What's New
|
Product Version |
Build |
|---|---|
|
ICS 25.1.3.0 |
22109 |
|
ISAC 22.8R7 Mobile Client 22.8R8 |
48847 18981 (Android) 96449 (iOS) |
|
WAF Default CRS |
1.0.4 |
| Default ESAP | 4.6.4 |
•Rest API Diagnostic Logs: A new Rest API Diagnostic Logging capability has been added to improve visibility into system health monitoring operations. Administrators can use these logs to assist troubleshooting and operational diagnostics, see Rest API Diagnostic Logs.
•Windows Hello for Business (WHfB) Single Sign-On Enhancements: This release includes enhancements to Windows Hello for Business (WHfB) Single Sign-On functionality, providing improved integration with modern authentication workflows and passwordless authentication deployments, see Windows Hello for Business SSO Server.
•FIDO2 Authentication Enhancements: ICS has been enhanced to support FIDO2-related authentication improvements, enabling support for modern passwordless authentication methods and strengthening identity security, see FIDO2 support for mobile ISAC .
•Active User Session API Enhancements: The Active User Sessions REST API has been enhanced to support filtering session data based on user, see Active User session.
•WebSocket Support Through HTTP(S) Proxy: Ivanti Connect Secure (ICS) now supports establishing and maintaining WebSocket connections to backend application servers through a configured HTTP(S) web proxy. This enhancement enables WebSocket-based applications to function seamlessly in environments where proxy routing is required by organizational policies.
•Automated Certificate Management Environment (ACME) Support: Ivanti Connect Secure now supports the Automated Certificate Management Environment (ACME) protocol to automate certificate requests, domain validation, certificate issuance, and certificate deployment on the designated interface, see ACME Server.
•Default VLAN ID Support with IPv6 on Internal Interfaces: Ivanti Connect Secure now supports the use of the Default VLAN ID when IPv6 is configured on the Internal Interface. This enhancement ensures that the Default VLAN ID remains available and functional when both IPv4 and IPv6 are enabled, see Default VLAN ID.
•Bulk ACL Management Using REST API: Ivanti Connect Secure now supports bulk management of Access Control Lists (ACLs) through REST API. Administrators can create, update, and delete multiple ACLs in a single API request, improving scalability and operational efficiency for large enterprise and MSP deployments, see Create Multiple ACLs .
•Postman Collection for ICS REST APIs: Ivanti Connect Secure now provides a Postman collection for publicly available REST APIs, enabling administrators and developers to quickly explore, test, and integrate ICS APIs using the Postman client, see Postman Collection.
•OAuth Group Claims for Role Mapping: Ivanti Connect Secure (ICS) now supports role mapping based on group claims received from OAuth providers such as Microsoft Entra ID (Azure AD). Administrators can use group information included in the OAuth ID Token or UserInfo response to assign user roles within ICS user realms, see OAuth Group Claims Role Mapping.
•HTTP/2 Ingress Support in NGINX: NGINX has been enhanced to support HTTP/2 for inbound client connections. HTTP/2 provides improved connection efficiency and performance through multiplexing and optimized protocol handling, see HTTP Protocol Configuration.
•Secure Boot and vTPM Support: GCP, AWS platform now provides secure boot support with vTPM functionality, enhancing security and integrity for virtual machines, see Secure Boot with TPM/vTPM.
•Virtual appliance platforms: Added support for the new virtual appliance platforms ISA-V 4500, ISA-V 6500, and ISA-V 8500 in Ivanti Connect Secure (ICS) version 25.1.3.0, see ISA VA Supported Platforms.
•Host Header Validation: Ivanti Connect Secure now provides a console-based option to disable Host Header Validation on the management interface. This enhancement supports deployments where the management interface is accessed through Network Address Translation (NAT), helping ensure administrative access in environments where Host Header Validation may otherwise block requests, see Host Header Validation.
•Configurable Certificate Challenge Timeout: Administrators can now configure the maximum interval between certificate challenge exchanges during the pre-authentication phase of certificate-based authentication. The timeout value can be set from 1 to 4 minutes, with a default value of 1 minute, see Certificate Challenge Timeout.
•UI Enhancement for Compliance Report: Failed policies now display the corresponding failed rule names and failure reasons. Additionally, Host Check results are presented in a separate column to improve visibility and reporting clarity, see Using Host Checker Reports and Logs.
|
Product Version |
Build |
|---|---|
|
ICS 25.1.1.0 |
11811 |
|
ISAC 22.8R5 Mobile Client 22.8R6 |
41063 17079 (Android) 5717 (iOS) |
|
WAF Default CRS |
1.0.4 |
| Default ESAP | 4.6.4 |
•Feature parity with ICS release 22.8R2.3 and 22.7R2.12
•Citrix Support: ICS now supports the use of Device ID as a unique identifier in Citrix Xendesktop LTSR 2507, enabling enhanced device-based authentication and tracking.
•Secure Boot and vTPM Support: Hyper-V, Openstack KVM, Azure platform now provides secure boot support with vTPM functionality, enhancing security and integrity for virtual machines, see Deployment Guide.
|
Product Version |
Build |
|---|---|
|
ICS 25.1.0.1 |
10387 |
|
ISAC 22.8R5 Mobile Client 22.8R6 |
41063 17079 (Android) 5717 (iOS) |
|
WAF Default CRS |
1.0.4 |
| Default ESAP | 4.3.8 |
There are no new ICS features in this release. This release includes patch for OpenSSL CVE-2025-15467. Feature parity of this release remains same as 25.1.0.0. Refer the KB for more info.
|
Product Version |
Build |
|---|---|
|
ICS 25.1.0.0 |
5663 |
|
ISAC 22.8R2 Mobile Client 22.8R3 |
33497 14 (Android) 95033 (iOS) |
| Default ESAP | 4.3.8 |
•Secure Boot with TPM/vTPM: The Secure Boot feature offers protection against unauthorized bootloader and kernel images, malware, and rootkits, and ensures compliance with security by design principle while improving boot time. For more information, see Secure Boot with TPM/vTPM.
•Rotate Internal Storage Key: This process encrypts sensitive information like passwords when storing them internally and ensures the encryption key is unique and random for every ICS instance, see Rotate Internal Storage Key.
•Security Enhanced WAF Operation: This feature protects Connect Secure gateway web applications by filtering and monitoring HTTP traffic, preventing attacks such as SQL injection, cross-site scripting (XSS), and other web exploits, see Configuring Web Application Firewall UI and Security Enhanced WAF Operation console.
•Shared Secret key: This feature configures a Shared Secret for each source/target pair at time of creation of Push Config Target, see Configuring Targets.
•Password key Generation: New API's introduced to generate and fetch the password key, see APIs.
•Next Generation Web server: The Next Generation Web Server has been developed to enhance the performance and scalability of web server infrastructure, see Next Generation Web Server. Web server logs are implemented for web-related event codes with debug severity, see Using the Debug Log.
•SELinux Security Policy: The ICS system provides an Enforcing only SELinux capability, ensuring that even the root user or admin cannot switch SELinux to permissive mode without rebooting the system, See SELinux Security Policy.
•Verbose Log: Administrators can toggle SELinux verbose logging to control the detail level of SELinux-related logs, see SELinux Verbose Log.