Sonicwall Capture Client 3.0: Release Notes
Sonicwall Capture Client 3.0: Release Notes
0
Release Notes
April 2020
These release notes provide information about SonicWall® Capture Client 3.0 release. Capture Client 3.0 is a
feature release that includes new features and enhancements. It also identifies the issues resolved from
previous versions.
NOTE: Existing Capture Client implementations are not automatically updated. You need to actively
update your Capture Client policy and select the appropriate version for your configuration.
To update Capture Client:
1 Navigate to Security Policies > Capture Client.
2 Hover over the Capture Client policy.
3 Click Edit.
4 Select the Settings tab and choose the Capture Client version from the drop-down list.
5 Click Update.
Topics:
• About Capture Client
• System Requirements
• New Features and Enhancements
• Resolved Issues
• Known Issues
• Licensing
• Upgrading Information
• SonicWall Support
System Requirements
Capture Client is a comprehensive endpoint security solution that protects Windows and macOS devices. It is
administered from the SonicWall Cloud Management Console, a cloud service requiring only a web browser and
an internet connection. To get maximum performance and protection, the following standards are
recommended:
• Minimum Hardware Requirements
• Supported Operating Systems
• Capture Client Compatibility with S1
• Browser Levels
• Third Party Software Interoperability
To install Capture Client on a system running Linux, the device must meet the following hardware requirements:
Preferred
Operating System Version SentinelOne Agent
Windows Operating System
Windows Server 2019 4.0.4.81 or later is
2016 preferred for all Windows
versions listed here.
2012 R2, 2012
2008 R2
Windows 10 32- and 64-bit
Windows 10 RS5 on 32- and 64-bit
Windows 8 Version 8.1 on 32- and 64-bit
Windows 7 Version 7 SP1 on 32- and 64-bit
NOTE: All agents running on Windows that are supported according to SentinelOne’s life cycle are tested for
compatibility with each Windows 10 Redstone release. Supported editions of Windows 7, 8, 8.1 and 10
include Home, Pro, Pro for Workstations, Enterprise, Education, Pro Education, and Enterprise LTSC. Core and
Mobile editions are not supported.
mac Operating System
macOS 10.15.4 Catalina 4.0.3.3085 or later
NOTE: Due to Apple Notarization requirements, macOS 10.15 up to 10.15.2 requires Capture Client 2.0.20 or
later and SentinelOne 3.2.1.2800 or later. macOS 10.15.3 or later requires SentinelOne 3.6.1.2964 or later to
be installed before upgrading macOS to 10.15.3.
macOS 10.14 and newer up to Mojave 4.0.3.3085 or later
10.14.6
NOTE: The SentinelOne macOS 2.6.3 or later is required for macOS Mojave. An existing SentinelOne 2.6.2 or
2.6.0 version must be upgraded to 2.6.3 or later, before upgrading to macOS Mojave.
NOTE: macOS 10.14.5 or later requires Capture Client 2.0.10 or later and SentinelOne 3.0.4 or later due to
Apple Notarization requirements.
macOS 10.13 or later High Sierra 4.0.3.3085 or later
macOS 10.12 Sierra 4.0.3.3085 or later
Linux Operating Systems
Amazon Linux 2018.03 4.0.3.11
2017.03
AMI 2
Red Hat Enterprise Linux (RHEL) 8 4.0.3.11
7.x
6.4+
Ubuntu 19.04, 19.10 4.0.3.11
18.04
16.04
14.04
CentOS 7.x 4.0.3.11
6.4+
Installation Notes
To ensure Capture Client operates effectively, the following guidelines are recommended:
• .NET Framework 4.0 or later needs to be installed. For Windows 7 and Windows 2008 R2, you may be
prompted for .NET 4.0 to be installed.
• On Windows 7, install the update to enable TLS 1.1 and TLS 1.2 as the default secure protocols in
WinHTTP in Windows. Add the registry subkey. These options are not supported in the default Windows
7 installation.
• For Windows 7 SP1 and Windows Server 2008 R2, the Microsoft Security Advisory 3033929,
https://docs.microsoft.com/en-us/security-updates/SecurityAdvisories/2015/3033929, must be installed
to meet the minimum requirements for the Capture Client installer. It provides SHA-2 Code Signing
Support.
• When the following Microsoft Security Updates are installed, you must restart the endpoint and run the
Agent installation again.
• Update 2758857 for Windows 7 and Windows Server 2008 R2 (https://www.microsoft.com/en-
us/download/details.aspx?id=35973)
• Update 2533623 for Window 7 SP1 and Windows Server 2008 R2
(https://www.microsoft.com/en-us/download/details.aspx?id=26767)
• Configure Microsoft Windows Volume Shadow Copy Service (VSS) before you install the agent. More
information is available in this knowledgebase article: https://www.sonicwall.com/support/knowledge-
base/configuring-windows-vss-for-rollback/180614060954053/.
