Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
en:dpi:update:previous:ver_8_0:start [2023/09/01 12:10] – elena.krasnobryzh | en:dpi:update:previous:ver_8_0:start [Unknown date] (current) – removed - external edit (Unknown date) 127.0.0.1 | ||
---|---|---|---|
Line 1: | Line 1: | ||
- | ====== Version 8.0 Brugge ====== | ||
- | {{indexmenu_n> | ||
- | Changes in version 8.0 Brugge((Brugge is the most picturesque city in Belgium, the country with the highest deployment of IPv6 (75%) in the world. Brugge as well as our St. Petersburg is called " | ||
- | - [[en: | ||
- | - Zello protocol recognition and its metadata export are added | ||
- | - Output of control commands is added [[en: | ||
- | - The feature to set the policing options using the JSON format is added | ||
- | - Service 12 intended to record subscriber traffic using the PCAP format is added | ||
- | |||
- | Changes in patch 8.0.5\\ | ||
- | - Further IPv6 support improvements | ||
- | - Bug fixes and improvements in the CGNAT and NAT 1:1 | ||
- | - Compatibility with different equipment in PPPoE termination mode (L2 BRAS) is improved | ||
- | - Stability of the operation within the multicluster mode is increased | ||
- | - Asynchronous tasks prioritizing feature is added. This has led to improvement in BRAS and SORM puller interaction | ||
- | |||
- | Changes in patch 8.0.6\\ | ||
- | - Counting of links to user profiles is fixed, so it allows to delete unused profiles | ||
- | - NAT assignment to a subscriber with multiple addresses (including the white ones) is fixed | ||
- | |||
- | :!: Before upgrading please make sure that the '' | ||
- | |||
- | Changes in 8.1.1 version\\ | ||
- | - Full IPv6 support in L3 and L2 BRAS is added along with integration with DHCP/ | ||
- | - WhatsApp, Viber, OpenVPN protocols detection is added | ||
- | - Service 13 - [[en: | ||
- | - UDP traffic blocking according to the black lists is added | ||
- | - IPFIX/ | ||
- | - Cipher Suite export for SSL/HTTPS within SORM (Russian lawful interception system) metadata is added | ||
- | - Authorization by ARP request is added | ||
- | - Billing data export using IPFIX protocol is added | ||
- | - Further improvements of Radius Accounting sessions compatibility | ||
- | - Improvements of NAT ports reusing | ||
- | - Issue with --bind request is fixed | ||
- | - The ' | ||
- | |||
- | Changes in 8.1.2 version\\ | ||
- | :!: fastradius upgrade to 8.1.2 version is needed in response to changing of protocol version\\ | ||
- | - Maximux login(user-name) size is increased up to 96 bytes | ||
- | - Fixed bug in mini Firewall (Service 13) | ||
- | - Fixed bug in setting Session-Timeout when getting the CoA: if it is not specified, then corresponding value will be taken from the configutation parameter | ||
- | |||
- | Changes in 8.1.4 version\\ | ||
- | :!: If you haven' | ||
- | - Fixed bug in defining of autonomous system when IPv6 addresses are used | ||
- | - ascheckip utility is added | ||
- | - New '' | ||
- | - Fixed the procedure for calling subscriber authorization | ||
- | |||
- | Changes in 8.1.5 version\\ | ||
- | :!: fastradius upgrade to 8.1.5 version is needed in response to changing of protocol version\\ | ||
- | - Fixed HTTP redirect in case of PPPoE termination | ||
- | - Escaping (quoting) for a number of characters to be used in json and fdpi_ctrl (in login profile names) is added | ||
- | |||
- | Changes in 8.2 version\\ | ||
- | :!: fastradius upgrade to 8.2 version is needed in response to changing of protocol version\\ | ||
- | - Fixed issues in CG-NAT : session reusing is improved, transit of fragmented ICMP is added | ||
- | - Fixes in L2 BRAS as a result of implementation | ||
- | - Fixed transmission of 32 bits AS in IPFIX | ||
- | - Added [[en: | ||
- | - Added [[en: | ||
- | - Improved support for the VAS Experts DPI-200 | ||
- | - Alerts log output when starting/ | ||
- | |||
- | Changes in 8.3.1 version\\ | ||
- | :!: Due to the change in the protocol version, it is required to update fastradius along with fastpcrf and fdpi_ctrl installed on individual servers up to 8.3.1 version\\ | ||
- | - [[en: | ||
- | - Support for [[en: | ||
- | - The following protocol signatures: Telegram, Viber, WhatsApp, VyprVPN with Chameleon technology (included in OpenVPN) are added | ||
- | - Recovery/ | ||
- | - Commands [[en: | ||
