DES-3800 series Firmware Release Note Firmware: 3.00.B57 Hardware: A1 & A2G for DES-3828 series / A1G for DES-3852 Date: July 05, 2007 Enhancements: 1. Add a CLI command “show current_config access_profile” for showing current ACL configuration. 2. When connecting to the system’s CLI, it shows a blank screen first and will show username/password text after the user enters any key. 3. When the user enables Access Authentication Control and logon thru Console: After wrong passwords are supplied for 3 times and the console screen is locked, a message is shown up to indicate the time left before the user can enter the password again. Problems Resolved: 1. The SSH connection is lost and the switch does not answer to ping when setting up large number of ACL rules and manipulating them under SSH connection. 2. Cannot ping DES-3828 Interface when setting up several CPU interface filtering rules that consist permit & deny rules. 3. Once Exhausted Mode of Safeguard engine is activated, the switch cannot go back to Normal Mode while the CPU is busy at updating ACL rules. 4. The value format of RMON etherHistoryUtilization object is incorrect. 5. When using Web-based Access Control, the authentication page does not appear if the user goes to the configured Redirection Page URL with a file name (eg. http://xx.xx.xx.xx/index.html) 6. When DES-3800 is connected with DES-6500 in STP enabled looped connection, power cycling the DES3800 will make STP failed. 7. Double VLAN member port cannot be successfully added via CLI. 8. The default route configured on DES3800 switch is not redistributed to others. 9. When using IGMP Snooping, multicast streams are flooded to some other non-joined ports. 10. The ‘new line’ symbol (0D0A) is inconsistent in config file. 11. When creating an IP interface on a VLAN via Web, a VLAN name longer than 20 characters is not allowed. 12. After changing DES-3828's ipif mask, the interface changes its state to down. 13. Cannot input a VLAN name longer than 10 characters when monitoring MAC address via Web. 14. When entering the command "config safeguard_engine" without any parameters, there is no error message. 15. The switch enters the exception mode periodically if OSPF is enabled in a large deployment environment. 16. Polish character "?" entered into Web interface makes the switch not work properly. 17. Cannot set default route using Web interface. 18. CPU utilization becomes 100% if enabling STP on a switch that has many (1000+) VLAN entries. 19. When enabling AutoConfig, the switch can be assigned an IP address but doesn't download config file automatically. 20. VRRP virtual IP doesn’t reply to ping. 21. The switch enters exception mode and hangs up if using SSH without TERM parameter (eg. unset TERM) under Linux environment. 22. After supplying power via PoE for a long time and then unplug the cable from the port, the PoE Status LED is still on. ============================================================= Firmware: 3.00.B29 Hardware: A1 & A2G for DES-3828 series / A1G for DES-3852 Date: November 13, 2006 Enhancements: 1. Support 3-Level User Account 2. Support Radius Accounting for management access 3. Support Per flow mirroring 4. Support PIM-SM 5. Support hardware-based multicast replication 6. Support IP MAC Port binding ACL mode 7. MAC-based Access Control (MAC) 8. Support telnet client 9. Support 0.0.0.0 for IP Setting to prevent from occupying IP address 10. Support log enhancement 11. When access violation (Port Security, IP-MAC-Port Binding), will record it to the Log 12. Send out SNMP Trap for IP-MAC-Port and Port Security violation 13. Support Password Recovery 14. Support SIM 1.6 (to attach to the system VLAN) 15. PVID =1 for ports removed from any VLAN 16. Support SSH 1.5 17. Support Proxy ARP 18. Add two MIB objects to clear FDB table and ARP table Problems Resolved: 1. The “show packet ports” page will be overlaid after refreshing. 2. SSH v2 does not work properly with Putty software. 3. Can not create IP interface via web interface 4. Can not configure the metric of default route via web interface 5. Can not configure the Secondary interface if the IP address is greater than the Primary interface. 6. After rebooting device, the static ARP entry will be lost 7. Device needs around 10 minutes to boot up even when there’re only few ACL configurations. 8. Configuring bandwidth control will fail if the LACP group is already created. 9. If the traffic matches the ACL rule first and the result is “permit”, the bandwidth control function will not work. 10. Safeguard engine can not return to the normal mode when the CPU is not busy any more. Note: For DES-3828P, after downloading the firmware, it will take about 5 minutes because the PoE firmware will be upgraded as well. ============================================================= Firmware: 2.00.B30 Hardware: A1 Date: April 14, 2006 Enhancements: 1. Support Dual configuration 2. Support STP Loopback Detection 3. Extends IP interface per VLAN from 2 to 10 4. Support Double VLAN 5. Support 802.1X Guest VLAN 6. Support IGMP V3 7. Support WRED congestion control 8. Support WAC (Web-based Access Control) 9. Support per port limit IP multicast address range 10. Rename the “CPU protection” with the “Safeguard Engine” feature. 11. Side fan and back fan (only for DES-3828P) log when failed or recovered. 12. RPS and main power supply log and trap 13. Support Route preference 14. Support per port shutdown function in the Broadcast storm control 15. Remove supporting for legacy PD in PoE function Problems Resolved: 1. The "zoom in" and " zoom out" functions were opposite in the SIM topology 2. Bandwidth Control doesn’t work from Web 3. SSHv2 can not work properly. 4. DES-3828P does not have the accuracy Power display, for example Power limit set to 15.4W, but the Current Power display is 16.7W. 5. When using D-View module to set ACL, ACL function fails 6. When using Tera Term SSH version 2.3.4, the program gives an error message saying "The program does not understand the servers version of protocol" and Devices will get into Exception mode. 7. Fix bugs of log with external power supply (DPS-200) 8. UDP Broadcast (attack tool) causes SIM fail and device reboot Note: Because the Dual configuration, the system setting will be cleared after the firmware updated to R2. It’s strongly recommended the user to backup the original configuration then to reload it after the upgrading. ============================================================= Firmware: 1.00.B31 Hardware: A1 Date: Dec 27, 2005 Problems Resolved: Fix the security issues recently reported for unauthorized system access. Enhancements: Limit the access by passwords generated by "D-Link PWD calculator". Before, if customers forgot their configured passwords, D-Link could generate passwords based on the MAC addresses provided by customers via D-Link HQ maintained PWD calculator. Thus customers can use those "backdoor" passwords via telnet/ web/ console to logon to their switch again. Now the access of those passwords generated by "D-Link PWD calculator" will be limited to console access only. This is to minimize the security concern. Note: This is a recommended security patch for your customers. ============================================================= Firmware: 1.00.B23 Hardware: A1 Date:Aug 17, 2005 DES-3828/3828DC/3828P first release. For functions support and configurations please refer to product spec and manuals for detail.