﻿<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>LevelBlue Knowledge Base » Knowledgebase » Legacy Products » Secure Web Gateway » Updates</title><generator>InstantKB.NET 2.0.6</generator><description>LevelBlue Knowledge Base</description><link>https://support.levelblue.com/kb/</link><webMaster>website@m86security.com</webMaster><lastBuildDate>Tue, 21 Apr 2026 19:38:04 GMT</lastBuildDate><ttl>20</ttl><item><title>Latest MHF/RHF patches for SWG v11.8.0</title><link>https://support.levelblue.com/kb/Goto20721.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul style="font-size: 10.6667px; line-height: 11.7333px;"&gt;    &lt;li style="line-height: 11.7333px;"&gt;SWG v11.8.0&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul style="font-size: 10.6667px; line-height: 11.7333px;"&gt;    &lt;li style="line-height: 11.7333px;"&gt;What are the latest MHF/RHF patches for SWG v11.8.0 ? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Information:&lt;/h2&gt;&lt;p style="line-height: 11.7333px;"&gt;&lt;span id="ctl00_ctlContentPlaceHolder_ctl00_ctlViewArticle_ctlPanelBar_lblArticleText"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;The latest patches for SWG 11.8 OS version are: &lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p style="line-height: 11.7333px;"&gt; &lt;/p&gt;&lt;p style="line-height: 11.7333px;"&gt;&lt;span style="font-size: 10px;" id="ctl00_ctlContentPlaceHolder_ctl00_ctlViewArticle_ctlPanelBar_lblArticleText"&gt;RHF#08 - &lt;span style="font-size: 10px;" id="ctl00_ctlContentPlaceHolder_ctl00_ctlViewArticle_ctlPanelBar_lblArticleText"&gt;&lt;a class="ApplyClass" href="ftp://outgoing:Mr8om21r@swgftp.trustwave.com/support/patches/11.8/RT/11.8.0.RHF08-01/swg_11_8_0_RHF08-01.fup"&gt;Runtime Hotfix #08&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="line-height: 11.7333px;"&gt;&lt;span style="font-size: 10px;" id="ctl00_ctlContentPlaceHolder_ctl00_ctlViewArticle_ctlPanelBar_lblArticleText"&gt;RHF#06 - &lt;span id="ctl00_ctlContentPlaceHolder_ctl00_ctlViewArticle_ctlPanelBar_lblArticleText" style="font-size: 10px;"&gt;&lt;a class="ApplyClass" href="ftp://outgoing:Mr8om21r@swgftp.trustwave.com/support/patches/11.8/RT/11.8.0.RHF06-02/swg_11_8_0_RHF06-02.fup"&gt;Runtime Hotfix #06&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="line-height: 11.7333px;"&gt;&lt;span style="font-size: 10px;"&gt;&lt;span id="ctl00_ctlContentPlaceHolder_ctl00_ctlViewArticle_ctlPanelBar_lblArticleText"&gt;RHF#04 - &lt;span id="ctl00_ctlContentPlaceHolder_ctl00_ctlViewArticle_ctlPanelBar_lblArticleText"&gt;&lt;a class="ApplyClass" href="ftp://outgoing:Mr8om21r@swgftp.trustwave.com/support/patches/11.8/RT/11.8.0.RHF04-01/swg_11_8_0_RHF04-01.fup"&gt;Runtime Hotfix #04&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="line-height: 11.7333px;"&gt;&lt;span style="font-size: 10px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;h2&gt;Notes:&lt;/h2&gt;&lt;p style="font-size: 10.6667px; line-height: 11.7333px;"&gt;&lt;span id="ctl00_ctlContentPlaceHolder_ctl00_ctlViewArticle_ctlPanelBar_lblArticleText"&gt;&lt;/span&gt;&lt;/p&gt;&lt;ul style="font-size: 10.6667px; line-height: 11.7333px;"&gt;    &lt;li style="line-height: 11.7333px;"&gt;These are FTP links, in some web browsers you may need to enter the username and password from the above URLs separately.&lt;/li&gt;    &lt;li style="line-height: 11.7333px;"&gt;General information about MHF/RHF patches for SWG OS is provided in KB article &lt;a href="https://support.levelblue.com/kb/KnowledgebaseArticle16782.aspx" target="_blank"&gt;Q16782&lt;/a&gt;.&lt;/li&gt;    &lt;li style="line-height: 11.7333px;"&gt;MHF/RHF patches are installed as local updates. Refer to the following KB articles for installation procedure guidelines:    &lt;ul style="line-height: 11.7333px;"&gt;        &lt;li style="line-height: 11.7333px;"&gt;&lt;a href="https://support.levelblue.com/kb/KnowledgebaseArticle13868.aspx" target="_blank"&gt;Q13868: Install local updates on SWG appliances&lt;/a&gt;&lt;/li&gt;        &lt;li style="line-height: 11.7333px;"&gt;&lt;a href="http://support.levelblue.com/kb/KnowledgebaseArticle14452.aspx" target="_blank"&gt;Q14452: .fup installation for SWG&lt;/a&gt;&lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;&lt;/ul&gt;&lt;p style="font-size: 10.6667px; line-height: 11.7333px;"&gt; &lt;/p&gt;</description><pubDate>Fri, 11 Aug 2017 17:43:10 GMT</pubDate><dc:creator>Stanislav Michailov</dc:creator></item><item><title>Version 11.5 End of Maintenance</title><link>https://support.levelblue.com/kb/Goto20730.aspx</link><description>&lt;h2 style="box-sizing: border-box; line-height: 18px; margin: 0px 0px 15px; font-size: 16px;"&gt;This article applies to:&lt;/h2&gt;&lt;ul style="box-sizing: border-box; margin-top: 0px; margin-bottom: 20px; list-style-type: square; list-style-position: outside; padding-left: 22px; padding-bottom: 3px; font-size: 10.6667px;"&gt;    &lt;li style="box-sizing: border-box;"&gt;SWG 11.5&lt;/li&gt;&lt;/ul&gt;&lt;h2 style="box-sizing: border-box; line-height: 18px; margin: 0px 0px 15px; font-size: 16px;"&gt;Information:&lt;/h2&gt;&lt;p style="box-sizing: border-box; margin: 0px 0px 15px; font-size: 10.6667px;"&gt;&lt;/p&gt;&lt;p class="MsoNormal" dir="LTR" style="box-sizing: border-box; margin: 0px 0px 15px;"&gt;The purpose of this notice is to inform you that the End of Maintenance period for Secure Web Gateway version 11.5 will be on &lt;strong&gt;October 19, 2016&lt;/strong&gt;.&lt;/p&gt;&lt;p class="MsoNormal" dir="LTR" style="box-sizing: border-box; margin: 0px 0px 15px;"&gt;To assist you in making the transition to a later, supported SWG version, we will extend the support period for an additional 6 months, until &lt;strong&gt;April 19, 2017&lt;/strong&gt; (SWG version 11.5’s End of Life). During that time, you will still receive database downloads and security patches. Once the End of Life occurs, Trustwave will stop supporting SWG Version 11.5.&lt;/p&gt;&lt;p class="MsoNormal" dir="LTR" style="box-sizing: border-box; margin: 0px 0px 15px;"&gt;To keep your Trustwave SWG Appliances up-to-date and supported, please upgrade to version 11.6, 11.7 or later. Doing so will ensure your Trustwave SWG Appliances are updated and supported. We recommend that you upgrade to our latest available version in order to enjoy our latest enhancements.&lt;/p&gt;&lt;p class="MsoNormal" dir="LTR" style="box-sizing: border-box; margin: 0px 0px 15px;"&gt;More information on the policy including definitions of key terms can be found in the &lt;a href="http://go.trustwave.com/m000cU30000qdl00FVu0RM0"&gt;Secure Web Gateway Life Cycle Support Policy&lt;/a&gt;.&lt;/p&gt;&lt;p class="MsoNormal" dir="LTR" style="box-sizing: border-box; margin: 0px 0px 15px;"&gt;The latest SWG versions and documentation can be found on the &lt;a href="http://go.trustwave.com/AV0V00RF30cqd0000l0v00M" class="ApplyClass"&gt;Secure Web Gateway product pages&lt;/a&gt;.&lt;/p&gt;&lt;p class="MsoNormal" dir="LTR" style="box-sizing: border-box; margin: 0px 0px 15px;"&gt;Please &lt;a href="http://go.trustwave.com/NF00wR0q000d0VM0Wc0003l"&gt;contact Customer Support&lt;/a&gt; if you need guidance and information on the upgrade process.&lt;/p&gt;</description><pubDate>Thu, 10 Nov 2016 11:17:36 GMT</pubDate><dc:creator>Shawn Cook</dc:creator></item><item><title>Latest MHF/RHF patches for SWG v11.7.1</title><link>https://support.levelblue.com/kb/Goto20719.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul style="font-size: 10.6667px; line-height: 11.7333px;"&gt;    &lt;li style="line-height: 11.7333px;"&gt;SWG v11.7.1&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul style="font-size: 10.6667px; line-height: 11.7333px;"&gt;    &lt;li style="line-height: 11.7333px;"&gt;What are the latest MHF/RHF patches for SWG v11.7.1 ? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Information:&lt;/h2&gt;&lt;p style="font-size: 10.6667px; line-height: 11.7333px;"&gt;The latest patches for this version of SWG are:&lt;/p&gt;&lt;p style="font-size: 10.6667px; line-height: 11.7333px;"&gt;RHF#02 - &lt;a href="ftp://outgoing:Mr8om21r@swgftp.trustwave.com/outgoing/support/patches/11.7.1/RT/11.7.1.RHF02-01/swg_11_7_1_RHF02-01.fup"&gt;Runtime Hotfix #02&lt;/a&gt;&lt;/p&gt;&lt;p style="font-size: 10.6667px; line-height: 11.7333px;"&gt;MHF#02 - &lt;a href="ftp://outgoing:Mr8om21r@swgftp.trustwave.com/outgoing/support/patches/11.7.1/MGMT/11.7.1.MHF01-01/swg_11_7_1_MHF01-01.fup" class="ApplyClass"&gt;Maintenance Hotfix #01&lt;/a&gt;&lt;/p&gt;&lt;p style="font-size: 10.6667px; line-height: 11.7333px;"&gt;&lt;span style="font-size: 10px;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;h2&gt;Notes:&lt;/h2&gt;&lt;p style="font-size: 10.6667px; line-height: 11.7333px;"&gt;&lt;span id="ctl00_ctlContentPlaceHolder_ctl00_ctlViewArticle_ctlPanelBar_lblArticleText"&gt;&lt;/span&gt;&lt;/p&gt;&lt;ul style="font-size: 10.6667px; line-height: 11.7333px;"&gt;    &lt;li style="line-height: 11.7333px;"&gt;These are FTP links, in some web browsers you may need to enter the username and password from the above URLs separately.