Enterprise AV Home WiFi Mobile Wifi Support Shop Deals

Note: This release is available through both online and offline firmware update mechanisms. Refer to the Installation Guide and User Manual for update methods and how to retrieve the package.

IMPORTANT:

Due to the nature of the SSL improvements in this release, users already using or planning on using the HTTPS scan functionality of the UTM should take the following into consideration:

  1. For environments where the HTTPS scanning function is enabled with the default UTM certificate already installed into every browser, after upgrading to this firmware version the UTM administrator will have to re-install the new certificate into every browser again to regain a transparent HTTPS browsing user experience. Otherwise, users will receive SSL certificate warnings from the browser when navigating to a HTTPS site.
  2. If the user has two or more different UTM models (e.g. one UTM50 and one UTM9S), the two UTMs will use the different certificates after upgrading to this firmware version. If the administrator wants all the UTMs to use the same certificate for HTTPS scan, the admin must import the same certificate to all UTMs as a custom certificate. The operation can be performed on the Application Security -> HTTP/HTTPS -> Certificate Management page in the web GUI.
  3. Factory default will now create another random HTTPS scan certificate. Administrators should re-install this newly generated certificate into every browser after every factory default.
  4. Restoring configuration before v1.3.15-44 will NOT restore the old default HTTPS scan certificate. Restoring configuration in firmware v1.3.15-44 and after will restore the random HTTPS scan certificate used when the backup configuration package was created.

New Features since the last release (v2.1.0-53):

  • Added Sprint 3G dongle support.

Resolved issues (Since v2.1.0-53):

  • Enhanced the strength of the HTTPS scanning service for all UTMs.
     

Known Issues:

  • Not able to hear voice after a call is established from DMZ to LAN with server on the WAN and DMZ side.
  • SSL VPN client cannot be installed in some PCs with 3G adapters.
  • In WAN loading balancing, if one of the WAN connections drop, all the lines get dropped and reconnected automatically.
  • VLAN on VDSL is not supported. (UTM9S).
  • Application control and firewall is now available for IPSEC traffic. With this new feature the IPSEC performance is up to 12% lower than the previous release.

Caveats:

When installing SSLvpn, if there is a failure, a cache clean-up of the SSL-VPN adaptor is necessary. Use one of the following URLs to initiate the cleanup:

  • For 32-bit PCs, select the following url:
    https://<device IP>scgi-bin/users_portal/removeactivex?launch=true&is32bit=true
  • For 64-bit PCs, select  the following url:
    https://<device IP>/scgi-bin/users_portal/removeactivex?launch=true&is32bit=false

To Install

  1. Download the file, unzip it and follow the instructions provided in the user manual to upload the firmware.

This product includes software code developed by third parties, including software code subject to the GNU General Public License ("GPL") or GNU Lesser General Public License ("LGPL"). As applicable, the terms of the GPL and LGPL, and information on obtaining access to the GPL Code and LGPL Code used in this product, are available to you at NETGEAR's Open Source Code Web page. The GPL Code and LGPL Code used in this product is distributed WITHOUT ANY WARRANTY and is subject to the copyrights of one or more authors. For details, see the GPL Code and LGPL Code for this product and the terms of the GPL and LGPL.

Last Updated:10/17/2025 | Article ID: 21086

This article applies to:

Recently Viewed Articles

    Our team is here to help!

    Phone
    Chat
    Email