Known Issues

The following table lists the known issues in respective release:

Problem Report Number

Release Note

Release 25.1.3.0

Upgrade and Deployment

1775958

Symptom: Upgrading from a staged package may fail with the following error: "ICS Service Package does not support package version on this device". This error can occur even when an ICS 25.1.2.0 or later package has been successfully uploaded to the staging area.

Conditions:

  • The ICS instance is running a version earlier than 25.1.2.0 on a virtual appliance.

  • An administrator stages an ICS 25.1.2.0 or later package successfully.

  • The administrator then attempts to perform the upgrade using the staged package.

Workaround: None. Upgrades to ICS 25.1.2.0 or later are not supported on earlier than 25.1.2.0. Try direct upgrade to get the error immediately.

1970766

Symptom: Upgrade from ICS 25.1.3.0 build to any 25.x build fails but the messages on Admin UI says: ICS Package scan completed successfully.

Condition: This issue occurs when the upgrade is attempted after running Ext ICT on ICS.

Workaround: After running an Ext ICT, reboot ICS before attempting the ICS upgrade. The upgrade completes successfully after the reboot.

1870595

Symptom: During an upgrade, the image displayed on the web interface appears oversized and zoomed in, resulting in a pixelated and misaligned appearance on the page.

Condition: Occurs while upgrading to Ivanti Connect Secure (ICS) version 25.1.3.0 (build or release).

Workaround: NA

1939424

Symptom: When an ICS custom image is selected on the GCP instance creation page, the Provisioned IOPS value is initially displayed as 2000.

Condition: This issue occurs while configuring the ICS instance in GCP, under the OS and Storage section, after selecting the custom ICS image. At this stage, the Provisioned IOPS value cannot be edited.

Workaround:

To set the correct Provisioned IOPS value:

1.In the OS and Storage section, select the required ICS custom image from the dropdown.

2.The Provisioned IOPS value is initially displayed as 2000.

3.Click Select to save the configuration.

4.Reopen the configuration by clicking Change.

5.The Provisioned IOPS value is now displayed as 3480.

6.Click Select again to save the configuration with the updated Provisioned IOPS value of 3480.

Clustering and High Availability

1921438

Symptom: End users may be required to re-authenticate after the VIP Holding Node setting is enabled or disabled in an Active-Passive cluster configuration.

Condition: This issue occurs when the VIP Holding Node option is enabled or disabled on an Active-Passive cluster.

Workaround: Use of the VIP Holding Node option is not generally recommended. If it must be enabled or disabled, perform the operation during a planned maintenance window to minimize user disruption and potential re-authentication events.

1969044

Symptom: End users can connect to the VIP, but backend resources become inaccessible. This occurs because network packets are no longer tagged after one of the VLAN interfaces goes missing.

Condition: This issue occurs when multiple VLAN interfaces are configured on a physical interface and VIP failover testing is performed by using the Failover VIP button and restarting services. During the failover process, a tentative IPv6 address may be observed intermittently. In some cases, one of the VLAN interfaces may be unexpectedly deleted or may no longer appear in the ifconfig output, resulting in loss of access to end-user resources.

Workaround: Reboot the affected ICS device to restore the VLAN interface and recover connectivity.

1967862

Symptom: Backend resources are not accessible.

Condition: This issue is seen under the following conditions:

Source Port under Roles is set to use VLAN Virtual Port.

Use /api/v1/cluster to change the cluster type from AA to AP.

Workaround: Do Failover VIP so that the VLAN virtual ports get created properly on the other node.

1938819

Symptom: EUP login lands in blank page in cluster

Condition: When logged in as an end user

Workaround: Clicking on home icon will do

1938796

Symptom: SSH, RDP Remote file transfer, RDP print fail to work in cluster

Condition: When tried in cluster

Workaround: N/A

1949670

Symptom: Deleting a host entry at the cluster level displays the same host entry removal message twice.

Condition: This issue occurs when a host entry is deleted in a clustered deployment.

Workaround: NA.

1954185

Symptom: The UEBA package is not synchronized to one of the nodes in a cluster.

Condition: This issue can occur when the UEBA package is uploaded to only one node in the cluster.

Workaround: Manually upload the same UEBA package to the affected node in the cluster to ensure successful synchronization and availability across all nodes.