&lt;/li&gt;    &lt;li style="line-height: 11.7333px;"&gt;General information about MHF/RHF patches for SWG OS is provided in KB article &lt;a href="https://support.levelblue.com/kb/KnowledgebaseArticle16782.aspx" target="_blank"&gt;Q16782&lt;/a&gt;.&lt;/li&gt;    &lt;li style="line-height: 11.7333px;"&gt;MHF/RHF patches are installed as local updates. Refer to the following KB articles for installation procedure guidelines:    &lt;ul style="line-height: 11.7333px;"&gt;        &lt;li style="line-height: 11.7333px;"&gt;&lt;a href="https://support.levelblue.com/kb/KnowledgebaseArticle13868.aspx" target="_blank"&gt;Q13868: Install local updates on SWG appliances&lt;/a&gt;&lt;/li&gt;        &lt;li style="line-height: 11.7333px;"&gt;&lt;a href="http://support.levelblue.com/kb/KnowledgebaseArticle14452.aspx" target="_blank"&gt;Q14452: .fup installation for SWG&lt;/a&gt;&lt;/li&gt;    &lt;/ul&gt;    &lt;/li&gt;&lt;/ul&gt;&lt;p style="font-size: 10.6667px; line-height: 11.7333px;"&gt; &lt;/p&gt;</description><pubDate>Thu, 20 Oct 2016 15:03:55 GMT</pubDate><dc:creator>Shawn Cook</dc:creator></item><item><title>How to apply hotfix for Logjam vulnerability on SWG acting as a server and a client.</title><link>https://support.levelblue.com/kb/Goto20294.aspx</link><description>&lt;h2 style="box-sizing: border-box; margin: 0px 0px 15px;"&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 13.5pt;"&gt;&lt;span style="font-family: verdana,sans-serif; font-size: 13px;"&gt;This article applies to:&lt;span style="font-weight: normal;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;ul style="list-style-type: square;"&gt;    &lt;li class="MsoNormal" style="line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;SWG 11.0&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;    &lt;li class="MsoNormal" style="line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;SWG 11.5&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;    &lt;li class="MsoNormal" style="line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;SWG 11.6&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 13.5pt;"&gt;&lt;span style="font-family: verdana,sans-serif; font-size: 13px;"&gt;Question:&lt;span style="font-weight: normal;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;ul style="list-style-type: square;"&gt;    &lt;li class="MsoNormal" style="line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;How to apply    hotfix for Logjam vulnerability on SWG acting as a server and a client.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 13.5pt;"&gt;&lt;span style="font-family: verdana,sans-serif; font-size: 13px;"&gt;Procedure:&lt;span style="font-weight: normal;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;Logjam vulnerability is related to Diffie-Hellman key exchange which allows Internet protocols such as HTTPS, SSH, IPsec, SMTPS and other that depend on TLS to agree on a shared key and negotiate a secure connection.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;Diffie-Hellmankey exchange is a cryptographic algorithm that allows Internet protocols to agree on a shared key and negotiate a secure connection. It is fundamental to many protocols including HTTPS, SSH, and protocols that rely on Transport Layer Security (TLS). &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;This hotfix addresses weaknesses in how Diffie-Hellman key exchange is deployed,which can result in a Logjam attack against the TLS protocol. The vulnerability is attributable to a flaw in the TLS protocol rather than an implementation vulnerability. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;A Logjam attack can affect any server that supports Ephemeral Diffie-Hellman export ciphers, as well as all modern web browsers. The attack allows a man-in-the-middle attacker to downgrade vulnerable TLS connections to 512-bit export-grade cryptography, enabling the attacker to read and modify any data passing over the connection.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;SWG in this case can act as Client and as Server. Please see below steps to apply the hotfix:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-size: 13px;"&gt;&lt;span style="font-family: verdana,sans-serif;"&gt;For SWG acting as a Server:&lt;/span&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;Auto hotfix (AHF) has been already released for downloading for SWG running software version v11.0,v11.5,v11.6. This patch will cause SSHd to not support Export Diffie Helman key exchange.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;Please note that our HTTPS service doesn't support EDH already therefore no change is needed.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-size: 13px;"&gt;&lt;span style="font-family: verdana,sans-serif;"&gt;For SWG acting as a Client:&lt;/span&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;After installing this hotfix, SWG will no longer support cipher suites using authenticated ephemeral Diffie-Helman (EDH) key agreements. Some websites will only negotiate TLS with this cipher, and so will no longer work. If the operation of such websites is critical, you can revert the change and allow SWG to use that cipher again. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;For this reason we created a separate patch which is not being distributed by any of SWG HotFixes (AHF,RHF,MHF).&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;This general patch disables EDH support automatically after the installation and puts additional script in case customer want to revert back the changes.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt;"&gt;&lt;span style="font-size: 13px;"&gt;&lt;span style="font-family: verdana,sans-serif;"&gt;Patch installation on SWG v11.5/11.6/11.7:&lt;/span&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-size: 13px;"&gt;&lt;span style="font-family: verdana,sans-serif;"&gt;To install this Hotfix (if you have already downloaded the Hotfix file, ignore steps 1-4): &lt;/span&gt;&lt;span style="font-family: verdana,sans-serif;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;1. Download the Hotfix from the FTP site to your local desktop ( hotfix link is also attached to this KB article). Note that you can verify the Hotfix content using the md5 utility against the md5 file from the FTP. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;2. In the Management Console, navigate to Settings &amp;gt; Updates &amp;gt; Updates Management. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;3. Click Import Updates at the lower right of the screen. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;4. In the Local Update Import window that opens, browse to the Hotfix fup file on your desktop; select it and click Upload in the window. The Hotfix will appear in the Available Updates window. If it does not appear right away, click the Refresh button. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;5. In the Available Updates window, select the Hotfix from the list and click Install Update. Once the Hotfix has been installed, it will move to the Installed Updates tab.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;During patch installation process 2 scripts will be loaded to the system:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-size: 13px;"&gt;&lt;em&gt;&lt;span style="font-family: verdana,sans-serif;"&gt;a./usr/share/perl5/update_https_module.pl&lt;/span&gt;&lt;/em&gt;&lt;span style="font-family: verdana,sans-serif;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-size: 13px;"&gt;&lt;em&gt;&lt;span lang="PL" style="font-family: verdana,sans-serif;"&gt;b ./usr/share/perl5/update_https_module_revert.pl&lt;/span&gt;&lt;/em&gt;&lt;span lang="PL" style="font-family: verdana,sans-serif;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;First script will be run automatically during the patch installation and second one will have to be run by TAC support technician as it requires root access (only when a revert is needed) .&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;A"dummy" commit after running the patch is needed to apply changes.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt;"&gt;&lt;span style="font-size: 13px;"&gt;&lt;span style="font-family: verdana,sans-serif;"&gt;Patch installation on SWG v11.0:&lt;/span&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;First of all we do recommend to upgrade to SWG 11.5 and apply the above hotfix. However if this is not possible please follow below instructions.&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;This Hotfix must be installed by the SWG administrator on top of SWG 11.0. ManagementHotfix 08-01 for SWG 11.0 must be applied before applying this hotfix. This Hotfix restarts the Scanning Server and will therefore impact user Web access for some minutes.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;Any future Management hotfixes applied to the Policy Server will revert this change. This hotfix cannot be reapplied afterwards. