Jobs (DE)Terms of UsePrivacy PolicyLegal Notice

Licensing of S/MIME gateway option

At the request of many of our customers we changed the licensing of the S/MIME gateway. It is now no longer licensed by user count but by the number of S/MIME keys. No license is required for S/MIME keys used as domain certificate (see next section).

New S/MIME gateway features

The S/MIME gateway now support the non-standardized concept of domain certificates. This feature can be used for free on almost all systems (exception: licenses without mail option like Enterprise VPN or Enterprise Proxy). With domain certificates, the S/MIME communication with specific peers is protected by a single S/MIME certificate for the whole domain instead of one certificate per email address. It is even possible to use the certificate of an internal CA. The peers however have to use S/MIME software which supports this concept and set it up accordingly.
It is no longer necessary to add users when the S/MIME gateway is used in combination with an internal mail server. For internal mail servers that guarantee correct sender addresses, a separate list with corresponding S/MIME keys is now maintained.
In the user administration you can now configure multiple S/MIME keys per user. When signing outbound emails the system will automatically select the matching key.
In previous releases it was possible to add multiple keys per user to decrypt inbound emails which had been encrypted with an old key. This functionality is now provided by the key-ring (see next section).

Backup when updating a key-pair in the keyring

When changing a key-pair in the keypair, a backup of the previous key-pair is kept on the device.
The S/MIME gateway uses backup keys to decrypt emails which have been encrypted with the old key during a key rollover phase.

Removal of expired entries in DNS IP objects

The default setting for deleting expired entries in DNS IP objects has been changed from "immediately" to "after 6 hours". This prevents permanent service restarts if DNS entries change after few minutes or even seconds. The update will alter the configuration of all IP objects which remove "immediately" automatically.

Let's Encrypt certificates

The Let's Encrypt client now uses the ACMEv2 protocol.

DHCP relay server

On all ethernet and VLAN interfaces the device can now act as a DHCP relay server, forwarding requests from clients to a DHCP server in a different network.

Endless loop when viewing IPsec log

In most IPsec log lines there's a link which opens an extra window to show all lines associated with the same connection. This extra window caused an endless loop, resulting in permanent high system load.

Minor bugfixes and improvements

Update of the POP3/IMAP4 server

This update fixes a critical security issue. An attacker was able to read protected information or even execute their own program code without authentication.

Improved macro detection in email attachments

Now macros will also be recognized if office documents have been mailed directly (not as attachment) or if they are attached to an attached email.

New categories for the commercial URL filter

New categories have been added to the commercial URL filter: Arms and weapons, DNS-over-HTTPS, Movies and series with questionable legal status, Education, Restaurants and recipe sites, Buy or rent a place to live, Stock markets and trading systems.

Adding new certificates to the keyring

For each certificate the corresponding root and intermediate CA certificates have to be stored. Previously the CA certificates had to be uploaded manually for each new certificate. Now the certificates of well-known root CAs will be added automatically. Certificates of intermediate CAs will be cached upon the first upload and added automatically when required by subsequent certificates. Adding multiple similar certificates as required by the S/MIME gateway feature becomes much more convenient in this way.

Minor bugfixes and improvements


DEFENDO forces a collection of best-of-breed security modules like firewall, VPN, proxies, virus scanner and anti spam system to interact for one purpose:
To be protected from all online threats and unwanted contents like malicious code, spam and hacker attacks.


Each IT scenario is different. The DEFENDO product family will adapt precisely to your demands.
DEFENDO applies for simple internet connections of small companies, for headquarters / branch office WANs, as well as for complex multi-tiered firewall systems.

More good reasons

  • No backdoors
  • More than 20 years of Internet security experience
  • Award-winning product
  • Support by our development engineers
  • Reseller loyalty
  • Made in Germany