1770956

Symptom: Antivirus or Firewall remediation actions to enable Real-Time Protection (RTP) do not work.

Condition: This issue occurs when using agentless Host Checker (HC) on Windows endpoints.

Workaround: NA

Configuration Management

1933309

Symptom: The Push Config feature does not work when pushing configuration from an ICS 25.1.1.0 gateway to an ICS 25.1.3.0 gateway after HTTP/2 is enabled on the target 25.1.3.0 device.

Condition: This issue occurs because the required HTTP/2 support and associated fix are available only in ICS 25.1.3.0.

Workaround: Either of the following options can be used:

Upgrade the source gateway to ICS 25.1.3.0 before performing the Push Config operation.

Disable the HTTP/2 feature on the target ICS 25.1.3.0 gateway when the source gateway is running a release earlier than 25.1.3.0.

1925041

Symptom: Importing a user configuration fails when the configuration includes Web Proxy settings.

Condition: Occurs when attempting to import a configuration containing Web Proxy configuration.

Workaround: Use the XML configuration file to import the Web Proxy settings successfully.

1936818

Symptom: There is no option to push HTML5 storage configuration through the configuration push mechanism.

Condition: This issue occurs when attempting to push HTML5 storage configuration.

Workaround: Use XML import or user configuration import to transfer the HTML5 storage configuration.

Web Proxy

1927755

Symptom: Web Proxy use cases configured through the REST API are not handled correctly.

Condition: This issue occurs when Web Proxy configuration or management operations are performed using the REST API.

Workaround: Use the Admin UI to configure and manage Web Proxy settings.

Monitoring and Logging

1938472

Symptom: TLS Syslog forwarding fails when configured to use a custom port.

Condition: This issue occurs when TLS Syslog is configured with a custom port instead of the default TLS Syslog port.

Workaround: Configure TLS Syslog to use the default port. TLS Syslog forwarding works as expected when the default port is used.

1961487

Symptom: When an SNMP request is performed for Fan Status or Power Status on ISA6500 or ISA8500 hardware devices, the SNMP MIB browser displays the message"No such object".

Condition: This issue occurs when querying the Fan Status or Power Status OIDs through an SNMP MIB browser on ISA6500 or ISA8500 hardware platforms.

Workaround: N/A

Networking

1951563

Symptom: Hostname resolution fails when a hostname is mapped to an IPv6 address.

Condition: This issue occurs when the hostname contains uppercase letters or special characters.

Workaround: Use only lowercase letters in the hostname. Hostname resolution works as expected.

1936692

Symptom: NFS mounts from the ICS shell may fail when the NFS server is located on a different network than the ICS internal interface.

Condition: NFS server is reachable only through a different network path.

Workaround: Add a route that allows the ICS management IP to reach the NFS share through the appropriate internal interface.

User Experience

1935112

Symptom: The Home button displayed on HTML5 maximum connections warning page does not redirect users to the Home page.

Condition: This issue occurs when users click the Home button on the maximum connections warning page.

Workaround: Close the tab or use the Home icon

Security and Compliance

1970177

Symptom: External ICT incorrectly detects the file /data/runtime/tt/report_behavioral_analytics_user.thtml.ttc as an anomaly.

Condition: This issue occurs when Source IP/Location-based restrictions are enabled.

Workaround: NA

Platform-Specific

1966605

Symptom: The message "generate_grub2_config: failed to stamp SB diagnostic version for system A" is displayed on the console.

Condition: This message may be observed during a fresh installation on the OpenStack KVM platform.

Workaround: NA

JSAM

1971454

Symptom: A warning message,"You don't have permission to change host files", is displayed when launching JSAM on Ubuntu.

Release 25.1.1.1

1879013

Symptom: JSAM launch fails on MAC OS

Condition: When JSAM is launched via all browsers.

Workaround: There is no workaround

1867641

Symptom: Copy and paste do not work in VNC.

Condition: Occurs when using an Ubuntu VNC bookmark.

Workaround: NA

1861808

Symptom: Copy and paste do not work in the HTML5 SSH bookmark.

Condition: Occurs when attempting to use Ctrl+C and Ctrl+V.

Workaround: Pasting with right-click works.

1874029

Symptom: End users are prompted to enter secondary authentication every time, even though Adaptive Auth is enabled under Realms.