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;After any future migration to SWG version 11.5, the string affected by this hotfix will not be recognized and the system will downgrade to a WEAK cipher list.For each device, the Allow Weak Ciphersuites check box in Devices&amp;gt; HTTPS &amp;gt; Advanced tab will be updated automatically and should be unchecked to return to usage of strong ciphers only. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;Inaddition, Logjam Hotfix CVE-2015-4000 for SWG 11.5 must be applied after the migration to version 11.5.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-size: 13px;"&gt;&lt;span style="font-family: verdana,sans-serif;"&gt;To install this Hotfix (if you have already downloaded the Hotfix file, ignore steps 1-4): &lt;/span&gt;&lt;span style="font-family: verdana,sans-serif;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;1. For each device under Devices, select HTTPS and in the Advanced tab,uncheck the Allow Weak Ciphersuites check box. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;2. Download the Hotfix from the FTP site to your local desktop ( hotfix is also attached to this KB article). Note that you can verify the Hotfix content using the md5 utility against the md5 file from the FTP. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;3. In the Management Console, navigate to Settings &amp;gt; Updates &amp;gt; Updates Management. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;4. Click Import Updates at the lower right of the screen. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;5. In the Local Update Import window that opens, browse to the Hotfix fup file on your desktop; select it and click Upload in the window. The Hotfix will appear in the Available Updates window. If it does not appear right away, click the Refresh button. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt;6. In the Available Updates window, select the Hotfix from the list and click Install Update. Once the Hotfix has been installed, it will move to the Installed Updates tab.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif; font-size: 13px;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-bottom: 11.25pt; line-height: 8.8pt;"&gt;&lt;span style="font-size: 13px;"&gt;&lt;span style="font-weight: normal; font-family: verdana,sans-serif;"&gt; &lt;/span&gt;&lt;span style="line-height: 13.5pt; font-family: verdana,sans-serif;"&gt;Notes:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-weight: normal;"&gt;&lt;span style="font-size: 13px;"&gt;If the system must be reverted back to support EDH, contact Trustwave Support at tac@trustwave.com.&lt;/span&gt;&lt;span style="font-size: 16px;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="font-size: 16px;" class="MsoNormal"&gt;&lt;o:p style="font-weight: normal;"&gt; &lt;/o:p&gt;&lt;/p&gt;&lt;/h2&gt;&lt;p style="font-size: 10.6667px; line-height: 11.7333px; box-sizing: border-box; margin: 0px 0px 15px;"&gt;&lt;/p&gt;</description><pubDate>Thu, 25 Jun 2015 03:44:19 GMT</pubDate><dc:creator>Mariusz Cieślak</dc:creator></item><item><title>End of Maintenance for Secure Web Gateway version 10.2</title><link>https://support.levelblue.com/kb/Goto19566.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Secure Web Gateway (SWG) 10.2 &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Secure Web Gateway 10.2 End of Life&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;Dear valued SWG customer,&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;According to the Trustwave Product Support Policy, we are announcing that the End-of-Maintenance period for Secure Web Gateway version 10.2 will close on October 1, 2014.   &lt;br /&gt;&lt;br /&gt;To assist you in making the transition to a later, supported version, we will extend the support period for an additional 6 months. During that time, until the version's End-of-Life, you will receive database downloads and security patches.   &lt;br /&gt;&lt;br /&gt;We will officially stop supporting SWG version 10.2 when this timeframe expires, on April 1, 2015. To keep your Trustwave SWG Appliances up-to-date and supported, please use the remaining period to upgrade to version 11.0, 11.5 or later. (To determine which supported versions can be installed on your existing hardware, see the &lt;a href="https://support.levelblue.com/software/secure_web_gateway/manuals/HWSupportMatrixApril2015.pdf" class="ApplyClass" target="_blank"&gt;Supported Versions matrix&lt;/a&gt;.)&lt;/p&gt;&lt;p&gt;The latest SWG versions and documentation can be found on the &lt;a href="https://support.levelblue.com/secure-web-gateway" class="ApplyClass" target="_blank"&gt;Secure Web Gateway support pages&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;Please &lt;a href="https://www.trustwave.com/Company/Support/" target="_blank"&gt;contact the Technical Assistance Center&lt;/a&gt; if you need guidance and information on the upgrade process.&lt;/p&gt;</description><pubDate>Mon, 20 Apr 2015 14:57:44 GMT</pubDate><dc:creator>Charles</dc:creator></item><item><title>MHF/RHF patch, what is it and how is it installed ?</title><link>https://support.levelblue.com/kb/Goto16782.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG v10.x &lt;/li&gt;    &lt;li&gt;SWG v11.x &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;What are the differences between MHF and RHF patches ? &lt;/li&gt;    &lt;li&gt;How should these patches be installed ? &lt;/li&gt;    &lt;li&gt;Is there any specific order of installation ? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Information:&lt;/h2&gt;MHF patch is a Maintenance Hot Fix, mainly addressing issues of the Policy Server role in SWG OS.&lt;br /&gt;RHF patch is a Run-time Hot Fix, addressing issues of the Scanning Server role in SWG OS.&lt;br /&gt;&lt;br /&gt;These patches are installed as local updates, refer to below KB article for installation procedure guidelines:&lt;br /&gt;&lt;a href="https://support.levelblue.com/kb/KnowledgebaseArticle13868.aspx" class="ApplyClass" target="_blank"&gt;Q13868: Install local updates on SWG appliances&lt;/a&gt;&lt;br /&gt;&lt;a href="http://support.levelblue.com/kb/KnowledgebaseArticle14452.aspx" target="_blank"&gt;Q14452: .fup installation for SWG&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;There are no internal dependencies between MHF and RHF patches, no specific order of installation is required.&lt;br /&gt;These patches are cumulative, and newer version of MHF/RHF patch will include the libraries included in the previous version of the MHF/RHF patch, respectively.&lt;br /&gt;&lt;br /&gt;Patch usually consists of Debian libraries that are being updated from version to version, as shown below for example:&lt;br /&gt;&lt;br /&gt;&lt;img alt="" style="width: 575px; height: 104px;" src="https://support.levelblue.com/kb/Uploads/Images/SM/16782/patches.png" /&gt;&lt;br /&gt;&lt;br /&gt;The patch is always installed first on the Policy Server and then the Policy Server is responsible to update internally the scanner(s) managed by this Policy Server.&lt;br /&gt;The installation order is also similar in the case of HA Policy Server, once the patch is installed on the Active Policy Server, it will also be installed on the Backup Policy Server. &lt;br /&gt;&lt;br /&gt;Refer to the below KB articles for the links to the most recent patches for different SWG OS versions:&lt;br /&gt;SWG v10.2 - &lt;a href="https://support.levelblue.com/kb/KnowledgebaseArticle16783.aspx" class="ApplyClass" target="_blank"&gt;Q16783&lt;/a&gt;&lt;br /&gt;SWG v11.0 - &lt;a href="https://support.levelblue.com/kb/KnowledgebaseArticle16784.aspx" target="_blank"&gt;Q16784&lt;/a&gt;&lt;br /&gt;SWG v11.5 - &lt;a href="https://support.levelblue.com/kb/KnowledgebaseArticle16785.aspx" target="_blank"&gt;Q16785&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;</description><pubDate>Wed, 23 Apr 2014 15:27:23 GMT</pubDate><dc:creator>Charles</dc:creator></item><item><title>Upgrade SWG version 10.2 to version 11.0</title><link>https://support.levelblue.com/kb/Goto16108.aspx</link><description>&lt;h2&gt;&lt;/h2&gt;&lt;h2&gt;&lt;/h2&gt;&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.x&lt;/li&gt;    &lt;li&gt;SWG 11.x&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;How do I upgrade my SWG from 10.2 to 11.0?&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;p&gt;A new system has been introduced into SWG 10.2 and 11.0 to enable the download and upgrade to a new version from the Policy Server Management GUI. Follow the steps below to complete the upgrade process: &lt;/p&gt;&lt;p&gt;1. Log into your SWG Policy Server. &lt;/p&gt;&lt;p&gt;2. Navigate to &lt;strong&gt;Administration &amp;gt; Updates &amp;gt; Update Management&lt;/strong&gt;.&lt;/p&gt;&lt;p&gt;3. Click &lt;strong&gt;Install &lt;/strong&gt;on the version 11 upgrade item. If this item is not present, click &lt;strong&gt;Retrieve Updates&lt;/strong&gt;.