What's New
version 25 1 3 1 product version build ics 25 1 3 1 23681 isac 22 8r7 mobile client 22 8r8 48847 18981 (android) 96449 (ios) waf default crs 1 0 4 default esap 4 6 4 this release includes security enhancement ivanti encourages customers to upgrade to this latest version rsa authentication manager 8 8 support for rsa authentication manager 8 8 is qualified as part of the validation for ics 25 x as a result, users who have upgraded to rsa authentication manager 8 8 will be able to use this functionality with ics 25 1 3 1 for rsa authentication manager 8 8 and newer versions, ivanti recommends using the new rsa (rest api) authentication server, see see using a rsa server (rest api) docid\ xspmmkliydjkgpv mrnqi import xml via rest api you can now import xml configuration files through a rest api the import xml rest api uses the same validation and processing workflow as the import xml operation in the ivanti connect secure (ics) admin ui, see import xml rest api https //docs ivanti com/ps/help/en us/ics/com/api/ics ips configurations using rest apis#import xml configuration version 25 1 3 0 product version build ics 25 1 3 0 22109 isac 22 8r7 mobile client 22 8r8 48847 18981 (android) 96449 (ios) waf default crs 1 0 4 default esap 4 6 4 rest api diagnostic logs a new rest api diagnostic logging capability has been added to improve visibility into system health monitoring operations administrators can use these logs to assist troubleshooting and operational diagnostics, see rest api diagnostic logs https //help ivanti com/ps/help/en us/ics/25 1 x/ag/logging n monitoring htm#rest windows hello for business (whfb) single sign on enhancements this release includes enhancements to windows hello for business (whfb) single sign on functionality, providing improved integration with modern authentication workflows and passwordless authentication deployments, see windows hello for business sso server https //help ivanti com/ps/help/en us/ics/25 1 x/ag/auth n directory srvrs htm#windows fido2 authentication enhancements ics has been enhanced to support fido2 related authentication improvements, enabling support for modern passwordless authentication methods and strengthening identity security, see fido2 support for mobile isac https //help ivanti com/ps/help/en us/ics/25 1 x/ag/network n host admin htm#fido2 active user session api enhancements the active user sessions rest api has been enhanced to support filtering session data based on user, see active user session https //help ivanti com/ps/help/en us/ics/22 x/apig/rest api soln guide/ics spec configs using restapis htm#fetch2 websocket support through http(s) proxy ivanti connect secure (ics) now supports establishing and maintaining websocket connections to backend application servers through a configured http(s) web proxy this enhancement enables websocket based applications to function seamlessly in environments where proxy routing is required by organizational policies automated certificate management environment (acme) support ivanti connect secure now supports the automated certificate management environment (acme) protocol to automate certificate requests, domain validation, certificate issuance, and certificate deployment on the designated interface, see acme server https //help ivanti com/ps/help/en us/ics/25 1 x/ag/certif security admin htm#acme default vlan id support with ipv6 on internal interfaces ivanti connect secure now supports the use of the default vlan id when ipv6 is configured on the internal interface this enhancement ensures that the default vlan id remains available and functional when both ipv4 and ipv6 are enabled, see default vlan id https //help ivanti com/ps/help/en us/ics/25 1 x/ag/network n host admin htm#default bulk acl management using rest api ivanti connect secure now supports bulk management of access control lists (acls) through rest api administrators can create, update, and delete multiple acls in a single api request, improving scalability and operational efficiency for large enterprise and msp deployments, see create multiple acls https //help ivanti com/ps/help/en us/ics/22 x/apig/rest api soln guide/ics spec configs using restapis htm#create2 postman collection for ics rest apis ivanti connect secure now provides a postman collection for publicly available rest apis, enabling administrators and developers to quickly explore, test, and integrate ics apis using the postman client, see postman collection https //help ivanti com/ps/help/en us/ics/22 x/apig/rest api soln guide/ics postman apis htm#top oauth group claims for role mapping ivanti connect secure (ics) now supports role mapping based on group claims received from oauth providers such as microsoft entra id (azure ad) administrators can use group information included in the oauth id token or userinfo response to assign user roles within ics user realms, see oauth group claims role mapping https //help ivanti com/ps/help/en us/ics/25 1 x/ag/auth realms htm#oauth http/2 ingress support in connect secure connect secure has been enhanced to support http/2 for inbound client connections http/2 provides improved connection efficiency and performance through multiplexing and optimized protocol handling, see http protocol configuration https //help ivanti com/ps/help/en us/ics/25 1 x/ag/network n host admin htm#http secure boot and vtpm support gcp, aws platform now provides secure boot support with vtpm functionality, enhancing security and integrity for virtual machines, see secure boot with tpm/vtpm https //help ivanti com/ps/help/en us/ics/25 1 x/sb ug/landingpage htm