H/OS Release Notes and History
H/OS 2.1.5.0
1/3/10, download
- New: Clustering of multiple SPG/VSP units
- New: Graphical Console (replacing the CLI)
- New: mail() function in HSL
- New: GuessAttachmentType() in HSL
- Imp: 3rd-party components updated
- Imp: Quarantine reset password, does not send a new password, instead allows it to be changed
- Imp: Overall improvements in functionality and reliability
- Imp: HSL cache [] is not LRU per default (least recently used)
- Bug: Domains were not disabled properly (nor alias domains)
- Bug: IP Policy response were not always received
- Bug: GetAttachmentName() were not decoded properly
- Bug: Self-genrated messages had the wrong Content-Disposition
- Bug: Unable to bind in queueprocessor (when custom source-ip was used)
- Bug: Domain reports could take very long time to complete
- Bug: Statistics could be collected for recipient instead of sender
- Bug: Disk, CPU and Memory usage where 24 hours off in bar-indicator
H/OS Extreme 1.4.0.5
1/3/10, download
- Bug: Resolved an issue that affected the UTM (anti-spam)
- Bug: Missing default configuration after factory reset
- Bug: Failover identification should be between 1-255
- Bug: PPTP users could not access network
- Bug: Web administration interface stopped working
- Bug: SMTP/UTM could not start
H/OS Extreme 1.4.0.4
21/1/10, download
- Bug: Resolved an issue that affected the UTM (anti-spam)
H/OS Extreme 1.4.0.3
18/1/10, download
- New: 3G/GSM modem support (with failover)
- New: Link aggregation (LACP or failover) implemented
- New: Internet failover (between two internet providers)
- New: Interface groups implemented
- New: Updating from firmware using "images"
- New: Automatic (online) updates (requires USB disk/stick)
- Imp: Throughput on multicore appliances improved
- Imp: IPSec performance improved on all appliances
- Imp: New BGP service (current BGP users need migrate)
- Imp: Improved IPv6 support for policies and NAT
- Imp: IPv6 Router Advertisement
- Imp: Many minor improvements
- Bug: Issue with preemptive failover resolved
- Bug: Issue with DNS for IPSec tunnels resolved
- Bug: Issue with UTM (realtime anti-spam) resolved
- Bug: Overall reliability improved
IMPORTANT
- Please export the configuration before updating
- DO NOT interrupt the 1.3.X to 1.4.X.X update process
- It's NOT possible to downgrade to 1.3.8
- Current BGP users SHOULD NOT upgrade without consulting us
- Supported 3G/GSM modems will be published later (E220, etc works)
H/OS 2.1.4.4
01/14/10, download
- Bug: Issue with domains without MX records resolved
- Bug: Internet Explorer 8 can now view message logs
- Bug: Exporting users can now handle invalid UTF-8 chars
H/OS 2.1.4.3
01/07/10, download
- Imp: Automatically format and use available disk (Xen and Hardware)
- Bug: Xen could not leave firmware OS
- Bug: Wrap-around long log lines in Web Administration
- Bug: Rate-control would cause random reboots
- Bug: GlobalView did not always start at boot
- Bug: Newly downloaded SpamAssassin rules were not applied until reboot
H/OS 2.1.4.2
12/22/09, download
- New: Console in Web Administration (Diagnostics > Local Console)
- New: Show licensed users in Web Administration and SOAP
- New: Access Quarantine from Web Administration
- Imp: 3rd-party components updated
- Imp: in_network() now supports IPv4 and IPv6
- Imp: dns() is now IPv6 ready, use dns4() or dns6() to choose
- Imp: Improved compability with "tag subject" and non UTF-8
- Imp: Colors in log search
- Imp: Fixed MX-shuffle (rare round-robin delivery problem)
- Imp: Delivery will only try the first three A/AAAA records
- Imp: Selecting text in Web Administration logs
- Imp: Many other improvements
- Bug: Next retry wasn't presented in the local timezone
- Bug: Rare bug while reverting between configurations
- Bug: Could not save whitelist in Internet Explorer 8
- Bug: Reload services when SSL certificate is updated
- Bug: Retention policy in Web Administration was restricted to 32-letter
- Bug: Adding one's own domains as domain alias confused quarantine
- Bug: Spelling corrections
- Bug: Overall stability fixes
H/OS 2.1.4.1
11/06/09
- Bug: Better handling of questionable SMTP responses.
