AirLink Manager (AM)/AirLink Mobility Manager (AMM) 2.17.3 is a minor release of the AirLink Manager Platform. The release is focused on security enhancements to the product after dedicated penetration testing by a certified third party. There are no new features in this release, but some known issues have been addressed.
Some of the changes made in AM/AMM 2.17.3 can have end user impact. Please refer to the product bulletin Security Improvements and Operational Impacts in AM/AMM 2.17.2.1 and 2.17.3 for further details.
These release notes are inclusive of all AMM R2.15.x+ versions.
AM/AMM 2.17.3 was officially released to General Availability on August 24, 2022.
AM/AMM 2.17.3 has been tested on Dell R250 and R650 servers and on VMware ESXi 6 and later.
AMM 2.17.3 has been tested on Google Chrome, Microsoft Edge and Firefox. Users that attempt to use a browser that is not supported will get a warning and may experience some issues.
The following table shows the minimum software version needed on the gateways to be used with AMM 2.17.3.
4.2.0-20180608.1 | 3.15.0-20180206.2 | ALEOS 4.4.9 | ALEOS 4.9.4 | ALEOS 4.11.1 | |
MG90 | ✔ | ||||
oMG2000 | ✔ | ||||
oMG500 | ✔ | ||||
LS300 | ✔ | ||||
GX400 | ✔ | ||||
GX440 | ✔ | ||||
GX450 | ✔ | ||||
ES450 | ✔ | ||||
RV (All) | ✔ | ||||
MP (All) | ✔ | ||||
LX (All) | ✔ |
Some features of AM/AMM 2.17.3 require later versions of the ALEOS or MG software.
Note: Updated Sept 20, 2022
As of AM/AMM 2.17.3, support for Calamp LMU2631CV model has been deprecated.
Reference | Problem Description |
10932 |
The “MinMemory” setting will not accept a value lower than 12 (GB). The Master Configuration script will validate the configuration but create error messages for known VMware issues and a warning if it detects the system RAM is 1G less than the value of “MinMemory”. |
10930 |
When creating a new zone and concurrently deleting the selected “Owner group” in a different tab, the zone can be still saved with the deleted group. The “Owner group” value in the zone list is blank. |
10918 |
When creating a new user/gateway and concurrently deleting the “Customer group”/“Group” in a different tab, the user/gateway can be still saved with the deleted group. The “Owner group”/“Group” value in the list is blank for that user/gateway. |
10905 |
Allow the router HFSN to have serial number where the value is 0000. |
10903 |
AM/AMM 2.17.3 will detect for clear text firewall rules on the AM/AMM upgrade and provide user messaging that directs users to make configuration changes to increase their end-to-end system security. |
10899 |
Notify users that the ’.vm’ suffix is added to KML report output file. |
10874 |
Restrict access to debug.vm to limit access to sensitive information. |
10872 |
Duplicate entries are being observed for oMG-Generic software packages on the AMM Software Repository page. |
10870 |
When checking Total Reach tab, some gateways update “Latest Connection Time” on all previously still connected devices whenever a new one connects. This leads to all devices connected to a gateway to have the same “Latest Connection Time”. |
10828 |
Increased the max client number of vsftp from 20 to 100. |
10823 |
For FTP log file upload: AMM gives an incorrect IP addresses to gateways without a management tunnel. |
10813 |
The Statistics Graph report is not displayed properly when clicking on hyperlinks from the Dashboard page. |
10775 |
To improve security of the solution, AM/AMM 2.17.3 blocks port 8082 (MSCI in clear text) by default. |
10774 |
Block port 1501 (dels) by default. |
10773 |
Groups in the node tree do not collapse after filtering gateways by group name. |
10766 |
System changes to improve CIS compliance. |
10758 |
Tomcat runs out of memory while loading generated reports during scalability testing. |
10743 |
Improvements that ensure that the AM/AMM goes through its proper shutdown procedure prior to reboot or power off to ensure that everything is left in a stable and consistent state. |
10737 |
Repeated warning message are displayed on HA configuration. |
10736 |
The ‘Configuration Audit’ report is removed in AM/AMM 2.17.3. |
10710 |
Addressed a logic error in High Availability detection of MySQL replication problems. |
10697 |
When a template was deployed to an MG90 gateway and it failed with a config sync error, the corresponding operation remained stuck in the “In progress” state instead of failing. |
10088 |
Upgraded MySQL to version 5.6.51 to address a number of identified security vulnerabilities. |
9961 |
Addressed an issue that if a template was generated from a device that only had time period/geographical region policies enabled on one of its WAN devices, then the template validation process will fail when deploying the template to a gateway. |
9841 |
Addressed an issue where the AM/AMM template deployment does not validate certain YAML files if they have keys deleted. |
9736 |
AM/AMM API improvement to make the number of concurrent requests limit configurable. |
9385 |
Addressed an issue with API monitoring where API requests with no client ID and/or user are captured in usage logs, but not displayed on AMM WebUI. |
9340 |
After installing an AM/AMM update, the High Availability feature is generating numerous security warnings that are not accurate. |
7123 |
This enhancement adds a status bar in the template editing page to display some summary information (fields that are changed) of the template, to make it easier to understand the content of the template. |
6793 |
Removed support for weak cipher in AM/AMM. |
6008 |
Improvements to the OpenVPN setup that allows for customer deployments that support both old and new routers and gateways. |
Each AMM release addresses any security vulnerabilities discovered since the previous release.
Reference | Problem Description |
10764 |
Improved the security of AM/AMM by upgrading hash function for both new and existing users password using KDF. |
10688 |
Upgraded jQuery to address known security vulnerabilities. |
10652 |
Improved the security of AM/AMM by removing services running as root. |
8924 |
Addressed an issue that allowed for Cross Site Request Forgery vulnerability in user creation with the POST method. |
Each AM/AMM release addresses any security vulnerabilities discovered since the previous release. This release addressed vulnerabilities as identified in 32 CVE tickets.
|
|
|
There are a number of known issues discovered after code freeze that will be addressed in a future AM/AMM release.
Reference | Problem Description |
10239 |
There is a known issue in how the AM/AMM calculates the amount of memory required for CSV AssetTemperature Stats Graph report. |
9398 |
At the top of the Dashboard view when a single device or several devices are selected, there is a section at the top of the right pane that describes how many devices are in the group or details on the gateway (depending on if group or gateway is selected). The group path elements are hyperlinks. Clicking on a group in the shown path should select the group on the left pane while refreshing the right pane with its gateways. However, nothing happens when those hyperlinks are clicked. |
9290 |
Special character (backslash) in a Zone name prevented Zone Maps from being displayed. Customers should avoid creating Zone names with backslashes in them. |
9273 |
There is conflicting validation/help text with the template for the QoS Rule “Destination Address” field. |
7216 |
There are directories found in /home/inmotion/ftp/MHS_logs/ with GNX device connected that should not be present. |
6523 |
Some gateways do not show up on the Dashboard in AM/AMM due to the UI pagination. Customers can change the default page size to address this issue. |
6225 |
Main Battery (“Mainbattery”) “link” on the Dashboard links to a Stats Graph report for this stat. Editing this stat causes the data to disappear. |
5718 |
The Bandwidth Consumption erroneously reports high data usage during Daylight Savings. |
4989 |
When the Stats Graph report is generated for stats whose values depend on the user’s measurement units setting (e.g. Imperial or Metric), the actual displayed units may not agree with those displayed in the graph’s title, which makes the report confusing. |