04 December 2015

Release Notes for Wanguard 6.1

Tags: Announcements, Changelog, Press Releases

December 4, 2015 - https://www.andrisoft.com - Andrisoft, developer of traffic monitoring and DDoS mitigation software, today announces a new major release of the Wanguard software platform.

Wanguard 6.1 brings the following new features and changes:

  • Administrators can create custom decoders that identify flows or packets sharing a particular pattern (e.g. to differentiate and classify the underlying protocols) in Configuration » General Settings » Custom Decoders.
  • New Filter mitigation options in Configuration » General Settings » Mitigation Settings:
    • TCP SYN Proxy
    • invalid TCP flags
    • invalid DNS packets
    • private/reserved IPs
    • connection oriented and connection less traffic rate-limiting
    • blacklisting by IP reputation services
    Filter can apply new filtering rules for packet payloads, countries, DNS transaction IDs. Filtering rules can be disabled, re-ordered and fine-tuned for each decoder.
  • A tighter integration between Filter and the software firewall (Netfilter/iptables framework) and Chelsio hardware filters. Newly generated anomaly reports contain pass/drop graphs for mitigated attacks.
  • Console users can create custom firewall rules in Reports » Tools » Firewall Rules.
  • New Software Firewall options in the Filter Configuration window. A new “FW Policy” field on Whitelist rules that explicitly permits traffic through the software firewall.
  • Configuration » General Settings » Anomaly Settings contains a new option for deduplicating anomalies that indicate the same attack matched by different decoders.
  • BGP Connections can be configured to allow BGP announcement withdrawals to be made after business hours.
  • Sensor graphs now use RRDCached when it is defined in Configuration » General Settings » Storage & Graphs Configuration.
  • Enhanced user authentication methods. New RADIUS options and a new HTTP authentication option.
  • Filter Clusters can be associated with other Filter Clusters.
  • The Latest Events tab from the South Region contains selectors for severity and components.
  • User role renamed Guest. Administrators can allow Guest access to Reports » Tools with greater granularity.
  • Configuration » General Settings » Anomalies renamed Anomaly Settings. Reports » Alerts & Tools renamed Tools.
  • Unattended installation when the following shell environment variables are set: WANGUARD_INSTALL_DB_USER, WANGUARD_INSTALL_DB_PASS, WANGUARD_CONSOLE_IP, WANGUARD_CONSOLE_DB_PASS.
  • Updated User Guide. Contains new Appendixes describing advanced BGP configurations.

For more information on Andrisoft Wanguard and its features, please visit https://www.andrisoft.com/software/wanguard.

To upgrade from 5.x, upgrade to 6.0 first. To upgrade from 6.0, follow the instructions listed here.

About Andrisoft

Andrisoft was founded in 2006, and since then it has maintained a strong business focus on software development, implementation and support of applications needed by Network Operation Centers. Andrisoft provides complete traffic monitoring and accounting, network protection and policy enforcement solutions for IP networks using the scalable, innovative, and high performing Wanguard software platform.

Wanguard 6.3 was released! Changelog and upgrading instructions on https://t.co/VksdOHbOHi
Follow Andrisoft on Twitter