- Imp: Russian and German in VSP's Getting Started.
- Imp: Spam Assassin size limited raised to 500KiB.
- Imp: Charset detection for Korean and other Asian languages.
- Bug: Scripting error for Anti-Virus block in Content Flow.
- Bug: Web Administration bug in Gettings Started for IE6/7.
- Imp: Flow blocks in IP Policy log their results.
- Bug: Japanese may now be default language in Quarantine.
- Imp: Statistic's performance is improvements.
- Imp: HSL does not resolve \$var to the value of $var.
- Imp: HSL function eval() implemented.
- Imp: Overall improvements in functionality and reliability.
H/OS 2.1.4
10/21/09
- Warning: Storage disk must be at least 2GB for all units and configurations
- Imp: Automatic initialization of new Storage disks for VSP/SPG
- Imp: Firmware updates by self hosted Web Updates
- Imp: Getting Started -guide in Console and Web Administration
- Imp: IPv6 support in Web Administration
- Imp: Keep current search in History/Queues while browsing and performing actions
- Imp: IP-address whitelist in Content-Flow
- Imp: Quarantine action "Empty" only empties the selected folder
- Imp: Japanese language support in Quarantine
- Bug: If no MX is found, try to use the A/AAAA record
- Bug: SNMP and NTP problems with reconfiguration
- Imp: 3rd party components updated
- Imp: Overall improvements in functionality and reliability
H/OS 2.1.3.2
09/08/09
- Imp: Overall improvements in functionality and reliability
H/OS 2.1.3.1
09/08/09
- Imp: Overall improvements in functionality and reliability
H/OS 2.1.3
07/10/09
- Imp: Throughput vastly improved, read the guidelines
- Imp: Option to disable internal statistics and history
- New: New HSL functions
- Imp: Overall improvements in functionality and reliability
H/OS 2.1.2
06/25/09
- New: SNMP monitoring; custom MIB with statistics and information
- Bug: Fixed Kaspersky engine error
- Imp: Truncate configuration from CLI to save memory
- Bug: Cache timeout set at execution instead of completion
- Imp: IP Policy may also block UDP packets ($protocol)
- Imp: Removed start-up related warnings
- Bug: http() function can handle more than 10 parameters
- Imp: Exceptions in Recipient Flow are reported as Defer()
- Imp: Global quarantine admin users may blacklist globally
- Imp: Blacklist handles domains and wildcard (%@domain)
- Imp: Notify senders that they are blacklisted
- Imp: Re-arranged tabs into new system menu in Web Admin.
- Bug: Redirection bug when accessing a HTTPS interface using HTTP
- Bug: Configuration upgrade for remote systems could cause timeouts
- Imp: Better transport-lookup for messages generated internally
- Imp: Mail function GetRoute() in HSL improved
- Imp: Array function array_reverse() in HSL
- Imp: Rate control function rate() in HSL
- Imp: Rate control module in Recipient and Authentication Flows
- Imp: Default message rate for authenticated users is 100 msg/h
- Imp: HSL may cache results per message/session
- Imp: Overall improvements in functionality and reliability
H/OS 2.1.1
06/03/09
- New: Advanced options on Mail Content Flow with custom rules
- Imp: Larger history (100.000 msgs.) for small disks (4 GB)
- Imp: Anti-virus and Pattern Analysis (SA) results in history
- Imp: Quarantine allows users to download messages
- Imp: Quarantine web interface scales content to browser size
- Imp: Quarantine accepts LDAP sign-in using alias as username
- Imp: Quarantine has Korean translation
- Imp: Quarantine displays outgoing queue
- Imp: Quarantine displays folder's message count on mouse over
- Imp: SPF module has trusted forwarders white-list field
- Imp: Option to reject messages with virus
- Imp: Recipient Flows reports the reason for rejection to sender
- Imp: Overall performance and reliability improved
- Bug: Quarantine now shows attachments correctly
- Bug: Delivery forced default transport during certain circumstances
- Bug: Quarantine now honors the LDAP version setting
- Bug: It is now possible to mix recipient flows with "disabled"
H/OS 2.1
05/18/09
- Imp: New Quarantine with LDAP support and Clustering
- Imp: Administrator can access the Quarantine using their credentials
- Imp: Quarantine has administrator-only folders (invisible to users)
- Imp: Reporting > Real Time Log displays Anti-Virus, LDAP, etc.