Condition: In rare situations, the ICS code fails to establish a connection with the UEBA database, which is required for Adaptive Auth functionality.

Workaround: Restarting the services resolves the issue.

Release 25.1.1.0

Clustering

1816740

Symptom: Internal ICT periodic and scheduled scans do not work in a cluster.

Condition: Observed in a clustered environment.

Workaround: NA

Windows Terminal Services

1819807

Symptom: The administrator is unable to enable the options “Deny single sign-on for sessions added by user” and “Enable Remote Desktop launcher”.

Condition: This issue occurs on the Terminal Services options page.

Workaround: NA

1820150

Symptom: The “Allow users to enable local resources defined below” options are enabled by default.

Condition: On the Terminal Services page, the administrator is unable to disable these options.

Workaround: NA

Logging & Debugging

1776690

Symptom: Process names specified in debug log configuration do not appear in the Admin logs.

Condition: This issue occurs when process names are included in the debug log settings.

Workaround: NA

Authentication

1800576

Symptom: End-user logins fail when authenticating against the certificate server.

Condition: This occurs when users present a certificate issued by a leaf (Subordinate) CA in a three-level certificate hierarchy (SubCA signed by Intermediate CA, which is signed by the Root CA), and OCSP checking is enabled for certificate validation.

Workaround: Enable TLS 1.3 on the server to restore successful user authentication.

UEBA

1796977

Symptom: Time mismatch observed in UEBA user anomaly reports displayed in the admin UI.

Condition: The issue occurs when downloading the reports as CSV files.

Workaround: Convert UTC timestamps to ICS local time, or vice versa, as required.

Backend Access & Domain Info

1788320

Symptom: Hostname and port-based Pass Through Proxy (PTP) does not work.

Condition: Issue is observed when attempting to connect to backend servers such as VDI.

Workaround: Accessing the backend server directly via the Rewriter component works.

1776653

Symptom: The List Domain Info page displays the same IP address and FQDN for all listed domains.

Condition: This issue occurs when configuring an AD server that has trusts established with other AD servers.

Workaround: NA

WAF

1799672

Symptom: WAF logs are not displayed in the event logs section.

Condition: This issue occurs when Nginx Fluent Bit is turned off.

Workaround: Disable and then enable the "WAF message" option under the event logs settings page.

JSAM

1788311

Symptom: PSAL is unable to download, as button is not working, particularly in Ubuntu 24, JSAM is also blocked.

Condition: Occurs when end users access ISAC options from a client session on Ubuntu 24, resulting in PSAL download failure and JSAM blockage.

Workaround: None available at this time.

1783670

Symptom: A warning pop-up message stating "You don't have permission to change host files" appears when launching the JSAM applet.

Condition: This issue is observed only when the DSID cookie is enabled at the role level option.

Workaround: Disable the DSID cookie at the role level option to resolve this issue.

Web Access

1799537

Symptom: 502 Bad Gateway error is observed.

Condition: Occurs when navigating to Maintenance > Archival > Archiving Servers and entering a valid hostname or IP address, but leaving the destination directory, username, and password fields empty. Selecting any archival component and saving changes triggers the error.

Workaround: NA

Release 25.1.0.1

Certificate & Authentication

1772978

Symptom: 3-level hierarchy certificate authentication is not functioning.

Condition: This occurs when OCSP is enabled for certificate status checking.

Workaround: None available at this time.

1711706

Symptom: When switching from TLS 1.2 to TLS 1.3, end users are not prompted to select a user certificate and instead see a "Missing certificate" error.

Condition: This issue occurs when the server is configured to use TLS 1.3.

Workaround: One of the following workarounds may resolve the issue:

Restart the end user machine.

Restart the ICS server.

Try accessing with a different browser.

HTML5

1777466

Symptom: Unable to create HTML5 SSH resource profile via REST API.

Condition: While creating resource via REST API.

Workaround: Works as expected with Admin UI.

1778321

Symptom: File upload fails during an SSH session.

Condition: This issue occurs when attempting to upload files within an HTML5 SSH session.

Workaround: NA

JSAM

1751812

Symptom: PSAL is unable to launch the Java applet (JSAM) on Mac machines on Safari browser.

Condition: This occurs when an end user accesses a JSAM bookmark on a Mac machine with "HTTP Only Device Cookie" enabled.

