What's New
11 min
22 8r1 11 important updates and improvements support for zta gateway version 25 1 1 0 and 22 8r2 8 critical service updates brief service disruption expected during maintenance window for zta administrators and zta end users no disruption for vpn end users running 22 7r2 5 or above 22 8r1 10 byod using machine certificate based validation this feature lets administrators enforce device trust by validating a machine level certificate installed on an endpoint when enabled, only devices presenting a valid, trusted machine certificate can register, authenticate, and access protected applications through zta for details, see enable byod using machine certificate based validation https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin entint htm#enable logging enhancements for application url application urls are now displayed across insights and logging, enabling more precise analysis and faster triage you can view and act on url data in insights all applications, discovered applications, and default gateway applications charts access logs application url is available for display, search, and filtering for details, see reviewing application usage https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin dashboard htm#reviewin3 and viewing log records https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin dashboard htm/#viewing16 isac log upload support with zta custom sign in url to accelerate troubleshooting and support, zta now lets administrators trigger client log uploads directly from the controller using the active devices page as soon as a device establishes a successful zta connection and appears in active devices, admins can initiate a client log upload without requiring enduser action this feature is supported with isac version 22 8 6 (44527) for more details, see initiating client log upload https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin dev p htm#initiati separate isac package management between nsa and zta isac client packages are separately provided for ics and zta gateways so that these can be managed independently this provides flexibility to plan for zta isac releases for more details, see working with client packages https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin update client htm#working troubleshooting enhancements this feature enhancement simplifies gateway troubleshooting, which includes enhanced debug log, node monitoring, tcp dump, system snapshot, and network command functionalities for more details, see troubleshooting gateway issues https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin cr gway htm#h2 12 zta gateway security hardening 25 1 0 0 zta gateway is now security hardened with the following security features nginx support selinux secure boot secure factory reset key management tls 1 3 support limitations 25 1 0 0 zta gateway currently supported platform is vmware esxi platform other cloud form factors like gcp, azure and aws will be supported in upcoming releases tls 1 3 support currently supported and validated only for isac windows and mac platforms for mobile clients (ios and android), support will be planned in the upcoming releases restricting to 255 characters in dns domain settings in the gateway configuration, you can add one or more comma separated domain names, but not beyond 255 characters for more details, see editing gateway configuration https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin cr gway htm#editing visibility into nat connections the dynamic ip pool option is removed from 22 8r2 7, 25 1 0 0 release and when creating any new gateway 22 8r1 9 important updates and improvements critical service updates 22 8r1 8 1 important updates and improvements support for zta gateway version 22 8r2 6 critical service updates 22 8r1 8 enhancement syslog server configuration to optimize syslog server connectivity and performance, the syslog server configuration interface now includes a new dropdown enabling users to explicitly select the server ca (certificate authority) when setting up secure connections this enhancement complements the existing client certificate option and addresses latency issues during ssl handshakes key improvements targeted server ca selection administrators can now specify which server ca to use when configuring syslog servers previously, if no server ca was selected, the system sequentially tested all trusted cas in the tenant during connection establishment, which increased connection times this results in a better performance and a better user experience reduced latency and streamlined handshakes enhanced the syslog forwarding mechanism to enable real time log delivery by directly consuming gateway log events improved security and accuracy by ensuring the correct server ca is always used, this enhancement minimizes the risk of mismatched certificates and strengthens secure logging communications enhanced user experience the refined ui makes syslog server setup more intuitive and efficient, speeding up configuration and accelerating message delivery administrators are encouraged to specify the relevant server ca when adding or editing syslog server configurations to gain the benefits of this enhancement for details, see syslog forwarding https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin entint htm#adding2 persistent tunnel support for nzta this feature enhances the reliability of user sessions by keeping the nzta tunnel active for the duration of the session idle timeout specified in session settings with this feature enabled, the tunnel remains connected until the session idle timeout is reached if persistent tunnel support is not enabled, the tunnel remains active only for the period defined in the tunnel idle timeout setting (range 5–120 minutes; default 15 minutes) when there is no network traffic once the tunnel idle timeout elapses, the nzta tunnel automatically terminates this new feature helps ensure uninterrupted connectivity throughout the entire session duration for details, see editing gateway configuration https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin cr gway htm#editing adding a vmware vsphere gateway https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin cr gway htm#h2 21 adding an amazon web services gateway https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin cr gway htm#h2 24 adding an azure gateway https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin cr gway htm#h2 27 adding a gcp gateway https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin cr gway htm#adding3 22 8r1 4 there are no new features 22 8r1 2 this release includes bug fixes docid 44gndqjltn2wheforzkin there are no new features 22 8r1 1 this release includes bug fixes docid 44gndqjltn2wheforzkin there are no new features 