Introduction
ivanti connect secure (ics) is a next generation secure access product, which offers fast and secure connection between remote users and their organization’s wider network ivanti connect secure modernizes vpn deployments and is loaded with features such as new end user experience, increased overall throughput and simplified appliance management noteworthy information with next generation web server enabled, pushconfig operations from releases prior to 22 8rx (using the legacy web server) to version 25 x are not supported 25 1 3 0 downgrade operations are no longer supported after the storage mounting/unmounting capability restriction changes administrators must use supported upgrade paths and rollback procedures installing older releases by bypassing version validation can result in incompatibilities between installation scripts and platform utilities and may cause installation failures to strengthen security, ivanti connect secure now enables only aes 256, sha 256, and dh 2048 bit or larger ikev2 phase 1 negotiation parameters by default administrators must ensure that ikev2 clients are configured to support these settings this enhancement applies to new installations, upgrades, and configuration imports (xml and binary) on ivanti connect secure gateways starting with release 25 1 3 0 if compatibility issues are encountered, administrators can manually disable individual negotiation parameters or disable all of them as needed for configuration imports originating from the same software version, the administrator configured settings are preserved for additional information, refer to the kb https //hub ivanti com/s/article/ivanti connect secure 25 1 3 0 ikev2 phase 1 security hardening changes article secure by default change for saml 2 0 sp signature validation starting with ics 25 1 3 0, when ivanti connect secure (ics) is configured as a saml 2 0 service provider (sp), signature validation of incoming saml responses is enabled by default this secure by default enhancement aligns with ivanti's recommended security best practices to ensure successful saml authentication, administrators must upload the identity provider's (idp) complete ca certificate chain to the trusted client cas list configuration > certificates > trusted client cas > import trusted client ca this change affects only deployments that use saml authentication on ivanti connect secure for additional information, refer to the kb https //hub ivanti com/s/article/saml 2 0sp signature validation behaviour in ics 25 1 3 0?language=en us article snmp configuration limitations the following limitations apply when configuring snmp snmp v2/v3 usernames can contain only alphanumeric characters snmp v3 passwords can contain alphanumeric characters and the following special characters only ! @ # % ^ & ( ) \ $ the length of snmp v3 usernames are limited to a maximum of 31 characters the length of system name, system location, and system contact fields are each limited to a maximum of 254 characters secure by default change for ldap server certificate validation starting with ics 25 1 3 0, the validate server certificate option is enabled by default when configuring a new ldap server to establish trust, administrators must ensure that the ca certificate required to validate the ldap server’s certificate chain is present in the trusted server cas list on ivanti connect secure if certificate validation cannot be configured due to technical constraints, administrators can explicitly disable this setting however, disabling server certificate validation is not recommended for additional information, refer to the https //hub ivanti com/s/article/saml 2 0sp signature validation behaviour in ics 25 1 3 0?language=en us https //hub ivanti com/s/article/saml 2 0sp signature validation behaviour in ics 25 1 3 0?language=en us kb https //hub ivanti com/s/article/ics 25 1 3 0 ldap server certificate validation enabled by default article secure by default to enhance security, the delete all cookies at session termination option is enabled by default under system > configuration > security > miscellaneous when this option is enabled, session cookies are removed when a user session ends in rare cases, during session migration between layer 7 access and other client launch types, some web browsers may withhold session cookies, which can prevent certain applications, such as jsam, from launching successfully if this behavior is observed, administrators can explicitly disable this setting for additional information, refer to the https //hub ivanti com/s/article/saml 2 0sp signature validation behaviour in ics 25 1 3 0?language=en us https //hub ivanti com/s/article/saml 2 0sp signature validation behaviour in ics 25 1 3 0?language=en us https //hub ivanti com/s/article/ics 25 1 3 0 ldap server certificate validation enabled by default https //hub ivanti com/s/article/ics 25 1 3 0 ldap server certificate validation enabled by default https //hub ivanti com/s/article/ics 25 1 3 0 enhanced session security with cookie deletion enabled by default https //hub ivanti com/s/article/ics 25 1 3 0 enhanced session security with cookie deletion enabled by default kb https //hub ivanti com/s/article/ics 25 1 3 0 enhanced session security with cookie deletion enabled by default article upload custom sign‑in pages feature is temporarily removed in ivanti connect secure 25 1 3 0 the ability to execute scripts from template files has been identified as a security weakness this feature will be temporarily removed until we re architect it without this security weakness customers will no longer be able to upload and use template based (thtml) custom sign‑in page zip packages customization on sign in