Known Issues
2 min
the following table describes the open issues with workarounds where applicable problem report description release 22 8r1 10 1821234 symptom tcp dump collection and upload from the nsa controller does not work on zta gateway workaround no workaround release 22 8r1 9 1746960 symptom zta gateway registered to the controller will be in "not ready" state and the gateway console will display "config pull status is config bad" workaround navigate to zta gateway console, under option 4>option 27(clear secure access config) release 22 8r1 8 1 1753137 symptom zta user session time out values will be default and greyed out in the global settings condition admin will not be able to modify the user session values on the zta tenant under global settings workaround if there is vtm subscription in the controller and has a vtm gateway added, it need to be deleted release 22 8r1 8 1764253 symptom when labeling (white labeling) in global settings are applied or modified in the tenant, these changes do not reflect in nsa and zta this occurs whether the settings were previously applied or if the tenant attempts to apply them again workaround currently, there is no workaround available 1745554 symptom risk level is not evaluated precisely under insight > devices the top risky application chart under insight > users > all users appears empty workaround na 1742051 symptom the endpoint location is shown as 'unknown' across all locations on analytics dashboards in the nsa controller workaround na 1710865 symptom anomalies are not visible on the analytics dashboard because the location for enrolled devices is shown as 'unknown' in the nsa controller condition anomaly detection requires accurate location data for endpoint devices connected to the nsa controller if the location is 'unknown', anomalies will not be displayed workaround na release 22 8r1 6 1698564 symptom enabling debug logs for zta gw under troubleshooting is failing workaround na 1698492 symptom standalone zta gateways registered to the controller cannot be added to the zta gateway group when trying to create new gateway group workaround create an empty gateway group navigate to standalone gateway and under overview > add gateway to the gateway group release 22 8r1 4 1630297 symptom admin will see the message "interface not enabled or invalid interface" when trying to perform portprobe from zta gateway troubleshooting commands with 22 8r2 3 v 723 gateways registered to 22 8r1 4 controller workaround portprobe should work fine when trying to perform from gateway console options release 22 8r1 2 1567059 symptom the ui screen appears blank when the endpoint machine is non compliant with host check (hc) condition end point machine non complaint with hc workaround close and reopen the isac 1565991 symptom mcafeeantivirushigh default av import issue workaround unmap default mcafeeantivirushigh device policy in auth policy or in secure access policy if configuration import error in admin logs or warning in device policy page create custom av policy for mcafeeantivirushigh and map it for the policy 1553286 symptom syslog forwarding configuration with "via gateways" on zta may impact syslog forwarding for nsa/zta cause system tries to forward logs "via controller" also even with configuration "via gateways" on zta workaround on zta, configure syslog server for zta "via controller" only 1546793 symptom unicodes are seen sometimes in the tenant ui instead of icons condition while using the tenant using chromium browser workaround no functional impact reopen the app in another tab in the browser, issue will not be seen release 22 8r1 1512873 symptom report job fails when creating a report adhoc or scheduled, and an admin configures it to share with any admin user in the tenant workaround na release 22 7r1 6 1474762 symptom the tenant might go into config error state when new esap 4 5 1 is enabled and the existing antivirus/antispyware/firewall/hd encryption polices has removed products workaround edit the existing device polices rules , unselect existing vendors/products and reselect and save for example, comodo security solutions corresponding product and vendor removed release 22 7r1 5 1442614 symptom error while trying to reset totp user account from nsa controller under administration > admin management > authentication servers if secondary auth is configured for the sign in policy workaround no workaround 1440328 symptom tcp dump action under gateway troubleshooting in nsa/zta fails to upload the dump to troubleshooting overview this issue happens intermittently when admin is unable to stop the tcp dump workaround try re triggering tcp dump action release 22 7r1 4 2 1425921 symptom ivanti secure access client page under administration > installation packages does not respond when we turn off "always auto update to latest version" option without selecting the client package version workaround select appropriate client package version and save before switching "always auto update to latest version" option release 22 7r1 4 1410360 symptom the consolidated landing page (zta+nsa) is currently in preview mode, you may see some discrepancies between the chart counts and the logs/table views of the