- | - A new feature allowing to specify or add comma-separated subnets when setting the NAT profile is added: example of format to use ' | ||
- | - A new feature allowing to consider only IPv4 CIDR-specified host addresses and when setting CIDR parameters: example of format to use ' | ||
- | - Added to BRAS auth: ability to specify within the RADIUS response that this response should be ignored silently. Attribute value '' | ||
- | - Fixed in BRAS L3 auth: if a subscriber has already been associated with a policing profile, and the policing was not specified in the authorization response, than the existing profile was not untied from the subsciber, which did not allow to delete the subscriber' | ||
- | - Fixed in BRAS DHCP: identification of obsolete BOOTP protocol. BRAS doesn' | ||
- | - Added to BRAS DHCP: unqualified DHCP packets are now stored in the pcap having '' | ||
- | - Improved in BRAS DHCP: when [[en: | ||
- | - Changed in BRAS DHCPv6: the subscriber’s unique key is now the subscriber’s MAC address instead of the Client DUID. This is associated with the fact that some home routers quite freely use DUIDs and can change it at any time despite that Client DUID is an immutable option according to RFC; | ||
- | - Added to BRAS DHCPv6: periodic sending of ICMPv6 RA with a DHCPv6 response; | ||
- | - Added to BRAS DHCPv6: periodic sending of [[en: | ||
- | - Added tp BRAS DHCPv6: fastdpi.conf parameter, | ||
- | - Fixed in BRAS PPPoE: rarely manifested, but critical error leading to system malfunction and associated with incomplete control of the packet length specified in the PPPoE/PPP headers and the actual length of the received packet (broken or specially incorrectly formed | ||
- | - Fixed in BRAS PPPoE: when starting fastDPI and restoring PPPoE sessions, accounting did not start; | ||
- | - Added to BRAS PPPoE: the ability to prohibit the recovery of PPPoE sessions when restarting the VAS Experts DPI, see [[en: | ||
- | - Added to BRAS PPPoE: control of the issued IP address overlapping when creating a session. If an active PPPoE session of another subscriber with that IP address already exists, the session will be closed. | ||
- | - Fixed in BRAS ARP: in the [[en: | ||
- | - Fixed in BRAS ARP: checking for session expiration should not apply to [[en: | ||
- | - Improved in BRAS CoA: CoA-Request changes the authorization status only when it is explicitly specified that the subscriber is unauthorized (if the attribute '' | ||
- | - Changed in BRAS CoA: behaviour of [[en: | ||
- | - Improved in BRAS Accounting: BRAS accounting has been significantly improved due to support of [[en: | ||
- | - Added to BRAS Accounting: the ability to exclude some classes from radius accounting by using '' | ||
- | - Added to BRAS Accounting: '' | ||
- | - Added to BRAS Accounting: '' | ||
- | - Improved in BRAS Accounting: now when fastDPI starts/ | ||
- | - Added to fastpcrf: improved support for the case when multiple fastdpi communicate with one fastpcrf server: now fastpcrf can communicate with fastdpi servers located on different interfaces, [[en: | ||
- | - Changed in fastpcrf: principle of forming Radius attributes '' | ||
- | - Changed in fastpcrf: due to implementation of [[en: | ||
- | - Changed in fastpcrf: '' | ||
- | - Added support for up to 5 nested MPLS tags in blocking, notification, | ||
- | - The outgoing connection buffer is increased, this will smooth out the peaks and reduce the likelihood of packet loss when delivering ipfix/ | ||
- | - Other beta fixes | ||
- | |||
- | Changes in 8.3.2 version | ||
- | - Fixed removal of service 4 (blacklist) with profile | ||
- | |||
- | You can check the current installed version using the following command | ||
- | < | ||
- | yum info fastdpi | ||
- | </ | ||
- | |||
- | [[en: | ||
- | |||
- | Downgrade to 8.2 version: | ||
- | |||
- | < | ||
- | yum downgrade fastdpi-8.2 fastpcrf-8.2 | ||
- | </ | ||
- | |||
- | Service restart is required after upgrading or downgrading: | ||
- | |||
- | < | ||
- | service fastdpi restart | ||
- | </ | ||
- | |||
- | |||
- | :!: Do not upgrade the Linux kernel. In newer versions of the kernel binary compatibility with Kernel ABI may be broken and the network driver will not boot after the update. If you did update, then temporarily (during solving the problem) configure the grub boot loader to load the previous kernel version (in the / | ||
- | |||
- | To check what's new in the [[en: |