GB-OS FIREWALL SOFTWARE
                              VERSION 6.2.05
                              RELEASE NOTES

Author:     Global Technology Associates, Inc.
Product:    GB-OS version 6.2.05
Date:       04 January 2017

-------------------------------------------------------------------------
GB-OS version 6.2.05 includes updated versions of the following GTA
products and utilities:

    GB-OS                       6.2.05

Release notes are located on the installation CD and on GTA's Web site.

For more about upgrading related software, see individual product
release notes.

-------------------------------------------------------------------------
CONTENTS
Release Notes sections are categorized first by feature addressed, then
by the type of change.

1.  INSTALL NOTES

2.  SYSTEM

3.  SERVICES

4.  USER INTERFACE

-------------------------------------------------------------------------

1.  INSTALL NOTES

    1.1 Entering New Activation Codes
    
        If upgrading from 6.1.x or below, new activation codes must be
        entered. GB-OS version 6.2.05 is available at no charge to customers 
        with a GTA support contract or annual maintenance agreement. 
        Other users should contact their local Authorized GTA Channel Partner 
        or email sales@gta.com for information and pricing of upgrade options.

        
    1.2 Upgrade Notes   
        
        1.2.1 Upgrading to GB-OS 6.2.x
        
        Firewalls must be on GB-OS version 6.1.x or higher to properly
        upgrade to GB-OS 6.2.x. See the Upgrade Guide for more information.
              
              
        1.2.2 GB-250 Rev A Not Supported
                    
        GB-250 Rev A firewalls are NOT supported in GB-OS 6.1.0 and above.
        Determine GB-250 Rev A or Rev B by the following:
              
        1. GB-250 Rev B firewalls have USB ports while GB-250 Rev A do
           not have USB ports. 
              
        2. GB-250 Rev B firewall serial numbers are:
           Starting at S/N 65002101 and above 
           Starting at S/N 65902101 and above
        
        1.2.3 Error Messages Upon Initial Reboot
    
        Upon rebooting after successful installation, the GTA
        Firewall UTM Appliance may display errors when accessed
        using the Web interface.  This is expected, these errors are
        generated because the browser's cache is trying to access
        files and locations that no longer apply. Click OK to any
        displayed errors and refresh the browser window to access
        GB-OS 6.2.05. If the error messages persist, clear your
        browser's cache.                         
              
              
        1.2.4 Web Filtering Upgrade Notice
      
        GB-OS 6.1.3 and above includes enhancements to the Web Filtering
        category listings. The Web Filtering categories will be modified 
        when your GTA firewall is updated to GB-OS 6.2.05. Existing Web 
        Filtering categories will be automatically mapped to the enhanced 
        categories included in GB-OS 6.1.4. Please review the Content 
        Filtering Feature Guide for details on the Web Filtering 
        category mapping.
            
        GTA strongly recommends reviewing the settings for all (new and 
        automatically mapped) categories and making any necessary 
        revisions to your Web Filtering settings and policies to ensure 
        they meet your corporate Internet Access Policy.

        1.2.5 IPS Upgrade Notice

        GB-OS 6.1.10 and above include enhancements to the IPS
        categories and rules. 

        GTA strongly recommends reviewing the settings for all enabled
        IPS rules and making any necessary revisions to your IPS settings
        to ensure they meet your corporate Internet Access Policy.

        1.2.6 GB-250 no longer support IPS, Anti-spam, and Anti-virus.
                    
        GB-250 firewalls do not support IPS, Anti-spam, and Anti-virus.
               
               
    1.3 SSL Certificate Replacement

        GB-OS version 6.2.05 and above install a new default security/SSL
        certificate. Some browsers, will not recognize the new certificate if
        the original has never been replaced. If you are unable to log on to
        the firewall after upgrading, delete the browser's cached security
        certificate, then close and restart your browser before
        reattempting remote access to your firewall.


