Known Issues
the following table lists the known issues in respective release problem report number release note release 25 1 3 1 1999102 symptom client log upload fails on macos when using the jsam applet condition the issue occurs when jsam is launched on a macos device workaround upload the client logs manually release 25 1 3 0 upgrade and deployment 1775958 symptom upgrading from a staged package may fail with the following error "ics service package does not support package version on this device" this error can occur even when an ics 25 1 2 0 or later package has been successfully uploaded to the staging area conditions the ics instance is running a version earlier than 25 1 2 0 on a virtual appliance an administrator stages an ics 25 1 2 0 or later package successfully the administrator then attempts to perform the upgrade using the staged package workaround none upgrades to ics 25 1 2 0 or later are not supported on earlier than 25 1 2 0 try direct upgrade to get the error immediately 1970766 symptom upgrade from ics 25 1 3 0 build to any 25 x build fails but the messages on admin ui says ics package scan completed successfully condition this issue occurs when the upgrade is attempted after running ext ict on ics workaround after running an ext ict, reboot ics before attempting the ics upgrade the upgrade completes successfully after the reboot 1870595 symptom during an upgrade, the image displayed on the web interface appears oversized and zoomed in, resulting in a pixelated and misaligned appearance on the page condition occurs while upgrading to ivanti connect secure (ics) version 25 1 3 0 (build or release) workaround na 1939424 symptom when an ics custom image is selected on the gcp instance creation page, the provisioned iops value is initially displayed as 2000 condition this issue occurs while configuring the ics instance in gcp, under the os and storage section, after selecting the custom ics image at this stage, the provisioned iops value cannot be edited workaround to set the correct provisioned iops value in the os and storage section, select the required ics custom image from the dropdown the provisioned iops value is initially displayed as 2000 click select to save the configuration reopen the configuration by clicking change the provisioned iops value is now displayed as 3480 click select again to save the configuration with the updated provisioned iops value of 3480 clustering and high availability 1921438 symptom end users may be required to re authenticate after the vip holding node setting is enabled or disabled in an active passive cluster configuration condition this issue occurs when the vip holding node option is enabled or disabled on an active passive cluster workaround use of the vip holding node option is not generally recommended if it must be enabled or disabled, perform the operation during a planned maintenance window to minimize user disruption and potential re authentication events 1969044 symptom end users can connect to the vip, but backend resources become inaccessible this occurs because network packets are no longer tagged after one of the vlan interfaces goes missing condition this issue occurs when multiple vlan interfaces are configured on a physical interface and vip failover testing is performed by using the failover vip button and restarting services during the failover process, a tentative ipv6 address may be observed intermittently in some cases, one of the vlan interfaces may be unexpectedly deleted or may no longer appear in the ifconfig output, resulting in loss of access to end user resources workaround reboot the affected ics device to restore the vlan interface and recover connectivity 1967862 symptom backend resources are not accessible condition this issue is seen under the following conditions source port under roles is set to use vlan virtual port use /api/v1/cluster to change the cluster type from aa to ap workaround do failover vip so that the vlan virtual ports get created properly on the other node 1938819 symptom eup login lands in blank page in cluster condition when logged in as an end user workaround clicking on home icon will do 1938796 symptom ssh, rdp remote file transfer, rdp print fail to work in cluster condition when tried in cluster workaround n/a 1949670 symptom deleting a host entry at the cluster level displays the same host entry removal message twice condition this issue occurs when a host entry is deleted in a clustered deployment workaround na 1954185 symptom the ueba package is not synchronized to one of the nodes in a cluster condition this issue can occur when the ueba package is uploaded to only one node in the cluster workaround manually upload the same ueba package to the affected node in the cluster to ensure successful synchronization and availability across all nodes 1770956 symptom antivirus or firewall remediation actions to enable real time protection (rtp) do not work condition this issue occurs when using agentless host checker (hc) on windows endpoints workaround na configuration management 1933309 symptom the push config feature does not work when pushing configuration from an ics 25 1 1 0 gateway to an ics 25 1 3 0 gateway after http/2 is enabled on the target 25 1 3 0 device condition this issue occurs because the required http/2 support and associated fix are available only in ics 25 