
16 Release and Migration Notes - What´s New with Barracuda NG Firewall 5.2.3?
Custom Network Objects Based on External Sources
Starting with release version 5.2.3, the firmware provides four custom dynamic network objects to be
filled by external sources. This allows e.g. to create firewall rules that block traffic to a list of known
botnet members while this list is maintained by a third party.
With firmware release version 5.2.3, certain improvements over the initially provided custom external
input function were implemented.
With 5.2.2, this function (/opt/CustomExternalAddressImport) could only handle a hard coded
maximum of 10,000 addresses. Address content in excess of this limit were not processed. This limit
is now configurable via a new option switch, -l. If the option is not used, then the default maximum of
10,000 entries applies. The absolute maximum to be supplied using this option switch is 500,000
entries which roughly translates to a RAM usage of 10 megabytes. The input data parsing was
changed to be more robust. All non-IPv4 address related characters are not just trimmed from the
input data file but replaced by whitespace. This means that e.g. 1.1.1.1;2.2.2.2;3.3.3.3 is now
also a legitimate input format. Previously processing the input would have concatenated the addresses
into one blob as the semicolon would just have been trimmed.
Changed Semantics for Traffic Shaping
Firmware release version 5.2.3 introduces a changed Traffic Shaping nomenclature. Shaping
Connector is now called
QoS Band, Virtual Shaping Tree is now named QoS Profile. Former Templates
were renamed to
Predefined Profiles, Basic Scheme to Basic Profile in the Traffic Shaping config and the
operational GUI. Within the firewall rule set, Forward and Reverse shaping were renamed to
QoS Band
See the Barracuda NG Firewall 5.2.3 Administrator’s Guide for in-depth information on this feature.
This document is downloadable through http://barracuda.com/doc.
This feature has already previously been provided as a hotfix to firmware version 5.2.2.
Commenti su questo manuale