corresponding charts workaround no workaround 1384267 symptom nsa will allow to add any number of nodes to the cluster with hardware devices while it is restricted to 2 nodes for virtual (isa v) gateways registered to controller workaround limit number of nodes to not more than 4 while registering hardware devices to nsa for classic ics while forming a cluster only 2 nodes are supported for 22 x ics release 22 7r1 3 1350201 symptom nsa log export for any l4 dashboard shows the active view data for the previous four days when performing the log export, it exports the log data for only the previous 1 hour workaround to display the correct logs in the csv/json export, select the custom time range that is needed for data export 1387881 symptom data mismatch will be seen in the active view (last hour) as a result of the zta overview page and consolidated dashboard (nsa+zta) displaying data from different time stamps workaround to display data inside a certain time range, a workaround is required to filter the data using the desired time range 1370506 symptom active view(last 1 hour) home page showing consolidated data for nsa+zta will show only the active user count activity and not all the user activity in the last 1 hour workaround the overall user activity for the zta users in the last 1 hour(active view) will be reflected in the overview page of zta 1389307 symptom nsa 'all gateway' count on the overview page as well as insight > gateways summary strip shows the registered and online gateways count only in the historic views workaround na 1375681 symptom application logo will be blank when trying to install the ivanti secure access client from the web browser flow just before it starts downloading the client workaround na (no impact on installing isac from web browser flow) 1391936 symptom on the consolidated landing page, the current day view (displayed as last x hours) may show a count mismatch between the summary panel and the table condition when admin wants to view details of current day's data workaround the admin can utilise the custom view to observe data for the same time range 1392136 symptom on the consolidated landing page sankey chart, the gateways shown in the gateways column might not correspond to the active gateways count condition when a user connects to a gateway but does not access any application through it workaround regard the summary panel gateways count as the accurate active gateways count 1391923 symptom the admin might notice discrepancies between the device counts in the summary panel and the table view when clicking on the counter condition endpoints without a device identification number or share the same device identification number workaround consider the summary panel count as the accurate count 1393507 symptom consolidating landing page(zta+nsa) is in preview mode and hence there could be data mismatch between the counts on the chart compared to the logs/table view of corresponding charts workaround no workaround 1393596 symptom admins might observe a slight difference in the cpu, swap memory, disk usage and network throughput values shown on the tooltip fortop gateways by health chart under nsa > insight > gateways and the table view logs for respective gateways workaround no workaround 1393987 symptom zta historic overview /users/applications is not properly displayed in few tenants workaround use the custom time range option to get the historic data 1393374 symptom the count shown for specific gateway version might differ between the gateway by version chart and the table view under insights > gateways in nsa workaround no workaround release 22 7r1 2 pzt 45006 symptom firewall device policy fails on endpoint when the advance settings are enabled on the firewall device rule with microsoft product on windows endpoint workaround na pzt 43989 symptom for pre canned roles login user, navigating to some pages shows not found message if the page is not meant for that role workaround na pzt 39046 symptom end user logins will be blocked and admin login will show 401 error when aaa journal version is in bad state once a new esap version is activated under administration > installers > esap workaround edit the already configured device policy and remove the unsupported products from it and add the supported products this applies for all the opswat based device policies (antivirus, firewall, patch, antispyware) irrespective whether these device policies are enforced on a specific secure access policy pzt 45091 symptom zta data mismatch on the home page (zta+nsa consolidated) as compared to the overview page showing only zta specific data in the controller workaround na pzt 45016 symptom user access/event logs not updated intermittently in the gateways due to which analytics dashboards will not show relevant data once the gateway is upgraded to 22 7r2/22 7r1 2 workaround reboot gateway to get the user access/event logs along with analytics data 1327244 symptom log export does not carry forward the advance filter, sort, search applied on the user access, event and admin logs under insights workaround na 1332914 symptom zta gateways showing fips version in the display of gateway console when gateway is upgraded to 22 7r1 from 