
23
Cisco PIX Security Appliance Release Notes Version 7.2
OL-10104-01
Caveats
CSCsc79110 Yes syslogs show user <unknown> when packets denied by vpn-filter
CSCsc81565 Yes Idle conn timeout reset when packet dropped by TCP normalizer
CSCsc81668 Yes https://<ip>/config
does not have the same privilege level as 'write'
CSCsc83471 Yes incorrect IPSec SA's may be deleted upon receiving DELETE notify
CSCsc86217 Yes Voice Proxy Function does not preserve DSCP bits.
CSCsc90826 Yes PIX 7.0 getting the error %PIX-1-106021 when ip verify command enable
CSCsc90944 Yes Malformed https proxy authentication page w/ linebreak
CSCsc91450 Yes FTP control channel timing out although data channel is active.
CSCsc92575 Yes Upgrade Activation Key reduces permitted interfaces
CSCsc93061 Yes Traceback after activation of vpn-filter
CSCsc94945 Yes Startup-config error with priority-queue and service-policy
CSCsc97846 Yes Significant CPU utilization increase when adding more logging hosts.
CSCsc97999 Yes Syslog Message ID 313003 is used incorrectly
CSCsc98339 Yes Standby unit may reload if active unit powered off
CSCsc99263 Yes GTPv1: Subsequent Create Req to modify PDP context IEs are not processed
CSCsc99364 Yes SSL Certs from Verisign Managed PKI do not install
CSCsd00051 Yes SNMP polling of ASA management interface stats may cause packet loss
CSCsd00175 Yes ASA w/ IPS may drop FIN/ACK packets resulting in half open FTP sessions
CSCsd01722 Yes PIX/ASA 7.0 logging message 419001 always sent in message lists
CSCsd02938 Yes ASA/PIX doesn't reconnect if websense server goes down
CSCsd03391 Yes TCP Intercept doesn't negate CPU impact when SYN flood from adjacent net
CSCsd03664 Yes Reload w/ Thread Name:Session Manager w/ high volume of L2L VPN traffic
CSCsd04327 Yes ASA out of order packets to ssm or inspect are dropped
CSCsd04700 Yes match port option for setting connection time-outs does not work
CSCsd07703 Yes Oracle Forms(Java) Applet not loading via WebVPN
CSCsd07783 Yes Transient NAT-T packets silently dropped if NAT-T is enabled
CSCsd08170 Yes UDP 500 not removed from pat port pool when crypto map is applied
CSCsd10138 Yes Traceback in Checkheaps thread when enabling LAN2LAN vpn
CSCsd11179 Yes SNMP polling of resource MIBS may cause packet loss
CSCsd11511 Yes Traceback due to memory corruption in sanity check of Checkheaps thread
CSCsd12670 Yes ASA, WebVPN errors when triggering a simple javascript
CSCsd13334 Yes Memory Leaking tunnel-group authorization-dn-attributes
CSCsd13636 Yes Reload with thread name dispatch unit
CSCsd15475 Yes Secondary unit doesn't get full config file after SSH reload on Primary
CSCsd16751 Yes GTP: wrong service-policy used when connection is re-used
Table 3 Resolved Caveats (continued)
ID Number
Software Version 7.2(1)
Corrected Caveat Title
Comentarios a estos manuales