22 7r1 6 admin experience enhancements "group by" option is added in the gateway list page to filter the list based on gateway type, connection status, version or region 22 7r1 4 admin ui user experience enhancements column reordering is newly added in the users l3 and l4 pages to move a column, a user can click the header and drag to its new position for more details, see using the insights menu to monitor user activity and service usage https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin dashboard htm 22 7r1 3 consolidated landing page drill down support for the sankey chart is newly added on the consolidated landing page with each chart, the view all link provides a page with detailed log records for that category for more details, see consolidated landing page, see consolidated landing page https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin dashboard htm#consolid all gateways counter all gateways counter is newly added on zta and nsa specific analytics landing page for more details, see reviewing your network activity https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin dashboard htm#reviewin 22 7r1 2 (preview) consolidated landing page a new unified landing page allows tenant admin to examine the shared analytics tables and charts for nzta and ics gateways for more details, see consolidated landing page https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin dashboard htm#consolid admin ui user experience enhancements improvements to the admin experience (modernize the table view for session management and log view) advanced filter on the page for managed users for more details, see checking the logs https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin dashboard htm#checking viewing gateway logs https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin cr gway htm#h2 9 viewing and terminating user sessions https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin dashboard htm#viewing terminating user sessions sync now a new sync now page allows the tenant admin to implement changes made and correct any configuration problems based on the alerts for more details, see synchronizing the configuration https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin dashboard htm#synchron 22 7r2 22 7r2 zta gateway version is the security hardened version with centos updates 22 7r1 configurable mtu size for gateways tenant admin can now define mtu size for zta gateways depending on their requirements and underlying network infrastructure for details, see adding a vmware vsphere gateway https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin cr gway html#h2 21 adding an aws gateway https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin cr gway html#h2 24 adding an azure gateway https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin cr gway html#h2 27 adding a kvm gateway https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin cr gway html#adding2 adding a gcp gateway https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin cr gway html#adding3 adding an oracle gateway https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin cr gway htm#adding4 password strengthening for local authentication server the local authentication server has stronger password restrictions for details, see workflow creating a local authentication policy https //helpstage ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin user auth htm#workflow renewed zta idp metadata in release 22 7r1 to ensure continued compatibility, download the renewed zta idp metadata from the zta tenant application configuration page and subsequently apply the updated information to the saas saml sso configurations 22 6r1 2 integrating nmdm with zta ivanti neurons for mdm provides compliance check and simplified onboarding experience for nzta end users connecting via mobile for details, see for details see integrating ivanti neurons for mdm with nzta https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin mdm htm hardened custom sign in policies and login urls as part of hardening custom sign in policies and login urls, the following changes are implemented instead of requiring administrators to configure enrollment policies, administrators will only need to configure user policies as a default, all configured user policies support enrollment single saml authentication server for user authentication and enrollment for details, see workflow creating a saml authentication policy with azure ad https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin user auth htm#workflow2 workflow creating an authentication policy for on premises ics saml https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin user auth htm#workflow6 workflow creating a saml authentication policy for okta https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin user auth htm#workflow3 workflow creating a saml authentication policy for ping identity https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin user auth htm#workflow4 workflow creating a local authentication policy https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin user auth htm#workflow 22 6r1 oracle cloud platform support for zta gateway zta gateway now supports deployment on oralce cloud platform for details see workflow creating a gateway in oracle cloud platform https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin cr gway htm#workflow6 launching the windows edge/webview2 browser in a typical enrollment, upon successful authentication to the controller, ivanti secure access client automatically shows the end user portal applications page through a windows edge/webview2 browser this feature is supported with isac client version 22 6r1 for details see enrolling a windows device https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin enrol client htm#enrollin reusable custom icon to associate with application the create application page provides an option to upload your own icon, which can be used to associate with more than one application for details see adding applications to the controller https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin app grp htm#addingappcontrl enhancements to l4, gateway logs, and logs tables the following list shows the enhancements to l4, gateway logs, and logs tables column resizing across zta pages cell content copy text from table pagination across zta pages minimum number of columns in all the tables in l4 dashboards enhancement to advanced filter for details see viewing detailed logs for a chart https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin dashboard htm#viewing3 and filtering the logs https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin dashboard htm#filterin simplifying device rules and policies, and global device preferences admin