- Due to numerous internal changes, once you have installed a version of 3.5 on your system it is NOT recommended for you to revert to or otherwise re-apply any 3.4 (or earlier) firmware version. Doing so can cause you to lose Message Log data, message content and some historical information. Please contact Technical Support prior to any attempt to return to the 3.4 firmware series.
- Clustering between a 3.5 system and a non-3.5 system is not possible. If one of the machines in a cluster does not see the firmware as available, please contact Technical Support. All members of a cluster should be running the same build version to obtain best results.
- Before upgrading from a non-3.5 release, please take note of the following internal changes:
- As of version 3.5.10.016, all DNS queries are now done directly. This can cause delivery failures and lost mail if hostnames are used in the configuration that are only resolvable through internal DNS. If using such a configuration, after upgrading to 3.5.10.016 or higher, please go to the BASIC > IP Configuration page and set the Use Only These Servers setting to "Yes''. This will force the Barracuda Spam & Virus Firewall to use the internal DNS servers.
- As of version 3.5.12, the following configuration changes will be made on ALL SYSTEMS upgrading from a pre-3.5.12 release. Because of this, it is HIGHLY RECOMMENDED that you create a new backup of your configuration after you upgrade to firmware version 3.5.12. Otherwise, restoring a backup made from a previous firmware version could inadvertently reverse these setting changes:
- Any spamhaus.org listing for sbl, xbl, or sbl-xbl that may currently be in your Custom External RBLs section will be REMOVED. If you wish to continue using any of these, you can manually re-enter them on the BLOCK/ACCEPT > IP Reputation page. Any other spamhaus.org entry that you may have added (such as zen or pbl) will remain in your settings and will not be affected.
- The Send Bounce option will be SET TO NO on all systems, regardless of your previous setting. If you wish notifications to go out to any sender whose email was blocked, you can re-enable this option from the BASIC > Spam Scoring page, in the Spam Bounce (NDR) Configuration section.
3.5.12:
3.5.11:
3.5.10 and earlier:
Note: All systems upgrading to this release will be subjected to the configuration changes noted in the "Upgrading to Version 3.5'' section above. If you do not wish to keep these changes, they can be reversed by going to the appropriate page and re-entering your desired values. After the new firmware has been applied, make sure to create a new backup of your configuration so that you will have a backup file with the setting modifications made by this firmware upgrade.
- When mail is relayed through a Trusted Forwarder configured on the Barracuda Spam & Virus Firewall, Reverse DNS and Blocked IP/Range are not applied to connecting IP addresses (both configured on the BLOCK/ACCEPT tab).
Build 024:
Build 023:
Build 022:
Build 014:
Build 012:
Build 010:
Build 007:
Build 006:
Build 005:
Build 004:
Build 003:
Build 002:
Build 001:
- Feature: Invalid Bounce Suppression on Barracuda Spam & Virus Firewalls used for relaying outbound emails. Enabling this feature with a special password on the new "BLOCK/ACCEPT > Sender Authentication'' page will cause all incoming NDRs to be rejected by the Barracuda Spam & Virus Firewall, except those for messages that originated from itself or another Barracuda Spam & Virus Firewall that uses the same special password.
- Feature: Ability to take action on a message based on its language, or character set. Configured on the "ADVANCED > Regional Settings'' page, messages can be blocked, quarantined, or tagged on the basis of the characters detected in the message itself.
- Feature: Ability to take action on a message based on the originating country, as determined by a Reverse DNS query of the originating IP address. Configured on the new "BLOCK/ACCEPT > Reverse DNS'' page, messages can be blocked, quarantined, or tagged on the basis of the country or TLD to which the source IP address resolves.
- Feature: Ability to specify full URLs to be exempted from Intent Analysis.
- Feature: Ability to specify URL patterns that should undergo Intent Analysis.
- Feature: Ability to configure a Loopback Adapter, useful when using the Barracuda Spam & Virus Firewall with a Barracuda Load Balancer in Direct Server Return.
- Enhancement: Ability to force SMTP/TLS connections for specific domain on models that support per domain settings. [20354]
- Enhancement: Weak SSL ciphers and SSLv2 for SMTP over TLS are disabled by default. [9572]
- Enhancement: Administrators will no longer be able to add any domain listed in the Domain Manager to the list of whitelisted Sender Domains. If you regularly have incoming messages from your own domains, the IP addresses of the sending mail servers should be whitelisted rather than the domain names. [18976]
- Fix: The "Reject Fake Sender Domain'' feature was removed to avoid denial of service attempts in modern spam campaigns.