22 5r1 x or 22 6r1 x although no functionality impact in end user application access workaround na release 22 6r1 2 pzt 42473 symptom enrollment fails from browser and will give error "sap is not configured for /login /login/enroll" when device policy is enforced on the user sign in policy and the same device policy is modified workaround navigate to secure access >manage users >user policies and need to edit/save the user policy on which device policy is mapped post changing the device policy pzt 42710 symptom if a user group has a saml attribute user rule mapped to it, changing saml auth to local auth in the user policy should alert with a warning workaround remove user rule which has saml attribute before changing user authentication server from saml auth to local authentication server pzt 42722 symptom mdm device rule should not be added to the device policy which is enforced on the admin sign in url under user policies workaround na pzt 42721 symptom analytics dashboard shows the mdm device attribute failure if there is a hybrid device policy(location, hc, mdm) enforced on secure access policy wherein the non compliance is actually due to hc/location failures workaround na pios 6533 symptom re authentication using login to ivanti secure access is not working workaround click on 'connect' button manually release 22 6r1 pzt 42203 symptom while editing an existing fqdn app policy with app discovery enabled to a url based policy, app discovery checkbox gets greyed out and not editable workaround uncheck the app discovery first and then edit the application url convert wildcard to url pzt 41958 symptom zta gateway shows upgrade failed and shows a different version on the secure access gateways dashboard when upgraded to latest version but the console of the gateway is successfully upgraded workaround none end to end use case when connecting to the gateway is not impacted as the gateway is already upgraded to the latest version pzt 41797 symptom upgrade/downgrade of esap might cause bad config state, if configured product not present in old release workaround if new product is configured with new esap version and downgraded to older version where that product is not available admin has to manually delete that product to get back the tenant in normal state for example, when upgrading from esap 4 1 6 to esap 4 2 6, admin has to manually remove the vendor name "broadcom" and product name "symantec endpoint protection (0 0 x)" from the configured av/as/firewall device policies pzt 41821 symptom gateway ui will not validate ip address /subnet and subnet gw info while creating zta gateway under manage gateways workaround admin has to provide the correct interface ip/subnet and subnet default gateway info while configuring zta gateway pzt 41719 symptom ueba threat data for the user in the zta analytics dashboards as compared to the ueba threat report is different for the same timestamp workaround na pzt 41837 symptom ueba threat score and ueba threat rank is not showing accurate for the users in active and historic view on the analytics dashboards in case of simultaneous (ics + zta) scenario workaround na release 22 5r1 2 pzt 41401 symptom error 401 un authorized when trying to login to the tenant with any of the pre canned role like read only, cxo and net admin if there are no gateways registered in the controller workaround register zta gateway in the tenant controller and login pzt 41264 symptom page not found when trying to login with the pre canned network admin role configured under system >admin roles workaround create a custom admin role with only permissions to view the manage gateways dashboard which serves the purpose of the network admin role pzt 41319 symptom after a fresh installation of the client, it closes unexpectedly condition manual or browser installation of the client workaround open the client from the system tray release 22 5r1 pzt 40857 symptom non compliance policy failure reason is empty on the drill down log view dashboard when non compliance is reported while accessing rdp/ipv4 application type workaround na pzt 40739 symptom non compliance policy failure reason on l4 (drill down) log dashboard states all the strings related to host check (hc) failures instead of a specific string, which caused the failure for that specific application access workaround na pzt 37613 symptom the timestamp displayed under the cards in the user info panel on landing page is incorrect in the historic view workaround na pzt 39046 symptom end user logins will be blocked and admin login shows 401 error when aaa journal version is in bad state once a new esap version is activated under administration> installers > esap workaround edit the already configured device policy and remove the unsupported products from it and add the supported products this applies for all the opswat based device policies (antivirus, firewall, patch, antispyware) irrespective whether these device policies are enforced on a specific secure access policy pzt 40518 symptom endpoint connection to the controller will fail and show the status as 'failed' when rule requirement > custom expression is configured under secure access > manage devices > device policies due to aaa