Release Notes CSG 7.2.40

Collax Security Gateway
23.04.2026

Installation Notes

Update Instructions

To install this update please follow the following steps:

Procedure

  1. It is highly recommended to backup of all server data with the Collax backup system before proceeding. Check that the backup was successful before proceeding with the update (this can be done within the backup information email).
  2. In the administration interface go to Menu → Software → System Update and press Get Package List. This will download the listed update packages. If successful the message Done! will be displayed on the screen.
  3. Click Get Packages to download the update packages.
  4. Click Install. This installs the update. The end of this process is indicated by the message Done!.
  5. A new kernel will now be installed. The system will reboot automatically after installing the update. An appropriate note will be shown if the update process is completed.

New in this version

System Management: Active Directory

Integration with Active Directory has been significantly enhanced. New features, such as the deputy rule, are now also available to AD users. At the same time, integration has been further improved and tailored specifically for Active Directory environments that have evolved over many years.

System Management: Minibus

A new component, the Minibus, has been introduced under the hood. This ensures that system tasks only run in parallel when doing so is possible without conflicts. It is a locking system with batch processing. This has become necessary because an increasing number of Docker containers can be active on a single system. It is important that they are started in a specific order and cannot interfere with other processes during startup.

System Management: Linux Kernel 6.6.130

This update installs the Linux Kernel 6.6.130.

Various software packages have been updated in this release. In addition to security-related updates, general maintenance and support updates have also been applied.

The updates and bug fixes affect the following packages:

  • Apache Web Server 2.4.66
  • OpenSSL Security Patches
  • Python 3.11.14
  • PHP7 Security Fix
  • glib2.0_2.58.3-2+deb10u9 library
  • netsnmp 5.7.3+dfsg-5+deb10u5
  • Intel microcode 20260227

Issues fixed in this version

System Management: Hard Drive Expansion

Previously, it was usually necessary to restart the server twice. With this update, you can change the size of the hard drive without needing to restart the server afterward.

Two-Factor Authentication: Error Displaying 2FA QR Code

When importing a 2FA secret key in the File Export > Web Server menu, the QR code could not be displayed after unchecking the “Local User” box, entering a username, and generating a random key. This issue has been resolved, so the QR code is now generated and displayed correctly.

Additional Software: Bitdefender - Proxy for Updates

Updates to the virus signatures (patterns) of the Bitdefender virus and spam filter will continue to be performed according to a scheduled cycle. Pattern updates can now be performed using an HTTP proxy through the implementation of a new Bitdefender SDK.

Notes

Additional software: Bitdefender - pattern update after commissioning

After starting up the Collax Antivirus powered by Bitdefender module, it may take a few minutes for the current virus patterns to be downloaded. If you click on Update Bitdefender in the virus scanner form during this time, you will receive an error message “Error connecting to server at /opt/lib/bitdefender//bdamsocket: -3”, because the background process has not yet been fully executed.

GUI: Sporadic hangs during running jobs

The progress of configuration jobs is displayed in the top right-hand corner of the web administration. In the case of extensive changes in the network area, especially with country locks (geo-ip), it can happen in rare cases that the job display hangs during activation. As of release 7.2.28, you will now receive the message “Network connection has been interrupted: Messages may be lost until the connection can be re-established.” informs you about such situations.

VPN: Fix for IKEv2 with Microsoft Windows crashes after 7.6 hours

VPN connections with IKEv2 and the on-board tools of Microsoft Windows are interrupted after interrupted after exactly 7.6 hours. The error occurs because Microsoft Windows proposes different algorithms during the IKE re-encryption than during the first connection. The problem can be solved with a registry fix by the value “NegotiateDH2048_AES256” under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\Parameters to 1 is set.

Under the following link you will find a REG file (registry entry) that adds the registry key. Collax accepts no liability for system errors resulting from this.