Unified Services Router Release Notes ============================================================== Important Notes: 1. Automatic factory reset when image upgrade detects a firmware region mismatch between RU and WW images. Such as firmware upgrade from RU->WW or WW->RU image. 2. Russian firmware version doesn’t support over 40bit encrypted algorithm according to regulatory restriction. 3. Microsoft Windows XP has some well-known limitation to access USB storage of DSR router, D-Link provides a Registry Script file named: WinXP.reg which can solve limitation of Windows XP environment. Without applying this script file, it cannot copy file from Windows XP to USB storage. (This issue will not happen when copy file from USB storage to Windows XP) ============================================================== Firmware version: 1.08B44 Problems Fixed: 1. Security Vulnerabilities Addressed: Devices respond clients some unnecessary information, and hence give hackers a chance to get a non-persistent root shell. Reference: (CVE-2013-5945, CVE-2013-5946) Solution: Remove all unnecessary root user accounts 2. After rebooting devices, synchronization with NTP didn't works. 3. Firewall rule with scheduling is not work. ============================================================== Firmware version: 1.08B39 Problems Fixed: 1. Including 1.08B31 all fixes for DSR-250N in this version 2. The MPPE function does not work in L2TP client mode 3. Restore configuration file to different HW version 4. WAN responses ARP packet 5. Add a message to inform user, who need to change 443 port number for sslvpn or remote management once two features are enabled. 6. Can't work with any AP connected with network cable 7. Device time not synchronizing with default NTP servers after reboot. 8. Firewall rule disable is not work unless reboot device. 9. WIFI stability issue under heavy BT traffic Known Issues: 1. PowerMode is not completely functional. 2. Wan is not getting IP from IPv6 DHCP server in stateful mode. 3. Netperf is unable to pass traffic over IPsec tunnel. 4. PPPoE performance worst if user changes the WAN MAC address. ============================================================== Firmware version: 1.08B31 Problems Fixed: 1. The OpenVPN Local Network page disappear when I used IE8 or IE9 to manage the DSR. 2. USB sharing could not download/upload large file 3. DWM-156 A3, A6 compatility issue 4. Security Vulnerabilities Addressed: Persistent root access. Reference: http://packetstormsecurity.com/files/118355/D-Link-DSR-250N-Backdoor.html Solution: Removed CLI commands that could allow someone to overwrite the super user password and gain root access to the device. Root user account will be completely removed in the next firmware version. 5. Prevent to upload config file into different model 6. Unable to change the Wireless output power 7. Device stuck under BT download 8. X.509 certificate expired issue 9. Security Vulnerabilities Addressed: uPnP vulnerabilities identified in the audit of libupnp code base. Reference: CVE-2012-5958, CVE-2012-5959, CVE-2012-5961, CVE-2012-5962, CVE-2012-5963, CVE-2012-5964, CVE-2012-5965 Solution: Patched Intel SDK libupnp v1.3.1 to add the following; 1) use 'snprintf' and 'strncpy' instead of 'sprintf' and 'strcpy', 2) While doing a 'strncpy', check if we are copying more bytes than the destination string size. 10. DNS query issue for L2TP WAN type Known Issues: 1. PowerMode is not completely functional. 2. Wan is not getting IP from IPv6 DHCP server in stateful mode. 3. Netperf is unable to pass traffic over IPsec tunnel. 4. PPPoE performance worst if user changes the WAN MAC address. 5. Device got defaulted after upgrade from 1.05B73_WW to 1.08B31_WW 6. Not able to establish L2TP over IPsec tunnel with same user multiple time after change IPsec policy. 7. The GRE function does not work 8. The MPPE function does not work in L2TP client mode. ============================================================== Firmware version: 1.05B53 New Features: 1. Support email address to be local ID in Ipsec policy. 2. Support SHA-1 in Phase 1. 3. Support DH group need support group 1, 2 and 5 for Phase 1. 4. Add PFS group 1, 2 and 5 for Phase 2. 5. Add a keyword with "." (dot) in Blocked Keywords text box. Problems Fixed: 1. DSR-250 and 250N don’t show Logs for tunnel disconnect and Logout for SSL VPN & port forwarding. 