1 3 0 workaround either of the following options can be used upgrade the source gateway to ics 25 1 3 0 before performing the push config operation disable the http/2 feature on the target ics 25 1 3 0 gateway when the source gateway is running a release earlier than 25 1 3 0 1925041 symptom importing a user configuration fails when the configuration includes web proxy settings condition occurs when attempting to import a configuration containing web proxy configuration workaround use the xml configuration file to import the web proxy settings successfully 1936818 symptom there is no option to push html5 storage configuration through the configuration push mechanism condition this issue occurs when attempting to push html5 storage configuration workaround use xml import or user configuration import to transfer the html5 storage configuration web proxy 1927755 symptom web proxy use cases configured through the rest api are not handled correctly condition this issue occurs when web proxy configuration or management operations are performed using the rest api workaround use the admin ui to configure and manage web proxy settings monitoring and logging 1938472 symptom tls syslog forwarding fails when configured to use a custom port condition this issue occurs when tls syslog is configured with a custom port instead of the default tls syslog port workaround configure tls syslog to use the default port tls syslog forwarding works as expected when the default port is used 1961487 symptom when an snmp request is performed for fan status or power status on isa6500 or isa8500 hardware devices, the snmp mib browser displays the message"no such object" condition this issue occurs when querying the fan status or power status oids through an snmp mib browser on isa6500 or isa8500 hardware platforms workaround n/a networking 1951563 symptom hostname resolution fails when a hostname is mapped to an ipv6 address condition this issue occurs when the hostname contains uppercase letters or special characters workaround use only lowercase letters in the hostname hostname resolution works as expected 1936692 symptom nfs mounts from the ics shell may fail when the nfs server is located on a different network than the ics internal interface condition nfs server is reachable only through a different network path workaround add a route that allows the ics management ip to reach the nfs share through the appropriate internal interface user experience 1935112 symptom the home button displayed on html5 maximum connections warning page does not redirect users to the home page condition this issue occurs when users click the home button on the maximum connections warning page workaround close the tab or use the home icon security and compliance 1970177 symptom external ict incorrectly detects the file /data/runtime/tt/report behavioral analytics user thtml ttc as an anomaly condition this issue occurs when source ip/location based restrictions are enabled workaround na platform specific 1966605 symptom the message "generate grub2 config failed to stamp sb diagnostic version for system a" is displayed on the console condition this message may be observed during a fresh installation on the openstack kvm platform workaround na jsam 1971454 symptom a warning message,"you don't have permission to change host files", is displayed when launching jsam on ubuntu 1679016 symptom jsam fails to launch on macos when accessed through the safari browser condition the issue occurs when users attempt to launch jsam using safari on macos workaround use microsoft edge or google chrome to launch jsam release 25 1 1 1 1879013 symptom jsam launch fails on mac os condition when jsam is launched via all browsers workaround there is no workaround 1867641 symptom copy and paste do not work in vnc condition occurs when using an ubuntu vnc bookmark workaround na 1861808 symptom copy and paste do not work in the html5 ssh bookmark condition occurs when attempting to use ctrl+c and ctrl+v workaround pasting with right click works 1874029 symptom end users are prompted to enter secondary authentication every time, even though adaptive auth is enabled under realms condition in rare situations, the ics code fails to establish a connection with the ueba database, which is required for adaptive auth functionality workaround restarting the services resolves the issue release 25 1 1 0 clustering 1816740 symptom internal ict periodic and scheduled scans do not work in a cluster condition observed in a clustered environment workaround na windows terminal services 1819807 symptom the administrator is unable to enable the options “deny single sign on for sessions added by user” and “enable remote desktop launcher” condition this issue occurs on the terminal services options page workaround na 1820150 symptom the “allow users to enable local resources defined below” options are enabled by default condition on the terminal services page, the administrator is unable to disable these options workaround na logging & debugging 1776690 symptom process names specified in debug log configuration do not appear in the admin logs condition this issue occurs when process names are included in the debug log settings workaround na authentication 1800576 symptom end user logins fail when authenticating against the certificate server condition this occurs when users present