Capture Client SentinelOne Version for SentinelOne Version for SentinelOne Version for
Version Windows macOS Linux
2.0.17 2.8.2.6745 3.0.2.2629 Not applicable
3.0.2.35 3.0.4.2657
3.1.5.63 3.2.0.2671
3.3.3.29 3.4.2.2857
3.4.4.5.1 3.6.0.2908
3.6.6.104 4.0.3.3085 (recommended)
4.0.4.81 (recommended)
2.0.20 3.0.2.35 3.0.2.2629 Not applicable
2.8.2.6745 3.0.4.2657
3.1.5.63 3.2.0.2671
3.3.3.29 3.2.1.2800
4.0.4.81 (recommended) 4.0.3.3085 (recommended;
must for fresh install of
2.0.20)
2.0.24 3.0.2.35 3.0.4.2657 Not applicable
3.1.5.63 3.2.0.2671
3.3.3.29 3.2.1.2800
3.4.4.51 3.4.2.2857
4.0.4.81 (recommended) 4.0.3.3085 (recommended;
must for fresh install of
2.0.24)
2.0.27 3.0.2.35 3.0.4.2657 Not applicable
3.1.5.63 3.2.0.2671
3.3.3.29 3.2.1.2800
3.4.4.51 3.4.2.2857
3.6.6.104 3.6.0.2098
4.0.4.81 (recommended) 4.0.3.3085 (recommended;
must for fresh install of
2.0.27)
2.0.28 3.0.2.35 3.0.4.2657 Not applicable
3.1.5.63 3.2.0.2671
3.3.3.29 3.2.1.2800
3.4.4.51 3.4.2.2857
3.6.6.104 3.6.0.2098
4.0.4.81 (recommended) 3.6.1.2964
4.0.3.3085 (recommended;
must for fresh install on
macOS 10.15.3)
3.0 3.4.4.5.1 3.4.2.2857 3.5.2.6
3.6.6.104 3.6.0.2908 4.0.3.11 (recommended)
3.7.2.45 3.6.2.2982
4.0.4.81 (recommended) 4.0.3.3085 (recommended)
NOTE: These browser levels apply to the browser running the Cloud Management Console.
Topics:
• Web Content Filtering
• Application Risk Management
• Active Directory Integration
• Notifications
• Support for Linux Endpoints
• Capture Client Version Management Improvements
NOTE: To enable this feature, the Capture Client Advance License is required.
There are several aspects to creating a strong content filtering policy. First it needs to be created, followed by
editing it to set the parameters you want. Use the following steps to guide you:
1 Add a web content filter.
2 Edit the web content filter.
3 Customize the default or timed filter features.
4 Set up localhost filtering.
Refer to the Capture Client Operations Guide for more details.
NOTE: To enable this feature, the Capture Client Advance License is required.
For details about application risk, navigate to Analytics > Application Risk. The table there lists the unpatched
applications and provides a risk level for each. The risk levels are:
• Critical (dark red)
• High (bright red)
• Medium (orange)
• No known risk (green)
Notifications
The Notifications feature allows administrators and users to see the status of any threats, events or alerts and to
set the rules for the kinds of notifications associated with these activities. When you first log into the Capture
Client, you can quickly see the number of notifications that are pending some kind of acknowledgment. Click
the Notifications icon in upper right corner, which opens the Notification Center.
All alerts are also listed in a table at Overview > Alerts. The table lists the alert severity, time it was detected,
type of issue, message, and status. Once you mouse over a particular threat, you also have the option to Mark it
as read or Delete it.
You can customize the alerts and notification settings to notify you of the things you are most concerned with.
Navigate to Management > Notifications to see all the options. You can set up notifications for:
• Email Settings
• Threats
• Threat Detected
• Threat Killed and Quarantined/Remediated
• Suspicious Activity Detected
• Suspicious Activity K&Q/Remediated
• Device events
• Infected Device
• Device Offline
• Scan Started
• Scan Completed Successfully
• Scan Completed with Errors
• Other Devices Event
• Licenses
• License Expiring Soon
• License Expired
Additional features that are not supported for Linux devices includes:
• Device control
• Web Protection
• Firewall enforcement
Known Issues
This section provides a list of known issues in this release.
NOTE: The Upgrade Client option doesn’t work if the endpoint device is enforced with either the
default/custom client policy and the endpoint Capture Client version is less than 3.x.
Licensing
SonicWall Capture Client can be licensed as a security service associated with a SonicWall network security
appliance or as a standalone service without an associated appliance.
Topics:
• Licensing with a Network Security Appliance
• Licensing without a Network Security Appliance
5 Click <Licenses> icon on the newly created client license in the table.
6 On the LICENSES page, scroll down to the DESKTOP & SERVER SOFTWARE section, find Capture Client in
the list, and click Action on Tenant.
7 Enter the activation key if you have and click Confirm, or click Cancel.
9 Once the server has been licensed, click on the <Service Status> icon.
10 Select Click here to access your Security Center. This redirects you to the Client Management Console for
login.
Upgrading Information
When initially setting up your Capture Client implementation, you can opt for self-managed updates or
SonicWall-managed updates. For the self-managed option, you control which version of the client get installed
on your devices by manually updating the required client version in the Capture Client policy. If you choose
SonicWall-managed under the Capture Client Policy, client systems are automatically upgraded when SonicWall
releases and promotes a new version of Capture Client. Refer to the Capture Client Operations Guide for details
on how to configure this.
NOTE: The Upgrade Client option is available beginning with the Capture Client 3.0 release. Customers
running older versions should not try the Upgrade Client option.
Legend
WARNING: A WARNING icon indicates a potential for property damage, personal injury, or death.
CAUTION: A CAUTION icon indicates potential damage to hardware or loss of data if instructions are
not followed.
IMPORTANT NOTE, NOTE, TIP, MOBILE, or VIDEO: An information icon indicates supporting information.