Resolved Issues
The following table lists release numbers and the PRS numbers with the summary of the issues fixed during that release:
Problem Report Number |
Summary |
Release 22.7R2.3 |
|
1393255 |
Session Management( idle timeout, max session lifetime, session extension, etc) are not working. |
1414793 | Intermittent failures in Push Config due to login failure |
1394301 | End-user certificate (containing UPN name) verification fails when intermediate certificates contains a UPN Name Constraint |
1414857 | Different users could be assigned the same IPv6 address from DHCP when very specific conditions are met. |
1302526 | Errors when multiple intermediate CA certificates had the same name |
1378157 | Sign In Page Localization |
1390101 | File browser shows black screen when tried to refresh or open in new window. |
1366376 | File browser shows blank white screen when accessing file share bookmarks through the browser. |
1302196 | Login Syntax Change Impact on Syslog Agents After Device Upgrade |
1352015 | Misleading SYS30912 errors appears under user access logs |
1376910 | Remove postgreSQL log files when CLI cleanup option 31 is selected. |
1379602 | Error Invalid Profile Type 1 when configuring SSH Advanced HTML5 resource |
1386705 | Session ID not showing as expected in User Access log |
1391194 | "Custom Settings" for Delegated Admin Role is not working as expected |
1355032 | Internal ICT scan failure (false positive) with a file nohup.out |
1356278 | External Integrity Scan and showing pyc files as new (false positive) |
1354977 | External Integrity Checker showing cert.pem.bak and key.pem.bak(false positive). Also flagging a file name pkgversion.3 (false positive) |
1395490 | Unable to configure Variable Attributes under Host Details in Terminal Services Configuration |
1397105 | Improve Watchdog log message to capture the command being executed by /bin/bash |
1379860 | Unable to enter characters when Chinese Traditional Taiwan language is enabled on local PC and html5 RDP resource. |
1413440 | Advanced HTML5 : improve pop up messages |
1368090 | ICS SNMP Unresponsive to ‘get’ queries |
1375437 | FTP Archiving failing for user logs |
1414845 | Program DSWSD recently failed when using certificate authentication |
1416142 | Process snapshots generated for unityConfigSpli & unityConfigNetc after registering ICS with Pulse One |
1413774 | License leasing not working correctly for appliances on 22.7Rx when the reserved license is configured as Zero |
1411563 | UI Issue with Radius Custom Rule Configuration with 22.7R2 and later |
1302207 | When the Active node shutdown from Active node the Passive node is not taking the VIP. |
1429771 | PSA7000 generating "First failure for a power supply reading" in the event logs |
1428971 | Implement log rotation for ive-ec2connect.log AWS deployments. |
1383587 |
AD domain join takes 15 mins to join. |
Release 22.7R2.2 |
|
1418051 |
Improved handling of CA/intermediate certificates that do not have a CN value |
1418054 |
Addressed issues when using two different CA/intermediate certificates that have the same CN and issuer. |
1418042 |
Addressed an issue with swap memory management on ISA8k |
1418049 |
Addressed an issue with swap memory management on VM devices |
1395150 |
UAL license not working for EU region |
Release 22.7R2.1 |
|
PRS-418942 |
Users are having failed realm restrictions even when the location is allowed. |
PRS-418576 |
User access logs displays the wrong Username, when ending a Terminal Session |
1379870 |
Traffic Segregation in Hyper-V is not saving the VLAN ID under available Interface. |
1302171 |
Users session gets disconnected on Windows 10 systems due to the Host Checker time out. For more see KB. |
1353427 |
IPTable rules default policy set to "ACCEPT" allowing all ports. |
1302246 |
User access logs provides 127.0.0.1 address for source IP when an attempt with wrong credentials fails. |
1302272 |
Session ID is not displayed in the "Closed connection" logs consistently. |
1350553 |
Staging user summary table entries are being appended |
1355655 |
JSAM Certificate is expired in 22.7R2 |
1352719 |
External Integrity Scan is Failing on the 22.7R2 server showing 85 mismatched files this occurred in Azure deployment only |
1373106 | Issue in displaying Special Characters when using French text in Welcome Message on ISA-6000. |
1373377 | ICS devices deployed in Azure are becoming unresponsive with "No space left on device" errors. |
1348873 |
iveConcurrentUsers count is 0 in SNMP Traps. |
1341262 |
Sometimes, Advanced HTML5 session does not respond to mouse clicks. |
1341797 |
Cluster creation with IPV6 and default VLAN Id is not supported. |
Release 22.7R2 |
|
Refer to Security Advisory and Patch Release section to see CVEs fixed.