&lt;/p&gt;&lt;p&gt;&lt;img alt="" src="https://support.levelblue.com/KB/Uploads/Images/JB/v11upgradeGuI.JPG" style="width: 600px; height: 147px;" /&gt;&lt;/p&gt;&lt;p&gt;4. The rest of the install process is automatic. &lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;To install the upgrade on scanners: &lt;/strong&gt;&lt;/p&gt;&lt;p&gt;1. Go to &lt;strong&gt;Administration &amp;gt; System Settings &amp;gt; Trustwave Devices&lt;/strong&gt;.&lt;/p&gt;&lt;p&gt;2. Right-click each relevant device and select &lt;strong&gt;Upgrade Scanners to PS Version&lt;/strong&gt;. &lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;h2&gt;Notes:&lt;/h2&gt;&lt;p&gt;The install process can take as long as 1 hour or more. During the upgrade process, GUI access can be limited or inaccessible. Allow extra time after notification that the install process is finished - back-end and other processes not visible may still be coming online and upgrading.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Important: &lt;/strong&gt;&lt;span style="text-decoration: underline;"&gt;The Upgrade will stop production scanning&lt;/span&gt;. &lt;/p&gt;</description><pubDate>Tue, 24 Sep 2013 08:28:14 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>No updates for Virtual SWG system</title><link>https://support.levelblue.com/kb/Goto15616.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;&lt;span style="line-height: 12px;"&gt;Virtual SWG 10.x&lt;/span&gt;&lt;/li&gt;    &lt;li&gt;&lt;span style="line-height: 12px;"&gt;Virtual SWG 11.x&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Symptoms:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;Updates are not installed, and no new updates are shown as available when attempting to retrieve manually.&lt;/li&gt;    &lt;li&gt;&lt;span style="line-height: 12px;"&gt;System Log shows an error on connecting with the Updates server.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Causes:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;This may happen due to the default date/time settings used for a Virtual installation - &lt;span style="line-height: 12px;"&gt;check the current date/time set on SWG to verify.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Resolution:&lt;/h2&gt;&lt;div&gt;Update the date/time settings using the config_time Limited Shell command. The best update method is to specify an NTP server, public or local.&lt;/div&gt;&lt;p&gt;&lt;/p&gt;</description><pubDate>Sun, 08 Sep 2013 07:05:56 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>SWG Support Policy Aug 2013</title><link>https://support.levelblue.com/kb/Goto16128.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;What is the Trustwave SWG support policy&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Information:&lt;/h2&gt;&lt;p&gt;See attached File&lt;/p&gt;&lt;br /&gt;</description><pubDate>Mon, 26 Aug 2013 03:18:54 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>.fup installation for SWG</title><link>https://support.levelblue.com/kb/Goto14452.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 9.x&lt;/li&gt;    &lt;li&gt;SWG 10.x&lt;/li&gt;    &lt;li&gt;SWG 11.x&lt;/li&gt;&lt;/ul&gt;&lt;span style="line-height: 12px;"&gt;&lt;div&gt;&lt;span style="line-height: 115%; font-size: 11pt; font-family: calibri, sans-serif;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="line-height: 115%; font-size: 11pt; font-family: calibri, sans-serif;"&gt;Itmay be needed to manually install an update, hotfix or patch to the SWG system. The instructions below will give you a step by step on how this is done&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;/ul&gt;    &lt;h2&gt;Procedure:&lt;/h2&gt;    &lt;p&gt;You will first need to download the patch/update to your local desktop. (This file should be provided by Trustwave support technician)&lt;/p&gt;    &lt;p&gt;In the SWG GUI, navigate to Administration -&amp;gt; Updates -&amp;gt; Update Management. Click “Import Updates” -&amp;gt; Browse your local PC and select the update/patch supplied by the Trustwave support technician. Click Import. &lt;/p&gt;    &lt;p&gt;Once the import process is finished, the file should be ready to install. In the available updates tab you should see the imported update/patch ready to install, click the icon and then click install. &lt;/p&gt;    &lt;div&gt;&lt;img alt="" src="https://support.levelblue.com/KB/Uploads/Images/JB/Capture.PNG" style="width: 485px; height: 258px;" /&gt;&lt;br /&gt;    &lt;/div&gt;    &lt;div&gt;&lt;br /&gt;    &lt;/div&gt;    &lt;div&gt;    &lt;p class="MsoNoSpacing"&gt;Once the install begins you should see an install screen.&lt;/p&gt;    &lt;p class="MsoNoSpacing"&gt;&lt;img alt="" src="https://support.levelblue.com/kb/Uploads/Images/JB/12-30-20011/fup%20installation%20for%20SWGstatuspage2.png" /&gt;&lt;/p&gt;    &lt;p class="MsoNoSpacing"&gt;&lt;/p&gt;    &lt;p class="MsoNoSpacing"&gt;Wait for the install to finish then click “Redirect to Login Page”.  The installation should be complete and the update/patch is now installed. &lt;/p&gt;    &lt;p class="MsoNoSpacing"&gt;&lt;/p&gt;    &lt;div&gt;&lt;br /&gt;    &lt;/div&gt;    &lt;p&gt;&lt;/p&gt;    &lt;/div&gt;    &lt;div&gt;&lt;br /&gt;    &lt;/div&gt;    &lt;h2&gt;Notes:&lt;/h2&gt;    &lt;p&gt;Manual Updates like these will cause certain processes to restart on the SWG; this may interrupt scanning in a production environment. It’s recommended to install an update or patch during a maintenance window where it’s appropriate for the system to go down. &lt;/p&gt;</description><pubDate>Fri, 23 Aug 2013 04:37:48 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>Install local updates on SWG appliances</title><link>https://support.levelblue.com/kb/Goto13868.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.x &lt;/li&gt;    &lt;li&gt;SWG 11.x &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;What is the procedure for installing a local update file on a Secure Web Gateway (SWG) appliance? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Reply:&lt;/h2&gt;&lt;p&gt;Patches, fixes and software updates for Secure Web Gateway appliances are released periodically. &lt;br /&gt;Patches typically address specific issues and are initially released as standalone packages before they are included in a general maintenance update. This article describes how to install any .fup patch or update.&lt;/p&gt;&lt;ol&gt;    &lt;li&gt;Download the update package as instructed by support personnel and save it locally on your desktop. &lt;/li&gt;    &lt;li&gt;Navigate to &lt;strong&gt;Administration&lt;/strong&gt; &lt;strong&gt;&amp;gt;&lt;/strong&gt; &lt;strong&gt;Updates and Upgrades&lt;/strong&gt; &lt;strong&gt;&amp;gt;&lt;/strong&gt; &lt;strong&gt;Management&lt;/strong&gt;.&lt;br /&gt;    &lt;img alt="" style="width: 600px; height: 277px;" src="https://support.levelblue.com/KB/Uploads/Images/SM/13868/01.PNG" /&gt; &lt;/li&gt;    &lt;li&gt;In the Available Updates tab, click &lt;strong&gt;Import Updates&lt;/strong&gt; .&lt;br /&gt;    &lt;br /&gt;    &lt;img alt="" style="width: 600px; height: 324px;" src="https://support.levelblue.com/KB/Uploads/Images/SM/13868/02.PNG" /&gt; &lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Browse&lt;/strong&gt; to the update location on the local machine and click the &lt;strong&gt;Import&lt;/strong&gt; button.&lt;br /&gt;    &lt;br /&gt;    &lt;img alt="" style="width: 600px; height: 322px;" src="https://support.levelblue.com/KB/Uploads/Images/SM/13868/03.png" /&gt; &lt;/li&gt;    &lt;li&gt;Wait for the upload process to complete.&lt;br /&gt;    The amount of time will vary depending on the size of the update and the speed of the connection to the Policy Server.  &lt;br /&gt;    Make sure that the required update package appears in the list of available updates.  &lt;br /&gt;    It may be necessary to click the &lt;strong&gt;Refresh&lt;/strong&gt; button in order to update the list.&lt;br /&gt;    &lt;br /&gt;    &lt;img alt="" style="width: 600px; height: 273px;" src="https://support.levelblue.com/KB/Uploads/Images/SM/13868/04.PNG" /&gt; &lt;/li&gt;    &lt;li&gt;&lt;span style="line-height: 12px; font-size: 11px;"&gt;To see more information about the update, click the &lt;strong&gt;+&lt;/strong&gt; icon next to the update row and click the Release Notes link in the detailed description.&lt;/span&gt; &lt;/li&gt;    &lt;li&gt;Click the required update and choose the &lt;strong&gt;Install Now&lt;/strong&gt; option.&lt;br /&gt;    &lt;br /&gt;    &lt;img alt="" style="width: 600px; height: 270px;" src="https://support.levelblue.com/KB/Uploads/Images/SM/13868/05.png" /&gt; &lt;/li&gt;&lt;/ol&gt;</description><pubDate>Fri, 09 Aug 2013 01:53:28 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>What is the procedure to follow if updates fail to install?</title><link>https://support.levelblue.com/kb/Goto15992.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.x &lt;/li&gt;    &lt;li&gt;SWG 11.x &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;What is the procedure to follow if all updates fail to install: Requests to https://mirror.updateng.finjan.com/updates return 500 (Connect failed: connect: Connection timed out; Connection timed out) &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Reply:&lt;/h2&gt;&lt;p&gt;1. Try to ping &lt;span style="line-height: 12px;"&gt;mirror.updateng.finjan.com and see if it resolves.