10.5.0 Release Notes
As the CloudGen Firewall has evolved over the years with its increasing number of features, the Release Notes articles have grown accordingly. This, in turn, has also added greatly to the number of entries in the menu column.
To make the Release Notes articles easier to read, they are now equipped with support elements that provide a better overview of all sections contained while making it easier to navigate between and within these sections.
Each of these sections can be expanded and collapsed separately to show only what you are interested in. Simply click below a header line to expand or collapse a section.
|
|
|---|---|
| Note that depending on a certain release, the sections can vary both in content and number. In addition, a headline may be appended with certain symbols with the following meaning: Critical information to be considered. Important information included in the section.
Product-related information, e.g., new features, resolved bugs. Product-related information that relates to known bugs. Note that regular information boxes in blue are not explicitly marked in the headline but may still appear in a section. Each section can be expanded individually for informational or printing purposes. |
| Important Announcements and Notes for Release 10.5.0Read this section before you continue with the Release Notes below. Installation of Firmware 10.5.0IMPORTANT Before updating to firmware 10.5.0, ensure that the box identity certificates and keys are updated to the length of 2048 bit!
After updating to release 10.0.0 from 8.3.x or 9.0.0, some files from the installation are not cleaned up as expected. Updating from firmware >= 9.0.1 doesn’t cause this issue and works as expected! Encryption, Weak CiphersNOTE: As of firmware release 10.0, weak ciphers no longer support specific features for security reasons:
For more information before migrating to 10.0.0, see https://documentation.campus.barracuda.com/wiki/spaces/NGFEOL/pages/5505178.
TLS inspection no longer supports hosts with SHA-1 signed certificates! (BNNGF-99949)
The Explicit Transport Listening IP field in VPN GTI Settings now displays network addresses in CIDR instead of Phion notation. [BNNGF-99632]
Access Rules and TLSAccess rules with a user agent policy must have TLS added as additional protocol so that the policy matches properly. [BNNGF-97989]
SNMPNOTE: The SNMP value for active C2S connections is wrong. [BNNGF-94918]
End-of-Life and End-of-Support StatusFor information on which devices and services have reached EoL or EoS, see: LicensingVirtual images are now distributed with the VFC model preset by default because the VF model is deprecated! |
General and Maintenance Information for the 10.5.0 Release NotesFirmware version 10.5.0 is a major release. Before installing the new firmware version: Do not manually reboot your system at any time during the update unless otherwise instructed by Barracuda Networks Technical Support. Upgrading can take up to 60 minutes. To keep our customers informed, the history of this Release Notes article, the "Known Issues" list (at the end of this article), and the release of hotfixes resolving these known issues are now updated regularly. If there are intermediate updates to this release, the corresponding notes can be found in this info box. 10.03.2025 – Release of firmware 10.5.0 18.3.2025 – Release of Hotfix 1160 - IPS FPU state handling for CGF/SE 10.0.1 24.3.2026 – Release of Hotfix 1159 - FEC handling leads to system crash. 7.4.2026 – Release of update package including a fix for a reboot loop which occured in specific situations. 5.5.2026 - Release of Hotfix 1168 - Cumulative for CGF 10.5.0 | |
| Recommendations and Prerequisites for Running Firmware Release 10.5.0Use the Appropriate Firewall Admin ReleaseBarracuda Networks recommends using the latest version of Firewall Admin for a new firmware release. As of the public availability of firmware 10.5.0, Barracuda Networks recommends using at least Firewall Admin version 10.5.0. You can download this version here: Barracuda Firewall Admin 10.5.0-213. Who Can Update to Firmware Release 10.5.0Read the Migration Notes 10.5.0 before updating to firmware 10.5.0. For more information on the migration process, see the https://documentation.campus.barracuda.com/wiki/spaces/NGFEOL/pages/380305480. |
| Update Information for 10.5.0While new requirements can result in adding new features, existing features can become obsolete over time. To keep the CloudGen Firewall up to date and performing properly, certain features will be removed completely, and others may be replaced with improved technology. Features that Will Become Obsolete in an Upcoming Release (after 10.5)CGA Proxy The CGA Proxy will be phased out in an upcoming release. CudaLaunch & SSL-VPN CudaLaunch and SSL-VPN will be phased out in an upcoming release and will be replaced with SecureEdge Access.
Features that Are No Longer Included in this Version 10.5If you require one of the listed features, do not update to this firmware version! SF Licensing Old SF licensing is longer supported and has been phased out. Cloud Deprecations The following features are no longer part of the 10.0 firmware release:
ClamAV ClamAV has been removed in firmware 10.0. M30 Modem The M30 modem is no longer supported. OMS Agent, Azure Log Monitor Agent The OMS Agent and the Azure Log Monitor Agent has been replaced with Azure Log API. Branch Office Box VPN Compression The “BoB” Branch Office Box VPN Compression is no longer supported by release 10.0. |
| New Features in Version 10.5.0Firmware 10.5.0 is a major release. HardwareA new hardware appliance is now available under the label F2000 Rev. A. For more information, see https://documentation.campus.barracuda.com/wiki/spaces/NGFEOL/pages/419496543.