2. “LAN clients” page is not displaying the connected information. 3. CLI wan1 status does not show wan1 physical interface information when device is in RU firmware dual PPPoE mode. 4. When server IP is configured with FQDN, Wan L2TP over DHCP connection does not reconnect after device reboot. 5. Default VLAN is associated with all the wireless SSID after reboot. 6. "Block ICMP" is not work for a SSL VPN policy with permit permissions. 7. Traffic is not going from PPTP/L2TP client to device's LAN after changing WAN ISP until disable and enable PPTP server again. 8. When the user login SSL portal with wrong credentials domain name in IE browser address bar, the browser will not refresh back to 'SSL portal login' page. 9. Dyndns name provided in the SSL portal page will be changed into the device WAN IP, if the user try to login SSL portal page with wrong credentials in Firefox browsers. 10. Device's MAC address field in WDS page is blank in RU image. 11. Device is taking 40-50 seconds to apply the configuration in VLAN page of RU image. 12. Wireless client status page is showing wrong Authentication and Encryption types. 13. Device GUI is getting stuck after running bulk traffic over PPTP/L2TP tunnel. 14. "Connect" button is not working for IPv6 gw-gw policy in Active VPNs page when IPv6 WAN is radvd IP. 15. No information on WLAN Domain when country code is set to Japan. 16. Firewall rule with schedule is working correctly only for GMT time zone. 17. Device displaying critical error message when trying to upload certificates to activate OpenVPN server/client. 18. Unable to access GUI after factory reset and power OFF/ON the device. 19. Wireless clients are not getting updated in Wireless Clients status page. 20. UPnP process is not running in Dual Stack IPv4/IPV6 mode. Known Issues: 1. Bandwidth Limit not functioning when port name is used in Traffic selector 2. PowerMode is not completely functional. 3. Wan is not getting IP from IPv6 DHCP server in stateful mode. 4. Netperf is unable to pass traffic over IPsec tunnel. 5. Transparent Mode is not supported. 6. Observed ping loss from WLAN clients to internet. ============================================================== Firmware version: 1.05B20_RU New Features: 1. Support 3G dongle DWM-152 A1/A2/A3, DWM-156 A1/A2/A3, Huawei E1550, E173. 2. Pre-Share key can be configurable in wireless wizard. 3. Change design to disable auto refresh for Traffic Monitor by default. Problems Fixed: 1. IPv6 to IPv4 tunneling is not work. 2. Internet web surfing is very slow for WLAN client if SPPE enabled. 3. Remove CLI command which is not supported in DSR-250/250N. 4. PPTP client is getting disconnected while uploading and downloading files using windows sharing. 5. Device shell is getting stuck after running bulk traffic over PPTP/L2TP tunnel. 6. Bandwidth Usage and Used applications are not displayed in dashboard. 7. Default VLAN will be associated with all the wireless AP after reboot. 8. Fixing L2TP doesn’t reconnects to L2TP server after reboot. 9. Fixing wireless clients is not displayed on status page. Known Issues: 1. Bandwidth Limit not functioning when port name is used in Traffic selector 2. PowerMode is not completely functional. 3. Wan is not getting IP from IPv6 DHCP server in stateful mode. 4. Netperf is unable to pass traffic over IPsec tunnel. 5. Transparent Mode is not supported. 6. Traffic is not going to device's LAN from PPTP/L2TP client after changing WAN ISP, unless PPTP server disables and then enables again. 7. Observed ping loss from WLAN clients to internet. 8. USB file sharing transmission will be disconnected if file size is over 600MB. ============================================================= Firmware version: 1.05B06_RU New Features: 1. Support SSH remote management from WAN port 2. Support LED and IPsec MIB. Problems Fixed: 1. Improving link up time of WAN interface less than 1 minute after device power on. 2. Fixing the printer shared port detection issue. 3. Fixing PPTP pass through is not working. 4. Fixing SSL tunnel is disconnected when user tries to download 200 MB file. Known Issues: 1. Bandwidth Limit not functioning when port name is used in Traffic selector 2. PowerMode is not completely functional. 3. Wan is not getting IP from IPv6 DHCP server in stateful mode.