Workaround: NA

Release 25.1.0.0

Authentication & User Login

1625208

Symptom: An "Invalid file" error occurs when uploading the sdconf.rec file during ACE server configuration.

Condition: This issue occurs when the sdconf.rec file is generated from an RSA server running version 8.8 or later.

Workaround: Use an sdconf.rec file generated from RSA server version 8.7 or lower.

1384221

Symptom: Advance HTML5 SSH session fails to login via private key.

Conditions:Occurs when attempting login via private key authentication in the web-based SSH client.

Workaround: Login via password is supported.

1634450

Symptom : Java Secure Application Manager (JSAM) does not work on Mac systems..

Condition: Occurs when an end user attempts to access the JSAM applet using the Pulse Secure application on a Mac; the application is unable to launch the Java applet.

Workaround: NA

1628264

Symptom: End user login is failing even though file is present in the path and logs are wrong; Host Checker is validating all the unselected policies.

Condition: If custom File process is selected and file is present in the mentioned path.

Workaround: Clientless is working.

1634677

Symptom: Default admin realm cannot be deleted.

Condition: When admin tries to delete default admin realm from UI.

Workaround: NA

1637539

Symptom: RADIUS disconnect requests do not terminate the session.

Condition: Occurs when “processing of RADIUS disconnect requests” is enabled in the RADIUS server configuration.

Workaround:NA

1642615

Symptom: Rarely, admin login fails with "invalid username or password" error message.

Conditions: Mostly observed when admin is logging in for the first time.

Workaround: None. Repeated login attempts should resolve the issue

Certificate, CRL, CA & Encryption Configuration

1561276

Symptom: The certificate authentication end-user page becomes inaccessible after enabling the "Advanced Certificate Processing Settings" option under trusted client CA configuration.

Condition: Occurs when, the “Advanced Certificate Processing Settings” option is enabled for a trusted client CA in the admin UI.

Workaround: Disable "Advanced Certificate Processing Settings".

1590484

Symptom: Node secret is not generated on the RSA server, resulting in the absence of the node verification file on the Ivanti Connect Secure (ICS) device.

Condition: After the first end-user login, the ICS device does not display (or contain) the node verification files, indicating that node secret establishment with RSA SecurID is not occurring as expected. There is currently no impact on system functionality.

Workaround: NA

1590662

Symptom: Enabling “Validate Server Certificate” for LDAP connections does not enforce or properly handle certificate validation.

Condition: Occurs when the “Validate Server Certificate” option is enabled in LDAP configuration. Despite this setting, the system either ignores certificate errors, does not validate the server certificate as expected, or behaves as though the option is disabled.

Workaround: NA

1622308

Symptom: The CRL Setting section is not visible in the Read-Only (RO) admin interface. Additionally, the CRL button is present but not greyed out (i.e., appears enabled) in the RO admin page

Condition: Occurs when Certificate Revocation List (CRL) checking options are enabled.

Workaround: NA

1651237

Symptom: WAF issue observed when configuring CRL (Certificate Revocation List) checking options in the following scenarios:

Manually configured CDP in Sub CA.

Backup CDP in ROOT CA.

CDP specified in trusted CA.

Condition: Occurs when configuring CRL checking options and using an IP address in the CRL URL.

Workaround: Use a domain name instead of an IP address in the CRL URL.

1648859

Symptom: ICS allows SHA1 trusted client/server CA certificate to import.

Condition: Occurs when importing SHA1 certificate under trusted client/server CA.

Workaround: NA

Active Directory

1546749

Symptom: Active Directory (AD) traffic segregation is not functioning as expected at both the global and server levels. Specifically, if DNS is configured on a non-internal port, domain join fails, and DNS traffic does not flow through the non-internal port.

Conditions:

DNS configured on a non-internal port/interface.

AD domain join operation attempted.

Workaround: NA

1624127

Symptom: On the AD troubleshooting page, DNS resolution checks fail for some AD servers when multiple AD servers are configured. DNS resolution is only successful for the AD server that is also configured as the DNS server.

Condition: When multiple AD servers are configured on the ICS device, the troubleshooting page may show DNS resolution failures for some of the AD servers.

Workaround:Configure the relevant AD server’s IP address as the primary DNS server on the ICS.

