Table Of Contents
Release Notes for the PIX Firewall Version 4.4(2)
Release Notes for the PIX Firewall Version 4.4(2)
October 1999
This document describes only the changes for the 4.4(2) version of the PIX Firewall software.
For information on 4.4(1) features, installation notes, limitations and restrictions, usage notes, and caveats, refer to the version 4.4(1) release notes at the following site:
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_v44/pixrn44.htm
Contents
System Requirements
The information contained in these release notes applies to all PIX Firewall hardware models running software version 4.4 or later.
Version 4.4 requires at least 16 MB of RAM (optional memory upgrades are available) and at least 2 MB of Flash memory. You can verify both of these requirements with the show version command.
Version 4.4 supports one of the following interface combinations:
•
One 4-port Ethernet card and one or two Ethernet or Token Ring cards, which can be intermixed such as a 4-port Ethernet card and two Token Ring cards
•
Up to four single-port Ethernet or Token Ring cards, either separate or intermixed
•
Two FDDI cards
Note
PIX Firewall Manager version 4.3(2)c and later works with version 4.4 but does not support the new features in version 4.4. You can view the PIX Firewall Manager version 4.3(2)c release notes online at the following site: http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_v50/pfm432c.htm
New and Changed Information
Version 4.4(2) contains bug fixes and minor enhancements to the PIX Firewall command set as described in the sections that follow.
New Commands
The sysopt noproxyarp if_name command disables sending ARP requests on an interface. This command was available in version 4.4(1), but was not documented.
Changed Commands
lists command changes in version 4.4(2).
Removed Components
No new components were removed in version 4.4(2).
Installation Notes
No new installation notes were added in version 4.4(2).
Limitations and Restrictions
No new limitations and restrictions were added in version 4.4(2).
Important Notes
The following usage notes apply to version 4.4(2):
alias Command
The translation of the inbound source address occurs before inbound filtering takes place, so a conduit command statement must refer to the DNAT IP address rather than the real foreign IP address.
For example, an alias command statement should appear in the configuration as follows:
alias (inside) 209.165.201.6 192.168.100.6 255.255.255.255The correct conduit command statement for this command is as follows:
conduit permit tcp host global_ip_address eq smtp host 209.165.201.6auth-prompt Command
The prompt string that you specify with the auth-prompt accept command appears twice when a user is authenticated. For example:
auth-prompt prompt Enter your user name and password:auth-prompt accept Success!When a user logs on, the following appears:
Enter your user name and password:User Name: usernamePassword: *******Success!Success!The repeating prompt text will be fixed in the next release.
Failover
The failover timeout command does not work in this release.
show conn Command
The show conn protocol udp command lists the DNS destination port as 1 instead of 53. For the UDP DNS service, the port field is overloaded with the ID of the request; the show conn command incorrectly returns the request ID instead of the port number.
Syslog
•
Syslog message %PIX-2-106002 is incorrectly listed in the System Log Messages for the PIX Firewall Version 4.4 guide as "TCP Connection denied by outbound list." The actual text of the message as it appears in a syslog message is "6 Connection denied by outbound list" when the message refers to TCP and "17 Connection denied by outbound list" when the message refers to UDP. All other information in the guide for this syslog message is correct.
•
Syslog message %PIX-5-304001 is incorrectly listed as %PIX-6-304001 in the System Log Messages for the PIX Firewall Version 4.4 guide. The "-5-" in the message number indicates that the message is a level 5 notification message. The incorrect number "-6-" indicated that the message was a level 6 informational message.
For more information, refer to the logging command page in Chapter 5, "Command Reference," in the Configuration Guide for the PIX Firewall Version 4.4.
TFTP
If you have an existing PIX Firewall configuration on a TFTP server and create a shorter configuration with the same filename to the TFTP server, some of the original configuration will remain after the first ":end" mark. This does not affect the PIX Firewall because the configure net command stops reading when it reaches the first ":end" mark. However, this may cause confusion when you view the configuration and see the extra text at the end of the configuration.
Caveats
This section lists resolved caveats.
Open Caveats
No new open caveats were introduced in version 4.4(2). All open caveats in version 4.4(1) still apply to version 4.4(2).
Resolved Caveats
lists resolved DDTS bug reports. All resolved caveats in version 4.4(1) apply to version 4.4(2).
Related Documentation
Use this document in conjunction with the version 4.4 PIX Firewall documentation set. You can view these documents at the following site:
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_v44/index.htm
Use also with the Release Notes for the PIX Firewall Manager Version 4.3(2)c, which applies to versions 4.3, 4.4, and 5.0. You can view this document at the following site:
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_v50/pfm432c.htm
Cisco Connection Online
Cisco Connection Online (CCO) is Cisco Systems' primary, real-time support channel. Maintenance customers and partners can self-register on CCO to obtain additional information and services.
Available 24 hours a day, 7 days a week, CCO provides a wealth of standard and value-added services to Cisco's customers and business partners. CCO services include product information, product documentation, software updates, release notes, technical tips, the Bug Navigator, configuration notes, brochures, descriptions of service offerings, and download access to public and authorized files.
CCO serves a wide variety of users through two interfaces that are updated and enhanced simultaneously: a character-based version and a multimedia version that resides on the World Wide Web (WWW). The character-based CCO supports Zmodem, Kermit, Xmodem, FTP, and Internet e-mail, and it is excellent for quick access to information over lower bandwidths. The WWW version of CCO provides richly formatted documents with photographs, figures, graphics, and video, as well as hyperlinks to related information.
You can access CCO in the following ways:
•
WWW: http://www.cisco.com
•
WWW: http://www-europe.cisco.com
•
WWW: http://www-china.cisco.com
•
Telnet: cco.cisco.com
•
Modem: From North America, 408 526-8070; from Europe, 33 1 64 46 40 82. Use the following terminal settings: VT100 emulation; databits: 8; parity: none; stop bits: 1; and connection rates up to 28.8 kbps.
For a copy of CCO's Frequently Asked Questions (FAQ), contact cco-help@cisco.com. For additional information, contact cco-team@cisco.com.
Note
If you are a network administrator and need personal technical assistance with a Cisco product that is under warranty or covered by a maintenance contract, contact Cisco's Technical Assistance Center (TAC) at 800 553-2447, 408 526-7209, or tac@cisco.com. To obtain general information about Cisco Systems, Cisco products, or upgrades, contact 800 553-6387, 408 526-7208, or cs-rep@cisco.com.
Documentation CD-ROM
Cisco documentation and additional literature are available in a CD-ROM package, which ships with your product. The Documentation CD-ROM, a member of the Cisco Connection Family, is updated monthly. Therefore, it might be more current than printed documentation. To order additional copies of the Documentation CD-ROM, contact your local sales representative or call customer service. The CD-ROM package is available as a single package or as an annual subscription. You can also access Cisco documentation on the World Wide Web at http://www.cisco.com, http://www-china.cisco.com, or http://www-europe.cisco.com.
If you are reading Cisco product documentation on the World Wide Web, you can submit comments electronically. Click Feedback in the toolbar and select Documentation. After you complete the form, click Submit to send it to Cisco. We appreciate your comments.
![]()
78-6804-02