virtual appliance platforms added support for the new virtual appliance platforms isa v 4500, isa v 6500, and isa v 8500 in ivanti connect secure (ics) version 25 1 3 0, see isa va supported platforms https //help ivanti com/ps/help/en us/ics/25 1 x/25 1 3 0/spg/client env contents htm#hypervis host header validation ivanti connect secure now provides a console based option to disable host header validation on the management interface this enhancement supports deployments where the management interface is accessed through network address translation (nat), helping ensure administrative access in environments where host header validation may otherwise block requests, see host header validation https //help ivanti com/ps/help/en us/ics/25 1 x/ag/security hardening htm#host configurable certificate challenge timeout administrators can now configure the maximum interval between certificate challenge exchanges during the pre authentication phase of certificate based authentication the timeout value can be set from 1 to 4 minutes, with a default value of 1 minute, see certificate challenge timeout https //help ivanti com/ps/help/en us/ics/25 1 x/ag/general access management htm#general access management 28561674 1012140 ui enhancement for compliance report failed policies now display the corresponding failed rule names and failure reasons additionally, host check results are presented in a separate column to improve visibility and reporting clarity, see using host checker reports and logs https //help ivanti com/ps/help/en us/ics/vnow/hccg/using host checker reports and logs htm version 25 1 1 0 product version build ics 25 1 1 0 11811 isac 22 8r5 mobile client 22 8r6 41063 17079 (android) 5717 (ios) waf default crs 1 0 4 default esap 4 6 4 feature parity with ics release 22 8r2 3 https //help ivanti com/ps/help/en us/ics/22 x/22 8r2 2/rn/landingpage htm and 22 7r2 12 https //help ivanti com/ps/help/en us/ics/22 x/22 7r2 11/rn/landingpage htm citrix support ics now supports the use of device id as a unique identifier in citrix xendesktop ltsr 2507, enabling enhanced device based authentication and tracking secure boot and vtpm support hyper v, openstack kvm, azure platform now provides secure boot support with vtpm functionality, enhancing security and integrity for virtual machines, see deployment guide https //help ivanti com/ps/help/en us/ics/25 1 x/sb ug/introduction htm version 25 1 0 1 product version build ics 25 1 0 1 10387 isac 22 8r5 mobile client 22 8r6 41063 17079 (android) 5717 (ios) waf default crs 1 0 4 default esap 4 3 8 there are no new ics features in this release this release includes patch for openssl cve 2025 15467 feature parity of this release remains same as 25 1 0 0 refer the kb https //forums ivanti com/s/article/resolution of openssl cve 2025 15467 in network security products for more info version 25 1 0 0 product version build ics 25 1 0 0 5663 isac 22 8r2 mobile client 22 8r3 33497 14 (android) 95033 (ios) default esap 4 3 8 secure boot with tpm/vtpm the secure boot feature offers protection against unauthorized bootloader and kernel images, malware, and rootkits, and ensures compliance with security by design principle while improving boot time for more information, see secure boot with tpm/vtpm https //help ivanti com/ps/help/en us/ics/25 1 x/sb ug/landingpage htm rotate internal storage key this process encrypts sensitive information like passwords when storing them internally and ensures the encryption key is unique and random for every ics instance, see rotate internal storage key https //help ivanti com/ps/help/en us/ics/25 1 x/ag/security hardening htm#rotate security enhanced waf operation this feature protects connect secure gateway web applications by filtering and monitoring http traffic, preventing attacks such as sql injection, cross site scripting (xss), and other web exploits, see configuring web application firewall ui https //help ivanti com/ps/help/en us/ics/25 1 x/ag/security hardening htm#configur and security enhanced waf operation console https //help ivanti com/ps/help/en us/ics/25 1 x/ag/security hardening htm#configur2 shared secret key this feature configures a shared secret for each source/target pair at time of creation of push config target, see configuring targets https //help ivanti com/ps/help/en us/ics/25 1 x/ag/config file admin htm#configuration file administration 293578963 1016669 password key generation new api's introduced to generate and fetch the password key, see apis https //help ivanti com/ps/help/en us/ics/22 x/apig/rest api soln guide/ics spec configs using restapis htm#generate2 next generation web server the next generation web server has been developed to enhance the performance and scalability of web server infrastructure, see next generation web server https //help ivanti com/ps/help/en us/ics/25 1 x/ag/security hardening htm#next web server logs are implemented for web related event codes with debug severity, see using the debug log https //help ivanti com/ps/help/en us/ics/25 1 x/ag/troubleshooting tools htm#web selinux security policy the ics system provides an enforcing only selinux capability, ensuring that even the root user or admin cannot switch selinux to permissive mode without rebooting the system, see selinux security policy https //help ivanti com/ps/help/en us/ics/25 1 x/ag/security hardening htm#selinux2 verbose log administrators can toggle selinux verbose logging to control the detail level of selinux related logs, see selinux verbose log https //help ivanti com/ps/help/en us/ics/25 1 x/ag/security hardening htm#selinux3