experience is enhanced by simplifying the device rules and policies for details, see creating device policies https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin dev p htm#creating , setting global device preferences https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin enrol client htm#setting 22 5r1 2 suppress eup auto launch allows admin to suppress the auto launch of the end user portal this option is enabled by default and works with isac 22 5r1 and later for details, see setting global device preferences https //docs pulsesecure net/webhelp/22 x/zta/ag/tadmin enrol client htm#setting 22 5r1 admin access control based on location, host checker, and network checks the admin's device geographic location/network/host checker compliance for admin sign in policy before providing access to admin login for details, see configuring default device policy for users http //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin dev p htm#configur enhancements to non compliance and anomalies l4 drill down logs the anomalies l4 table now includes mac address and source ip address columns the non compliances l4 table now includes acknowledged, non compliant policy type, non compliance policy reason, mac address and source ip address columns for details, see using the active anomaly and non compliance charts http //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin dashboard htm#using10 log export options to the admin from gateway and l4 (drill down view) logs in any of the l4 pages, export the displayed log as a csv or json text file, or create schedules to set up log export jobs for details, see viewing detailed logs for a chart http //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin dashboard htm#viewing3 exporting logs from l4 (drill down view) logs and gateway logs for details see exporting logs http //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin dashboard htm#exportin gateway creation config ui simplification create zta gateway and create zta gateway group are grouped under create for details, see adding a vsphere gateway http //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin cr gway htm#h2 21 acknowledge non compliance in the non compliance info panel on the landing page acknowledge individual non compliances and remove them from the active total filter on acknowledged, unacknowledged (active), or all non compliances for details, see using the summary ribbon http //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin dashboard htm#using2 22 4r3 role based access control for admin users with role based access control (rbac), organizations can easily add admins and assign them specific roles, with differing levels of access to the nsa admin portal in addition to an existing set of default roles, administrators can now create custom granular roles for specific functions within the nsa admin portal for details, see role based access control for admin users https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin user auth html#role based http proxy support support proxy configuration in gateway to connect to zta for details, see adding a vsphere gateway https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin cr gway html#h2 21 adding an aws gateway https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin cr gway html#h2 24 adding an azure gateway https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin cr gway html#h2 27 adding a kvm gateway https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin cr gway html#adding2 adding a gcp gateway https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin cr gway html#adding3 22 4r1 applications and application groups ui change group together multiple applications for which a single secure access policy is required adding applications to the controller https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin app grp html#addingappcontrl and adding application groups to the controller https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin app grp html#adding2 zta gateway connection control for trusted networks zta gateway can sometimes be bypassed so that users can connect directly to specific applications for example, you might want users to bypass zta for a specific application if they are connected directly to your trusted corporate network zta gateway tunnel creation will be bypassed on the endpoint since resource access will go through the physical interface for details, see configuring a default gateway for application discovery https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin cr gway html#configur2 gateway re registration zta gateway can now be re registered in case if the gateway registration was not successful and can edit gateway configuration parameters on registration failures, admin can trigger the registration manually along with the current debugging options such as networking tools, reboot etc you can also regenerate and download the gateway init config from the controller admin interface as when required the admin can also use registration error report, which provides insight about the registration failure and suggest solutions to overcome it for details, see re registering a vmware vsphere gateway https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin cr gway html#re regis1 , re registering an amazon web services gateway https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin cr gway html#re regis and re registering a gcp gateway https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin cr gway html#re regis2 limitations azure and kvm does not allow the user to update configuration after the gateway is deployed so, if any config update is needed in azure or kvm gateways (zta) ,we need to redeploy the zta gateway location/network rule support in default device policy location/network policy based enforcement can be applied for any user policy for details, see options for location rules https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin dev p html#options7 and options for network rules https //help ivanti com/ps/help/en us/nsa/22 x/nsa zta/ag/tadmin dev p html#options10 22 3r4 management port support on zta gateway with this feature, zta gateway can use management interface to communicate with controller and ntp server 22 3r1 optimal gateway selection (ogs) end user ux improvements simplified configuration users and secure access policy configurations actionable insights step up authentication, subsequent login and chart visibility device risk assessment risksense integration, default device policy application visibility improvements secure access policy for discovered applications lookout swg/casb forward proxy integration external browser support minimum client version lock down mode support psal with browser extension
