Limitations
3 min
the following limitations apply to this release nzta controller 22 8r1 11 supports zta gateway 25 1 0 1 only for fresh deployments you must deploy a new gateway instance and migrate your configuration since direct upgrade from zta gateway 25 1 0 0 to 25 1 0 1 is not supported in the current release dynamic ip pool is not supported for 22 8rx and 25 1 0 0, to be supported from zta gateway version 25 1 1 0 upgrade from version 22 8rx or 22 7rx to 25 x is not supported in zta gateway 25 1 0 0 zta gateway currently supported platform is vmware esxi platform in 22 8r1 10 other cloud form factors like gcp, azure and aws will be supported in upcoming releases tls 1 3 support currently supported and validated only for isac windows and mac platforms for mobile clients (ios and android), support will be planned in the upcoming releases search domain length limit the search domain field is limited to a maximum of 255 characters short domain dns suffix is not supported nslookup is not supported on windows and mac os rbac if the tenant has both nsa and zta gateway, setting any common permissions while creating an custom rbac admin role applies to both nsa and zta gateway for example, if custom admin role has modify permission for zta gateway then the same applies to nsa gateway also okta and pingid saml authentication methods are supported for macos and windows variants only each application can only be accessed with ping/ssh using the addressing method specified when registering it that is, if you registered the application using an fqdn, you cannot access it using an ip address pzt 24825 tenants wanting to use their own public key infrastructure with device certificates (known in this document as byoc bring your own certificate), the following limitations apply for existing tenants, to convert from a non byoc tenant to a byoc tenant is not supported this is supported only for newly created tenants after tenant creation, the admin must configure the tenant as byoc before registering a gateway or enrolling an end user device for existing tenants, to convert from a byoc tenant to a non byoc tenant is not supported as the tenant needs at least one customer ca if all customer cas are removed after gateways or devices have been enrolled, those existing gateways and devices will not function properly a ca is not permitted to be used by more than one byoc tenant