pages using the previously uploaded template files will also no longer working refer the faq # for additional detail when adding or deleting multiple ldap groups simultaneously, group names containing dc=local (non builtin groups) may trigger cumulative waf anomaly scoring, causing the request to be blocked this behavior is intentional and is not whitelisted to preserve security enforcement to avoid request blocking, administrators should add or delete ldap groups containing dc=local individually rather than performing bulk operations if password policy controls are enabled but the configured ldap server does not support the password policy control extension, error messages similar to the following may appear in the ldap server logs or console slap global control unrecognized control 1 3 6 1 4 1 42 2 27 8 5 1 previously, the same log messages were generated regardless of whether the operation was performed through the admin ui or the rest api as a result, operations initiated via the rest api could produce misleading log entries that implied the action was performed from a ui page the log messages have been revised to use a more generic description, accurately reflecting the operation without referencing a specific interface previous log format adm31403 totp user '\<username>' account has been unlocked from '\<authservername>' auth server user's pageadm31403 totp user '\<username>' account has been reset from '\<authservername>' auth server user's page updated log format adm31403 totp user '\<username>' account on auth server '\<authservername>' has been unlockedadm31403 totp user '\<username>' account on auth server '\<authservername>' has been reset a dashboard banner now displays the type of server for which the server certificate validation option is available but not enabled 25 1 1 1 this release version includes security enhancement ivanti encourages customers to upgrade to this latest version 25 1 1 0 outbound http/https proxy connections are restricted to a defined allow list of well known proxy ports to align with secure by default allowed ports 8080, 8118, 8123, 10001–10010, 10080, 3130, 3445, 8008, 8010, 3128 feature parity with ics release 22 8r2 3 https //help ivanti com/ps/help/en us/ics/22 x/22 8r2 2/rn/landingpage htm and 22 7r2 12 https //help ivanti com/ps/help/en us/ics/22 x/22 7r2 11/rn/landingpage htm starting with ics version 25 1 1 0 the default global (system > configuration > client configuration ) and role level ( user > user roles > \<name> > vpn tunnelling > ivanti secure access client settings ) options for the isac desktop user experience (ux) is set to neux for fresh installations of ics ensure your environment allows installation and execution of the react native appx bundle used by neux follow the guidance in the forum https //hub ivanti com/s/article/unable to switch ui mode in windows ivanti secure access client isac?language=en us article to enable the appx bundle applies to new installations to ics 25 1 1 0, and later cluster setup which is running with version 22 8rx does not support upgrade to ics 25 x version cluster upgrade supports only on ics 25 1 0 0 and above to ics 25 1 1 0 saml authentication server configuration using the saml 1 1 protocol is deprecated at ics 25 x versions from 25 1 1 0 onwards, the system will not allow new saml 1 1 server configuration and will not allow to import any existing configurations saml 2 0 is the option supported this deprecation was initially notified as part of this kb https //hub ivanti com/s/article/ivanti connect secure features and options becoming unsupported or deprecated in 22 7rx 22 8rx and 25 x the username displayed in the end user portal is always in lowercase, similar to other authentication methods the correct casing is maintained in the user access and other logs before performing a pushconfig operation from an older release to version 25 1 1 0, you must disable the http only device cookie on the target device for admin roles navigate to administrators > admin roles > delegated admin roles > administrators > session options for user roles navigate to users > user roles > \[role name] > session options referrer header validation is enabled by default to block csrf attacks, providing an additional layer of security all cookies will be deleted upon session terminated by default, enhancing security and privacy content security policy (csp) headers are now implemented for end user pages to provide additional protection against cross site scripting (xss) attacks " the next generation web server (nginx) will restart when performing any of the following certificate related operations user connections may drop during this period mapping a device certificate to a port importing or deleting a trusted client ca making changes to inbound tls versions and cipher suites 25 1 0 1 to enable tls 1 3 functionality, ensure that the enable tls v1 3 key value pair is configured and pushed to isac mobile client (android/ios) from the mdm server key value pair setting configuration key enable tls v1 3 value type boolean configuration value true 25 1 0 0 to enable tls 1 3 functionality, ensure that the enable tls v1 3 key value pair is configured and pushed to isac mobile client (android/ios) from the mdm server key value pair setting configuration key enable tls v1 3 value type boolean configuration value true ics license server cannot lease licenses to license clients running versions 22 7rx, 22 8rx, or 25 1 x x see, forum https //forums ivanti com/s/article/ics version 25 1 0 0 unable to serve licenses to the clients with error manifest check failed for licenseserverproto cgi certificate based authentication will not work after upgrading to 25 1 0 0, if