a certificate issued by a leaf (subordinate) ca in a three level certificate hierarchy (subca signed by intermediate ca, which is signed by the root ca), and ocsp checking is enabled for certificate validation workaround enable tls 1 3 on the server to restore successful user authentication ueba 1796977 symptom time mismatch observed in ueba user anomaly reports displayed in the admin ui condition the issue occurs when downloading the reports as csv files workaround convert utc timestamps to ics local time, or vice versa, as required backend access & domain info 1788320 symptom hostname and port based pass through proxy (ptp) does not work condition issue is observed when attempting to connect to backend servers such as vdi workaround accessing the backend server directly via the rewriter component works 1776653 symptom the list domain info page displays the same ip address and fqdn for all listed domains condition this issue occurs when configuring an ad server that has trusts established with other ad servers workaround na waf 1799672 symptom waf logs are not displayed in the event logs section condition this issue occurs when nginx fluent bit is turned off workaround disable and then enable the "waf message" option under the event logs settings page jsam 1788311 symptom psal is unable to download, as button is not working, particularly in ubuntu 24, jsam is also blocked condition occurs when end users access isac options from a client session on ubuntu 24, resulting in psal download failure and jsam blockage workaround none available at this time 1783670 symptom a warning pop up message stating "you don't have permission to change host files" appears when launching the jsam applet conditio n this issue is observed only when the dsid cookie is enabled at the role level option workaround disable the dsid cookie at the role level option to resolve this issue web access 1799537 symptom 502 bad gateway error is observed condition occurs when navigating to maintenance > archival > archiving servers and entering a valid hostname or ip address, but leaving the destination directory, username, and password fields empty selecting any archival component and saving changes triggers the error workaround na release 25 1 0 1 certificate & authentication 1772978 symptom 3 level hierarchy certificate authentication is not functioning condition this occurs when ocsp is enabled for certificate status checking workaround none available at this time 1711706 symptom when switching from tls 1 2 to tls 1 3, end users are not prompted to select a user certificate and instead see a "missing certificate" error condition this issue occurs when the server is configured to use tls 1 3 workaround one of the following workarounds may resolve the issue restart the end user machine restart the ics server try accessing with a different browser html5 1777466 symptom unable to create html5 ssh resource profile via rest api condition while creating resource via rest api workaround works as expected with admin ui 1778321 symptom file upload fails during an ssh session condition this issue occurs when attempting to upload files within an html5 ssh session workaround na jsam 1751812 symptom psal is unable to launch the java applet (jsam) on mac machines on safari browser condition this occurs when an end user accesses a jsam bookmark on a mac machine with "http only device cookie" enabled workaround na release 25 1 0 0 authentication & user login 1625208 symptom an "invalid file" error occurs when uploading the sdconf rec file during ace server configuration condition this issue occurs when the sdconf rec file is generated from an rsa server running version 8 8 or later workaround use an sdconf rec file generated from rsa server version 8 7 or lower 1384221 symptom advance html5 ssh session fails to login via private key conditions \ occurs when attempting login via private key authentication in the web based ssh client workaround login via password is supported 1634450 symptom java secure application manager (jsam) does not work on mac systems condition occurs when an end user attempts to access the jsam applet using the pulse secure application on a mac; the application is unable to launch the java applet workaround na 1628264 symptom end user login is failing even though file is present in the path and logs are wrong; host checker is validating all the unselected policies condition if custom file process is selected and file is present in the mentioned path workaround clientless is working 1634677 symptom default admin realm cannot be deleted condition when admin tries to delete default admin realm from ui workaround na 1637539 symptom radius disconnect requests do not terminate the session condition occurs when “processing of radius disconnect requests” is enabled in the radius server configuration workaround \ na 1642615 symptom rarely, admin login fails with "invalid username or password" error message conditions mostly observed when admin is logging in for the first time workaround none repeated login attempts should resolve the issue certificate, crl, ca & encryption configuration 1561276 symptom the certificate authentication end user page becomes inaccessible after enabling the "advanced certificate processing settings" option under trusted client ca configuration condition occurs when, the “advanced certificate