journal version failure workaround edit the device policy with custom expression and save again so aaa journal version will recover release 22 4r3 pzt 38904 symptom tenant admin ui will be logged out frequently with 401 error and end user connections will be blocked due to incorrect cache in aaa workaround find the xml import failure log in insight > admin logs and remove the unsupported product version from the device rule and save it pzt 39870 symptom multiple sap policies with having device policy configured with av rule results in incorrect cache on aaa workaround na release 22 4r1 pzt 39050 symptom intermittently it is observed inconsistency in historic view data in analytics dashboards workaround na pzt 38904 symptom gcp gateway is not in the connected state after reboot using the gcp vm control options (reset and stop/start) workaround post deploying the gateway instance in gcp after the successful registration of gateway to the controller, reboot from serial console of the instance once to avoid the issue also we dont recommend to use hard reset to reboot the cloud gateways pzt 39351 symptom application details with kerberos/ldap/ntp or unknown port numbers not detecting while creating secure access policy when migrating from ics to zta workaround admin need to modify the application details manually by adding the relevant port number at the end of fqdn/ip for example in case of ldap, ldap\ //\<fqdn> need to be changed to \<fqdn> 389 and for kerberos, kerberos\ //\<ip> need to be changed to \<ip> 88 pzt 29634 symptoms ivanti client is not able to connect to the gateway and fails with error 1147 invalid client certificate during upgrade/rollback of a standalone or gateway group workaround if it is a standalone gateway, then the gateway need to be added to a gateway group and removed back to perform certificate renewal and reboot the gateway if a gateway is already a part of gateway group, then it needs to be removed and added back to the gateway group pzt 38904 symptom gcp gateway is not in the connected state after reboot using the gcp vm control options (reset and stop/start) workaround post deploying the gateway instance in gcp after the successful registration of gateway to the controller, reboot from serial console of the instance once to avoid the issue also we dont recommend to use hard reset to reboot the cloud gateways pzt 39046 symptom end user logins will be blocked and admin login will show 401 error when aaa journal version is in bad state once a new esap version is activated under administration > installers > esap workaround edit the already configured device policy and remove the unsupported products from it and add the supported products this applies to all the opswat based device policies (antivirus, firewall, patch, antispyware) irrespective whether these device policies are enforced on a specific secure access policy pzt 39002 symptom at end of every end ueba threat score is recalculated and there could be a change in the threat score workaround na pzt 38858 symptom after upgrading mod aaa to latest build, assigned roles are missing in cache and admin login might fail workaround after upgrading edit admin groups and then save pzt 38995 symptom enrollment/auth is blocked when connection is made from an endpoint which does not have the source ip listed in allow/block criteria in the network device policy which is enforced on user policy workaround create network device policy to allow the source ip/s instead of denying as the default action is to deny pzt 38975 symptom 500 error intermittently seen on the dashboard when un enrolling clients from 'manage devices' and new device enrollment will fail on the endpoint due to connectivity issue between the client service and redis workaround restart client service on the controller pzt 38722 symptom non compliance count mismatch on the analytics dashboards in the summary strip and non compliance info panel in historic view when non compliances are reported in the same hour from the same user workaround no workaround pzt 38718 symptom \ carta check failing on mac osx for the predefined and custom device policies workaround disconnect and connect again to re evaluate the compliance and perform remediation accordingly pzt 38717 symptom firewall device policy not evaluated on the endpoint when default microsoft product is configured while having 'rule options' and rule monitoring on workaround no workaround pzt 38690 symptom if previously selected client package version is not present after upgrade, latest version will be set to default with auto upgrade enabled workaround select the required client version if the admin don't want to use latest client version after upgrade pzt 38619 symptom risksense notify device policy blocks enrollment via web browser when applied on the enrollment user sign policy workaround device policy should be configured with multiple device rules apart from risksense notify policy or connect to zta connection profile directly from ivanti client already installed on the endpoint pzt 38618 symptom ui misaligned when host checker policy fails in the web browser and 'try again' button is clicked on windows endpoint workaround no workaround pzt 38599 symptom