client uses sha 1 based certificates sslv3, tls1 0 and tls1 1 versions are removed and there are additional cipher changes implemented as part of this release for more information, see configuring ssl options https //help ivanti com/ps/help/en us/ics/25 1 x/ag/network n host admin htm#network and host administration 1399867268 681281 use of sha1 for digital signature is not supported, use sha2 and above sha2 is the minimum required version in digital signatures ics server will no longer connect or validate with sha1 in digital signatures enable sha2 as response signature algorithm in ocsp response on ocsp responder if the ics only contains sha1 device signed certificates, the user interface fails to launch at least one sha2 signed certificate or any newer version after sha1 is mandatory certificate validation http/1 1 enforcement for ocsp requests starting with version 25 1 0 0, certificate validation process now explicitly enforces the use of http/1 1 for online certificate status protocol (ocsp) requests this ensures consistent and reliable communication during certificate status checks for more info refer kb https //forums ivanti com/s/article/deprecation of ocsp requests over http 1 0 in ivanti connect secure ics 22 7 onwards cluster upgrade is not supported from 22 8r2 to 25 1 0 0 to upgrade, break the cluster, upgrade and then create the cluster again for more information, see cluster migration from 22 8rx to 25 x https //help ivanti com/ps/help/en us/ics/25 1 x/mig/22 x 25 x migration/cluster upgrade htm#top in this release, the /api/v1/healthcheck rest api response has been updated to return content as bytes, which aligns with the default behavior of many web frameworks and libraries when handling api responses previously, the response was returned as a string this change could impact systems or integrations assuming the response would always be a string upgrade or binay import is not supported if sha 1 certificates are configured on any ics ports configs with deprecated features will be upgraded or imported to 25,x but will not be qualified please refer the kb https //forums ivanti com/s/article/ivanti connect secure features and options becoming unsupported or deprecated in 22 7rx 22 8rx and 25 x for more details arping command no longer resolves hostnames the command now requires a direct ip address as input attempts to use hostnames will result in an error example error bad value for ai flags don’t use a hostname with arping the arp maintenance > troubleshooting > tools > commands > arp option no longer supports hostnames as input you must now specify a direct ip address when using this command attempts to use hostnames will result in following error example error bad value for ai flags don’t use a hostname with arping with q1 2026 release of ics, the default esap version will be 4 6 4 esap 4 6 4 has been released in q2 2025 offline and online viewer for advanced html5 recordings advanced html5 external storage recording files for rdp, ssh, and vnc sessions can be viewed using the remotespark player the online player is available through the remotespark player https //www remotespark com/view/player html web interface, allowing users to play recorded sessions directly in a browser in addition, offline player installers for windows and macos are available, enabling users to view recorded session files locally without requiring access to the web based player or an internet connection to download the html5 offline viewer, click the download link https //portal ivanti com/customer/product downloads , sign in to the ivanti support portal, and navigate to download > network security > ivanti connect secure > ics html5 offline viewer macos ics html5 offlineviewer aarch64 dmg windows ics html5 offlineviewer x64 en msi rsa authentication for rsa authentication to work, add the agent's host name in rsa auth manager and configure it in ics ensure the rsa/ace server has a host entry in ics tcp is now enforced as the only supported communication protocol for the rsa securid integration legacy udp based communication is no longer supported update firewall rules to allow outbound tcp from ics to the rsa authentication manager on the configured securid agent port(s) used in your environment, see kb https //hub ivanti com/s/article/error ad 36 cannot upload configuration file invalid file seen when importing ace sdconf rec file into ics 25 x for more details as tcp is used, hostname based validation is mandatory as a result, the hostname configured in ics (network → overview) must match the agent hostname defined in the rsa authentication manager this replaces the earlier flexibility of using internal ip addresses, which was possible with the legacy udp based integration the above scenarios apply to rsa authentication manager 8 7 and below unsupported features ivanti connect secure features and options becoming unsupported or deprecated in 22 7rx, 22 8rx, and 25 x, refer to article https //forums ivanti com/s/article/ivanti connect secure features and options becoming unsupported or deprecated in 22 7rx 22 8rx and 25 x licenses an ics instance running version 22 8r3 can be configured as a license server and is qualified to lease licences to 22 8rx and 25 x instances acting as license clients while an ics instance running version 22 7rx may technically be able to lease license to 22 8rx or 25 x clients, this configuration has not been qualified therefore, it is recommended to use ics version 22 8r3 or later when configuring a license server known limitations cluster node name restriction cluster node names should not be configured as "localhost2" using "localhost2" as a node name is not supported and may result in unexpected behavior