1634104

Symptom: AD server uses AES256 encryption type for Kerberos. Authentication protocol even when AES 256 encyption option is not enabled.

Condition: Admin tries to authenticate using AD server and goes for Kerberos Authentication Protocol (default option), with AES 256 option disabled in server configurations (default setting).

Workaround: NA

1642170

Symptom: Change Machine Password in Troubleshooting section of AD server configuration does not work.

Condition: Occurs when using a Windows AD 2025 server.

Workaround: Use a Windows AD 2022 server, if possible.

OAuth

1642111

Symptom: OAuth traffic segregation is not working as expected at either the global or server levels; OAuth traffic is not routed through the configured port as intended.

Condition: Occurs when traffic segregation policies are applied globally or per authentication server for OAuth traffic.

Workaround: NA

1622322

Symptoms: OAuth time skew is not functioning according to the configured values.

Condition: OAuth-protected operations (such as token validation) are not honoring the custom time skew settings as specified in the configuration. This can result in unexpected authentication or token validation failures if there is a time difference between the client and server.

Workaround: NA

UEBA

1641932

Symptom: In a cluster setup, UEBA (User and Entity Behavior Analytics) functionality does not work for the first user who accesses the system after an upgrade

Condition: This issue occurs only in clustered environments and affects the very first user session after the system is upgraded.

Workaround: No workaround is needed; from the second user onwards, UEBA functionality resumes and works as expected.

1648442

Symptom: After upgrading, User and Entity Behavior Analytics (UEBA) does not show expected logs for the first user session. Subsequent user sessions display logs correctly, and UEBA functionality proceeds as intended.

Condition: Occurs when accessing UEBA immediately after upgrade.

Workaround: Accessing UEBA as a second user (or after the first attempt) resolves the issue; all relevant logs are displayed thereafter.

Behavioral Analytics

1637718

Symptom: An error message "Unable to load any data. Try applying valid filters and reload the page." is shown, and no data is displayed.

Condition: Occurs when user records are filtered by MAC address in the Behavioral Analytics User Report.

Workaround: NA

1640860

Symptom: Cleared anomalies do not appear in the Behavioral Analytics User Report.

Condition: Occurs after manually clearing (removing/dismissing) some anomalies and then viewing the Behavioral Analytics User Report..

Workaround: NA

Bookmark

1630234

Symptom: JSAM (Java Secure Application Manager) bookmark access does not work when Java Runtime Environment (JRE) 1.8 is installed on the client system.

Condition: Occurs when an end user attempts to access JSAM profiles using JRE 1.8.

Workaround:Install Java Development Kit (JDK) 21 instead of JRE 1.8.

1670354

Symptom: "Request Header Or Cookie Too Large" message appears when accessing any kind of bookmarks added for the end-user.

Condition: Occurs when the end-user opens the bookmark and tries to open the child links of the same page.

Workaround: NA

1669941

Symptom: File browsing page refresh is not working.

Condition: Occurs when user accesses the file share path via the browse option.

Workaround: User can access admin created bookmark and perform a page refresh to make it work.

1670579

Symptom: Multiple monitors use case does not work.

Condition: Occurs when RDP bookmark created for Smart card VM.

Workaround: No issue is seen with single monitor.

1677378

Symptom: WTS bookmark fails to Autolaunch when end user login successfully.

Condition: When WTS bookmark is configured with autolaunch enabled and Hostchecker is also enabled.

Workaround: Disable Hostchecker so that WTS bookmark autolaunchs whenever enduser logins successfully.

1628122

Symptom: When a bookmark is created, the description field automatically includes an extra "0" (zero).

Condition:Occurs during bookmark creation (no additional specific conditions noted).

Workaround: NA

1641211

Symptom: RDP print functionality is not working.

Condition: Occurs when the print option is enabled in an RDP HTML5 bookmark.

Workaround: NA

Host Checker

1644287

Symptom : Host checker version displays as 1.0 in MAC.

Condition : When a user launches the Host Checker application on Mac, the version shown in installed applications displays as 1.0.

Workaround : Host Checker functions correctly; only the displayed version is "1.0".

1634866

Symptom:  HTML5 client copy-paste functioality does not work.

Condition: Occurs when a user attempts to use Command+C/Command keyboard shortcuts for copy-paste operations on a Mac.

Workaround: Select the required content in the HTML5 client, then right-click and use the context menu to copy and paste the content on the local machine.