processing settings” option is enabled for a trusted client ca in the admin ui workaround disable "advanced certificate processing settings" 1590484 symptom node secret is not generated on the rsa server, resulting in the absence of the node verification file on the ivanti connect secure (ics) device condition after the first end user login, the ics device does not display (or contain) the node verification files, indicating that node secret establishment with rsa securid is not occurring as expected there is currently no impact on system functionality workaround na 1590662 symptom enabling “validate server certificate” for ldap connections does not enforce or properly handle certificate validation condition occurs when the “validate server certificate” option is enabled in ldap configuration despite this setting, the system either ignores certificate errors, does not validate the server certificate as expected, or behaves as though the option is disabled workaround na 1622308 symptom the crl setting section is not visible in the read only (ro) admin interface additionally, the crl button is present but not greyed out (i e , appears enabled) in the ro admin page condition occurs when certificate revocation list (crl) checking options are enabled workaround na 1651237 symptom waf issue observed when configuring crl (certificate revocation list) checking options in the following scenarios manually configured cdp in sub ca backup cdp in root ca cdp specified in trusted ca condition occurs when configuring crl checking options and using an ip address in the crl url workaround use a domain name instead of an ip address in the crl url 1648859 symptom ics allows sha1 trusted client/server ca certificate to import condition occurs when importing sha1 certificate under trusted client/server ca workaround na active directory 1546749 symptom active directory (ad) traffic segregation is not functioning as expected at both the global and server levels specifically, if dns is configured on a non internal port, domain join fails, and dns traffic does not flow through the non internal port conditions dns configured on a non internal port/interface ad domain join operation attempted workaround na 1624127 symptom on the ad troubleshooting page, dns resolution checks fail for some ad servers when multiple ad servers are configured dns resolution is only successful for the ad server that is also configured as the dns server condition when multiple ad servers are configured on the ics device, the troubleshooting page may show dns resolution failures for some of the ad servers workaround \ configure the relevant ad server’s ip address as the primary dns server on the ics 1634104 symptom ad server uses aes256 encryption type for kerberos authentication protocol even when aes 256 encyption option is not enabled condition admin tries to authenticate using ad server and goes for kerberos authentication protocol (default option), with aes 256 option disabled in server configurations (default setting) workaround na 1642170 symptom change machine password in troubleshooting section of ad server configuration does not work condition occurs when using a windows ad 2025 server workaround use a windows ad 2022 server, if possible oauth 1642111 symptom oauth traffic segregation is not working as expected at either the global or server levels; oauth traffic is not routed through the configured port as intended condition occurs when traffic segregation policies are applied globally or per authentication server for oauth traffic workaround na 1622322 symptoms oauth time skew is not functioning according to the configured values condition oauth protected operations (such as token validation) are not honoring the custom time skew settings as specified in the configuration this can result in unexpected authentication or token validation failures if there is a time difference between the client and server workaround na ueba 1641932 symptom in a cluster setup, ueba (user and entity behavior analytics) functionality does not work for the first user who accesses the system after an upgrade condition this issue occurs only in clustered environments and affects the very first user session after the system is upgraded workaround no workaround is needed; from the second user onwards, ueba functionality resumes and works as expected 1648442 symptom after upgrading, user and entity behavior analytics (ueba) does not show expected logs for the first user session subsequent user sessions display logs correctly, and ueba functionality proceeds as intended condition occurs when accessing ueba immediately after upgrade workaround accessing ueba as a second user (or after the first attempt) resolves the issue; all relevant logs are displayed thereafter behavioral analytics 1637718 symptom an error message "unable to load any data try applying valid filters and reload the page " is shown, and no data is displayed condition occurs when user records are filtered by mac address in the behavioral analytics user report workaround na 1640860 symptom cleared anomalies do not appear in the behavioral analytics user report condition occurs after manually clearing (removing/dismissing) some anomalies and then viewing the behavioral analytics user report workaround na bookmark 1630234 symptom jsam (java secure application manager) bookmark access does not