This is an old revision of the document!
Changelog of SSG BETA-version
Changes in version 14.0 BETA1
- [BRAS] Support for L2TP termination
- [BRAS] Support for DHCP-Dual
- [DPI] Migration to DPDK 24.11, support for new NICs (Intel E830 200G, Intel E630, Napatech SmartNIC)
- [CLI] Added support for
subs_id
in commands:dhcp show
,dhcp reauth
,dhcp6 show
,dhcp6 reauth
, anddhcp disconnect
Changes in version 14.0 BETA2
- [DPI] New protocols added: AGORA_STREAMS(49314), AZAR_CALL(49315), WECHAT_CALL(49316), TEAMS_CALL(49317). List of protocols
- [DPI] Improved support for LINE_CALL, VYKE_CALL protocols. List of protocols
- [DPI] Fixed smartdrop behavior
- [DPI] Added validation for complex protocols. List of protocols
- [DPDK] Increased the maximum number of dispatchers to 32
- [IPFIX/Netflow] Added the ability to change IPFIX/Netflow parameters without restarting fastDPI. A new config parameter
ipfix_reserved
has been added to reserve memory for enabling/changing IPFIX/Netflow parameters. If IPFIX/Netflow parameters are set in the configuration file, memory reservation for IPFIX/Netflow is automatically enabled and parameters/new exporter types can be changed without restarting fastDPI. - [FastRadius] It is now possible to set both
bind_ipv6_address
andbind_ipv6_subnet
. If the Framed-IPv6-Prefix has a /128 mask, it is not checked against thebind_ipv6_subnet
restriction. - CLI command
dev info
now includes the name of the LAG that the port belongs to - [PCRF][PPP][Framed-pool] Added: DHCP option
Client-Id
now includestunnel-IP
as part of the subscriber ID. Format of DHCP optionClient-Id
with fastpcrf.conf optiondhcp_client_id=1
is as follows:[conntype][subs_id][tunnel_ip] conntype = 1 (1 byte) subs_id - 16 bytes tunnel_ip - 4 bytes
Tunnel IP is available in L2TP; for PPPoE, tunnel IP = 0.
- [IPFIX] Message aggregation added for IPFIX streams: FullFlow/DNS/META/NAT
- [IPFIX] Added parameter
ipfix_mtu_limit
to restrict maximum message size for IPFIX UDP packets - [IPFIX DNS] New elements added to IPFIX DNS: 224 (ipTotalLength) and 43823:3206 (DNS transaction id)
- [VRRP] Fixed proper handling of the
vrrp_enable
option change - [BRAS][PPP] PPP session key is now compound:
l2subs_id
+tunnel-IP
. For PPPoE sessions, tunnel IP = 0. CLI commands that usesubs_id
as a key (subs prop show
,l2tp show session
,l2tp term
, etc.) may now return multiple entries with the samel2subs_id
.
Changes in version 14.0 BETA3
- [DPI] Added cloud protocols with identifiers 55296..58367
- [IPFIX] Fixed IPFIX exporter reinitialization bugs
- [BRAS][subs_grooming] Fixed potential crash due to race condition during fastDPI shutdown
- [CLI] Added commands to display mempool properties and statistics
hal mempool props hal mempool stat
DPDK must be built with statistics collection enabled to display mempool stats
- [BRAS][DHCP] Fixed crash when parsing Framed-Pool Renew response if it contains no DHCP options
- [PCRF][Acct] Fixed: Interim-Update sending is now disabled when
Acct-Interim-Interval = 0
is explicitly set in the RADIUS response - [VASE_CLI] Created a unified CLI for managing DPI, BRAS, DHCP (KEA), ROUTER (BIRD) with support for authorization and command logging via TACACS (VEOS 8.x required)
- [SNMP] Created a module for monitoring system components via SNMP
Changes in version 14.0 BETA4
- [DPI] Added DOQ 49318 protocol (DNS-over-QUIC)
- [Router] Announcing subscriber white addresses for 1:1 NAT individually and after authentication
- [PCRF] Added support for service 19 "DNS spoofing", profile required.