1664534

Symptom: Host Checker Component and PSAL is not launching for the remediation scenarios in Edge and Chrome browser.

Condition: If 3 or more HC policies configure (Custom or Predefined).

Workaround: Use Firefox browser or enable browser extension for Chrome/Edge.

1641387

Symptom: Host Checker Policies are empty in the remediation > Enable Custom Actions field.

Condition: In all conditions, it is empty.

Workaround: NA

1657227

Symptom: 502 bad gateway message is seen.

Condition: When user clicks "Profile" hyperlink in the HC page.

Workardound: N/A

REST API

1612333

Symptom: "IP Pool cannot be empty" error observed when switching from DHCP-based IP assignment to Pool-based for VPN Connection Profiles via REST API.

Condition: Occurs when the "ip-address-pool" attribute is provided before the "ip-address-assignment" attribute in the request body.

Workaround: Provide "ip-address-assignment" before the "ip-address-pool" attribute in the request body.

1601479

Symptom: Configuring FQDN based lockdown exception rule for a connection set fails when attempted via the REST API.

Condition: Occurs when attempting to configure an FQDN-based lockdown exception rule for a connection set using the REST API.

Workaround: Configure the FQDN-based lockdown exception rule manually via the Ivanti Connect Secure (ICS) administrative user interface.

1634397

Symptom: Exception rule creation when using rest API failed.

Condition: Occurs during attempts to create an exception rule via REST API.

Workaround: None

1658685

Symptom: REST API call to set FIPS is failing with error: "Non FIPS Cipher is selected when FIPS mode is on (Outbound)".

Condition: Occurs when enabling FIPS using REST API and TLS 1.3 is selected in In-Bound settings.

Workaround: Configure FIPS manually from Admin UI page.

Upgrade

1634850

Symptom: Bind failed related logs are seen for few seconds.

Condition: During ICS upgrade.

Workaround: NA

1640944

Symptom:The error message /bin/tar: tlscerts/cert.pem: Not found in archive is displayed on the console.

Condition: Occurs during the Ivanti Connect Secure (ICS) upgrade process.

Workaround: NA

1658693

Symptom: ICS console shows boot manager screen.

Condition: Occurs while performing an upgrade.

Workardound: Perform a reset or reboot from the boot manager; the upgrade will restart.

1600182

Symptom: The message "Unable to synchronize time, either NTP server(s) are unreachable or provided symmetric key(s) are incorrect" appears in the system logs.

Conditions: This occurs after a system upgrade or a reboot.

Workaround: NA

Config Import

1641516

Symptom: File system check (fsck) related messages are seen in the console.

Condition: Occurs when an administrator performs a reboot or clears the device configuration.

Workaround: No functionality impact observed.

1666021

Symptom: Push config fails for custom port syslog server config.

Condition: Occurs when configuration is pushed from a lower build ICS to the latest.

Workaround: Configure using the ICS Gateway UI.

1666027

Symptom: Syslog XML import fails for custom port syslog server config.

Condition: Occurs when exported from ICS lower build and imported to latest ICS build.

Workaround:Configure using the ICS Gateway UI.

1664557

Symptom: Blank screen appears when attempting to use a custom sign-in page imported via XML or binary.

Condition: Due to Perl modules upgrade, stricter rules are applied in handling HTML files.

Workaround: Import the custom sign-in page as a zip file format; UI will display any errors encountered. Resolve the errors, then re-upload the custom sign-in pages.

1669912

Symptom: HTML5 storage config is not getting imported.

Condition: Occurs when importing binary HTML5 config.

Workaround: : Configure using the ICS Gateway UI.

WAF

1634835

Symptom: When an Admin attempts to delete more than 198 users at once, the Web Application Firewall (WAF) blocks the request.

Condition: Occurs during the deletion of more than 198 users in a single operation.

Workaround: Delete users in smaller batches of up to 150 users at a time to avoid WAF blocking.

1634847

Symptom: No "Upload successful" message is displayed after uploading a WAF ruleset package.

Condition: Occurs when an administrator uploads a WAF ruleset package through the UI.

Workaround: Check the admin logs to confirm the status of the upload.

1665495

Symptom: WAF messages are seen in event logs.

Condition: When accessing HTML5 bookmarks via REST API.