work when java runtime environment (jre) 1 8 is installed on the client system condition occurs when an end user attempts to access jsam profiles using jre 1 8 workaround \ install java development kit (jdk) 21 instead of jre 1 8 1670354 symptom "request header or cookie too large" message appears when accessing any kind of bookmarks added for the end user condition occurs when the end user opens the bookmark and tries to open the child links of the same page workaround na 1669941 symptom file browsing page refresh is not working condition occurs when user accesses the file share path via the browse option workaround user can access admin created bookmark and perform a page refresh to make it work 1670579 symptom multiple monitors use case does not work condition occurs when rdp bookmark created for smart card vm workaround no issue is seen with single monitor 1677378 symptom wts bookmark fails to autolaunch when end user login successfully condition when wts bookmark is configured with autolaunch enabled and hostchecker is also enabled workaround disable hostchecker so that wts bookmark autolaunchs whenever enduser logins successfully 1628122 symptom when a bookmark is created, the description field automatically includes an extra "0" (zero) condition \ occurs during bookmark creation (no additional specific conditions noted) workaround na 1641211 symptom rdp print functionality is not working condition occurs when the print option is enabled in an rdp html5 bookmark workaround na host checker 1644287 symptom host checker version displays as 1 0 in mac condition when a user launches the host checker application on mac, the version shown in installed applications displays as 1 0 workaround host checker functions correctly; only the displayed version is "1 0" 1634866 symptom html5 client copy paste functioality does not work condition occurs when a user attempts to use command+c/command keyboard shortcuts for copy paste operations on a mac workaround select the required content in the html5 client, then right click and use the context menu to copy and paste the content on the local machine 1664534 symptom host checker component and psal is not launching for the remediation scenarios in edge and chrome browser condition if 3 or more hc policies configure (custom or predefined) workaround use firefox browser or enable browser extension for chrome/edge 1641387 symptom host checker policies are empty in the remediation > enable custom actions field condition in all conditions, it is empty workaround na 1657227 symptom 502 bad gateway message is seen condition when user clicks "profile" hyperlink in the hc page workardound n/a rest api 1612333 symptom "ip pool cannot be empty" error observed when switching from dhcp based ip assignment to pool based for vpn connection profiles via rest api condition occurs when the "ip address pool" attribute is provided before the "ip address assignment" attribute in the request body workaround provide "ip address assignment" before the "ip address pool" attribute in the request body 1601479 symptom configuring fqdn based lockdown exception rule for a connection set fails when attempted via the rest api condition occurs when attempting to configure an fqdn based lockdown exception rule for a connection set using the rest api workaround configure the fqdn based lockdown exception rule manually via the ivanti connect secure (ics) administrative user interface 1634397 symptom exception rule creation when using rest api failed condition occurs during attempts to create an exception rule via rest api workaround none 1658685 symptom rest api call to set fips is failing with error "non fips cipher is selected when fips mode is on (outbound)" condition occurs when enabling fips using rest api and tls 1 3 is selected in in bound settings workaround configure fips manually from admin ui page upgrade 1634850 symptom bind failed related logs are seen for few seconds condition during ics upgrade workaround na 1640944 symptom \ the error message /bin/tar tlscerts/cert pem not found in archive is displayed on the console condition occurs during the ivanti connect secure (ics) upgrade process workaround na 1658693 symptom ics console shows boot manager screen condition occurs while performing an upgrade workardound perform a reset or reboot from the boot manager; the upgrade will restart 1600182 symptom the message "unable to synchronize time, either ntp server(s) are unreachable or provided symmetric key(s) are incorrect" appears in the system logs conditions this occurs after a system upgrade or a reboot workaround na config import 1641516 symptom file system check (fsck) related messages are seen in the console condition occurs when an administrator performs a reboot or clears the device configuration workaround no functionality impact observed 1666021 symptom push config fails for custom port syslog server config condition occurs when configuration is pushed from a lower build ics to the latest workaround configure using the ics gateway ui 1666027 symptom syslog xml import fails for custom port syslog server config condition occurs when exported from ics lower build and imported to latest ics build workaround \ configure using the ics gateway ui 1664557 symptom blank screen appears when attempting to use a custom sign in page imported via xml or binary condition due to