- Imp: The console's startup screen displays IP address
- Imp: FTP access requires full permissions or the "f"-flag
- Imp: Administrators cannot change their own permissions
- New: Added "null" transport (discards messages)
- Imp: VMware ESXi users need to resize the disk during install
- Imp: Added "Per Domain" for the SMTP Recipient Flow lookup module
- Bug: Trace configuration revisions changes by administrator user.
- Imp: Recipient Flows are per-domain instead of per-incoming.
- Imp: Improved queue/history management responsiveness
- Imp: Performance optimizations
- Imp: 3:rd Party Components Updated
- Imp: CLI command "version" displays appliance information
- Imp: Overall performance and reliability improved
H/OS Extreme 1.3.8
05/13/09
- Imp: Web Access Control can read policies from FTP
- Bug: Web Authentication reliability is improved
- Imp: Longer DHCP lease times possible
- Bug: Policy Routing is more tolerant to slow connections
- Imp: PPTP Proxy support 3 connections from one client
- Imp: Updating can be performed from firmware
H/OS 2.0.9
03/24/09
- New: Import Configuration from Clipboard
- Bug: Installer on Windows 2000
- Bug: Installer field validation
- Imp: Warning on VMware Configuration Import
- Imp: Repair License in Web Admin.
- Bug: History Page in Internet Explorer fixed
- Imp: Changes in terminology (Process Flow = Content Flow, etc)
- Bug: Long lines message bug fixed
- New: Implemented cache [] function();
- Bug: IP Policy cache is now cleared properly
- Imp: Web Admin. Script fields is monospace and support [tab]
- New: Added !~ (negated regular expression) matching
- Imp: Updates 3d-party libraries
- New: Caches the Incoming's smtp_rcpt_lookup
- Imp: Clear cache button (Mail Gateway -> Settings)
- Bug: Non-UTF-8 bug (Mail Gateway -> Activity)
- Imp: IP Policy performance improved
- Bug: HTTP re-configured during address change
- Imp: Removed reverse DNS lookups
- Bug: Memory storage capacity resolved
- Bug: Authentication and Recipient Flow re-configuration
- Bug: NTP producing false error messages
- Imp: Autodetect language in Web Admin.
- Imp: Mail Content Flow didn't virus-check spam messages
- Imp: Overall improvements and stability
H/OS 2.0.8
02/27/09
- Imp: Firmware Update with step-by-step guide
- Imp: VSP Installation with quick-start guide
- Imp: "Paging" in Mail Gateway Activity tabs
- New: dnstxt(), dnsmx() and implode() functions in HSL
- Bug: 500-errors handled correctly
- New: Support for alternative DNS in lookup-mx
- Bug: Handle UTF-8 in Tag Subject i Mail Flow
- New: More languages added
- Imp: Graph directions changed (left to right)
- Imp: More SMTP debugging
- New: Direct Processing gives reject function
- New: Reject() function in Mail Flow
- Imp: Set concurrent connections per Incoming (server)
- Imp: Function declaration and "include" support in HSL
- Imp: Full UTF-8 support
- Imp: Overall improvements and stability
H/OS Extreme Release 1.3.7
02/03/09
- Imp: WebAuth improvements (expiration, default group)
H/OS Extreme Release 1.3.6
01/22/09
- Imp: FTP Proxy now offers wire-speed performance
- Imp: FTP Proxy port cache improves transfer reliability
- Bug: Mobile IPSec reliability problem fixed
H/OS 2.0 Release 1.0.7.2
01/16/09
- Imp: SMTP/LDAP SMTP authentication support
- Bug: Disk Operation Stability
- Imp: Storage Management (backup and restore)
- Imp: Add multiple domains from Web Admin
- Imp: Authentication and Recipient Flows
- Imp: Many new functions added to HSL (see Wiki)
- Imp: Secure Disk Wipe from Recovery Console
- Imp: Send test mail to administrator from Web Admin
- Imp: Reset Statistics in Web Admin
- Bug: DNS/MX resolving
- Imp: Authentication in Outgoing Transports
- Imp: Preview mail in Quarantine
- Bug: Quarantine handles quoted-printable