- [DPDK] Added
dpdk_engine=6
(mqrx-bridge
) — number of RSS dispatchers per bridge. Total number of dispatchers =dpdk_rss * number of bridges
. NIC configuration: RX queue count =dpdk_rss
, TX queue count = number of worker threads (num_threads
). Intended for setups with many bridges (dev1:dev2:dev3:…) for 100G+ NICs, as a replacement for the cluster approach. On-stick devices are supported. - [DPDK] Removed dedicated mempools. The fastdpi.conf option
dpdk_emit_mempool_size
is deprecated and no longer used. - [VLAN-Rule] Moved vlan group data from UDR to SDR. Global rules for vlan drop/pass/hide/permit set by the previous CLI command
vlan group
were converted and moved from UDR to SDR, with removal from UDR. - [VLAN] VLAN rules — added CLI commands:
vlan rule add
- add new rule to SDRvlan rule modify
- modify existing rule in SDRvlan rule delete
- delete rule from SDRvlan rule show
- show all rules for the specified VLAN/QinQvlan rule dump
- dump all rules in SDRvlan rule purge vlan
/qinq
/all
- clear SDR for VLAN/QinQ or bothvlan rule apply
- apply rules; by default, rules are applied 5 minutes after the last SDR modification
- [IPv6] Added direction detection in combined traffic (IN+OUT on one port) based on the local flag for IP addresses. Enabled via
combined_io_direction_mode
option
Changes in version 14.0 BETA4.1
- [BRAS] Fixed compatibility with the old format of service 18, where there were fewer protocols and both fields in the profile needed to be filled
- [DPI] Lowered detection priority for
telegram_tls
Changes in version 14.0 BETA4.2
- [DPI] Improved detection of
WECHAT
andWECHAT_CALL
- [BRAS][Framed-Route] Fixed: possible crash when freeing memory
- [BRAS] Refactored PCRF connectivity: in the new implementation, all connections are equal; an error on any triggers reconnection of all connections and a switch to another PCRF. Added CLI commands:
pcrf connect show
— show current status and accumulated statistics for PCRF connections.- Force connection to the specified PCRF
pcrf connect switch [<pcrf_index>]
, where<pcrf_indxed>
is the index of the connection line in theauth_server
parameter. If<pcrf_indxed>
is not specified — defaults to 0.
- [IPFIX DNS] Added the ability to send DNS MX responses via IPFIX. Enabled by setting bit 3 (4) of the
ajb_save_dns
parameter
Changes in version 14.0 BETA4.3
- [DPI] Added FakeTLS protocol (49319) with validation
- [BRAS][DHCP] Changed: sliding window algorithm for rate limit
- [BRAS] Fixed: time comparison error when loading ip_prop from UDR
- [VLAN-Rule] Added support for 'any' instead of '*' when describing VLAN range
'*.*' is interpreted in bash command line as a file search mask, so now instead of '*', you can specify 'any' ('*' is still supported): 'any.any' - equivalent to '*.*' 'any' - equivalent to '*' '68.any' - equivalent to '68.any' 'any.78-90' - equivalent to '*.78-90'
- [BRAS] Removed support for DHCP-Dual (moved to next release)
- [DPI][LOG] Messages about insufficient SSL parsers are written to the slave log not for every event, but at a frequency of 1/50000.
Changes in version 14.0 BETA4.4
- [DPI] Added protocols ZALO_CALL(49320) and VK_CALL(49321)
- [DPI] Fixed blocking in hard mode for SSL
- [Acct] Added attribute
VASExperts-Service-Type
. Radius acct start/interim/stop sends the authorization type in theVASExperts-Service-Type
attribute. - [CLI] Added:
stat flow ip6
command to display IPv6 flow statistics - [CLI] Added:
stat flow ip4
command to display IPv4 flow statistics. Analogous to the output infastdpi_stat.log
. - [IPFIX] Fixed ExportTime formation error in IPFIX Fullflow
- [CLI] Added
stat netflow
command. Displays general statistics for Netflow/IPFIX (same as infastdpi_stat.log
under the "Statistics on NFLW_export" section) - [DNS] Added support for substitution/blocking/dropping of DNS requests A, AAAA, MX, HTTPS
- [CLI] Added
stat firewall
command
Update instructions
You can check the current installed version with the command below
yum info fastdpi
If you have CentOS 6.x or CentOS 8.x installed, then switch the repository once with the command:
sed -i -e '/^mirrorlist=http:\/\//d' -e 's/^# *baseurl=http:\/\/mirror.centos.org/baseurl=http:\/\/vault .centos.org/' /etc/yum.repos.d/CentOS-*.repo
and then update as usual.
To install the test version, you should issue the following command:
yum --enablerepo vasexperts-beta update fastdpi
Downgrade to 13.3:
yum downgrade fastdpi-13.3 fastpcrf-13.3 dpiutils-13.3 fastradius-13.3
After an update or version change, a restart of the service is required.
Was this information helpful?