SCG 5 X Ve RN
SCG 5 X Ve RN
SCG 5 X Ve RN
A10
February 2024
Release summary
This release introduces Enterprise SONiC operating system for Dell PowerSwitch switches, ability to integrate secure connect
gateway with credential vault for remote support activities, and availability of online update for Docker and Podman containers.
Additionally, this release discontinues support for TLS 1.0 and 1.1, addresses bugs, adds compatibility with newer firmware
versions, and introduces several enhancements. See v5.22.00.18.
Release history
The following table lists the released secure connect gateway — virtual edition versions:
Release summary 1
v5.22.00.18
● Added support for Enterprise SONiC operating system for Dell PowerSwitch switches.
● Ability to integrate secure connect gateway with credential vault for remote support activities.
● Ability to enable or disable SNMP and Redfish listening services in alert delivery settings.
● Automatic deletion of Redfish subscription in iDRAC when iDRAC is deleted from secure connect gateway.
● Availability of the online update for Docker and Podman containers.
NOTE: The online update is not available for non-root, IPV6 Podman containers.
● Discontinued support for TLS 1.0 and 1.1.
● Added support for:
○ iDRAC9 firmware version 2.85.85.85 on 13th generation PowerEdge server.
○ Azure 22H2 OS 7.00.00.00 on 14th generation AX nodes.
○ Azure 22H2 OS 7.00.30.00 on 15th generation AX nodes.
○ Operating system 10.5.6.0 for S and Z series PowerSwitch switches.
○ Enterprise SONiC operating system 4.2.0 for S and Z series PowerSwitch switches.
○ OpenManage Enterprise version 4.0.
○ Red Hat Enterprise Linux versions 8.9 and 9.3 operating systems on the managed devices.
● Enhancements and bug fixes.
v5.20.00.10
● Integrated secure connect gateway with the credential vault, CyberArk with Conjur API.
● Enabled on-premise support for TLS 1.3 connections.
● Ability to schedule gateway health checks.
● Introduced the ability to bundle and download all log files for troubleshooting.
● Added support for CIFS share type in backup and restore feature.
● Added support for:
○ iDRAC9 firmware version 7.00.60.00 on 16th generation and 15th generation PowerEdge servers.
○ iDRAC9 firmware version 7.00.55.00 on C6615.
○ iDRAC9 firmware version 7.00.45.00 on R360 and T360.
○ iDRAC9 firmware version 7.00.30.00 on XE8640, XE9680, XR5610, XR8610t, and XR8620t.
○ Operating system 10.5.5.3 for S and Z series PowerSwitch switches.
○ Operating system 10.5.5.3 for N3248TE, S5448F, and Z9432F PowerSwitch switches.
○ Red Hat Enterprise Linux versions 8.7 operating system on the managed devices.
○ Dell Data Analytics Engine
● Discontinued support for NFS share type for MX7000 export and application logs.
● Enhancements and bug fixes.
● Includes the following fixes from the 5.18 Host OS patch update 10:
○ PowerScale data items API calls show as failed after secure connect gateway upgrade to version 5.18.
○ When the remote support on the Remote access tab remains unchanged or displays an incorrect value.
v5.18.00.20
● Enabled support for SNMP v3.
● Enabled a 24-hour lock period if the wrong username and password is entered in curl commands while resetting the
password for security purposes.
● Backup and restore capability to schedule and create on-demand backup of secure connect gateway system information.
● Enabled automatic clearing of data collection tasks that were unresponsive for seven days.
● Added memory partitioning for containers to avoid out-of-memory conditions.
● Added support for:
○ iDRAC9 firmware version 7.00.30.00 on 16th generation and 15th generation PowerEdge servers.
○ iDRAC9 firmware version 7.00.00.00 on 16th generation, 15th generation, and 14th generation PowerEdge servers.
○ iDRAC9 firmware version 7.00.39.00 on XE9640.
○ iDRAC9 firmware version 7.00.35.00 on C6615.
2 Release summary
○ iDRAC9 firmware version 6.10.85.00 on XR4510c and XR4520c.
○ iDRAC9 firmware version 6.10.43.00 on XR8620t.
○ iDRAC9 firmware version 6.10.39.00 on C6620, MX760c, R660, and R760.
○ iDRAC9 firmware version 6.00.49.00 on XR4510c and XR4520c.
○ Operating system 10.5.5 for S and Z series PowerSwitch switches.