|
|
PRS-418027 |
Sending iveMaxConcurrentUsersSignedIn SNMP alert for Leased licenses from License Server. |
PRS-419899 |
Keyboard input is printed twice when host and PC language is Chinese. |
PRS-419817 |
Geolocation based realm restriction failing for user login. |
PRS-418576 |
User access logs Shows wrong Username ,when ending a Terminal Session. |
PRS-419357 |
System State storage size has reached max limit. |
PRS-419198 |
Automatic detection with "unknown Keyboard" as keyboard layout does not work in Advance HTML5 pre-Login |
PRS-419162 |
Wildcard Device certificate deletion with REST API is not working Properly. |
PRS-419394 |
Difficulty in Joining Device to Domain Using Only Reset Join option with AD Authentication. |
PRS-419159 PRS-420242 |
VPN users dropped suddenly on gateway due to reboot. |
PRS-419107 |
Avoid False Positives in ICT |
PRS-419098 |
High CPU usage is noticed in all of the 12 nodes deployed. |
PRS-419086 |
Import of System config/XML config related to bandwidth Management fails on ICS |
PRS-418969 |
Certificate Auth failing is due to Missing Authority Key Identifier. |
PRS-418954 |
Mitigating login issues through reboot or failover. |
PRS-418930 |
Certificate Host checker is failing after upgrading to 22.6R2. |
PRS-418849 |
Unable to authenticate user using certificate with "Wrong Certificate::unsupported name constraint type". |
PRS-416861 |
“Dropping the duplicate tunnel session from client” is seen in User Access Logs. |
PRS-418161 |
SNMP Traps are not being generated when the redundant power supply is turned off. |
PRS-418682 |
Singpass (SAML) Authentication fails when Load balancer URL is configured under the "Host FQDN for SAML". |
PRS-418443 |
Not able to update ICS server appliance from 22.4R2 to 22.6R2. |
PRS-418434 |
SSO stoped working for the FileShare Bookmarks after upgrading ICS to 22.6R2 version. |
PRS-418392 |
Rewrite getting blank page via Host-based PTP. |
PRS-418219 |
MDM Setup Issues with Microsoft Intune with Authentication and Authorization Challenges. |
PRS-417969 |
AD join fails with ISA when Domain name has a special character '&' |
PRS-418134 |
SID is not being displayed completely. |
PRS-417750 |
iOS 17 has introduced a change in the IKE code, to make it stricter in compliance with RFC7296 |
PRS-417300 |
Ikev2 error messages seen in the User Access logs. |
PRS-417319 |
High CPU usage at 100 % for ICS due to 64K size DNS response. |
PRS-417668 |
Scrolling Bar Accessibility Issue on welcome page in Multiple Browsers. |
PRS-417152 |
Upgrade to 9.1 R18.1 fails due to SSH/Telnet deprecation check. |
PRS-417355 |
Inactivity reminder timeout, when users are using web session post migrating to 22.3R1. |
PRS-417140 |
Failing to get Intune MDM Attribute Intermittently. |
PRS-416968 |
Chinese characters in file share bookmarks are garbled. |
PRS-416896 |
After migration to ICS the Disk Space is showing as full on the active node in A/P cluster. |
PRS-416479 |
Website loading slow after the upgrade with PassThroughProxy. |
PRS-416169 PRS-420178 PRS-419764 |
Unable to connect to VPN, SAML authentication fails after upgrading the appliance to 22.4R2. |
PRS-418524 |
Unexplained reboots on ISA 8000c A/A Cluster. |
PRS-417756 |
DFS Share access is not working with 22.5R2.1. |
PRS-418105 |
Web process crash on PSA 7000c due to memory leak. |
PRS-417933 |
ICS Azure VM Virtual Wagent showing status not ready and impacting in taking Azure level VM backup in 22.x. |
PRS-417302 |
Database percentage = 99, shard 3 operation above threshold. |
PRS-417816 |
ICS Realm limits are not honored when nSA Named User Licensing mode is used. |
PRS-417665 |
REST-based configuration updates may fail with an HTTP 500 error. |
PZT-45037 |
SNMP trap messages under Event log to be removed. |
PZT-44342 |
