Commit Graph

135 Commits

Author SHA1 Message Date
fumingwei
c6ac2f2b16 feature:TSG-18248:删除decoder BGP配置项及其相关代码 2023-12-29 17:04:45 +08:00
fumingwei
f99fed10ec feature:TSG-18248:删除Decoders GTPC相关配置项及其代码 2023-12-29 17:04:45 +08:00
fumingwei
b70f452e8b feature:TSG-18248:删除firewall Decoders.RADIUS相关配置项及其代码 2023-12-29 17:04:43 +08:00
fumingwei
898fd56b28 feature:TSG-18248:删除wannat配置项及其相关代码 2023-12-29 17:00:47 +08:00
fumingwei
4ecad45965 feature:TSG-17838:构建TSG 9140 NPB容器化镜像 2023-12-10 12:37:39 +00:00
liuxueli
bcdf7c673c 更新firewall, stratum, 关闭radius, gtpc的插件配置项 2023-11-23 12:01:15 +00:00
fumingwei
e058996dd1 refactor:delete P1403,P0804 refer config 2023-11-21 20:10:41 +08:00
liuxueli
f48651c704 上传遗漏修改的配置文件 2023-11-21 20:10:40 +08:00
liuxueli
3d6db66ef1 删除tsg_master,packet_capture_plug,tsg_vulpes,session_record,libhos-client-cpp,更新重构版本firewall 2023-11-21 20:10:39 +08:00
fumingwei
7dcf7851d3 feature:temp commit refactor firewall config 2023-11-21 20:09:00 +08:00
fumingwei
abaee156ef feature:7400,9140新增provision sip,bgp,dtls开关 2023-09-22 18:06:12 +08:00
liuxueli
61775257c9 TSG-17093: OS默认开启stat_policy_enforcer插件 2023-09-18 13:43:01 +00:00
yangwei
1b7444b1d3 feat(sapp): update to sapp-4.3.23.7f030e5
Conflicts:
	ansible/install_config/group_vars/rpm_version.yml
2023-08-25 20:44:44 +08:00
linxin
f8580d24fb TSG-16748: 在os 23.08版本中注释掉stat_policy_enforcer插件 2023-08-22 10:22:45 +08:00
liuxueli
64e6d700e0 更新stat_policy_enforcer: TSG-16619: 输出statistics_rule_hits的计数 2023-08-13 13:31:43 +00:00
liuxueli
75bb77a08d 更新sapp、tsg_master、firewall、statistics_metrics、libfieldstat4、libstatistics, 支持:
TSG-16060: 支持输出命中Statistics Policy和object的Metrics
2023-08-06 21:45:09 +08:00
yangwei
53c8a6bc7d feat(rpm and sapp.toml update): sapp.toml & mail.so
1、sapp.toml 默认polling_priority=100
2、update to mail-1.0.19.e982b44, Fix TSG-12082 and Fix TSG-11013
2023-07-12 14:50:23 +08:00
liuxueli
0ad4e347b9 修正fs2_sysinfo.metrics/fs3_sysinfo.metrics的路径 2023-07-06 13:48:03 +00:00
liuxueli
de0d5fa9d8 修正capture_packet_plug插件的部署位置 2023-07-05 20:38:21 +08:00
luwenpeng
a844427fec TSG-15732 TSG-OS适配网络浮动许可证
1.更新aksusbd驱动,并禁用开机自启
    2.更新环境变量HASPUSER_PREFIX的目录,并添加到hasp_monitor.service中
    3.HASPUSER_PREFIX目录下增加默认配置文件hasp_25743.ini
        * 注释 Admin License Manager Server Address(部署时按需配置)
        * 默认禁用广播
    4.hasp_monitor.server只有在TSG-X设备上执行开机自启
2023-06-30 11:16:55 +00:00
fumingwei
2ae5c6aaa3 bugfix:TSG-15718:修改因sapp配置文件错误导致firewall容器启动失败问题 2023-06-28 20:52:16 +08:00
刘学利
3cd287f168 更新sapp、tsg_master、quic、session_record: 2023-06-27 12:25:15 +00:00
liuchang
04f34ba72d change plugin name from session_marker_record to session_flags 2023-06-27 06:16:41 +00:00
liuxueli
1634c5bdd2 更新tsg_master、tsg_conn_sketch、app_sketch_local,修复或新增:
TSG-15317 - VoIP Records中RTP原始包缺少文件下载地址
tsg_master,app_sketch_local: 增加MAAT4的输出统计
2023-06-05 11:22:48 +00:00
fumingwei
124a06ba6a bugfix:修改配置文件笔误 2023-05-31 07:59:56 +08:00
liuxueli
0c00e277ab 更新tsg_master、firewall、tsg_conn_sketch插件,修复:
TSG-15152 - Dashboard Main下Security Policy Monitor统计数量远低于Sessioin Records对应时间范围内的统计数量
TSG-15269 - monitor rdp和monitor openvpn的策略,安全日志中有对应日志,但策略详情页log count为0
TSG-14403 - 安全策略命中allow,deny,intercept动作后,流量不会再命中Service Chaining原始流量策略
TSG-15196 - 同时设置条件一样的Security-allow和Proxy-Intercept,同时命中,优先级应Allow>Intercept
TSG-14259 - Security Events命中Intercept动作后SSL.Server Side Version、SSL.Client Side Version为空
