Release notes for update package 1741-5242

This update package improves the detection capabilities of the Forcepoint NGFW system.

RELEASE DATE:    Thursday June 20, 2024
MD5 CHECKSUM:    24a3f4563f2444d4ee7221adb8b7d415
SHA1 CHECKSUM:    a0d4485d18933a0d6a13d3ae5252ea9e800eb8e8
SHA256 CHECKSUM:    261d507d07771c9b58a04a182a68d5818a75916e6ce62bc1a242e825570d650d


UPDATE CRITICALITY:    MODERATE

MINIMUM SOFTWARE VERSIONS
- Forcepoint NGFW Security Management Center:    6.10.1.11125
- Forcepoint NGFW:    6.8.1.24103

Jump to: Other Changes

LIST OF OTHER CHANGES:

New objects:

TypeName
ApplicationMicrosoft-Defender-For-Endpoint
SituationURLList for Microsoft-Certificate-Revocation-List-Service
SituationURLList 3211315
Element RefApplication dependency from Microsoft-Defender-For-Endpoint to Microsoft-Active-Protection-Service
Element RefApplication dependency from Microsoft-Defender-For-Endpoint to Microsoft-Certificate-Revocation-List-Service
Element RefApplication dependency from Microsoft-Defender-For-Endpoint to Microsoft-Login
Element RefApplication dependency from Microsoft-Defender-For-Endpoint to Microsoft-SmartScreen
Element RefApplication dependency from Microsoft-Defender-For-Endpoint to Microsoft-Azure
Element RefApplication dependency from Microsoft-Defender-For-Endpoint to Microsoft-Windows-Push-Notification-Service
Element RefApplication dependency from Microsoft-Defender-For-Endpoint to Microsoft-Windows-Update

Updated objects:

TypeNameChanges
SituationURLList 3211294
Detection mechanism updated
SituationURL_List-DNS-Over-HTTPS
Detection mechanism updated
SituationURLList 3211276
Detection mechanism updated
IPListTOR exit nodes IP Address List
IPListAmazon AMAZON
IPListMicrosoft Azure datacenter for australiaeast
IPListTOR relay nodes IP Address List
IPListMicrosoft Azure datacenter for centralindia
IPListMicrosoft Azure datacenter for centralus
IPListMicrosoft Azure datacenter for eastus2
IPListMicrosoft Azure datacenter for eastus
IPListMicrosoft Azure datacenter for centralfrance
IPListMicrosoft Azure datacenter for japaneast
IPListMicrosoft Azure datacenter for southcentralus
IPListMicrosoft Azure datacenter for westeurope
IPListMicrosoft Azure service for AzureActiveDirectory
IPListMicrosoft Azure datacenter
IPListMalicious Site IP Address List
IPListMicrosoft Azure service for PowerPlatformPlex
IPListMicrosoft Azure service for Dynamics365BusinessCentral
IPListNordVPN Servers IP Address List
IPListAmazon AMAZON us-east-1
IPListForcepoint Drop IP Address List
IPListMicrosoft Azure service for SerialConsole
IPListMicrosoft Azure service for AzureAdvancedThreatProtection
IPListMicrosoft Azure service for AzureBotService
IPListMicrosoft Azure service for AzureCloud
IPListMicrosoft Azure service for AzureCosmosDB
IPListMicrosoft Azure service for AzureDatabricks
IPListMicrosoft Azure service for AzureDataExplorerManagement
IPListMicrosoft Azure service for AzureDigitalTwins
IPListMicrosoft Azure service for AzureKeyVault
IPListMicrosoft Azure service for AzureMonitor
IPListMicrosoft Azure service for AzureMonitor_Core
IPListMicrosoft Azure service for AzureSiteRecovery
IPListMicrosoft Azure service for GatewayManager
IPListMicrosoft Azure service for GuestAndHybridManagement
IPListMicrosoft Azure service for LogicApps
IPListMicrosoft Azure service for LogicAppsManagement
IPListMicrosoft Azure service for MicrosoftCloudAppSecurity
IPListMicrosoft Azure service for PowerQueryOnline
IPListMicrosoft Azure datacenter for qatarcentral
IPListMicrosoft Azure service for AzureSecurityCenter
IPListMicrosoft Azure service for AzureAttestation
IPListMicrosoft Azure datacenter for spaincentral
IPListMicrosoft Azure service for PowerPlatformInfra
ApplicationMicrosoft-Windows-Update
Application detection context content changed
ApplicationMicrosoft-Certificate-Revocation-List-Service
Description has changed
Application detection context content changed
ApplicationMicrosoft-SmartScreen
Application detection context content changed
Application Port "tcp/443 tls: mandatory" -> "tcp/443 tls: free"
TLS Match identification changed from true to false
ApplicationMicrosoft-Office-365
ApplicationMicrosoft-Active-Protection-Service
Description has changed
Application detection context content changed
Application Port "tcp/443 tls: mandatory" -> "tcp/443 tls: free"
ApplicationMicrosoft-Windows-Push-Notification-Service
Category tag application_group Application Routing removed
Application detection context content changed
Application Port "tcp/80 tls: no" added
ApplicationTOR
ApplicationDNS-Over-HTTPS
ApplicationCertificate-Revocation-List-Service
ApplicationNordVPN
ApplicationMicrosoft
ApplicationMicrosoft-Login
ApplicationMicrosoft-SharePoint-Online

HOW TO IMPORT AND ACTIVATE THE DYNAMIC UPDATE PACKAGE

  1. Download the dynamic update package, then make sure that the checksums for the original files and the files that you have downloaded match.
  2. In the Management Client, select Menu > File > Import > Import Update Packages.
  3. Browse to the file, select it, then click Import.
  4. Select  Configuration, then browse to Administration > Other Elements > Updates.
  5. Right-click the imported dynamic update package, then select Activate.
  6. When the activation is finished, refresh the policy on all NGFW Engines. If your policy uses a custom template, you might need to edit the policy.

DISCLAIMER AND COPYRIGHT

Copyright © 2024 Forcepoint
Forcepoint and the FORCEPOINT logo are trademarks of Forcepoint.

All other trademarks used in this document are the property of their respective owners.

Every effort has been made to ensure the accuracy of this document. However, Forcepoint makes no warranties with respect to this documentation and disclaims any implied warranties of merchantability and fitness for a particular purpose. Forcepoint shall not be liable for any error or for incidental or consequential damages in connection with the furnishing, performance, or use of this manual or the examples herein. The information in this documentation is subject to change without notice.