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 12px;"&gt;2. Check &lt;/span&gt;&lt;a href="http://www.whatsmydns.net/#A/mirror.updateng.finjan.com" style="line-height: 18px; font-size: 8pt;"&gt;http://www.whatsmydns.net/#A/mirror.updateng.finjan.com&lt;/a&gt; to see if there is a worldwide problem, and try to ping the various IPs of &lt;span style="line-height: 12px;"&gt;mirror.updateng.finjan.com&lt;/span&gt;&lt;/p&gt;&lt;p&gt;3. If you are running Version 11.x and behind a proxy, make sure you have installed MHF01 or higher.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size: 8pt;"&gt;It is probable that your firewall blocks &lt;/span&gt;&lt;span style="font-size: 8pt;"&gt;mirror.updateng.finjan.com. Check your firewall and open port 443 to &lt;/span&gt;&lt;span style="line-height: normal;"&gt;[1] &lt;/span&gt;&lt;strong style="font-size: 8pt; line-height: normal;"&gt;updateng.finjan.com&lt;/strong&gt;&lt;span style="line-height: normal;"&gt; and [2] &lt;/span&gt;&lt;strong style="font-size: 8pt; line-height: normal;"&gt;mirror.&lt;span style="line-height: 12px;"&gt;updateng.finjan.com&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description><pubDate>Mon, 08 Jul 2013 02:43:50 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>How do changes to cloud configuration get passed to the Mobile Security Client (MSC)?</title><link>https://support.levelblue.com/kb/Goto15933.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 10.x&lt;/li&gt;    &lt;li&gt;SWG 11.x &lt;/li&gt;    &lt;li&gt;MSC 2.0 &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;After making changes to cloud configuration (like proxy port numbers), how does the update get passed to the MSC? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Reply:&lt;/h2&gt;&lt;p style="line-height: 12px; font-size: 11px;"&gt;As stated in the MSC Administrator Guide:&lt;/p&gt;&lt;p style="line-height: 12px; font-size: 11px;"&gt;&lt;span style="line-height: 12px;"&gt;"Checks for MSC configuration updates are performed once per hour. When a configuration update is detected, a fresh copy is downloaded and applied, and the MSC begins utilizing the new configuration &lt;/span&gt;&lt;span style="line-height: 12px;"&gt;immediately; this is all transparent to the end-user.&lt;/span&gt;&lt;/p&gt;&lt;p style="line-height: 12px; font-size: 11px;"&gt;The MSC is capable of handling most configuration changes automatically as long as there are no certificate authority-related changes, and at least one Server IP address remains unchanged so that the new configuration can be obtained. However, browsers will need to be restarted in order to use an updated PAC file."&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 12px; font-size: 11px;"&gt;For more information, see chapter 8 in https://support.levelblue.com/software/secure_web_gateway/manuals/11.0/Trustwave_MSC-2_0_1-AdministratorGuide.pdf&lt;/span&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;The SWG GUI provides the following options to manage client updates. (In &lt;strong&gt;Internal mode&lt;/strong&gt;. &lt;span style="line-height: 12px;"&gt;In &lt;strong&gt;PKI mode&lt;/strong&gt;, cloud users are certified and managed externally.)&lt;/span&gt;&lt;span style="line-height: 12px;"&gt;:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Administration &amp;gt; Cloud &amp;gt; Configuration &amp;gt; Provisioning &lt;/strong&gt;tab&lt;strong&gt;: &lt;/strong&gt;You can select to send an email update upon configuration changes.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Administration &amp;gt; Cloud &amp;gt; Email Template: &lt;/strong&gt;You can customize the emails that are sent after any cloud configuration change.&lt;/p&gt;&lt;p&gt;Also check the &lt;strong&gt;Users &amp;gt; Cloud User Certificate Management&lt;/strong&gt; tab for user certificate actions.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 12px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;</description><pubDate>Mon, 08 Jul 2013 02:22:56 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>No updates for Virtual SWG system</title><link>https://support.levelblue.com/kb/Goto15617.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul style="line-height: 12px; font-size: 11px;"&gt;    &lt;li style="line-height: 12px;"&gt;&lt;span style="line-height: 12px;"&gt;Virtual SWG 10.x&lt;/span&gt; &lt;/li&gt;    &lt;li style="line-height: 12px;"&gt;&lt;span style="line-height: 12px;"&gt;Virtual SWG 11.x&lt;/span&gt; &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Symptoms:&lt;/h2&gt;&lt;ul style="line-height: 12px; font-size: 11px;"&gt;    &lt;li style="line-height: 12px;"&gt;Updates not installed, and no new updates are available when retrieving updates manually. &lt;/li&gt;    &lt;li style="line-height: 12px;"&gt;&lt;span style="line-height: 12px;"&gt;System log shows an error on connecting with the Update server.&lt;/span&gt; &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Causes:&lt;/h2&gt;&lt;ul style="line-height: 12px; font-size: 11px;"&gt;    &lt;li style="line-height: 12px;"&gt;This may happen due to the default date/time settings used for a Virtual installation - C&lt;span style="line-height: 12px;"&gt;heck the current time/date set on SWG to verify.&lt;/span&gt; &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Resolution:&lt;/h2&gt;&lt;div style="line-height: 12px; font-size: 11px;"&gt;Update the date/time settings using the &lt;strong&gt;config_time&lt;/strong&gt; limited shell command. The best update method is to specify an NTP server, public or local:&lt;/div&gt;&lt;div style="line-height: 12px; font-size: 11px;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="line-height: 12px; font-size: 11px;"&gt;&lt;img alt="" src="https://support.levelblue.com/KB/Uploads/Images/SM/15617/config_time.png" /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;</description><pubDate>Mon, 17 Jun 2013 01:29:20 GMT</pubDate><dc:creator>ofer Kalef</dc:creator></item><item><title>Updating SWG from version 9.2 to 10.1.2</title><link>https://support.levelblue.com/kb/Goto14558.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 9.2.x &lt;/li&gt;    &lt;li&gt;SWG 10.x &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;What is the best procedure for upgrading Secure Web Gateway from version 9.2.x to 10.1.2? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Procedure:&lt;/h2&gt;&lt;h3&gt;# General remarks&lt;/h3&gt;&lt;div&gt;&lt;p&gt;There are a number of ways to move a Secure Web Gateway environment from 9.2 to 10.1.2.  The best option for a specific organization will depend on their topology (whether it is a High Availability setup with two Policy Servers, a single Policy Server with a few Scanners, or an All-In-One) and their requirements for acceptable system downtime.&lt;/p&gt;&lt;p&gt;For smaller environments or All-In-One setups, the migration option might fit better than a clean installation on a second Policy Server (PS).&lt;/p&gt;&lt;p&gt;Once a PS has 10.1.2 up and working, Scanners can be upgraded independently (although they must start with at least version 9.2) by using a command in the Limited Shell (LS). This command ('config_upgrade') is basically a new installation over the network, which preserves each scanner's configuration settings.&lt;/p&gt;&lt;p&gt;A Scanner should not be listed in the devices tree of two or more Policy Servers at the same time. A scanner which is supposed to be 'moved' from one PS to another, must be deleted and added in the devices lists accordingly.&lt;/p&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-weight: normal;"&gt;A Policy Server on 10.1.&lt;/span&gt;&lt;strong&gt;2&lt;/strong&gt;&lt;span style="font-weight: normal;"&gt; can restore a Rollback Backup files from version 9.2 and 10.0.&lt;/span&gt;&lt;/div&gt;&lt;h3&gt;# Preparation &lt;/h3&gt;&lt;p&gt;&lt;span style="line-height: 17px; font-size: 11px;"&gt;Create a &lt;/span&gt;&lt;span style="line-height: 17px; font-size: 11px;"&gt;bootable USB key with all of the necessary files on it.&lt;/span&gt;&lt;br style="line-height: 17px;" /&gt;&lt;/p&gt;&lt;ul style="font-size: 11px; line-height: 12px;"&gt;    &lt;li style="line-height: 12px;"&gt;Use a key which is at least 2 GB in size, and make it bootable.  Any appropriate tool will do (e.g., under Linux use “UNetbootin”, or under Win7 use the Windows version of this tool (link °4)).  &lt;/li&gt;    &lt;li style="line-height: 12px;"&gt;Unzip the &lt;span style="line-height: 17px; font-size: 11px;"&gt;&lt;strong&gt;1.4.1-05&lt;/strong&gt; installer files (link °1),&lt;/span&gt; and copy all files onto the USB key. DO NOT USE an older version of these files. &lt;/li&gt;    &lt;li style="line-height: 12px;"&gt;Copy the 10.0-19 ISO (link °2) onto the key.  &lt;/li&gt;    &lt;li style="line-height: 12px;"&gt;&lt;span style="line-height: 11px; font-size: 11px;"&gt;Copy the 10.1-12 ISO (link °3) onto the key.