Enhancements

This release of the product includes these enhancements.

Enhancements in Secure SD-WAN version 7.1.1

Enhancement Description
Local Sandbox - Advanced Malware Detection & Protection option
You can now configure an Advanced Malware Detection & Protection local sandbox to detect advanced threats by analyzing the behavior of files in a restricted operating system environment.
Note: You need a local Advanced Malware Detection & Protection server to use this local sandbox service.

For more information, see the Connect Secure SD-WAN to a sandbox service and the Define Sandbox Service elements sections in the Forcepoint FlexEdge Secure SD-WAN Product Guide.

Enhancements in Secure SD-WAN version 7.1

Enhancement Description
BGP Monitoring Protocol (BMP) Configuration

You can now configure BMP options from the Dynamic Routing Editor. It is used to monitor BGP sessions and send the monitored data from BGP routers to the network management entities. Also, when configured the log events includes the information for the configured options, and which in turn helps to make correlation of BMP and engine logs easy for analytics.

For more information, see Create core elements for dynamic routing, and Enable BGP on the Engine, Engine Cluster, or Virtual Engine sections in Forcepoint FlexEdge Secure SD-WAN Product Guide.

Improved Application Health Monitoring
The Application Health Monitoring feature now comes with the following support:
  • Enhanced engine monitoring and better support for non-TCP traffic, that is there is now support for health monitoring of applications that use UDP for data transport.
  • Visibility into application health history and health status history of network applications.
  • Better ISP link status monitoring.
  • Application health status history.

For more information, see Application Health Monitoring Dashboard section in Forcepoint FlexEdge Secure SD-WAN Product Guide.

Improved SD-WAN algorithms and link selection logic
The following are tuned to provide better user experience:
  • Engine logic is updated to avoid too much packet loss before the traffic is sent to the better links.
  • The QoS link value selection feature was not working as intended. The QoS link value is tuned to make QoS link value selection feature to work as intended.

Also, the Default SD-WAN Link Balancing Preference option is made available to allow you to set the preferences on how the traffic is balanced over the links for each engine.

For more information, see Create Link Usage Profile elements section in Forcepoint FlexEdge Secure SD-WAN Product Guide.

Tunnel interface now supports multiple IP addresses It is now possible to add multiple IP addresses (that can be of types IPv4 and IPv6) for tunnel interfaces.