TSG-14064 - 满足Session Records产生满足条件的流量未产生Session日志
TSG-13577 - deny-rate limit动作日志中记录的包数与策略捕包包数相差很大
TSG-14402 - 有应答的DNS协议链接误识别为Asymmetric
TSG-13319 - 双方向流量错误标注Flag:Asymmetric
TSG-14616 - Security Shunt对应流量结束30分钟后无对应策略动作统计
TSG-14580 - Security策略Shunt动作生效情况下,对应流量产生Session Records日志
TSG-14773 - Allow+IP优先级低于Shunt+IP+SSL
TSG-15232 - VoIP、GTP-C日志统计vsys不准确
2023-05-30 21:35:37 +08:00
fumingwei
b49d10c4f3 bugfix:7400和9140设备停用shaping_master,暂时不启用conusl服务 2023-04-04 17:55:54 +08:00
fumingwei
fba8e630c1 feature:新增sce功能 2023-03-01 13:30:21 +00:00
liuxueli
3b78bbade3 更新sapp、tsg_master、wire_graft、libwire_graft,修复或新增:
TSG-13844 - 7400设备内存突增导致多个服务重启出现告警
TSG-12461 - SAPP静态链接jemalloc后导致加壳失败
OMPUB-809 - 22.12版本sapp-pr硬锁无效
TSG-13942 - Session Records的Interim日志中Shaping Rule IDs为空
TSG-13294 - 安全策略条件flags+http+部分filter时,无法命中策略
TSG-13959 - 功能端支持从redis中读取是否开启Session Record的开关
TSG-13864 - 建议在Security Events中加上字段common_flags_identify_info
2023-03-01 06:27:01 +00:00
刘学利
4ed4c71f58 TSG-13817 - 安全策略DNS协议得drop动作 after_n_packets填上非0值 无效果 2023-02-16 12:28:38 +00:00
fumingwei
cceea9f706 bugfix:更新telegraf到v1.25.0,修改sapp necessary_plug_list.conf配置文件,修改/etc/consul.d目录权限 2023-02-10 05:23:13 +00:00
fumingwei
a7dbdbcf66 feature:TSG-13617:OS支持渲染shaping master的配置 2023-02-09 09:40:29 +00:00
彭宣正
4b6b3ed01c 🐞 fix(TSG-13319,TSG-13478,TSG-13511,TSG-13547,TSG-13549,TSG-13502,TSG-13622): update session_marker_record-2.0.6 to session_marker_record-2.0.9 2023-02-09 17:16:11 +08:00
fumingwei
4954768a8a feature:TSG-13307:在os中部署consul 2023-02-09 16:35:52 +08:00
fumingwei
ea6825199b feature:TSG-13632:OS支持渲染firewall的配置(整合firewall的业务插件) 2023-02-09 15:57:34 +08:00
fumingwei
ed863618c2 feature:TSG-12553:新增容器hotfix功能 2022-12-27 17:27:49 +08:00
彭宣正
8334770457 feat(TSG-12542): 新增session_marker_record插件,session_record新增common_flags 2022-12-06 17:34:53 +08:00
彭宣正
71e852ca5f 🔧 build: update conflist.conf, add fw_dtls_plug 2022-09-22 10:24:12 +08:00
fumingwei
db01424847 bugfix:修改TSG-X-P0906环境下程序的日志输出 2022-09-15 14:28:32 +08:00
liuxueli
86a61c6feb 更新:tsg_master、libmaatframe、app_sketch_local,新增:
TSG-11860 - 功能端支持匹配Tunnel Object作为策略条件,以及输出Tunnel Object信息至安全日志和过渡日志
TSG-11848 - 为适应K8S容器环境,tsg_master增加从配置文件中读入处理机IP的功能
TSG-11481 - app_sketch适配新版lua执行器接口,实现app自定义脚本支持上下文
2022-09-13 12:17:25 +08:00
fumingwei
970654f76e feature:删除tsg-x-p0906中workload.slice配置 2022-09-02 10:23:54 +08:00
fumingwei
590666a855 bugfix:删除tsg-x-p0906环境下tsg-os-provision role 2022-09-01 18:55:09 +08:00
fumingwei
391d14d471 bugfix:删除tsg-x-p-0906环境下workload.target 2022-09-01 18:55:09 +08:00
liuxueli
c099c4483b TSG-11513, TSG-11500: 暂时关闭DICTATOR内存池管理 2022-08-15 10:02:02 +08:00
刘学利
91ce6b97a1 更新: tsg_master、app_sketch_local、dns、ssl、bgp、libmaatframe、app_proto_identify, 新增或修复: 2022-08-01 09:19:40 +00:00
fumingwei
1db1146f09 feature:TSG-X-0906环境下应用fatal日志输出到标准输出 2022-07-07 15:56:10 +08:00
fumingwei
39d8f71268 feature:TSG-10783:构建vsys os镜像 2022-07-03 22:27:20 +08:00
liuxueli
358070ff2a 更新conflist.inf,增加RDP解析层的配置项 2022-05-18 17:25:09 +08:00
liuxueli
2adf6256a2 更新tsg_master、rdp、libMESA_field_stat2,新增或修复:
TSG-10110 - 功能端业务总控支持在策略日志中填充RDP协议字段
TSG-10107 - Firewall支持RDP协议解析
TSG-10617 - E现场:FieldStat2输出prometheous格式,剩余空间较小,snprintf导致内存越界
2022-05-16 11:21:32 +08:00
fumingwei
cd0376ba50 feature:TSG-10176:TSG-X-P1403继续适配centos7,新增TSG-X-P0804适配rockylinux8.5 2022-04-12 16:15:25 +08:00