&lt;/span&gt; &lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;span style="line-height: 10px;"&gt;If performing a clean installation, make sure that you have a 10.1 license key. The format of 9.x and 10.1.x keys is different, so a 9.2 key would not be accepted on a cleanly installed 10.1 appliance. For any license issue, please contact your Trustwave Sales representative and request a new license with the same options.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="line-height: 10px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;h3&gt;# Upgrade&lt;/h3&gt;&lt;p&gt;1) Release Policy Server High Availability (PS HA), if applicable:&lt;/p&gt;&lt;ul&gt;    &lt;li&gt;Stop synchronization between the master and backup policy servers &lt;/li&gt;    &lt;li&gt;Release HA &lt;/li&gt;    &lt;li&gt;Access the Backup PS GUI, and remove the scanner devices (select the IP, right click, 'Delete Device') &lt;/li&gt;    &lt;li&gt;Shut down the backup PS (Limited Shell: 'poweroff') &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;2) On the (to-be-upgraded) Policy Server, delete the scanners from the devices tree (select the IP, right click, 'Delete Device'), to make sure they are still up and untouched until the PS is fully upgraded. All scanners will continue to work and scan traffic.&lt;/p&gt;&lt;p&gt;3) Plug in the USB key. If the local console is not accessible remotely (for example, via an IP KVM), also connect a USB keyboard and VGA monitor.&lt;/p&gt;&lt;p&gt;4) Reboot the appliance (Limited Shell: 'reboot').&lt;/p&gt;&lt;p&gt;5) Perform each of the &lt;strong&gt;three phases of the upgrade&lt;/strong&gt;: &lt;/p&gt;&lt;ul&gt;    &lt;li&gt;Boot from the USB key and run the &lt;strong&gt;migration to 10.0&lt;/strong&gt;, as described in the &lt;a class="ApplyClass" href="https://support.levelblue.com/software/secure_web_gateway/manuals/9.2.0/SWGInstallationUtility1.1.pdf"&gt;&lt;span style="color: #1f5080;"&gt;Tech Brief Installation Utility&lt;/span&gt;&lt;/a&gt; document &lt;/li&gt;    &lt;li&gt;Boot from the hard disk, log in to the PS GUI from a browser, navigate to the Updates section, and install &lt;strong&gt;10.0 Maintenance Fix 01&lt;/strong&gt; (listed in 'Available Updates'). &lt;/li&gt;    &lt;li&gt;Reboot the appliance from the USB key and run the &lt;strong&gt;migration to 10.1&lt;/strong&gt;.  When the upgrade has finished and the appliance is rebooting, unplug the USB stick. &lt;/li&gt;&lt;/ul&gt;&lt;p&gt;6) After the appliance finishes booting, log in to the PS GUI, and install all recent patches:&lt;/p&gt;&lt;ul&gt;    &lt;li&gt;&lt;strong&gt;Maintenance Fix 10.1.2&lt;/strong&gt; (listed in 'Available Updates') &lt;/li&gt;    &lt;li&gt;recent Management and Runtime Hotfixes (Knowledge Base Article 14562, please contact Support if you do not have access)&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;7) Check the configuration and policies (AD configuration and import, &lt;span style="line-height: 12px; font-size: 11px;"&gt;Upstream Proxy Policies, etc.&lt;/span&gt;).&lt;/p&gt;&lt;p&gt;8) Add the scanners back into the devices tree (one by one, or in groups). Make sure that a scanner is not listed under and managed by any other PS.&lt;/p&gt;&lt;p&gt;9) Log in to the Limited shell via SSH, and run 'config_upgrade' in order to upgrade the scanners. Wait until all of the scanners are updated and stable. (Note: The scanners will go offline during the upgrade.  It is possible to upgrade scanners individually or in groups in order to prevent all scanners from being offline at once.  The upgrade can take a while, since the Policy Server will copy the ISO to each scanner over the network, and each scanner must then install the ISO. This process takes some time, however it will take less time than an installation from USB.)&lt;/p&gt;&lt;p&gt;10) Establish Policy Server HA again, if applicable: &lt;/p&gt;&lt;ul&gt;    &lt;li&gt;Perform steps 3 through 6 on the backup PS (migration and updates). &lt;/li&gt;    &lt;li&gt;On the master PS, setup HA again, enable synchronization (do not synchronize unless all updates are installed). &lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;h3&gt;&lt;strong&gt;# Alternatively: PS on the side (‘PS clone’) in order to test the process in advance&lt;/strong&gt;&lt;/h3&gt;&lt;div&gt;Advantage: Production environment is not affected &lt;span style="line-height: 12px; font-size: 11px;"&gt;(Main difference: this is a clean install, not a migration process)&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;1) Boot from USB and &lt;strong&gt;install&lt;/strong&gt; 10.1.0 clean (do not choose the migration option)&lt;/div&gt;&lt;div&gt;2) On the Limited Shell, run 'setup', and configure the appliance according to your needs&lt;/div&gt;&lt;div&gt;3) Enter the GUI, install your license (PS must have access to the Update Server, otherwise the license cannot be applied)&lt;/div&gt;&lt;div&gt;4) &lt;span style="line-height: 12px; font-size: 11px;"&gt;Install all recent AV / URL / Security Updates&lt;/span&gt;&lt;/div&gt;&lt;div&gt;5) Install all recent patches&lt;/div&gt;&lt;div&gt;&lt;ul&gt;    &lt;li&gt;&lt;strong&gt;Maintenance Fix 10.1.2&lt;/strong&gt; (listed in ‘available updates’) &lt;/li&gt;    &lt;li&gt;&lt;span style="line-height: 12px; font-size: 11px;"&gt;recent Management and Runtime Hotfixes (Knowledge Base Article 14562&lt;span style="line-height: 12px; font-size: 11px;"&gt;, please contact Support if you do not have access&lt;/span&gt;)&lt;/span&gt;    &lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;6) Copy the latest Rollback Backup files (from the source PS) to an FTP or Samba location&lt;/div&gt;&lt;div&gt;&lt;ul&gt;    &lt;li&gt;The actual backup file (xxxxx_backup_yyyy_mm_dd_hh_mm_ss.tar.enc) &lt;/li&gt;    &lt;li&gt;index.xml &lt;/li&gt;    &lt;li&gt;date &lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;7) Restore&lt;/div&gt;&lt;div&gt;&lt;ul&gt;    &lt;li&gt;Configure the PS’s Rollback settings (with FTP selected, it might be necessary to add a trailing '/' after the server´s IP) &lt;/li&gt;    &lt;li&gt;Navigate to Administration &amp;gt; Rollback &amp;gt; Restore &lt;/li&gt;    &lt;li&gt;Start Rollback Restore &lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;NOTE: After this Rollback Restore has been performed, all scanners will be listed under Devices. Remove them immediately on the "new" Policy Server in order to avoid conflicts. &lt;/div&gt;&lt;div&gt;In addition, this Policy Server will have the IP configuration of the PS from which the Backup originates &lt;span style="line-height: 12px; font-size: 11px;"&gt;(in the Database and GUI, not in terms of network-settings)&lt;/span&gt;. This address is probably different from the setting after step [2].  To correct this, follow the steps below:&lt;/div&gt;&lt;div&gt;&lt;ul&gt;    &lt;li&gt;Navigate to Administration &amp;gt; System Settings &amp;gt; Devices &amp;gt; select Policy Server IP &lt;/li&gt;    &lt;li&gt;In the pane on the right hand side, click the Edit button, select the correct IP address under 'Device IP', and click the Save button.  Commit this change. &lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;8) From here, follow steps 7+ of the migration process as described above in order to transition the 9.2-scanners to 10.1.2. &lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;h2&gt;Notes:&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;Download Links USB installer:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;1) &lt;a href="http:///" class="ApplyClass"&gt;ftp://outgoing:Mr8om21r@ftp.finjan.com/support/vsi/1-4-1--5/VSI_1.4.1-05_79592M-2011-11-27_1102.tgz&lt;/a&gt;&lt;/p&gt;&lt;p&gt;2) &lt;a href="http:///"&gt;ftp://outgoing:Mr8om21r@ftp.finjan.com/support/images/10.0/1000-b19-04-10-2010--12-26PM.iso&lt;/a&gt;&lt;/p&gt;&lt;p&gt;3) &lt;a href="http:///"&gt;ftp://outgoing:Mr8om21r@ftp.finjan.com/support/images/10.1/1010-b12-10-04-2011--10-32AM.iso&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family: calibri,sans-serif; font-size: 13px;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;4) &lt;a target="_blank" href="ftp://outgoing:Mr8om21r@ftp.finjan.com/support/TrustwaveUSB/TrustwaveUSB.EXE" class="ApplyClass"&gt;USB Creator for Win7&lt;/a&gt; (do not select “reboot” at the end of this process; see the &lt;a target="_blank" href="ftp://outgoing:Mr8om21r@ftp.finjan.com/support/TrustwaveUSB/TrustwaveUSBTOOL.avi"&gt;howto movie&lt;/a&gt;)&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;br /&gt;Recent Patches &lt;/strong&gt;(as of May 2012)&lt;/p&gt;&lt;p&gt;Update 10.1.2: Updates &amp;gt; Available Updates&lt;/p&gt;&lt;p&gt;&lt;span style="line-height: 12px; font-size: 11px;"&gt;Recent Management and Runtime Hotfixes: Knowledge Base Article 14562&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;br /&gt;Documentation:&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;5) &lt;a target="_blank" href="ftp://outgoing:NavEmccfkt7@ftp.finjan.com/support/vsi/1-4-1--5/SECURE%20WEB%20GATEWAY%2010.1%20Upgrade%20Release%20Notes.pdf"&gt;Secure Web Gateway 10.1 Upgrade Release Notes&lt;/a&gt;&lt;/p&gt;&lt;p&gt;6) &lt;a class="ApplyClass" href="https://support.levelblue.com/software/secure_web_gateway/NGupdates/OSupdates/swg_maintenance_release_10_1_2.pdf"&gt;Secure Web Gateway 10.1.2 Release Notes&lt;/a&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;</description><pubDate>Wed, 01 Aug 2012 07:18:55 GMT</pubDate><dc:creator>Charles Creegan</dc:creator></item><item><title>What is the SWG update server address?