○ Operating system 6.6.3.6 for PowerSwitch switch model N3224T-ON.
○ Red Hat Enterprise Linux versions 8.8, 9.1, and 9.2 operating systems on the managed devices.
○ SUSE Linux Enterprise Server 15 SP5 operating system on the managed devices.
○ Dell OpenManage Server Administrator version 11.0.1.
○ Direct liquid cooling device CHx80.
○ Port 8080 for APEX Navigator for Multicloud Storage
● Removed root access requirement for registration.
● Removed support for Skyline.
● Enhancements and bug fixes.
● Fixes available when you apply OS Patch: 10 on 5.18:
○ PowerScale data items API calls show as failed after secure connect gateway upgrade to version 5.18.
○ When the remote support on the Remote access tab remains unchanged or displays an incorrect value.
v5.16.00.14
● Support to deploy secure connect gateway using Docker, Podman, and Kubernetes containers.
● Complete support for IPV6.
● Improvements to error messages that may occur while configuring proxy server settings.
● Complete support for Dell ML3 tape libraries.
● Removed the option to enter a root password during the secure connect gateway registration.
● Added support for:
○ iDRAC9 firmware version 6.10.25.00 for XR5610 and XR7620.
○ iDRAC9 firmware version 6.10.29.05 for HS5610, HS5620, R660xs, and R760xs.
○ iDRAC9 firmware version 6.10.35.00 for XE9680.
○ iDRAC9 firmware version 6.10.39.00 for C6620.
○ iDRAC9 firmware version 6.10.47.00 for XE8640.
○ iDRAC9 firmware version 6.10.55.00 for R760xd2, R860, R960, and T560.
○ iDRAC9 firmware version 6.10.75.00 for R760xa.
○ Operating systems 10.5.3.x and 10.5.4.x for PowerSwitch switches.
○ ESXi 8.0 and Windows 2022 operating systems on managed devices.
○ Azure 22H2 OS node.
● Enhancements and bug fixes.
v5.14.00.16
● Support to enable more than one iDRAC firmware release version for various devices at once.
● Added support for:
○ iDRAC9 firmware versions 6.10.00.00 and 6.00.30.00 on 15th generation and 14th generation PowerEdge servers.
○ Firmware version GT280R010-01 for ME4.
○ Firmware version 3.40 for VRTX.
○ Firmware version 2.00.00 for MX7000.
○ OpenManage Enterprise version 3.10.
○ SLES 15 SP4 operating system on the managed devices.
● Enhancements and bug fixes.
v5.14.00.12
Bug fixes. See Issues fixed in v5.12.00.10.
Release summary 3
v5.14.00.10
● Enable or disable Dell technical support agent to remotely initiate collections on PowerEdge servers and PowerSwitch
switches.
● Enable remote access only for PowerEdge servers and PowerSwitch switches from the secure connect gateway user
interface.
NOTE: You can manually enable remote access only for PowerSwitch switches running OS 10.5.2 or lower. For
PowerSwitch switches running OS 10.5.3.x or later, remote access is automatically enabled. Also, switches running
OS 10.5.3.x or later must be added to secure connect gateway by configuring the device to connect to the Dell backend
through a secure connect gateway instance unlike switches running OS 10.5.2 or lower that must be added from the
secure connect gateway user interface.
● View the heartbeat status of the secure connect gateway virtual appliance through port 443.
● View banners on the secure connect gateway user interface to notify about new features, bug fixes, support for new device
models or firmware, and so on.
● Delete a collection from the secure connect gateway user interface manually.
● View the metadata collected during periodic collections.
● Configure secure connect gateway to collect telemetry on a weekly basis.
● Schedule the interval in which the collected telemetry must be purged.
● Information about configured witness nodes on an iDRAC is included in a collection.
● The serial number of the secure connect gateway virtual appliance is automatically populated when you select Customer
Management Station as the storage type.
● Added support for:
○ Dell OpenManage Server Administrator version 10.3.
○ Red Hat Enterprise Linux versions 8.5, 8.6, and 9.0 operating systems on the managed devices.
○ VMware ESXi 8.0 operating system on the managed devices.
○ Ubuntu 22.04 operating system on the managed devices.
○ iDRAC firmware versions 5.10.50.00 and 6.00.02.00.
○ S5000 series servers.
● Bug fixes.
v5.12.00.10
● Added support for:
○ FN410T, FN410S, and FN2210S switches.