device policy enforced on the sign in policy does not get updated when any device rule is modified to that corresponding device policy workaround navigate to secure access >manage users >user policies and edit the user policy where the device policy is enforced and 'update user policy' pzt 38502 symptom non compliance card shown on analytics dashboard for applications having device policy enforced which is configured for one operating system and the non compliance is reported on another operating system workaround no workaround pzt 38501 symptom saml user with error "invalid assertion" received on the endpoint frequently in the cef browser when connecting to zta workaround click on 'sign in' and re try on getting the error dialog with "invalid assertion" pzt 38428 symptom location device rule does not save properly when denying access from a specific city but allowing access from the same country workaround \ delete the location rule and add a new one pzt 38327 symptom no error string or instruction displayed on the ivanti client when network/location/risksense policy is enforced on user enrollment/authentication sign in url and the compliance fails on the endpoint due to any of these device policies workaround navigate to insight >logs >access logs to view the compliance logs for admin no workaround for the end user pzt 38315 symptom zta gateway console may show register as one of the option in the menu, even though the gateway is already registered condition sometimes with cloud it is taking a while for the registration process to get completed hence when the console options are displayed after registration process is triggered , the register option is still present in the console menu workaround pressing enter key after few secs the register option won't be present in the gateway console menu pzt 38265 symptom controller ui should show error while creating gateway group if one of the gateway in the gateway group is mapped with a known network tag in gateway selector configuration workaround \ no workaround pzt 38256 symptom session migration from one network to another still shows the session with the older source ip under insights >users > active sessions workaround no workaround pzt 37981 symptom time of day device policy cannot be enforced while creating secure access policy when gateway selectors are used workaround use standalone gateways or gateway groups instead of gateway selectors pzt 37841 symptom report format csv/json has the epoch timestamp instead of human readable workaround no workaround pzt 37765 symptom authentication url gives error as 'sap is not configured' when trying to open from browser workaround navigate to secure access >manage users >user groups edit the user group and save it again pzt 37613 symptom the timestamp displayed under the cards in the user info panel on landing page is incorrect in the historic view workaround no workaround pzt 36884 symptom sankey chart does not show the exact path for application being accessed with respect to user group workaround no workaround pzt 36623 symptom allowed domains added under any configured application shows ip address instead of the application name when accessed on analytics dashboards workaround no workaround pzt 36050 symptom sign in button is visible for the end user even when the ueba score has crossed the threshold and user is denied login workaround no workaround pzt 29634 symptom ivanti client will not be able to connect to the gateway and fails with error 1147 invalid client certificate workaround remove gateway from the gateway group and then add it back pzt 27457 symptom policy failure dashboard shows compliance and network rule failures when any one of the rule is passing on the client machine having a common policy enforced which comprises of network and compliance rules together workaround no workaround release 22 3r4 pzt 31655 symptom mfa support signing in an older version client through a mfa device policy with totp enabled causes a loading components page or loop after totp registration in the end user portal workaround totp is supported for client versions applicable to the 22 2r1 release only make sure your client software is up to date pzt 35144 symptom admin rules cannot be deleted when attached to an admin group workaround select only rules that are not associated with any admin groups for deletion pzt 35194 symptom applications page lacks row level actions workaround scroll to top after selection to edit/delete pzt 36050 symptom sign in button is visible for the end user even when the ueba score has crossed the threshold and user is denied login workaround n/a pzt 36753 symptom subscription page gateway filters don't work under some conditions workaround none pzt 36884 symptom sankey chart does not show the exact path for application being accessed with respect to user group workaround n/a pzt 37424 symptom when ics and zta components already installed on the endpoint, auth re directs to default login url instead of custom saml auth url when trying to enroll with multi sign in url workaround deep clean endpoint with all client components and do fresh installation pzt 37536 symptom non compliance cards not seen on the analytics dashboards for