</title><link>https://support.levelblue.com/kb/Goto14508.aspx</link><description>&lt;h2&gt;This article applies to:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;SWG 9.x &lt;/li&gt;    &lt;li&gt;SWG 10.x &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Question:&lt;/h2&gt;&lt;ul&gt;    &lt;li&gt;I want to restrict Policy Servers' requests, but updates should be allowed. What access do I have to permit through my Firewall? &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Reply:&lt;/h2&gt;&lt;p&gt;The required access is:&lt;/p&gt;&lt;ul&gt;    &lt;li&gt;Destination &lt;strong&gt;Port 443&lt;/strong&gt; / HTTPS &lt;/li&gt;    &lt;li&gt;Hosts [1] &lt;strong&gt;updateng.finjan.com&lt;/strong&gt; and [2] &lt;strong&gt;mirror.&lt;span style="line-height: 12px; font-size: 11px; "&gt;updateng.finjan.com&lt;/span&gt;&lt;/strong&gt; &lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Notes:&lt;/h2&gt;&lt;p&gt;Trustwave strongly recommends that you use DNS. The IP addresses of these servers could change.&lt;/p&gt;</description><pubDate>Mon, 14 May 2012 02:24:49 GMT</pubDate><dc:creator>Rudolf Kessler</dc:creator></item><item><title>Preventing ICAP Scanning Loops</title><link>https://support.levelblue.com/kb/Goto13071.aspx</link><description>&lt;div class="atb17"&gt;&lt;li&gt;&lt;b&gt;Description&lt;/b&gt;&lt;br /&gt;In some environments, the only device that is allowed to connect directly to the web is the cache appliance.  In such cases, the Vital Security Web Appliance must be configured to proxy its connections through the cache appliance.  When the cache appliance is also an ICAP client, it is important to ensure that the Vital Security's transactions do not receive ICAP processing. &lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb18"&gt;&lt;li&gt;&lt;b&gt;Symptoms&lt;/b&gt;&lt;br /&gt;When transactions that originate from the Vital Security Web Appliance are scanned through ICAP, users might report lengthy scanning times for Java applets and ActiveX controls.  If a sniffer is used to analyze the traffic, the administrator might see the same code (for example, a Java .class file) being requested multiple times.  Additionally, updates might not install. &lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb19"&gt;&lt;li&gt;&lt;b&gt;Cause&lt;/b&gt;&lt;br /&gt;All Vital Security Web Appliances, regardless of role, must be able to connect to the Internet.  The reason for this is broken out by role below:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;All in One / Policy Server:&lt;/strong&gt;  These appliances must connect to the Internet in order to download both security and operating system updates.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;All in One / Scanning Server:&lt;/strong&gt;  These appliances must connect to the Internet in order to prefetch content for scanning purposes.  A common scenario in which prefetching occurs is when Vital Security analyzes a Java .class file that has dependencies on other Java .class files.  Vital Security will request all of the associated .class files so that the entire applet can be scanned as a whole.&lt;br /&gt;&lt;br /&gt;If transactions originating from the Vital Security appliances are passed back via ICAP, then the appliances may waste cycles scanning updates that do not need to be scanned.  Additionally, prefetched content will be double-scanned, and this could result in scanning recursion and double-prefetching, which will increase system utilization and decrease overall performance. &lt;/li&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class="atb20"&gt;&lt;li&gt;&lt;b&gt;Solution&lt;/b&gt;&lt;br /&gt;The best way to prevent scanning loops is to configure the ICAP client (the cache appliance) so that transactions that originate from the IP addresses of the Vital Security Web Appliances do not receive ICAP processing.  Neither REQMOD nor RESPMOD processing should be performed on transactions that originate from Vital Security.  Additionally, if the IP addresses of the  appliances are ever changed, the policy on the cache appliances should be updated so that transactions originating from the new  IP addresses are not scanned.&lt;br /&gt;&lt;br /&gt;Please note that these configurations are only necessary when the Vital Security Web appliances use an ICAP-enabled cache appliance as their upstream proxy.  This includes any situations where the traffic might be transparently redirected to the ICAP-enabled cache appliance.  However, when Vital Security appliances are allowed to connect directly to the Internet (without going through the cache appliance), there is no need to apply these configurations on the cache appliance.&lt;br /&gt;&lt;br /&gt;Different cache appliances (and different versions of the same cache appliance) can vary in their configuration.  For details on configuring a specific cache appliance to bypass ICAP for connections that originate from Vital Security's IP, we recommend contacting the vendor of the cache appliance.  The vendor will be able to identify the best way to apply this configuration in your environment.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;VSOS&lt;br /&gt;&lt;/strong&gt;all SWG versions&lt;/li&gt;&lt;/div&gt;&lt;dl style="margin-top: 10px;"&gt;    &lt;dt&gt;&lt;i&gt;This article applies to:&lt;/i&gt;&lt;/dt&gt;    &lt;dd&gt;&lt;i&gt;NG 5000&lt;/i&gt;&lt;/dd&gt;    &lt;dd&gt;&lt;i&gt;SWG 3000 / NG 6000&lt;/i&gt;&lt;/dd&gt;    &lt;dd&gt;&lt;i&gt;SWG 7000 / NG 8000    &lt;dl style="margin-top: 10px;"&gt;        &lt;dt&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt; &lt;/dt&gt;        &lt;dd&gt;&lt;i&gt;Finjan KB 1096&lt;/i&gt; &lt;/dd&gt;    &lt;/dl&gt;    &lt;/i&gt;&lt;/dd&gt;&lt;/dl&gt;</description><pubDate>Mon, 09 Aug 2010 02:42:09 GMT</pubDate><dc:creator>Rudolf Kessler</dc:creator></item><item><title>Rollback Restore fails if Policy Servers are in HA mode</title><link>https://support.levelblue.com/kb/Goto13674.aspx</link><description>&lt;div class="atb65"&gt;&lt;li&gt;&lt;b&gt;Description&lt;/b&gt;&lt;br&gt;&lt;P&gt;High Availability mode must be disabled prior to restoring a rollback.&lt;/P&gt;&lt;/div&gt;&lt;br&gt;&lt;div class="atb66"&gt;&lt;li&gt;&lt;b&gt;Symptoms&lt;/b&gt;&lt;br&gt;When restoring a rollback, a "&lt;EM&gt;Restore failed&lt;/EM&gt;" pop-up dialog box appears.  Further information regarding this event is absent from the System Log.  If a packet capture is recorded while trying to restore the rollback, no connections to the backup location (e.g., FTP server) are observed.&lt;/div&gt;&lt;br&gt;&lt;div class="atb67"&gt;&lt;li&gt;&lt;b&gt;Cause&lt;/b&gt;&lt;br&gt;This is the correct behavior for a Finjan system operating in High Availability mode.  It prevents the functionality of the standby policy server from being adversely affected if High Availabiliy is disabled in the restored backup.&lt;/div&gt;&lt;br&gt;&lt;div class="atb68"&gt;&lt;li&gt;&lt;b&gt;Solution&lt;/b&gt;&lt;br&gt;The administrator should verify that High Availability is disabled before restoring a rollback.  Should any changes be required in order to disable High Availability, these changes must be committed, and the administrator should wait until all devices have finished committing before restoring the rollback.&lt;BR&gt;&lt;BR&gt;If appropriate, High Availability should be enabled again after the rollback is fully restored and all devices are stable.&lt;BR&gt;&lt;BR&gt;Details about enabling and disabling High Availability for specific VSOS releases can be found in the Management Console Reference Guide.