
Certificate fails when Mobile Filter is installed |
12825 |
|
Mobile Filter - Dr Watson during
the transfer of log files from the client to the server. |
17969 |
|
Mobile Filter - Doesn’t
handle FileType monitoring functionality |
20209 |
|
Mobile Filter -Doesn’t
support SearchEngine CachedURL |
20210 |
|
Mobile Filter - Service needs
to be updated to allow use of Access Control DLL for MF |
20269 |
|
Mobile Filter - DBModify
will fail to upgrade a Mobile Filter database |
20437 |
|
Mobile Filter - Exceptions
raised in service when proxy thread is running |
20445 |
|
Mobile Filter Client does
not filter ports greater than 32,767 correctly |
20509 |
|
Changes to the
rules schema for the 'What' objects not taken into account.” |
20743 |
|
Not able to configure the
CNDS post install |
20777 |
|
Installing CNDS manually crashes |
20780 |
|
Mobile Client COM Error
when synchronizing after log files deleted |
20859 |
|
Runtime Error in
scadminservice |
20986 |
|
Create shortcuts in
Configuration Wizard fails leaving Configuration Wizard unable to complete |
21298 |
|
Download Internet Threat
Database fails after upgrade |
21536 |
|
Unable to add Corporate Web
Filter details to Mobile Filter using SQL 2005 |
21537 |
|
Group policy application
fails after Mobile Filter client is installed |
21839 |
|
Log files SCNM2WF and SCNMGW
absent. |
21996 |
|
Double-clicking on Update
Configuration hangs the Web Filter Manager |
23485 |
|
Privacy edition password details are not remembered after upgrade. |
26483 |
|
The option to "not download" the Threat Database is not offered during an upgrade. |
26496 |
|
Sites are not correctly categorized as 'Company & Intranet' during an upgrade. |
26655 |
Web Filter 5.5.0.504 has the following known issues:
|
Description |
Issue Number |
|
Known
Issues in 5.5.0.504 |
|
|
VCA Results are not correctly updated in the Monitored Data. |
4729 |
|
VCA
categorizations are incorrect when "Block Until Categorized" option
is switched on. To avoid both these situations you should set the VCA
machine's subnet to be unmonitored. For 4729 ISA Server platform, you should
create a new admin user for the VCA machine and then set that user to
unmonitored. 13010 is only an issue for SurfControl Web Filter
for Windows. |
13010 |
|
If a user generates Internet traffic via a proxy, EUM reports this user name to the Web Filter server, which then monitors all proxy server hits with this user name. Any subsequent traffic going through this same proxy is recorded against the user logged into it. This can give the impression that a single user generated a lot of internal traffic. |
5249 |
|
If the Web Filter service is set to manual and is therefore not running after a restart, or the service is terminated by anything other than stopping the service from within Web Filter, the rules admin will not import any rules, giving the message: "You must stop the following service(s) before performing this operation: Web Filter service running no QACOM17". |
7102 |
|
Mobile Filter Clients can't upgrade via the web when
"Offline Action" is set to block all. Forcing Clients to upgrade while "Offline Action" is set to "Block All" stops the client from upgrading via a web page as all internet activity is being blocked on the client machine. |
9266 |
|
Policy Override is not available within the Rules
Administrator on the Remote Admin installation. This is because the client is the same across platforms and policy override is not supported by the pass-by platform. There are only two available options on the Select Server Platform Type page during installation: 1. Windows 2000/2003 (Pass by). 2. Microsoft ISA Server. |
10644 |
|
Upgraded User defined categories containing a single
category will be renamed to the name of the category they contain. For example a user defined category 'MyCategory' containing 'sport' will be renamed to 'sport'. If 'sport' already exists one instance (depending on categorization priority) will be renamed 'sport(1)'. Users who wish to avoid this should enter characters in the SmartScan window for categories they wish to keep prior to upgrade and then remove them afterwards. |
11813 |
|
When changing the Spider Settings file location in the Settings tab of the VCA application and applying the changes, this new location is not used until the application is closed and reopened. |
11839 |
|
When changing the SurfControl Mobile Filter database a reboot is required before the new database is used. |
12473 |
|
The SurfControl Mobile Filter server can be installed successfully on a server that does not have Microsoft IIS installed, even though Mobile Filter will not work if IIS is not present. |
12646 |
|
The following situation causes a problem: The user(s) no longer exist(s) on the domain controller at the time a scheduled Network Group Update event was run AND their last connection was later than that configured in the dialog for automatically removing users after a given period of inactivity.