○ iDRAC9 firmware versions 5.10.10.00 and 5.10.30.00 on 15th generation and 14th generation PowerEdge servers.
○ iDRAC8 with Lifecycle Controller version 2.83.83.83 on 13th generation PowerEdge servers.
○ Ubuntu 20.04.4 operating system on managed devices.
○ Dell ML3 tape libraries.
NOTE: Remote monitoring and service request creation capabilities are not available for Dell ML3 tape libraries.
○ OpenManage Enterprise 3.9.
● Retired support for:
○ VMware vSphere ESXi 6.0
○ Disk Library Mainframe (DLm) series 1 and 2
○ DSSD
○ VMwCloudVxRail
○ Dell EMC Symphony
○ GeoNas
○ Invista
○ PowerOne Controller
● Ability to select the client TLS protocol for outbound TLS sessions from secure connect gateway to your devices or
components, such as LDAP server, SMTP server, iDRAC devices and so on. For steps to enable inbound sessions to secure
connect gateway from devices using TLS v1.0 or v1.1, see https://www.dell.com/support/kbdoc/000190634.
● Display information about other gateways in the cluster to which the virtual appliance is associated.
● Renamed Cases to Service requests.
● User interface improvements and bug fixes.
4 Release summary
v5.10.00.10
● Display list of services and their running status and description on the Network and service connectivity page.
● Rebranded PowerVault to PowerVault MD3 and ME4.
● Receive alert and event information using Redfish protocol from iDRAC9 devices running firmware version 5.x or later.
NOTE: If Redfish protocol is disabled, SNMP protocol is used to receive the alert and event information.
● Ability to configure security certificates to securely access secure connect gateway through port 5700.
● Ability to enable common name and certificate authority checks while setting up an adapter.
● Ability to update secure connect gateway.
● Ability to collect application logs from MX7000 devices.
● Added support for:
○ OpenManage Enterprise version 3.8.2 and 3.8.3
○ XC450 and XC7525 appliances
○ Firmware version 5.00.10.20
● Retired support for the following hypervisors:
○ ESX 4.0 and 4.1 U3
○ ESXi 4.0, 4.0 U3, 4.1, 4.1 U3, 5.0, 5.0 U3, 5.1, 5.5 U1, 5.5 U2, 5.5 U3, 6.0, 6.0 U1, 6.0 U2, and 6.0 U3
○ Citrix XenServer 6.0, 6.2, 6.5, 7.0, 7.1 LTSR CU2, and 7.2
● Retired support for the following operating systems running on the local system:
○ Windows 2008 Small Business Server
○ Windows 2011 Small Business Server
○ SUSE Linux Enterprise Server 12, 12 SP1, and 12 SP2
○ Debian 8.x and 9.x
● User interface and performance enhancements.
● Bug fixes.
Compatibility
For the complete list of supported device types and device models, see the Secure Connect Gateway 5.x — Virtual Edition
Support Matrix available on the Secure Connect Gateway - Virtual Edition documentation page.
Important Notes
To collect Tech-Support logs from Enterprise SONiC operating system, select the device with Enterprise SONiC operating
system on the Devices page, and select Technical support from the Collection purpose list. If you disable collection of
identification information on the Telemetry Settings page, the Tech support logs are not collected from Enterprise SONiC
operating system.
Release summary 5
Known issues
Email notifications are not sent when SMTP is configured with
authentication
Description
When SMTP is configured with authentication, you will not receive email notifications.
Workaround
Configure SMTP without authentication.
Version affected
5.22
Tracking number
835
6 Release summary
Logout of secure connect gateway, wait for 10 minutes, login again, and click Install now on the About page.
Version affected
5.22
Tracking number
13671
Release summary 7
None
Version affected
5.12 and later
Tracking number
484
Fixes
This section provides information about the issues that were fixed in the latest and earlier releases.
8 Release summary
● 13354—you have to reset settings as you do not receive the default daily health check emails after upgrading to 5.20.
● 13424—when secure connect gateway is updated, a success message is displayed when download is still in progress and
then an error message is displayed.
Release summary 9
Issues fixed in v5.14.00.10
● 472—when you are unable to connect to the policy manager virtual appliance, you could not disable the policy manager
settings that are configured in secure connect gateway. The EsrsDigitalTwin service was always displayed in the list of
stopped services on the Dashboard page.
● 471—the Gateway status was displayed as OFF on the Dashboard page even when all the services are running and the
gateway is connected to the Global access and Enterprise servers.