2.  SYSTEM

    2.1 Modifications 
        2.1.1   Fix issue where some GB-Ware boot very slowly.
                GBOS62050029886

        2.1.2   Add support for USB 3.0 to GB-Ware installer.
                GBOS62050029946

     2.2 Bug Fixes
        2.2.1   Support FTP servers sending closing CRLF in a separate packet.
                GBOS62050029976

3.  SERVICES
                
    3.1 Modifications 
        3.1.1   Increase BGP ASN width from 5 to 10 digits.
                GBOS62050029916

        3.1.2   Upgrade IPS engine to 2.9.0.0.
                GBOS62050029991

        3.1.3   Upgrade SSL library to 1.0.2j.
                GBOS62050029826

        3.1.4   Upgrade DHCP service to 4.3.5.
                GBOS62050029856

        3.1.5   Upgrade NTP service to 4.2.8p9.
                GBOS62050029906

        3.1.6   Upgrade DNS server to 9.10.4-p4.
                GBOS62050029851

        3.1.7   Upgrade IPSec service to 5.5.1.
                GBOS62050029881

        3.1.8   Add ability to configure TFTP filename in DHCP server.
                GBOS62050030036

    3.2 Bug Fixes
        3.2.1   Allow SSL browser to negotiate TLS 1.0 and TLS 1.1 to internal
	        servers.
                GBOS62050029817

        3.2.2   Upgrade library for talking to USB key block to better support
		USB 2.0 and 3.0.
                GBOS62050029846

        3.2.3   Fix issue with binding interface for DHCP relay not working.
                GBOS62050016836

	3.2.4   Fixed issue with group network override when configuring
		multiple networks.
                GBOS62050029806
                
4.  USER INTERFACE

    4.1 Modifications
        4.1.1   Add ability to select count for reports.
                GBOS62050029966

        4.1.2   Add checkbox to enable/disable DNSSEC with DNS proxy.
                GBOS62050029891

        4.1.3   When flushing ARP table, send gratuitous ARP for configured IPv4
		addresses.
                GBOS62050029891

        4.1.4   Reconfigure IPSec tunnels when saving encryption objects.
                GBOS62050029956

        4.1.5   Add ability to export and import historical data.
                GBOS62050029821

        4.1.6   Add "Strict-Transport-Security" and "Content-Security-Policy"
		options to HTTP header.
                GBOS62050029836

        4.1.7   Fix issue with sort table sometimes displaying alert.
                GBOS62050029841

        4.1.8   Add option to IPSec object to specify exchange mode supported
		by IPSec.
                GBOS62050029896

        4.1.9   Add IPSec object supporting Microsoft Azure.
                GBOS62050029876

        4.1.10  Add IPSec object supporting Amazon VPC AWS.
                GBOS62050029871

        4.1.11  Update ciphers used for firewall administration.
                GBOS62050029831

        4.1.12  Add "Compatibility" option to SSOauth service configuration
		to allow connecting to legacy servers.
                GBOS62050029861

        4.1.13  Add IPSEC verification warning, if using pre-shared secrets with
		aggressive mode.
                GBOS62050029861

        4.1.14  When downloading IOS remote access IPSEC configuration, use
		IKEv2 if configured.
                GBOS62050029991

        4.1.15  When downloading Linux remote access IPSec configuration, force
		phase 2 to use SHA1.
                GBOS62050029632

        4.1.16  Add user verification warning, if using EAP/XAUTH with old
		passwords.
                GBOS62050030021

        4.1.17  Add IPSec verification warning, if using IPSec object that has
		aggressive mode enabled.
                GBOS62050030026

        4.1.18  Add DNS proxy verification warning, if not using DNSSEC or
		trying to use DNSSEC with forwarders.
                GBOS62050030031

        4.1.19  Add ability to capture IPSec packets.
                GBOS62050030041

    4.2 Bug Fixes
        4.2.1   Verify certificates haven't expired.
                GBOS62050030016

        4.2.2   When switching GB-Ware video mode, correctly update MBR.
                GBOS62050030001

-------------------------------------------------------------------------
Global Technology Associates, Inc.
3361 Rouse Rd, Suite 240
Orlando, Florida 32817
www.gta.com
407.380.0220