Introduction
Ivanti Connect Secure (ICS) is a next generation Secure access product, which offers fast and secure connection between remote users and their organization’s wider network. Ivanti Connect Secure modernizes VPN deployments and is loaded with features such as new end user experience, increased overall throughput and simplified appliance management.
Noteworthy Information
•This release supports 8500 and 6500 hardware devices, and this ICS version is embedded in the hardware and is not available for download.
•This release can only be upgraded on ISA 6500 hardware devices.
•This release version includes security enhancement. Ivanti encourages customers to upgrade to this latest version.
•This release supports 6500 hardware devices, and this ICS version is embedded in the hardware and is not available for download.
•Outbound HTTP/HTTPS proxy connections are restricted to a defined allow list of well-known proxy ports to align with Secure by Default.
Allowed ports: 8080, 8118, 8123, 10001–10010, 10080, 3130, 3445, 8008, 8010, 3128.
•Feature parity with ICS release 22.8R2.3 and 22.7R2.12
•Starting with ICS version 25.1.1.0 the default global (System > Configuration > Client configuration) and Role level (User > User Roles > <name> > VPN tunnelling > Ivanti Secure Access Client Settings) options for the ISAC Desktop user experience (UX) is set to NeUX for fresh installations of ICS.
•Ensure your environment allows installation and execution of the React Native Appx bundle used by NeUX.
•Follow the guidance in the forum article to enable the Appx bundle.
•Applies to: New installations to ICS 25.1.1.0, and later.
•Cluster setup which is running with version 22.8Rx does not support upgrade to ICS 25.x version. Cluster upgrade supports only on ICS 25.1.0.0 and above to ICS 25.1.1.0.
•SAML Authentication Server configuration using the SAML 1.1 Protocol is deprecated at ICS 25.x versions. From 25.1.1.0 onwards, the system will not allow new SAML 1.1 server configuration and will not allow to import any existing configurations. SAML 2.0 is the option supported. This deprecation was initially notified as part of this KB.
•The username displayed in the End User Portal is always in lowercase, similar to other authentication methods. The correct casing is maintained in the User Access and other logs.
•Before performing a pushConfig operation from an older release to version 25.1.1.0, you must disable the HTTP Only Device Cookie on the target device.
•For Admin Roles: Navigate to Administrators > Admin Roles > Delegated Admin Roles > Administrators > Session Options.
•For User Roles: Navigate to Users > User Roles > [Role Name] > Session Options.
•Referrer header validation is enabled by default to block CSRF attacks, providing an additional layer of security.
•All cookies will be deleted upon session terminated by default, enhancing security and privacy.
•Content Security Policy (CSP) headers are now implemented for end user pages to provide additional protection against Cross-Site Scripting (XSS) attacks."
•The Next Generation Web Server (Nginx) will restart when performing any of the following certificate-related operations. User connections may drop during this period:
•Mapping a device certificate to a port.
•Importing or deleting a trusted client CA.
•Making changes to inbound TLS versions and cipher suites.
To enable TLS 1.3 functionality, ensure that the enable_tls_v1_3 Key Value Pair is configured and pushed to ISAC mobile client (Android/iOS) from the MDM server.
Key-Value Pair Setting
•Configuration Key: enable_tls_v1_3
•Value Type: Boolean
•Configuration Value: true
•To enable TLS 1.3 functionality, ensure that the enable_tls_v1_3 Key Value Pair is configured and pushed to ISAC mobile client (Android/iOS) from the MDM server.
Key-Value Pair Setting
•Configuration Key: enable_tls_v1_3
•Value Type: Boolean
•Configuration Value: true
•ICS License Server cannot lease licenses to License Clients running versions 22.7Rx, 22.8Rx, or 25.1.x.x. See, forum.
•Certificate based authentication will not work after upgrading to 25.1.0.0, if client uses SHA-1 based certificates.
•SSLv3, TLS1.0 and TLS1.1 versions are removed and there are additional cipher changes implemented as part of this release. For more information, see Configuring SSL Options.
•Use of SHA1 for digital signature is not supported, use SHA2 and above:
•SHA2 is the minimum required version in digital signatures. ICS server will no longer connect or validate with SHA1 in digital signatures.
•Enable SHA2 as response signature algorithm in OCSP response on OCSP responder.
•If the ICS only contains SHA1 device signed certificates, the user interface fails to launch. At least one SHA2 signed certificate or any newer version after SHA1 is mandatory.
•Certificate Validation: HTTP/1.1 Enforcement for OCSP Requests Starting with version 25.1.0.0, certificate validation process now explicitly enforces the use of HTTP/1.1 for Online Certificate Status Protocol (OCSP) requests. This ensures consistent and reliable communication during certificate status checks. For more info refer KB.
•Cluster upgrade is not supported from 22.8R2 to 25.1.0.0. To upgrade, break the cluster, upgrade and then create the cluster again. For more information, see Cluster Migration from 22.8Rx to 25.x.
•For RSA Authentication to work, Add the agent's host name in RSA Auth Manager and configure it in ICS. Ensure the RSA/ACE server has a host entry in ICS.
•TCP is now enforced as the only supported communication protocol for the RSA SecurID integration. Legacy UDP-based communication is no longer supported.
•Update firewall rules to allow outbound TCP from ICS to the RSA Authentication Manager on the configured SecurID agent port(s) used in your environment, see KB for more details.
•As TCP is used, hostname-based validation is mandatory. As a result, the Hostname configured in ICS (Network → Overview) must match the Agent Hostname defined in the RSA Authentication Manager.
•This replaces the earlier flexibility of using internal IP addresses, which was possible with the legacy UDP-based integration.
•In this release, the /api/v1/healthcheck REST API response has been updated to return content as bytes, which aligns with the default behavior of many web frameworks and libraries when handling API responses. Previously, the response was returned as a string. This change could impact systems or integrations assuming the response would always be a string.
•Upgrade or Binay Import is not supported if SHA-1 certificates are configured on any ICS ports.
•Configs with deprecated features will be upgraded or imported to 25,x but will not be qualified. Please refer the KB for more details
•arping command no longer resolves hostnames. The command now requires a direct IP address as input. Attempts to use hostnames will result in an error.
Example error: Bad Value for ai_flags. Don’t use a hostname with arping.
•The ARP Maintenance >Troubleshooting >Tools >Commands>ARP option no longer supports hostnames as input. You must now specify a direct IP address when using this command. Attempts to use hostnames will result in following error.
Example error: Bad Value for ai_flags. Don’t use a hostname with arping.
Unsupported Features
•Ivanti Connect Secure: Features and Options Becoming Unsupported or Deprecated in 22.7Rx, 22.8Rx, and 25.x, refer to article.
Licenses
An ICS instance running version 22.8R3 can be configured as a License Server and is qualified to lease licences to 22.8Rx and 25.x instances acting as license clients. While an ICS instance running version 22.7Rx may technically be able to lease license to 22.8Rx or 25.x clients, this configuration has not been qualified. Therefore, it is recommended to use ICS version 22.8R3 or later when configuring a license server.
Known Limitations
•Cluster Node Name Restriction: Cluster node names should not be configured as "localhost2". Using "localhost2" as a node name is not supported and may result in unexpected. behavior.
•Per-app VPN on iOS in version 25.1.0: Occasionally, ICS does not fulfill certain requests, resulting in partial functionality for this use case. It is planned to resolve this issue in the upcoming 25.1.1.0 release.