Workaround: NA

Network Operations

1616321

Symptom: Bandwidth management does not work.

Conditions: Occurs when SSL is used.

Workaround: Use ESP protocol instead of SSL.

1637651

Symptom: Traceroute output displays %int0, %ext0, %mgt0.

Condition: NA

Workaround: NA

1648583

Symptom: Pushing config does not works using IPv6.

Workaround: Use IPv4 for push config functionality to work.

1663938

Symptom: Unable to view the charts for Concurrent Users, Hits Per Second, etc in Overview Page.

Conditions: Occurs when attempting to view stats for another member in the cluster.

Workaround: View stats from the Admin UI of the respective cluster node.

Impacted Functionality: Graphs on Admin UI page.

1665464

Symptom: "IPv6 not enabled on any port" error message is displayed when using troubleshooting commands.

Condition: Occurs when VLAN ports are configured with IPv6 address, but internal, external, and management ports are not configured with IPv6 address.

Workaround: This is a display issue and does not impact functionality.

1665457

Symptom: Portprobe is not working with management port VLAN.

Condition: Occurs when admin attempts to perform portprobe using VLANs created on the management port.

Workaround: NA

1628560

Symptom:Ivanti Connect Secure (ICS) is sending syslog messages (for both TCP and UDP) over the management port.

Conditions: This occurs when syslog is configured with default settings.

Workaround: Disable the management port.

UI

1641679

Symptom:Screen recording for an end-user session fails (recording cannot be saved or downloaded).

Condition: Occurs when the “Screen Recording End User” option is enabled in a bookmark and an end user attempts to utilize session recording.

Workaround: Open the browser’s developer tools console and enter $rdp.close( ). This triggers a pop-up allowing the user to save the session recording to the client device.

1574532

Symptom: When an invalid URL is accessed in the end-user login page, clicking the OK button does not redirect or navigate the user to the home page.

Condition: Occurs when a user browses to any invalid URL on the end-user login page and interacts with the error prompt by clicking “OK”.

Workaround: NA

1679335

Symptom: Sample template files related to Kiosk and SoftID are not working for custom sign-in pages.

Condition: Seen on both Kiosk and SoftID templates.

Workaround: NA

1648229

Symptom: Error 403 is seen while enabling/disabling/vip failover node in AP cluster with NSA 22.8R1.4 and 25.1.0.0 gateway.

Workaround: Try performing enable/disable/vip failver from the gateway UI

LDAP

1634055

Symptoms: Encountered an error "Invalid LDAP server IP address".

Condition: This occurs when attempting to configure an LDAP server using an IPv6 address.

Workaround: NA

1634087

Symptom: When configuring a Backup LDAP server, an error “Invalid admin Credentials” is encountered.

Condition: Occurs while entering the Backup LDAP Server IP and Base DN during server configuration.

Workaround: NA

JSAM

1566054

Symptom: JSAM is not accessible on Ubuntu; an error "Application launcher is not installed" is seen.

Condition: JSAM is not accessible on Ubuntu.

Workaround: NA

1635741

Symptom: Unable to access the intranet server "tools-svr.engdevroot.com" using JSAM.

Condition: Occurs when trying to access "tools-svr.engdevroot.com" using JSAM.

Workaround : NA

Deployment

1671089

Symptom: Assuming ownership of connection set fails after turning on FIPS mode where TLS 1.3 is enabled.

Condition: Next generation service restart causes the failure.

Workaround: Add sleep time after enabling FIPS mode.

1670033

Symptom: ICS returns blank page when public sites are accessed.

Condition: When public sites are enabled with CSP.

Workaround: NA

1674580

Symptom: Package upload fails for 2nd node.

Condition: During cluster upgrade.

Workaround: It automatically tries to upload package again and cluster upgrade proceeds further.

1669339

Symptom: Login through Rest API fails with TLS 1.3 enabled after Lockdown Exception rules are configured.

Condition: Occurs when REST API is triggered.

Workaround: Login using Admin UI.

Logs

1676718

Symptom: Failed to update profile for user message seen in Event logs.

Conditions: Messages are seen under the following conditions::

Secondary auth is enabled for a User Realm

Adaptive Authentication is enabled for the User Realm

End user trying to login using ISAC

Workaround: None. Adaptive Auth functionality is not affected.