- Fix: Resolved issue that prevented a configuration backup from getting created on certain systems that did not have any Valid Recipients specified. [14649]
- Fix: Resolved issue with POP-based Single Sign-On accounts that in certain situations enabled administrator privileges to specific usernames. [11187]
- Fix: Message Log searches that include an escaped single quote will now return the expected results. [20124]
- Fix: Removed misleading "Outside Connectivity'' test from the "Test Configuration'' button. [19289]
- Fix: Resolved issue that prevented certain Japanese characters from being used in comments for certain entries. [18233]
- Fix: Removed case sensitivity from Valid Recipient listings. [20243]
- Fix: Updated various helpfiles.
Build 025:
- Note: Entries made on the Explicit Users page for native recipient verification will not be synchronized across a cluster.
- Enhancement: Increased performance of Realtime Intent Analysis.
- Enhancement: Ability to specify a port when using the SMTP Auth Proxy method for SMTP Authentication. [18027]
- Enhancement: Increase quarantine notification font size. [17937]
- Enhancement: Clarify recipient verification deferrals in the Message Log display.
- Enhancement: Support for timezone changes for Chile and Pakistan.
- Fix: Security - Resolved potential cross scripting vulnerability in the LDAP test script called from the Web GUI when no Administrator IP/Range has been configured. Discovery credited to: Information risk Management : research@irmplc.com : www.irmplc.com. Discovery date: 24 April 2008
- Fix: Resolved issue causing corruption to Bayesian tracking database that would result in immediate failure of message classification.
- Fix: Increase recipient verification resources for decreased LDAP deferrals. [16208]
- Fix - Outbound: Resolved issue preventing configuration backups for Outbound models. [15225]
Build 020:
Build 019:
Build 018:
Build 017:
Build 016:
Build 015:
Build 014:
Build 013:
Build 011:
Build 009:
Build 008 (beta):
- Feature: Ability to specify trusted forwarders that are to bypass IP address analysis (rate control, SPF sender authentication, and IP reputation tests). Full Header Scanning will now look for the mail relay not listed in the "BASIC > IP Configuration'' page that last processed the incoming message and perform IP address analysis on that mail relay only, instead of on all relays that were declared in the message headers.
- Enhancement: End-user interface is now available in Danish. [3947]
- Fix: Restored ability to use the Barracuda Spam & Virus Firewall in full Outbound mode.
- Fix: Custom logos are no longer lost upon firmware upgrade. [12440]
- Fix: Improved several filters in the Message Log including the "Reason Contains'' and "Time Range'' filters, and any searches that look for extended-ASCII characters. [14044, 14129, 14376]
- Fix: Restored handling of keywords that contain extended-ASCII characters. [13873]
- Fix: Improved protection against DOS attacks by modifying how incoming connections that exceed Rate Control settings are handled. [14136]
- Fix: Repaired the "Bulk Edit'' button. [14578]
- Fix: Improved synchronization of Bayesian databases across a cluster, particularly when initially creating a cluster. [1192]
- Fix: Restored cluster status display. [12939]
- Fix: Restored administrator ability to re-deliver messages blocked due to intent. [13595, 14185]
- Fix: Removed misleading "Configuration Updated'' message from all pages. [13473]
- Fix: Improved algorithm for detecting extensions within archives. [11266, 14560]
- Fix: Improved synchronization of messages counts across a user's Quarantine Inbox, the Quarantine Summary, and the administrator's Account View. [13762]
- Fix: Restored ability to advance one page in the Message Log. [14379]
- Fix: Restored ability to specify the SMTP/SmartHost port. [14727]
- Fix: Improved handling of encoded Subject lines. [13790]
- Fix: Strengthened compliance with PCI regulations. [14210]
- Fix: Updates to various helpfiles and UI labels.
- Fix: Updates to UI translations for various languages, including Russian, Spanish, and Japanese.
- Fix - Outbound: Restored header information in the Message Details for outbound messages. [14260]
- Fix - Outbound: Forwarding a quarantined message to a blank email address now produces the appropriate error message. [14322]
- Fix - Outbound: Restored the "Preferences'' button for the Message Log. [12842]
Build 004 (beta):
Build 002 (beta):
- Feature: Support for DomainKeys has been added. Configured on the "ADVANCED >Email Protocol'' page, settings include what action to take with a signed message that fails verification, as well as disabling this inspection method altogether.
- Feature: Native recipient verification is now available. Email recipients can be validated against a list of email addresses specified directly on the Barracuda Spam & Virus Firewall, in addition to methods such as LDAP.
- Feature: Emails retrieved from a remote email server using POP3 or IMAP can be sent through the Barracuda Spam & Virus Firewall for spam scanning prior to delivery to your local inbox. Note that this feature cannot be used when "LDAP Routing'' is enabled.