- Bug: Quarantine reports handles quoted-printable
- Imp: Warn users when Quarantine getting full
- Imp: Scripting Testing Tool
- Imp: Searching logs indicates when showing realtime
- Imp: Custom icons for script blocks in Web Admin
- Imp: Improved anti-virus detection
- Imp: SOAP Interface improvements
- Imp: Better Default Flows
- Bug: Resolved back-to-default-config bug
H/OS Extreme Release 1.3.5
11/26/08
* Bug: Policy Routing availability bug fixed * Imp: UTM logging is not sent to queue/mail * Imp: STP can be disabled for bridges * Imp: PPTP Proxy now provides logging * Imp: netdump includes more interfaces * Imp: WINS server distribution * Bug: CLI improvement and fixes * Bug: DHCP DNS distribution bug fixed * Imp: IPSec compability improvments * Imp: DHCP relay is easier to manage * Bug: UTM whitelist now works as expected * Imp: BGP TCP-MD5 support * Imp: Assymetric load balancing features
H/OS 2.0 Release 1.0.6.2
11/25/08
- Bug: Quarantine templates
H/OS 2.0 Release 1.0.6.1
11/20/08
- Bug: Quarantine templates
H/OS 2.0 Release 1.0.6
11/12/08
- Imp: Send Domain Reports from Web Admin
- Bug: Domain Statistics reported correctly (lowercase)
- Bug: Overall Web Admin reliability
- Imp: LDAP debugging
- Imp: Mail throughput performance vastly improved
- Imp: SPF Query Tool in Web Admin
- Imp: in_network() now supports IP-ranges in HSL
- Imp: Block() may send reason for blocking in HSL
- Imp: dnsptr() to lookup PTR (ipv4 and ipv6) in HSL
- Imp: 5 s timeout for dns() request by default in HSL
- Imp: in_file() function (eg. black/white-lists) in HSL
- Imp: First comment in a Flow Script shown as title
- Imp: Customize generated e-mail
- Imp: Multiple LDAP servers on incoming listerners
- Imp: Default contact changed to "Postmaster"
- Imp: Multidimensional arrays in HSL
- Bug: Overall reliability and functionality
- Imp: Quarantine translated to Swedish and customizable
- Imp: Better default mail gateway Process Flow
H/OS 2.0 Release 1.0.5
08/21/08
- Imp: Improved quarantine with reports
- Imp: Statistics in Web Administration
- Imp: Domain reports with additional statistics
- Imp: Logging is separated and improved
- Imp: Message tracking (Activity)
- Imp: Web Administration re-organization
- Bug: Storage recovery from power failures
- Imp: Certificate tunable "Optional but Verify"
- Imp: Error messages are displayed as dialogues
- Imp: Generate SSL certificates (Diagnostics section)
- Imp: Name (tag) configuration revisions
- Imp: SOAP configuration API (using WSDL file)
- Imp: NFS replaces SMB for network storage
- Imp: Graceful shutdown and restart
- Imp: Boot procedure with progress and log
- Imp: Multidimensional arrays in HSL
- Imp: Headers are UTF-8 decoded in HSL
- Imp: GetDSN(), GetRoute(), DeliverAsSpam() in HSL
H/OS 2.0 Release 1.0.4.1
06/09/08
- Bug: Web Administration error on factory reset units
- Imp: Added German and Japanese language support
- Imp: HSL Scripting in Outgoing Queue
- Imp: Domain name variable in HSL
- Imp: WrapMessageAddHeader function added in HSL
- Imp: Revert to default config upon fatal errors
- Imp: Disable Incoming Listeners upon storage failure
- Imp: Regular Expression modifiers in HSL
- Imp: Initial Access Control Flow statistics
- Imp: Incoming Queue shows entire message
- Imp: http() and explode() functions added to HSL
- Imp: Pattern Analysis (spam assassin) module added
- Imp: LDAP testing on Diagnostics section
- Bug: Max Message Size can be increased
- Bug: Overall reliability and functionality
H/OS 2.0 Release 1.0.3
05/15/08
- Imp: Added Italian, Spanish and Korean language support
- Imp: Overall reliability improved
H/OS 2.0 Release 1.0.2
05/12 2008
- Bug: SPF calculated $spamscore incorrectly
- Imp: Reboot to Update Firmware from Web Admin.