Under NT username handling, the user(s) is/are removed. However, under Netware handling, the user(s) is/are not removed and neither are their groups updated. The workaround to this is to manually delete the user(s) once you know that they should no longer be present. |
12922 |
|
During product upgrades an option is available to update the database currently in use by Web Filter via a separate dialog (SurfControl Database Updater). If this is chosen the main InstallShield window remains active allowing the Cancel button to be selected. If the Cancel button is pressed on the main dialog and then the Update button selected on the SurfControl Database Updater dialog a severe error is generated - "ERROR: Unable to copy driver file to system directory". The Web Filter can be installed after this message has been closed. However, performing an uninstall of Web Filter throws another severe error - "ERROR: Timed out while waiting for Web Filter Service to respond". The Web Filter will continue to uninstall but the subsequent reboot will take considerably longer than usual. |
12938 |
|
Missing text in controls and message boxes. This behavior is caused by a bug in McAfee VirusScan's buffer overflow protection. There is a patch available at: http://sdownload.nai.com/products/protected/hotfix/VSE80P05.Zip |
16940 |
|
Help Desk functionality has been dropped from version 5.5. The version 5.0 asp page will not function with version 5.5. |
19004 |
|
Added Protocols in Rules Admin (in v5.0.1.49) are seen as ‘Other’ after upgrade to 5.5.0.??? |
19894 |
|
In a multi collector environment upgrade after the first collector has upgraded the database the other collectors will attempt to import the flat-files, but this process will fail and the files will be left in the TMP directory. During the upgrade on the other collectors the end-user will see a message box stating that the flat-files are being imported, but these will just be changed to IMP files, and will not actually be imported, and the end-user is not informed that these files have not been imported. |
20826 |
|
If a user disables e-mail notifications for ISA alerts in the e-mail tab of the service settings, the ISA alert itself is disabled in the ISA Server. |
20828 |
|
Nothing is shown in the SurfControl Web Filter Manager Monitored Data during an upgrade of a split Rules and Monitor environment. To solve this issue, close and re-open the Web Filter Manager. |
20872 |
|
A "Client Upgrade" dialog box is displayed in Mobile Filter for every categorization request when an update available |
20929 |
|
ScEumLoginAgent.exe will not work on Windows NT computers. |
20976 |
|
When upgrading the Remote Administrator all current scheduler items will be lost, and will have to be re-entered. |
21006 |
|
The Web Filter service will stop when archiving and compacting databases. These events should be scheduled to run out of normal office hours. |
21582 |
|
Due to changes in the database tables After an upgrade from v5.0.1.49, existing Monitored Destinations or VCA Data in Custom Categorization is not displayed. |
21827 |
|
If Windows 95/98 machines on the network are configured for User Level Share, when anyone goes to open a file from one of those machines, the domain controller records that the remote user logged onto the Windows 95/98 machine. This results in the browser activity from the Windows 95/98 machine being recorded under the incorrect user name. Windows NT domain controllers demonstrate the same behavior. |
N/A |
|
When installing a Remote Administrator, users will be presented with the dialogs to set-up username support as in the Complete Product. The information from these dialogs is necessary to browse and display data at the user specified Context in the NDS Tree. The specified NDS Context should be the same as the one used in the Complete Product, but the username and password information can be different. If a different username is specified, this user should have the same rights to the NDS Context as the user specified in the Complete Product. In addition make sure you choose the same options for username monitoring in all installations. |
N/A |
|
The NetWare NLM for Username support only supports 8.3 DOS directory formats; therefore, please copy the NLM into a 8.3 DOS directory. |
N/A |
For more information, please refer to the SurfControl Knowledge Base. Contact SurfControl
Technical Support for further assistance.