● 488—for devices on which remote access is disabled, the device status was displayed as Success with warnings in place
of Success. However, when the heartbeat status is received for the device, the device status was automatically updated to
Success with warnings.
Limitations
● When you install secure connect gateway on a virtual machine with a Podman container that has McAfee anti-virus already
installed, you cannot access secure connect gateway. To access secure connect gateway, perform the following steps:
1. Stop the McAfee anti-virus services on the device.
2. Proceed with the secure connect gateway installation.
3. Restart the anti-virus services.
● Secure connect gateway does not support PowerConnect 55xx switches as the 4.x firmware contains older versions of JSch
libraries which are vulnerable to security issues.
● In the telemetry that is collected from servers running ESXi 8.0 operating system, storage information is not available.
● When you initiate a remote session on a secure connect gateway virtual appliance that is part of a cluster, information about
the remote session may be displayed on the user interface of a random virtual appliance in the cluster than on which the
session was initiated.
● When you update secure connect gateway v5.12.00.10 to v5.14.00.10, the custom security certificates that are uploaded for
port 9443 are not retained. So after the update, you must manually upload the certificates in the Certificate management
section in the Environment configuration page.
NOTE: This limitation is applicable only when you update from v5.12.00.10 to v5.14.00.10. The certificates are retained
when you update to later versions.
10 Release summary
● In the Audits tab, some devices are still displayed with their earlier name. For example, Isilon was renamed as PowerScale/
Isilon in v5.12.00.10. But, the device is displayed as Isilon in the Audits tab, whereas, it is displayed as PowerScale/Isilon on
the Devices page.
● Although a device is reachable from other systems in the same network, you may not be able to add it in secure connect
gateway. This issue occurs when the IP address of the device belongs to the network bridge IP range or docker IP range.
NOTE: The default docker IP range is 172.17*, and the default network bridge IP range is 172.18*.
If the device IP address belongs to the network bridge IP range, log in to secure connect gateway virtual appliance using root
credentials and run the following commands:
4. docker network create --driver bridge --subnet <IP address of the device>/24 sae-srs-
bridge
If the device IP address belongs to the docker IP range, log in to secure connect gateway virtual appliance using root credentials
and perform the following steps:
1. Go to /etc/docker/dockerdCfg.json.
2. Replace
{
"ip-forward" : true,
"userland-proxy" : false,
"iptables" : false,
"tls" : false,
"hosts" : ["unix:///var/run/docker.sock","tcp://0.0.0.0:2375"],
"insecure-registries" :
["127.0.0.1:9443","localhost:9443","dockerhost:9443","esrsde-app:9443"]
}
with
{
"hosts" : ["unix:///var/run/docker.sock","tcp://0.0.0.0:2375"],
"insecure-registries" : ["127.0.0.1:9443","localhost:9443"],
"bip": "<IP address of the device>/24"
}
Release summary 11
Table 2. Secure Connect Gateway resources (continued)
For more information about See Available at
Features available in secure connect User's Guide
gateway and how to use the features
List of supported devices, protocols, Support Matrix
firmware versions, and operating
systems
List of attributes that are reported in Reportable Items
the telemetry that is collected by secure
connect gateway from different device
types
New features, enhancements, known Release Notes
issues, and limitations in the release
Secure connect gateway infrastructure, Infrastructure and Alert Policy Guide
alert processing, and automatic service
request creation policies
Integrating data center tools and REST API Guide
applications with secure connect
gateway using Representational State
Transfer (REST) APIs
Troubleshooting issues that may occur Troubleshooting Guide
while using secure connect gateway
Procedural or reference information to Online Help Secure connect gateway user interface
help with using the application
Peer-to-peer questions about secure Community forum Secure Connect Gateway community
connect gateway
Video tutorials to learn about the Secure Connect Gateway Virtual Edition YouTube
features of secure connect gateway — playlist
virtual edition
12 Release summary
Notes, cautions, and warnings
NOTE: A NOTE indicates important information that helps you make better use of your product.
CAUTION: A CAUTION indicates either potential damage to hardware or loss of data and tells you how to avoid the
problem.
WARNING: A WARNING indicates a potential for property damage, personal injury, or death.
© 2022 - 2024 Dell Inc. or its subsidiaries. All rights reserved. Dell Technologies, Dell, and other trademarks are trademarks of Dell Inc. or its
subsidiaries. Other trademarks may be trademarks of their respective owners.