17.5 Changelog
From Edge Threat Management Wiki - Arista
Jump to navigationJump to search
17.5
In an ongoing effort to modernize the local web administration, this release features updated screens in the Network and System sections of the administration. This release also introduces a new App called Dynamic Blocklists that enables you to block IP addresses from externally maintained lists.
General updates and enhancements
- UI Refresh for many screens including the Network and System sections of the web administration.
- Ability to copy / duplicate items - As part of the new UI refresh, you can now copy / duplicate items. For example, you can duplicate a Bypass Rule if you want to make a new rule with a small change.
- New App (Dyamic Blocklists) - The Dynamic Blocklists App enables you to specify external sources by URL and automatically fetches the list of IP addresses. If enabled, any IP addresses in any external list will be blocked in either direction. The Dynamic Blocklist App is included in the NG Complete license.
- Gratuitous ARP - The firewall can now send unsolicited ARP announcements to neighboring devices on WAN interfaces. This is particularly useful on WAN links which can be disconnected if no ARP announcements occur during a period of time. The option is disabled by default and can be enabled in the Advanced * * * Network Options "Send unsolicited R/ARP updates on WANs".
- Global Web Filter Block / Pass lists - You can now configure Block and Pass lists in Web Filter that are global to all Web Filter policy instances. A new "Global" checkbox in the Block and Pass lists defines whether the URL should apply across all policies.
- WireGuard Profiles - You can now configure profiles in WireGuard to specify the routed networks to configure for clients.
- Search and Filter in WireGuard tunnels - The WireGuard Tunnels grid now supports search and filter so you can quickly find a specific tunnel configuration.
- OpenVPN inline profile upload - When configuring an OpenVPN tunnel you can now use inline configuration format.
Bug fixes and security updates
- Fixed - IPsec tunnels "Active WAN" setting now works with WAN Balancer.
- Fixed - WireGuard app failed to initialize if an IP address pool conflicted with any local subnet.
- Patched command injection vulnerabilities found in the shell scripts that control various features.
Upgrade notes
- Post-upgrade browser hard-refresh required - After the appliance reboots on 17.5, perform a one-time hard-refresh, before making any changes under Config → Network or Config → System.
- OpenVPN Fallback Cipher field - A new Fallback Cipher field has been added on the OpenVPN Advanced tab; if your existing Cipher field contained a colon-separated list, Fallback Cipher is initialized to AES-128-CBC on upgrade — review it, adjust if your legacy clients require a different fallback, and re-download / redistribute the client .ovpn files. Single-cipher configurations are unaffected.
- OpenVPN cross-user authentication enforced - Across Active Directory, Local Directory, and RADIUS, a user can no longer connect using another user's client-config file.
- @SafeCheck validation on by default - All settings saves are now validated; pre-existing settings that fail validation can be temporarily un-blocked with the runtime SafeCheck bypass flag while you clean them up.
- The Virus Blocker app using Bitdefender has been replaced by ClamAV. The Virus Blocker lite app is now Virus Blocker and there are no license requirements to use virus filtering. For older versions still using Virus Blocker with Bitdefender all entitlements will be disabled by the end of 2026.
- Disconnect unused Google Drive - Customers who are not actively using the Google Drive connection should manually disconnect it from Config → Administration → Google.