application types ssh, telnet, rdp and ipv4 workaround n/a pzt 37765 symptom authentication url gives error as 'sap is not configured' when trying to open from browser workaround navigate to secure access > manage users > user groups edit the user group and save it again pzt 37803 symptom the page appears broken when visiting gateway logs in chrome browser workaround please follow these steps in your chrome browser go to chrome //settings/system # enable hardware acceleration by clicking on the "use hardware acceleration when available" switch relaunch the browser pzt 37841 symptom report format csv/json has the epoch timestamp instead of human readable workaround n/a pzt 37912 symptom auth failure messages with the username as system are observed in the top auth failures chart on l2 all users dashboard when authentication method is saml and the user has crossed the ueba threat score threshold configured as a part of actionable insights workaround n/a pzt 37966 symptom when ip resource is added with fqdn sub domain, fqdn sub domain is not sent for the client workaround add fqdn as main resource and add ip as sub domains pzt 37981 symptom time of day device policy cannot be enforced while creating secure access policy when gateway selectors are used workaround use standalone gateways or gateway groups instead of gateway selectors pzt 38101 symptom if 22 2r1 or below version of gateways are present & ogs feature is configured, older gateways may not go to ready state workaround upgrade gateways to 22 3r1 and above to use ogs feature pzt 38173 symptom user name with %40 is shown in tenant access log when saml based authentication and device policy are enabled at secure access policy (sap) workaround n/a release 22 3r3 pzt 6921 symptom after un enrollment of profile, the vpn connection should be disconnected instantly and the profile should be removed from workaround open and move between the screens a pop up message should appear warning that the certificate is revoked the profile is removed automatically pzt 7581 symptom vod is not notifying the end user when notification is turned off workaround enable notification for the in ios device settings pzt 8610 symptom simultaneous connections after switching to a new user, shows the enrollment details workaround n/a pzt 8740 symptom os check for android is failing while updating the policy dynamically workaround none pzt 8866 symptom dynamic policy update is not working when the same ios os device policy is updated for deny and allow access workaround none pzt 9926 symptom esap upgrade for sometimes does not work when classic vpn and connections use different esap versions workaround make sure classic vpn and connections use the same esap version pzt 9979 symptom captive portal detection is not working with connection workaround open a browser window the user should then be re directed to the captive portal for guest authentication pzt 10287 symptom resource access is not going over when chrome is enabled with secure dns feature workaround disable the secure dns option on chrome settings or use the dns server which supports 443 https //en wikipedia org/wiki/public recursive name server https //en wikipedia org/wiki/public recursive name server pzt 10340 symptom \[windows] simultaneous connections with the bng vpn and (corporate) connections both active, microsoft outlook is not reachable workaround n/a pzt 10600 symptom \[windows] nslookup with non fqdns is always forwarded to the dns server workaround n/a pzt 10946 symptom 9 2 0 on demand will be triggered only when the per app application is being used to access the resources workaround n/a (use classic per app vpn applications to access the resources to get connect with ) pzt 10971 symptom 9 2 0 transition update mdm profile and push disconnects the connection workaround n/a (mdm always set its latest update configuration as default and it is limitation) pzt 12681 symptom for windows 10 prompts for credentials when the device is unenrolled workaround post enrollment, wait for approximately 2 minutes and try to connect to the controller the user will get the certificate revoke message, and after accepting the warning the profile and certificates are deleted pzt 14224 symptom if you have a classic ondemand vpn connection and your connection is in monitoring mode, when you attempt to access a resource, connects to the classic ondemand vpn profile and displays a transition notification to the user workaround n/a pzt 14316 symptom fails with error 1111 when a classic vpn fails to resolve the fqdn workaround the user must disconnect both classic and connections, then connect first followed by the classic vpn alternatively, set the client dns ip address to public to facilitate resolving classic and connections pzt 14581 symptom when for desktops is uninstalled, stale certificates are not cleaned up workaround manually delete certificates from the cert/key store pzt 15072 symptom the aaa service should send only one alert for one object error workaround n/a pzt 15278 symptom client config mac delete and add connection not allowed, but the add and delete button is not shown as disabled workaround n/a pzt 19786 symptom login not happening immediately after resetting