AuthenticationSecurity Group TagsThe CloudGen Firewall now supports Security Group Tags to control the flow of information in an Cisco Trusted Network in conjunction with a Identity Service Engine running pxGrid 2.0. For more information, see https://documentation.campus.barracuda.com/wiki/spaces/CGFv105/pages/379094788. Besides the main configuration, the SGT feature will show up at different locations in the user interface:
OAuth2 Authentication“Open Authorization” as an open standard for access delegation has been added as a new feature to the list of authentication schemes. For more information, see https://documentation.campus.barracuda.com/wiki/spaces/CGFv105/pages/379094783. Reporting Enhancements - Extended Firewall HistoryAs of this firmware release 10.5.0, the user is provided the option of writing the firewall’s history in extended form into a dedicated database. If this option is activated, a related button will be displayed in FIREWALL > History. For more information, see https://documentation.campus.barracuda.com/wiki/spaces/CGFv105/pages/379093673. SMTP-Authentication for NotificationsNotifications now also supports SMTP via OAuth2 (Azure Entra). For more information, see
Authentication TestYou can now perform authentication test for newly configured authentication schemes. Basically, you must first configure the authentication scheme and can then test it with real user data to be entered in the test view. You can invoke the test page at CONTROL > Box, left menu column, Authentication Test. If a new scheme is available, it will indicated by the entry Do Authentication Test. In the dialog window presented next, enter you credentials in the related input fields and click Do Test.
Barracuda Firewall AdminSingle Sign OnAs of firmware release 10.5.0, Barracuda Firewall Admin now supports Single Sign On (SSO) into the firewall. This option is available after enabling it explicitly. For more information, see https://documentation.campus.barracuda.com/wiki/spaces/CGFv105/pages/425328663. Firewall Admin SettingsThe option for Always use Session Password (recommended) has been removed at Firewall settings, Client Settings > Authentication. Extended Firewall HistoryThe firewall history view at CONFIGURATION > FIREWALL > History now provides the option of writing the view’s entries into a history database. For more information, see https://documentation.campus.barracuda.com/wiki/spaces/CGFv105/pages/379093673. Auto-Lock for Service TabsDouble-clicking on a service tab in the configuration tree while keeping the CTRL-button pressed will open the related service label in the ribbon bar and immediately put the service node into locked mode. Switching from a CC User Interface Item directly to a Related BoxBeing logged in a Control Center in the view EVENTS and being presented a full list view of events from managed boxes, you can now switch directly from an event entry to the related box: The entry is based on the template “Log in to Box <yourbox>”.
VPN-GTI EditorA new filter system has been implemented for the VPN GTI Editor. You can access and configure this filter by invoking the VPI GTI Editor on the required level (global, range, or cluster), When clicking the down-arrow on the upper-right corner, you can invoke a help-page that describes the various options of how to feed the edit line to set up a correct filter.
External FeedsThe Control Center now provides an additional option for file updates: External Feeds. External Feeds provide the option of importing IP addresses and networks into Global Firewall Objects which can then be forwarded to managed firewalls to be considered in an access rule. For more information, see https://documentation.campus.barracuda.com/wiki/spaces/CGFv105/pages/379094774.
Configuration OriginsCreating a new configuration for a Control Center or a CloudGen Firewall is usually done interactively by an administrator in Barracuda Firewall Admin. However, configurations can also be created automated by the ConfTemplate framework or by another mastering instance like in SecureEdge. The Configuration Origins feature has been implemented to enable an administrator/user to distinguish between which source controls the parameter in question. There are three sources a parameter can be configured/modified/deleted:
Indicator for Source of ControlIf a parameter is controlled by manual editing, a ‘pencil’ symbol left to the edit field will indicate this in the related configuration view. If such a parameter will be controlled by ConfTemplates, the user will see an ‘eye’ symbol instead indicating that the ConfTemplate controlled parameter is for a manual modification now in ‘read only’ mode. The same applies for a ConfTemplate managed parameter if a parameter is controlled by a SecureEdge instance. In short, the following list of priorities apples:
RESTThe REST framework has been improved at several places. Sharing Explicit Policy ProfilesShared Policies can now be created, updated, deleted, listed, and shared:
The policyType can be one of the following:
It then can be referenced on a global, range, or cluster level:
Custom ApplicationsREST API endpoints were added to create, update, delete, list and read custom applications according to these two application types: Node LockingBefore these improvements, it was necessary to lock the whole box node for editing/modification a box' subnode. As of firmware 10.5.0, now the affected node can now be locked via its REST endpoint without preventing other administrators accessing another node on the same node level of the box. RCS Messages for ConfTemplatesRCS commit messages can now be specified in the ConfTemplates REST API endpoints. Access RulesConfUnits have been updated and now support access rules.
Resetting a ConfTemplates Instance to its Originating ConfTemplateSometimes it can happen that a user wants to reset a specific ConfTemplate instance to its originating ConfTemplate. His can now performed by using the following REST API command: curl --request POST \
--url <https://<REST-API-IP>>:8443/rest/cc/v1/ranges/<range>/clusters/<cluster>/boxes/<box>/ resetToConfTemplate \
--header 'Authorization: Basic cm9vdDphOjphYWM3NzQ0M2RmNzdmNDRkMjJmZmNhMWY1ZDJiODdjMA=='
ConfTemplates ImprovementsConfTemplates Accessibility via TabThe Configuration Templates window is now being displayed as part of a ‘Tab’ in the ribbon bar. This provides a higher degree of flexibility during configuration processes so that a user can switch from the ConfTemplates view to another view related to a another tab.
Simplification of ConfTemplates ConfigurationIn the Configuration Units view, the parameter Configuration Unit Condition has been removed. Existing ConfTemplates will not be affected, the parameter will be continued to be evaluated. However, as of firmware 10.5.0, it is no longer necessary to configure this parameter. The Template Binding parameter has been removed because its relevance has been replaced by the new Configuration Origins feature.
TelemetryThe list of telemetry has been updated with new parameters: For more information, see https://documentation.campus.barracuda.com/wiki/spaces/CGFv105/pages/379094195.
|
| Resolved Bugs and Improvements in Release 10.5.0Box Installations, Installer Update
Authentication
Barracuda Firewall Admin
Barracuda OS
Cloud AWS
|