- Bug: Removed extra newline in messages
- Bug: Database conversions could fail
- Imp: Ability to disable ACL flow for services
- Bug: NTP synchronization problem solved
- Imp: Model-specific performance optimizations
- Bug: Recovery from power failure
- Bug: Windows (SMB) share no longer fails
- Imp: Added date/time functionality to HSL
- Imp: Overall reliability improved
H/OS 2.0 Release 1.0.1
04/28 08
- Bug: Problems in the parser of the mail scanner are fixed
- Bug: Ajax problems in the mail processing flow are fixed
- Imp: New functions in HSL (Halon Scriping Language)
- Imp: UTF-8 support in HSL
- Bug: Internet Explorer and Opera support
- Imp: Overall reliability improved
H/OS Extreme Release 1.3.4
18/06 2008
Network Adapter Driver Update.
H/OS Extreme Release 1.3.3
13/06 2008
Added TLS passthrough for UTM/SMTP Proxy.
H/OS Extreme Release 1.3.2
11/06 2008
Maintenance release which add support for other vendor's IPSec, among other things.
H/OS Extreme Release 1.3.1
Maintenance release.
H/OS Extreme Release 1.3.0
We are pleased to announce a new version of H/OS, with a lot of changes and new features available such as a PPTP Proxy and "Application Policies" which will add policies in the background to ease for you.
- WebUI
- The WebUI have got an updated look and we also changed the terminology a bit, eg. "Split firewall" has been renamed to the better self-explained "Visual Filters" and "Firewall routes" has been renamed to the more widely spread "Policy Routing".
- Fallback
- Fallback is a new feature we introduce that will help you not to loose your Halon on remote due to a misconfiguration. It can be enabled under "Applications -> Control Panel -> Fallback". It requires that you "confirm" a configuration within 30 seconds or it will fallback to the latest "confirmed" configuration. If you mange your Halon through the WebUI it will be confirmed automatically, when using the CLI you must issue a "confirm" after each configuration modification within 30 seconds (repeated warnings will appear).
- UTM
- We now have moved our Halon-UTM appended headers to X-headers (X-Halon-UTM) so they will be treated correctly as extensions to the SMTP protocol.
- Policies
- Introducing Application Policies will Help you configure a service without adding obvious policies in the background, they are up for review under the "Internal Policies" in the policy listing. Application Policies are enabled by default but can be disabled under "Application Policies -> Options". Below follows a list with services which has "Application Policies".
- UTM/SMTP Service.
- UTM/POP3 Service.
- PPTP Service, the default behaviour is that all remote clients will have full access to your network when connected, this can be overridden by a DROP IN ON PPTP. And if the PPTP Proxy is enabled, you will not need to have any PPTP rules at all.
- IPSec Tunnels, policies to establish a tunnel will be created, but you will have to add policies on the tunnel interface itself before any traffic will pass.
- DNS Cache, you may want to block DNS requests incoming on ether1.
- TCP Balancer, the TCP balancer now get policies added in the background, no user added configurations is needed.
- Internal clients will be allowed to connect outging.
- This update will affect your configuration in some way as it is configured today, probably only in a way where you have duplicates of rules. And once again, if you have a PPTP Server please note that if you do not have a rule that disallows traffic in on the PPTP interface; Dial-in users will gain full access to your network, this may in some cases not be what you want.
- PPTP & PPTP Proxy
- We now include a PPTP Proxy which will help you handle multiple PPTP connections from and to the same IP. Its highly recommended that you enable this service and also enable Passthrough on ether2.
As you read above if the PPTP Proxy is enabled, you will no longer need any policies allowing PPTP, and please note that the default behaviour is that all remote clients will have full access to your network when connected, this can be overridden by a DROP IN ON PPTP. - DNS Cache
- The internal DNS Cache may now hold user defined A-records, see "Applications -> DNS Cache".
If you are unsure how this update will affect your configuration and do not have a too advanced configuration you might as well just reset the configuration and rerun the first run wizard which now also includes UTM/SMTP and activation of the PPTP Proxy.