Config sync rule on the nSA shows Failed and Pending status. |
PZT-44321 |
Readiness failures observed in Gateway. |
PZT-44103 |
Single node cluster to support config sync and Report generation. |
PCS-44875 |
Event logs are filled with certificate expired error message. |
PCS-44362 |
Failed to save package, cannot copy UEBA package. |
Release 22.6R2.1 |
|
PRS-417750 |
iOS 17 has introduced a change in the IKE code, to make it stricter in compliance with RFC7296 |
PRS-418167 |
Program "impexpserver"crashed while importing Connection Profile via XML. |
PRS-418021 |
UEBA option is missing in Pulse one admin UI. |
PZT-42378 |
Peer SP configurations are not getting uploaded to nSA with appropriate title. |
PZT-42049 |
Gateway information not being synced with nSA on 22.5R2.1 version. |
PZT-41931 |
ICS is synchronizing users in Auth Servers to Pulse One. |
PZT-41850 |
ICS Gateway (Event, Admin and user access) Logs are not seen in nSA controller. |
PZT-41637 |
HTTP error 500 after PUT and Unknown errors in Gateway Events Access logs |
PZT-41535 |
Config sync rule on the nSA shows Failed and Pending status. |
Release 22.6R2 |
|
PCS-41732 |
Port probe: Internal port IPv6 address is incorrectly populated when the user selects Management port with family type as IPv6. |
PCS-43985 |
VPN tunneling filter deletion for IPv6 under System > Network > VPN tunneling. IPv6 filter not assigned to VPN clients if no filter is specified. |
PCS-35445 | Unable to set FIPS mode for web server. |
PRS-416742 |
User Access log may fill quickly. |
PRS-417352 |
Pulse One config sync issue after clearing nSA registration. |
PRS-417245 |
ICT detects random mismatch while integrity scan. |
PRS-416118 |
Host Checker with Certificate check fails due to CRL expiration frequency error. |
PRS-416313 |
Advance HTML5 RDP Access with white space and resolution issue. |
PRS-416834 |
Remote file transfer Advance HTML5 issue is resolved. |
PRS-416483 |
NTP stops working after internal port is set with a default VLAN, though NTP is set to external or management port. |
PRS-416460 |
Folders and files names containing character such as &,# does not open in Windows Fileshare. |
PRS-416274 |
PSAM sessions may disconnect frequently after upgrading to 22.4R2 ICS. |
PRS-416776 |
Error on Safari browser searching for browser extension. Added check for Safari browser on 22.x end-user portal with respect to ISAC launch. Now clicking on ISAC launch, will not redirect to browser extension. |
PRS-416627 |
DHCP FQDN’s getting truncated in ICS DNS query. |
PRS-416157 |
Lost syslog connection to server. |
PRS-415988 |
Active directory users with HC log links from the active directory page will now redirect to the destination page. |
PRS-417128 |
Unable to fetch device username attribute from Airwatch MDM. |
PZT-41472 |
Config sync template status not progressing and shows as Pending. |
PZT-41791 |
Frequent restarts of Fluent-Bit services. |
PCS-43559 |
AD join from troubleshooting page fails with Error "Failed to find DC for domain <DOMAIN NAME> - Undetermined error". |
PCS-42906 |
Few expired trusted server CA are not getting deleted. |
PCS-38894 |
Advanced HTML5 external storage feature will not work. |
PCS-42311 |
VPN fails to connect with Login Failed Error on Android with Host Checker. |
PCS-39986 |
ICS initial configuration is not getting configured automatically from vApp options. |
PCS-41405 |
VM upgrade and installation progress messages before reboot are not seen on VM serial console. |
PCS-40467 |
On single core CPU platform, web server snapshot can be generated upon Security related configuration change. |
PCS-25948 |
SAML versions and configuration mode. |
Release 22.5R2.1 |
|
PRS-416873 |