password for account lock cases workaround n/a pzt 20681 symptom "subject name format" and subject name" saml attributes are displayed under the saml config table, and custom attributes are displayed under the saml app attributes table as expected once configured, these attributes are not deleted even if the admin tries to delete them through the ui we are still allowing deletion since we have to allow the admin to change the values if needed workaround n/a pzt 23409 symptom cef eup on mac network error message is thrown in the cef based eup post authenticating with workaround close the cef portal and launch it again pzt 25360 symptom gateway service rest api dynamic tunnel configuration values are incorrectly exposed workaround updated apis are targeted to be made available in v21 11 pzt 26083 symptom a resource or application is intermittently not accessible when the connection resumes from the connect idle state workaround close the web browser and launch the application through the end user portal pzt 26394 symptom in some scenarios, logs are not visible in the controller for an esxi gateway workaround perform a warm restart of the gateway from the console pzt 26399 symptom sometimes gets stuck in a connect requested state workaround n/a pzt 27820 symptom windows 11 an internet application is blocked when the same dns ip address is configured on both the client device's physical network interface and in the dns settings workaround use a different dns ip address for the physical interface and for the dns settings pzt 29002 symptom manual configuration of a saml authentication server is not supported with gateways older than v21 12 workaround upgrade all gateways to v21 12 or later alternatively, for gateways older than v21 12, use only the metadata file based configuration method pzt 29280 symptom in some circumstances, gateways are not being automatically upgraded as per the configured maintenance schedule workaround if a scheduled update fails, update the gateway manually pzt 31744 symptom application groups filter is not shown correctly and is hidden behind another panel unable to view the filtered application fully in the chip below workaround none pld 952 symptom unable to take a connection to the state where on demand functionality is initiated workaround n/a release 22 3r1 pzt 27457 symptom policy failure dashboard shows compliance and network rule failures when any one of the rule is passing on the client machine having a common policy enforced which comprises of network and compliance rules together workaround none pzt 34006 symptom even when default policy evaluation fails, controller to client connection will be intact and not disconnected workaround none pzt 35683 symptom carta message appears in client window, while searching any non compliance application in search engine workaround disable this prefetching feature in the browser (for example, google chrome) pzt 36083 symptom isac uninstallation will be stuck with certificate deletion prompt on windows for connections condition on uninstalling isac with client connection workaround none pzt 36623 symptom allowed domains added under any configured application shows ip address instead of the application name when accessed on analytics dashboards workaround none pzt 36639 symptom session details not reported on and logs are not generated workaround none do not edit the json filter manually pzt 36750 symptom lockdown enable/disable done on tenant, taking 3 9 minutes to reflect in client connstore dat file condition when we make changes with respect to lockdown in the tenant workaround none pzt 36813 symptom risk sense evaluation for windows 10 22h2 endpoints is returning as 'not available' workaround install any vlc app pzt 36911 symptom top risky applications chart does not show any data when gateway filter is applied on all users dashboard workaround n/a pzt 36976 symptom internet traffic might be blocked during reconnection after recovering from sleep workaround restart the dsaccessservice using activity monitor or restart the machine pzt 36977 symptom connection shows "limited connectivity" and "invalid client certificate" messages workaround in the ui, delete the connection and then add the connection manually pcs 38630 symptom upgrade from pre 22 3r1 to 22 3r1 appears to be stuck after importing system data condition when upgrading the gateway from pre 22 3r1 to 22 3r1 workaround the issue is seen due to increase in ics package size refer https //kb pulsesecure net/articles/pulse secure article/kb44877/?ka13z000000l3z5 https //kb pulsesecure net/articles/pulse secure article/kb44877/?ka13z000000l3z5 pcs 39165 symptom for realms with totp enabled as secondary auth server authentication may fail with an internal error occurred log workaround go to users realm > realm name > secondary auth server select any other auth server available in the list and save select the previously selected auth server pcs 39291 symptom when home icon in floating tool bar is clicked, the end user gets "the page you requested could not be found" error conditions when the user clicks on home icon in the floating tool bar within an advanced html5 session workaround clear the browser cache and re try