perl modules upgrade, stricter rules are applied in handling html files workaround import the custom sign in page as a zip file format; ui will display any errors encountered resolve the errors, then re upload the custom sign in pages 1669912 symptom html5 storage config is not getting imported condition occurs when importing binary html5 config workaround configure using the ics gateway ui waf 1634835 symptom when an admin attempts to delete more than 198 users at once, the web application firewall (waf) blocks the request condition occurs during the deletion of more than 198 users in a single operation workaround delete users in smaller batches of up to 150 users at a time to avoid waf blocking 1634847 symptom no "upload successful" message is displayed after uploading a waf ruleset package condition occurs when an administrator uploads a waf ruleset package through the ui workaround check the admin logs to confirm the status of the upload 1665495 symptom waf messages are seen in event logs condition when accessing html5 bookmarks via rest api workaround na network operations 1616321 symptom bandwidth management does not work conditions occurs when ssl is used workaround use esp protocol instead of ssl 1637651 symptom traceroute output displays %int0, %ext0, %mgt0 condition na workaround na 1648583 symptom pushing config does not works using ipv6 workaround use ipv4 for push config functionality to work 1663938 symptom unable to view the charts for concurrent users, hits per second, etc in overview page conditions occurs when attempting to view stats for another member in the cluster workaround view stats from the admin ui of the respective cluster node impacted functionality graphs on admin ui page 1665464 symptom "ipv6 not enabled on any port" error message is displayed when using troubleshooting commands condition occurs when vlan ports are configured with ipv6 address, but internal, external, and management ports are not configured with ipv6 address workaround this is a display issue and does not impact functionality 1665457 symptom portprobe is not working with management port vlan condition occurs when admin attempts to perform portprobe using vlans created on the management port workaround na 1628560 symptom \ ivanti connect secure (ics) is sending syslog messages (for both tcp and udp) over the management port conditions this occurs when syslog is configured with default settings workaround disable the management port ui 1641679 symptom \ screen recording for an end user session fails (recording cannot be saved or downloaded) condition occurs when the “screen recording end user” option is enabled in a bookmark and an end user attempts to utilize session recording workaround open the browser’s developer tools console and enter $rdp close( ) this triggers a pop up allowing the user to save the session recording to the client device 1574532 symptom when an invalid url is accessed in the end user login page, clicking the ok button does not redirect or navigate the user to the home page condition occurs when a user browses to any invalid url on the end user login page and interacts with the error prompt by clicking “ok” workaround na 1679335 symptom sample template files related to kiosk and softid are not working for custom sign in pages condition seen on both kiosk and softid templates workaround na 1648229 symptom error 403 is seen while enabling/disabling/vip failover node in ap cluster with nsa 22 8r1 4 and 25 1 0 0 gateway workaround try performing enable/disable/vip failver from the gateway ui ldap 1634055 symptoms encountered an error "invalid ldap server ip address" condition this occurs when attempting to configure an ldap server using an ipv6 address workaround na 1634087 symptom when configuring a backup ldap server, an error “invalid admin credentials” is encountered condition occurs while entering the backup ldap server ip and base dn during server configuration workaround na jsam 1566054 symptom jsam is not accessible on ubuntu; an error "application launcher is not installed" is seen condition jsam is not accessible on ubuntu workaround na 1635741 symptom unable to access the intranet server "tools svr engdevroot com" using jsam condition occurs when trying to access "tools svr engdevroot com" using jsam workaround na deployment 1671089 symptom assuming ownership of connection set fails after turning on fips mode where tls 1 3 is enabled condition next generation service restart causes the failure workaround add sleep time after enabling fips mode 1670033 symptom ics returns blank page when public sites are accessed condition when public sites are enabled with csp workaround na 1674580 symptom package upload fails for 2nd node condition during cluster upgrade workaround it automatically tries to upload package again and cluster upgrade proceeds further 1669339 symptom login through rest api fails with tls 1 3 enabled after lockdown exception rules are configured condition occurs when rest api is triggered workaround login using admin ui logs 1676718 symptom failed to update profile for user message seen in event logs conditions messages are seen under the following conditions secondary auth is enabled for a user realm adaptive authentication is enabled for the user realm end user trying to login using isac workaround none adaptive auth functionality is not affected