Error joining ICS to AD domain if SMBv1 is disabled. If you upgrade to 22.5R2.1, with SMBv1 disabled, AD Domain join fails after upgrade. Do a reset join on troubleshooting page post upgrade. For more information, see forum link. |
PRS-416911 |
SAML Transfer failed with error message "Relay State does not match with the Server Host name". The Sign-in policy should be configured with the login URL, if the login URL is different from the Host FQDN. |
PRS-416576 |
An iOS/Android device connected to an ICS gateway with L3 App Visibility enabled and registered with nSA experiences a process crash. |
PRS-416513 | ICS is synchronizing users in Auth Servers to Pulse One. |
PRS-415055 |
Launch JSAM policy fails to launch JSAM |
PRS-416351 |
HTML Tag's are not working as expected in the Personalized greetings page. |
PRS-416032 |
Unable to download files or folders that contain special characters while using Windows file sharing. |
PCS-40794 |
Launching the Web bookmark via JSAM has issues. |
PRS-415997 |
CGI server process crashing frequently in unique environments and configurations. |
PRS-415690 |
Settings are lost after hard power cycle or power loss - ISA hardware appliance. |
PRS-415097 |
SAML authentication fails with some SAML providers due to formatting errors based on RFC-2045. |
PRS-415886 |
Built in Integrity check scanner tool in ICS does not accept 0 in hour field for scheduled scan so cannot be scheduled between 12 AM and 1 AM. |
PRS-414815 |
File share contents are not available when browsing the file via bookmarks if the file share is only \\server\ and not \\server\share. |
PRS-416062 |
Member of A/A cluster froze with kernel panic error. |
PCS-41273 |
End-users are receiving "VPN Server is busy and unable to accept new connections." on the ISA Client, and unable to access intranet. |
PCS-40656 |
On a Mobile device, if user logged in to web portal via browser and launching VPN connection will fail to establish VPN session. |
PCS-41007 |
ICS does not send logs to remote syslog servers and nSA impacting analytics. |
PCS-40006 |
File browsing with hostname is going through IPV4 address when"Preferred DNS Response:" is configured as IPv6. |
Release 22.4R2.1
|
|
PRS-415402 |
Filename Is Trimmed After Uploading via File Share Server Bookmark in ICS 22.X Versions. See forum link for more details. |
PRS-415686 |
ISAC shows password expiration warning even when the number of days configured in realm for warning is less than the password expiration day for Embedded Browser Sessions. |
Release 22.4R1
|
|
PCS-34411 |
Logs are not pushed from gateways to nSA. |
PRS-414033 |
Boot failure issues with the ISA 8K devices. |
PRS-415234 | TOTP Remote server fail with REST API error |
PRS-415017 | Unexpected re-boot on ISA6000-V running 22.2R4 |
PRS-414999 | One of the nodes in APAC region was unresponsive. |
PRS-414278 | Camera redirection does not work on ICS. |
PRS-414111 | Sign-out screen is garbled when browser language is Japanese |
PRS-414024 | Unable to add perpetual license on the ISA device |
PRS-412571 | Ivanti Connect Secure - Sorting issue for the core access files |
PRS-412382 | 22.1R6 System.J corrupted which causes reboot the device |
PCS-36684 |
Page refresh issue on end user portal. |
Release 22.3R1
|
|
PCS-37128 |
XML import fails in release 22.2R1 version when HTML5 resource profiles exported from release 9.1R15 or R16 . |
PCS-35512 |
User browses to appserver URL with 8083 port (http://appserver:8083/test.asp), it re-directs to some other webpage. |
PCS-36787 |
Certificate validity check shows certificate expired for less than 90 days. |
PCS-37104 |
Downloaded Protected Zip File (1KB) is empty but actual file size is 2.07MB. |
PCS-36764 |
File cannot be downloaded or deleted from the end user UI. |
PCS-37090 |
Black screen is shown when user tries to download PSAL from Safari browser. |