&lt;/div&gt;&lt;br&gt;&lt;div class="atb69"&gt;&lt;li&gt;&lt;b&gt;Software Version&lt;/b&gt;&lt;br&gt;up to 9.2-M01&lt;/div&gt;&lt;br&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article applies to:&lt;/i&gt;&lt;dd&gt;&lt;i&gt;NG 5000&lt;/i&gt;&lt;/dd&gt;&lt;DD&gt;&lt;I&gt;NG 6000&lt;/I&gt;&lt;/DD&gt;&lt;DD&gt;&lt;I&gt;NG 8000&lt;/DD&gt;&lt;/DL&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt;&lt;DD&gt;&lt;i&gt;Finjan KB 12675&lt;/i&gt;&lt;/DL&gt;</description><pubDate>Wed, 23 Dec 2009 00:00:00 GMT</pubDate><dc:creator>support finjan</dc:creator></item><item><title>Blade Server Firmware Upgrade Process</title><link>https://support.levelblue.com/kb/Goto13080.aspx</link><description>&lt;IFRAME src="https://support.levelblue.com/kb/attachments/1110.pdf" width=670 height=800&gt;&lt;/IFRAME&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article applies to:&lt;/i&gt;&lt;dd&gt;&lt;i&gt;NG 8000&lt;/dd&gt;&lt;/DL&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt;&lt;DD&gt;&lt;i&gt;Finjan KB 1110&lt;/i&gt;&lt;/DL&gt;</description><pubDate>Fri, 27 Mar 2009 00:00:00 GMT</pubDate><dc:creator>support finjan</dc:creator></item><item><title>NG-6000 Firmware update process</title><link>https://support.levelblue.com/kb/Goto13376.aspx</link><description>&lt;IFRAME src="https://support.levelblue.com/kb/attachments/1525.pdf" width=670 height=800&gt;&lt;/IFRAME&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article applies to:&lt;/i&gt;&lt;dd&gt;&lt;i&gt;NG 6000&lt;/dd&gt;&lt;/DL&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt;&lt;DD&gt;&lt;i&gt;Finjan KB 1525&lt;/i&gt;&lt;/DL&gt;</description><pubDate>Fri, 27 Mar 2009 00:00:00 GMT</pubDate><dc:creator>support finjan</dc:creator></item><item><title>How to avoid simultaneous scanner restarts during an upgrade</title><link>https://support.levelblue.com/kb/Goto13539.aspx</link><description>&lt;div class="atb62"&gt;&lt;li&gt;&lt;b&gt;Question&lt;/b&gt;&lt;br&gt;&lt;P&gt;&lt;FONT face=Arial&gt;When upgrading, all the remote scanners simultaneously restart, bringing the appliances out of production. What can be done in order to prevent this behavior when upgrading the Finjan to a newer software version?&lt;/FONT&gt;&lt;/P&gt;&lt;/div&gt;&lt;br&gt;&lt;div class="atb63"&gt;&lt;li&gt;&lt;b&gt;Answer&lt;/b&gt;&lt;br&gt;&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: black"&gt;&lt;FONT face=Arial&gt;In order to update each scanner separately and avoid simultaneous scanner restarts, please browse to the management console of the appliance and then click on the Settings tab -&amp;gt; Devices -&amp;gt; Policy Server -&amp;gt; VSOS Updates -&amp;gt; Click the Update selected Scanning Servers -&amp;gt; Apply and commit changes, as depicted in the screenshot below:&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;SPAN style="COLOR: black"&gt;&lt;FONT face=Calibri&gt;&lt;IMG alt="" src="https://support.levelblue.com/kb/attachments/images/908~selective_update.jpg" border=0&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/div&gt;&lt;br&gt;&lt;div class="atb64"&gt;&lt;li&gt;&lt;b&gt;Software Version&lt;/b&gt;&lt;br&gt;&lt;FONT face=Arial&gt;8.5.0&lt;/FONT&gt;&lt;/div&gt;&lt;br&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article applies to:&lt;/i&gt;&lt;dd&gt;&lt;i&gt;NG 1000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 5000&lt;/i&gt;&lt;/dd&gt;&lt;DD&gt;&lt;I&gt;NG 6000&lt;/I&gt;&lt;/DD&gt;&lt;DD&gt;&lt;I&gt;NG 8000&lt;/DD&gt;&lt;/DL&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt;&lt;DD&gt;&lt;i&gt;Finjan KB 1790&lt;/i&gt;&lt;/DL&gt;</description><pubDate>Mon, 23 Mar 2009 00:00:00 GMT</pubDate><dc:creator>Eric Hanson</dc:creator></item><item><title>Offline Updates</title><link>https://support.levelblue.com/kb/Goto13307.aspx</link><description>&lt;IFRAME src="https://support.levelblue.com/kb/attachments/1441.pdf" width=670 height=800&gt;&lt;/IFRAME&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article applies to:&lt;/i&gt;&lt;dd&gt;&lt;i&gt;NG 1000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 5000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 8000&lt;/dd&gt;&lt;/DL&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt;&lt;DD&gt;&lt;i&gt;Finjan KB 1441&lt;/i&gt;&lt;/DL&gt;</description><pubDate>Mon, 23 Mar 2009 00:00:00 GMT</pubDate><dc:creator>support finjan</dc:creator></item><item><title>Why does there appear to be a duplicate Security Update after 8.4.0 installation?</title><link>https://support.levelblue.com/kb/Goto13244.aspx</link><description>&lt;div class="atb54"&gt;&lt;li&gt;&lt;b&gt;Question&lt;/b&gt;&lt;br&gt;Why does the security update that I previously installed on 8.3.X  (as shown in the Installed Update tab) reappear on the Available Updates tab together with the 8.4.0 installation?&lt;/div&gt;&lt;br&gt;&lt;div class="atb55"&gt;&lt;li&gt;&lt;b&gt;Answer&lt;/b&gt;&lt;br&gt;8.4.0 does not support the format of the previously installed security update and has reset the system to use security update #52. Please make sure to install the latest security update after the 8.4.0 installation.&lt;BR&gt;&lt;BR&gt;&lt;STRONG&gt;Note:&lt;/STRONG&gt; You will see both security updates afterwards in the Installed Updates tab, but from the logs you can see that they are actually different (e.g. one is &lt;STRONG&gt;SECURITY_UPDATE8&lt;FONT color=#ff0000&gt;3&lt;/FONT&gt;0000053&lt;/STRONG&gt; and the second one is &lt;STRONG&gt;SECURITY_UPDATE8&lt;FONT color=#ff0000&gt;4&lt;/FONT&gt;0000053&lt;/STRONG&gt;).&lt;BR&gt;&lt;BR&gt;&lt;div style="width:670px;overflow-x:scroll;"&gt;&lt;img alt="" src="https://support.levelblue.com/kb/attachments/images/446~KB1348.jpg" border=0&gt;&lt;/div&gt;&lt;/div&gt;&lt;br&gt;&lt;div class="atb56"&gt;&lt;li&gt;&lt;b&gt;Software Version&lt;/b&gt;&lt;br&gt;8.4.0&lt;/div&gt;&lt;br&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article applies to:&lt;/i&gt;&lt;dd&gt;&lt;i&gt;NG 1000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 5000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 8000&lt;/dd&gt;&lt;/DL&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt;&lt;DD&gt;&lt;i&gt;Finjan KB 1348&lt;/i&gt;&lt;/DL&gt;</description><pubDate>Mon, 23 Mar 2009 00:00:00 GMT</pubDate><dc:creator>support finjan</dc:creator></item><item><title>Why can't the McAfee 5200 Engine be Installed?</title><link>https://support.levelblue.com/kb/Goto13484.aspx</link><description>&lt;div class="atb62"&gt;&lt;li&gt;&lt;b&gt;Question&lt;/b&gt;&lt;br&gt;When I try to install the NAI Engine file update (McAfee new 5200 engine), I get an update failed message.&lt;BR&gt;Why do I get this message and what should I do?&lt;/div&gt;&lt;br&gt;&lt;div class="atb63"&gt;&lt;li&gt;&lt;b&gt;Answer&lt;/b&gt;&lt;br&gt;As noted on our website (&lt;A href="http://www.finjan.com/Content.aspx?id=1799"&gt;&lt;FONT color=#0000ff&gt;http://www.finjan.com/Content.aspx?id=1799&lt;/FONT&gt;&lt;/A&gt;), the McAfee Anti-Virus engine version 5100 will be End of Life by January 31st 2008. Customers using the McAfee Anti-Virus engine on the Vital Security Appliance series should upgrade to the following Maintenance releases in order to support the new Anti-Virus engine: &lt;/div&gt;&lt;br&gt;&lt;div class="atb64"&gt;&lt;li&gt;&lt;b&gt;Software Version&lt;/b&gt;&lt;br&gt;8.4.0&lt;BR&gt;8.4.3&lt;BR&gt;8.5.0&lt;/div&gt;&lt;br&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article applies to:&lt;/i&gt;&lt;dd&gt;&lt;i&gt;NG 1000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 5000&lt;/i&gt;&lt;/dd&gt;&lt;DD&gt;&lt;I&gt;NG 6000&lt;/I&gt;&lt;/DD&gt;&lt;DD&gt;&lt;I&gt;NG 8000&lt;/DD&gt;&lt;/DL&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt;&lt;DD&gt;&lt;i&gt;Finjan KB 1662&lt;/i&gt;&lt;/DL&gt;</description><pubDate>Mon, 23 Mar 2009 00:00:00 GMT</pubDate><dc:creator>support finjan</dc:creator></item><item><title>How do I Install a Failed Update?</title><link>https://support.levelblue.com/kb/Goto13209.aspx</link><description>&lt;div class="atb35"&gt;&lt;li&gt;&lt;b&gt;Question&lt;/b&gt;&lt;br&gt;I retrieved either an Anti-Virus / URL category / OS update and it is displayed in my Available Updates section. &lt;BR&gt;However, when I try to install it I get "update failed" message, or if it is an OS update, it seems that the update status page is stuck.&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;div&gt;&lt;img alt="" src="https://support.levelblue.com/kb/attachments/images/742~564.jpg" border=0&gt;&lt;/div&gt;&lt;/P&gt;&lt;P&gt;How can I install this failed update?&lt;/P&gt;&lt;/div&gt;&lt;br&gt;&lt;div class="atb36"&gt;&lt;li&gt;&lt;b&gt;Answer&lt;/b&gt;&lt;br&gt;If the update status page is stuck, delete the IE cookies (see also article &lt;STRONG&gt;Update Status Page Stuck -&lt;/STRONG&gt; &lt;A href="http://kb.finjan.com/article.asp?article=1025&amp;p=4"&gt;&lt;FONT color=#0000ff&gt;http://kb.finjan.com/article.asp?article=1025&amp;p=4&lt;/FONT&gt;&lt;/A&gt;).&lt;BR&gt;Otherwise: navigate to Settings -&amp;gt; Updates -&amp;gt; Available Updates and delete the update that failed (marked with a red cross).&lt;BR&gt;Select Retrieves Updates and try again to reinstall this update.&lt;BR&gt;&lt;BR&gt;&lt;div style="width:670px;overflow-x:scroll;"&gt;&lt;img alt="" src="https://support.levelblue.com/kb/attachments/images/374~update failed.jpg" border=0&gt;&lt;/div&gt;&lt;BR&gt;&lt;P&gt;&lt;/P&gt;&lt;LI&gt;&lt;STRONG&gt;Software Version&lt;/STRONG&gt;&lt;BR&gt;8.3.x&lt;BR&gt;8.4.x&lt;BR&gt;8.5.0&lt;/LI&gt;&lt;/div&gt;&lt;br&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article applies to:&lt;/i&gt;&lt;dd&gt;&lt;i&gt;NG 1000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 5000&lt;/i&gt;&lt;/dd&gt;&lt;dd&gt;&lt;i&gt;NG 8000&lt;/dd&gt;&lt;/DL&gt;&lt;DL style="margin-top:10px;"&gt;&lt;DT&gt;&lt;i&gt;This article was previously published as:&lt;/i&gt;&lt;DD&gt;&lt;i&gt;Finjan KB 1293&lt;/i&gt;&lt;/DL&gt;</description><pubDate>Mon, 23 Mar 2009 00:00:00 GMT</pubDate><dc:creator>support finjan</dc:creator></item></channel></rss>