IBM QRadar Network Security firmware version 5.4.0 release notes

IBM QRadar Network Security firmware version 5.4.0 is available. These release notes address compatibility, installation, and other getting-started issues.

Description

IBM QRadar Network Security firmware version 5.4.0 is a firmware update for the XGS NGIPS network protection platform. This release provides the following updates to IBM Security Network Protection Firmware Version 5.3.3:

New functionality:

  • X-Force Exchange (XFE) integration
    • API key and password pair authentication with XFE service.
    • Malware Analysis: Send files to XFE for analysis and view results on the Status page.
  • Multiple Administrator Accounts
    • Authenticated by Active Directory or Lightweight Directory Access Protocol (LDAP).
    • User role management:
      • Administrator role for full authorization.
      • Viewer role for read-only authorization only via Local Management Interface (LMI).
    • Access control:
      • Local Management Interface
      • Local Console
      • Secure Shell with password
      • Secure Shell using key
  • Debug filter for debug log analysis
    • New tuning parameters for debug filters.
    • Added new settings in CLI and LMI to enable/disable this feature.

Enhancements:

  • Added Intrusion Prevention license.
  • Network Intrusion Prevention license health check is now supported by the SiteProtector System.
  • Enhanced hardware failure detection, and added two failure detection events.
  • Added new capabilities for protecting against IPv6 in IPv4, and IPv4 in IPv6 tunneling.

Changed features:

  • SSH Public Key Management is integrated into Administrator Accounts.
  • Changed the product name to IBM QRadar Network Security in the documentation, tools, and on-line help.
For new and enhanced features, see technote #1998843:

Announcement

The IBM QRadar Network Security firmware version 5.4.0 announcement is available at http://www.ibm.com/common/ssi/index.wss. See the announcement for the following information:
  • Detailed product description, including a description of new functionality
  • Product-positioning statement
  • Packaging and ordering details
  • International compatibility information

Compatibility

The following web browsers are currently supported by the IBM QRadar Network Security local management interface:
  • Internet Explorer 10 or 11
  • Firefox 28 and later
  • Google Chrome 34 and later
To manage Network Security 5.4.0 appliances using the SiteProtector System, you must apply the following database service packs:
  • SiteProtector System 3.0 - Install all DBSPs up to and including SP3.0 DBSP 3.0.0.66
  • SiteProtector System 3.1.1 - Install all DBSPs up to and including SP3.1.1 DBSP 3.1.1.49

    Important: Ensure that the SiteProtector Core is at version 3.1.1.5 before applying this Database Service Pack (DBSP) update to the IBM QRadar Network Security appliance.

    To use IBM Security Network Protection Manager (NPM) 1.0, an add-on module to the SiteProtector System, to interoperate with IBM QRadar Network Security firmware version 5.4.0, you must apply the latest NPM hotfix or update. Contact IBM Support for details.

Installation and Configuration

Prior to running firmware updates on a Network Security appliance, migrate your policies in SiteProtector to the new version:
For step-by-step installation instructions, see the Installing Updates topic in the IBM Knowledge Center:

Note: After installation, clear web browser cache, cookies, and temporary internet files.

Known issues

You can find a list of known issues for IBM QRadar Network Security 5.4.0 in Technote # 1998843:

Appliance Support Lifecycle

This release does not impact the product lifecycle. For IBM Security Network Protection XGS appliance support lifecycle, see technote #1644709:

Copyright statement

© Copyright IBM® Corporation 2012, 2021. U.S. Government Users Restricted Rights - Use, duplication or disclosure restricted by GSA ADP Schedule Contract with IBM Corp.