PCS-37092 |
End user Onboarding option is not displaying on MAC OS. |
PCS-36675 |
Panel Preferences for Admin/end user bookmarks is not shown. |
Release 22.2R1
|
|
PCS-36319 |
Save All Logs option missing from Events/User Access/Admin Access Logs |
PCS-34870 |
Clear config data fails with errors. |
PCS-33729 |
Cache cleaner policy is not getting imported when importing XML file for user role configured with cache cleaner policy. |
PCS-34546 |
9.X HLGW : KVM : Post upgrade not able to access GUI |
PCS-34530 |
Rollback via console is not working on KVM appliance. |
PCS-34357 |
Bandwidth consumption is more than configured when downloading files using SSL tunnel mode. |
PCS-34870 |
Reboot fails on selecting clear config from CLI menu. |
Release 22.1R6
|
|
PCS-36093 |
Configuration import fails with reason: software version used to create import file was '9.1R14 (build 16847)' current version of software is '22.1R1 (build 421)'" |
Release 22.1R1
|
|
PCS-30919 |
Copy paste from Advance HTML5 session stops working after a while. |
PCS-32765 |
Flow change seen in End User portal while internal server File Browsing. |
PCS-30489 |
Bandwidth not restricted for the user even though VPN Tunnels Maximum Bandwidth value is set. |
PCS-32836 |
Pulse Client copyright date is not updated with 2022 year. |
PCS-32596 |
Upgrade from 9.1R13 and 9.1R12 GA to 9.1R13.1 is failing at the upload step with Access restricted error. |
PCS-32906 |
ISA VM machine ID getting changed. |
PCS-32354 |
Registration status of ICS is in green color. |
PCS-33249 |
Error message at the end of successful completion of ICS boot. |
PRS-407283 |
Multicast and broadcast packets soft lockup issue observed with ICS Gateway on AWS. |
PRS-408401 |
Configuration import fails on ISA. The Migration Guide is updated with the supported configuration migration path. ICS Release 21.12R1 supports config import from Release 9.1R13 and below |
PRS-407958 |
ICS on VMware console shows watchdog |
PRS-407283 |
ICS 21.12 soft lockup in AWS. |
PRS-407281 |
Node is not accessible, software lockup issue. |
Release 21.12R1 |
|
PRS-405611 |
Login to PDC to get authentication twice one before HC and one after HC when using DUO-LDAP. |
PCS-30626 |
Failed to update profile for user error is seen in user access logs for every user. |
PCS-30694 |
Number of concurrent users exceeded msg seen, even though licensed through nSA named licensing |
PCS-31161 |
Error updating data messages seen after upgrade to 399. |
PCS-31046 |
XML import from 9.X HLGW to 21.X not working on a specific scenario. |
PCS-30652 |
Host checker failed in Mac OS with server has not received any information for this policy error. |
PCS-31213 |
PDC L3 Multicast with 21.9R1 - IGMPv3 to v2 fallback is not happening automatically. |
PCS-31193 |
health check REST API is returning 500 Internal Server error. |
PCS-30658 |
System Maintenance > Run Diagnostics throws error. |
PCS-29657 |
Kill command seen on the virtual console on fresh deploy of 21.6R2_273. |
PCS-30629 |
Old sign-in page seen if ICS is not able to reach remote TOTP server. |
PCS-30854 |
Push Config of Selective Config fails with error related to HTML5-access sessions. |
PRS-406156 |
Chinese characters on the end user portal page is not appearing properly. |
PRS-406805 |
Issue with VLAN while getting the tunnel IP in A/P cluster. |
PCS-31734 |
Host Checker Compliance Result user access logs have either device_id or browser_id which is mandatory for analytics. |
PCS-31730 |
nSA ICS Overview dashboard Info panel showing empty values. |
PRS-404854 |
ICS Gateway: Temp license is not expired even at 56 days. |
PCS-31473 |
TCP dump not uploaded to nSA |
PRS-405612 |
LDAP: Login in PDC gets authentication twice one before HC and one after HC when using DUO-LDAP |