- Feature: Multiple email servers can be specified for a particular domain for load balancing and a failover email server can be designated for use whenever the destination email server for a domain is unreachable. Each entry in a list delimited by commas (",'') or semi-colons (";'') will used in round-robin fashion, with relative weights determined by the number of times a particular entry is listed. A list separated by spaces (" '') will be treated as a failover list, with an entry getting used only if all entries preceding it in the list are unreachable.
- Enhancement: Domains can be designated as aliases of another accepted domain on the Barracuda Spam & Virus Firewall, and specific email addresses can be configured as aliases to another email address.
- Enhancement: The quarantine welcome email to new users now supports HTML messages. [11004]
- Enhancement: The Energize Updates page now lists the complete timestamp (date and time) of when the definitions were generated. [9636]
- Fix: When using the SMTP authentication method "SMTP AUTH Proxy'', the Barracuda Spam & Virus Firewall will treat an unresponsive SMTP proxy server as an authentication failure. [12105]
- Fix: Improved keyword filtering for non-English phrases. [12244]
- Fix: Improved the "Score Range'' filter of the Message Log. Supported ranges now include negative values, and both the upper and lower limits are now treated as part of the search so that search results will include messages whose scores match the upper or lower limit. [12728, 13667, 13919]
- Fix: Resolved issue that made it appear as though a guest user could delete user accounts. [13163]
- Fix: Blocking attachments with the extension ".dat'' no longer blocks messages containing .pdf files. [4725]
- Fix: Blocking attachments with the extension ".exe'' no longer blocks messages containing .dll files. [6093]
- Fix: Messages that are blocked due to a Subject or Header keyword will bypass any further processing of the message body. This means that body keyword Whitelists will NOT override Subject or Header blocks. [9003]
- Fix: Messages containing unrecognized character encodings will now undergo additional processing rather than being deferred. [10799]
- Fix: An occasional problem where BCC information was revealed when viewing quarantined messages has been resolved. [11019]
- Fix: Spaces are no longer inserted on the left of each line in the source view for a message. [10790]
- Fix: Restored the quarantine usage graph in Spam Quarantine Summaries that are sent to an alternate quarantine notification address. [10002]
- Fix: Automatic backups now only start when enabled with the on/off checkbox. [10485]
- Fix: Improved calculations for the first hour of statistics in the Daily Traffic Reports. [10395]
- Fix: Less-than (<) and greater-than (>) signs are properly encoded in the Message Queue display. [9565]
- Fix: Updates to various helpfiles and UI labels. Most notably, the "ADVANCED > SSL'' page has been renamed to "Secure Administration''.
- Fix: Updated various UI translations, including Japanese, Chinese, German, and Russian. [12124]
- Fix: Outbound - Messages delivered from the Global Quarantine Inbox via the "Deliver'' link are now both delivered and removed from the inbox. [12275]
- Fix: Outbound - The 'Sender Whitelisted' column of the Message Log now reflects the current whitelist status of the sender. [8911]
Build 030:
- Fix: The "Daily Mail Statistics'' now reflect 4 weeks worth of data. [11257]
- Fix: Updates to various English and Japanese helpfiles.
- Fix: Updates to UI translations for all languages.
Build 029:
Build 027:
Build 026:
- Feature: Ability to specify trusted forwarders that are to bypass IP address analysis (rate control, SPF sender authentication, and IP reputation tests). Full Header Scanning will now look for the mail relay not listed in the "BASIC > IP Configuration > Trusted Forwarder Configuration'' section that last processed the incoming message and perform IP address analysis on that mail relay only, instead of on all relays that were declared in the message headers.
- Enhancement: Updated Outlook Plugin to version 2.1.0.9, containing expanded support for Microsoft Vista. [15469]
- Fix: When a From header includes both a quoted name and a bracketed address, the quoted name is no longer checked against sender whitelists. [10929, 11034, 13432]
- Fix: Whitelisting messages via the "Whitelist'' button no longer automatically marks the message as "Not Spam''. [13825]
- Fix: Improved the "Score Range'' filter of the Message Log. Supported ranges now include negative values, and both the upper and lower limits are now treated as part of the search so that search results will include messages whose scores match the upper or lower limit. [12728, 13667, 13919]
- Fix: Improved handling of user passwords that contain Japanese or Cyrillic Characters. [15319]
- Fix: Repaired the Top SPF Violations Report. [12241]
- Fix: Disabled unused cluster ports. [15597]
- Fix: Minor UI adjustments for alignment issues that are apparent only when using a non-English UI.
- Fix: Updates to various English and Japanese helpfiles.
- Fix: Updates to UI translations for all languages, especially Japanese.