H/OS Extreme Release 1.2.6
06/08 2007
We are pleased to announce a new version of H/OS, with many new features such as
Basic Mode and more powerful configuration options.
- FTP
- The "FTP Data" firewall service definition got changed from destination port 20 to source port 20. This is something you need to take into consideration if you're using the FTP Control (Data) service.
- The FTP Proxy service's data connections operates on port span 53000 to 53500, and two policies are added in the background. The first allows traffic from source port 20 to ports 53000 - 53500 on the firewall any port. The second allows the clients on the activated interface to connect to the firewall's proxy on port 53000-53500. This will provide a more reliable behavior, and the policies are "Keep Looking", and may therefore be overridden by your own policies.
- Policies
- The behavior for policy flows that operate over NAT (for example ether2 to ether1 where ether1 is "WAN" and uses NAT) has changed. The old behavior was to check the address/port conditions when packets were traversing the second (outgoing) interface. Since NAT changes the source address while traversing the NAT:ed (WAN) interface in the outgoing direction, the condition check usually failed, and the flow was broken. The new behavior is to ignore the conditions on the second (outgoing) interface, making it work over NAT without any disadvantages in security.
- A new visual improvement in the policy listing shows stateful, bi-directional policies between two interfaces (for example etherX <-> [halon] <-> etherY) in a new way, in two lines. The reason for this, is that the conditions are swapped depending on the direction in which the packets are traveling.
- Support for ToS (type of service) filtering is added. It is specified in the "flags" field (Firewall > Policies > New Policy > Advanced > Flags if using Advanced Mode) as "TOS:1" up to "TOS:255".
- Firewall Routes
- There is a new failsafe mode for firewall routes called Fallback. It will choose the first gateway in the list if possible, and "fail over" to the next gateway if the previous does not respond to ping.
- Unified Threat Management
- Possibility to acquire unlimited UTM domains and wild card "catch all". (requires add-on license)
- Intrusion Detection
- The intrusion detection engine now supports all Snort syntax rule-files. Therefore, it does not operate inline.
- Web Administration Interface
- A new Basic Mode has been added, referring to the old, classical, mode as Advanced. It installs default policies and NAT entries, and provides visualized, easy-to-deploy, policy and NAT items. The "NAT Wizard" is removed and replaced with a Basic Mode Wizard, which is presented as a first run dialog, if the configuration is reset.
- New "Web Tools" are included, such as an IP Calculator for netmask to bitmask conversions, and a HEX converter.
- Bridges
- Improved bridge mode for WLAN and LAN.
- VPN
- New IPSec Tunnel Mode; "Transport", for compatibility with some VPN gateways.
- MRU and MTU settings for PPTP.
H/OS Extreme Release 1.2.5
04/13 2007
- New VPN Wizard
- New packet logging features, possibility to log packet data and show derived policy
- Improved bridging
- Improved UTM logging and statistics
- New UTM reporting module
H/OS Extreme Release 1.2.4
02/20 2007
- DynDNS Client
- Multiple Administrator accounts
- New Policy listing
- FTP Proxy improvements
- Improved DHCP Handling
- Halon Remote Manager speed improvements
H/OS 1.0 Release 3.1.5
New features:
- Possibility to name unit for easier management.
- Scheduled system reports by mail containing graphs, logs, configuration and system information.
- Dynamic DNS client.
- SX-101C VPN limit raised to 50.
Improvements:
- Option to change the default ports for the internal web administration.
- Minor web administration layout and structure changes.
- Improved IDS customization, checkbox for disabling specific IDS rules.
- Better firewall logging, now back trace in log on blocked rules.
- Changed the password limit for PPTP password to 20 characters.
- CLI improvements, Virtual Addresses are now also shown in "interface view"-mode.
Bugs fixed:
- PPTP user image shown as empty the first 10 minutes after a reboot.
- Minor graphical bug when disabling/enabling firewall rules.
- Minor DHCP server bug when using DHCP on WAN.
- Proper netmask for failovers.




Reading spam costs money. See how much you can save.
Get rid of spam, right now. Try the SX (firewalling security gateways) or SPG (spam prevention) product series for free.