Subscription based capacity license
With this release of 10.1, a column Type is added in the System tab of the Licenses page. This column displays if the capacity license added is perpetual or subscription based in nature. If subscription, the Expiration column displays if the capacity license is valid or expired along with the expiration date.
To view the Licenses page, go to Manager → <Admin Domain Name> → Setup → Licenses.
Upgrade an already upgraded capacity license
With this release of 10.1, a capacity license once upgraded can further be upgraded based on new throughput requirements. For example, if a capacity license of 10G is upgraded to 20G, then this 20G capacity license can be further upgraded to 30G, 40G, 60G, or 100G.
To upgrade a capacity license, go to Manager → <Admin Domain Name> → Setup → Licenses.
Public GTI credentials for File Reputation
With this release of 10.1, the public GTI credentials for file reputation are available in the McAfee Update Server. The GTI credentials (username and password) are automatically downloaded to the Manager and needs to be pushed to the Sensor.
To view the McAfee Global Threat Intelligence server for file reputation, go to Manager → <Admin Domain Name> → Integration → GTI.
Support automatic import of Solr data
During the Manager upgrade, if it involves major change in Solr version, Solr data folder is deleted as part of installation due to compatibility issues between older and newer versions. After installation is complete, the Manager will automatically import the Solr data.
Note
- An informational fault is displayed in the Manager → Troubleshooting → Logs → Faults page, to notify you about start and end of automatic import of Solr data.
- A critical fault is displayed in the Manager → Troubleshooting → Logs → Faults page, to notify you about the failure in import of Solr data.
| Manager Version | Solr Version | Support automatic import of Solr data |
|---|---|---|
| 10.1.7.4 | 6.1.0 | No |
| 10.1.7.7 | 6.1.0 | No |
| 10.1.7.29 | 8.4.1 | No |
| 10.1.7.35 | 8.4.1 | No |
| 10.1.7.40 | 8.4.1 | No |
| 10.1.7.44 | 8.4.1 | Yes |
Display CVE ID in Attack Log grid
Starting with this release of 10.1, the Manager displays the CVE ID column in the Attack Log page. This column displays CVE IDs of those attacks present in the signature set that have a valid CVE ID assigned to them.
To view this column, go to Analysis → <Admin Domain Name> → Attack Log.
Note
In case you are upgrading the Manager from version 10.1.7.29, 10.1.7.35 or 10.1.7.40 to 10.1.7.44, the CVE ID column in the Attack Log page displays CVE IDs only for the alerts (that have valid CVE IDs assigned to them in thesignature set) generated post upgrade. You will not be able to view the CVE IDs for old alerts. In order to view CVEIDs for such alerts:
- Double-click on the old alert for which you want to view the details.
The <Attack Name> panel opens on the right hand side.
- Click on the Description tab in the panel and scroll down to the Reference section.
You can view the CVE ID in this section, provided the alert has a valid CVE ID assigned to it in the signature set.
Configuration of E-mail Server listening port
Starting with this release of 10.1, you have the option to change the SMTP port number in the Manager. This would allow you to configure SMTP on any port of your choice while configuring the e-mail server.
To configure the port number in the Manager, go to Manager → <Admin Domain Name> → Setup → E-mail Server.
Email notifications for expiring passwords
Starting with this release of 10.1, users can enable email notifications for expiring passwords. The Manager sends email notifications to the users when their passwords are about to expire, thereby increasing the possibility of the users knowing about expiring passwords. These emails are sent every day until the last day of expiry. For example, if you set the warning interval as 4 days, the user receives 1 email everyday for 4 days before the password expires.
Note
This feature works only when the E-mail Server is configured.
To view the Get Email Notification for Expiring Password option under Password Expiration section, go to Manager → <Admin Domain Name> → Setup → GUI Access → Password Control.
Allow for longer domain names when setting up notifications
Starting with this release of 10.1, it is increased to support up to 255 characters. You can change the domain length in Firewall, IPS Quarantine, IPS Events, NTBA Quarantine Events, Faults, and User Activity tabs of the Manager.
Show power supply status
Starting with this release of 10.1, a new column for displaying power supply status is added in Devices → <Admin Domain Name> → Global → Device Manager → Sensors.
You can also configure these modes through Sensor CLI.
Display serial number
Starting with this release of 10.1, the transceiver serial number is displayed in the Serial Number column of Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Physical Ports → Monitoring Portspage.
Note
This command is applicable to NS5x00, NS7x00, and NS9x00 Sensors.
Note
For RJ45, the serial number is displayed as Not Applicable.
The I/O module serial number is displayed in the grid view in Devices → <Admin Domain Name> → Devices → <Device Name> → Setup → Physical Ports → Monitoring Ports.
You can also configure these modes through Sensor CLI.
Layer 2 Assert and Deassert modes
Starting with this release of 10.1, these modes can be configured from Devices → <Admin Domain Name> → Devices → <Device Name> → Troubleshooting → Layer 2 Bypass → Layer 2 Pass-Through Monitoring.
Note
It must be noted that Deassert mode is displayed only if previously Layer 2 mode is set to Assert mode.
You can also configure these modes through Sensor CLI.
The Manager database fails to start
Starting with this release of 10.1, while troubleshooting reasons for the Manager database failing to start on a Windows system, check if Manager database process is already running. This can be verified by opening Windows Task Manager and looking for mariadbd.exe with Memory foot print of hundreds of MB.
Manager shell commands
The following Manager shell commands are added:
| Command | Description |
|---|---|
| snmp | Displays the list of commands in Manager shell to perform actions on SNMP service in the Linux based Manager. |
| snmp disable | Disables SNMP service in the Linux based Manager. |
| snmp enable | Enables SNMP service in the Linux based Manager. |
| snmp list | Displays a list of all the SNMP commands. |
| snmp restart | Restarts the SNMP service in the Linux based Manager. |
| snmp start | Starts the SNMP service in the Linux based Manager. |
| snmp status | Displays if the SNMP service in the Linux based Manager is running or not. |
| snmp stop | Stops the SNMP service in the Linux based Manager. |
The following Manager shell commands are updated:
| Command | Description |
|---|---|
| Run | Updated the list of executable files available to run the scripts. |
| Scp from remote | Added syntax for scp from with a key. |
| Scp to remote | Added syntax for scp to remote with a key. |
| Show executables | Updated the list of executable files displayed. |