Skip to main content

September 4, 2026

Omnissa Unified Access Gateway Release Notes

Unified Access Gateway 2506 | 31 JUL 2025
Check for additions and updates to these release notes.

Unified Access Gateway appliance helps enable secure remote access for virtual desktops, internal sites, applications, and file repositories users. To learn more, see Unified Access Gateway Documentation.

Omnissa Unified Access Gateway Release Notes provides information about the new features and enhancements in each release. This page contains a summary of the new capabilities, issues resolved, and known issues that are reported in each version.

What's New

Unified Access Gateway 2506 provides the following new features and enhancements:

  • Support for Device X.509 certificate and SAML authentication

    Added support for Device X.509 certificate authentication (enabling mutual TLS authentication with Horizon Client) followed by SAML authentication. The feature is currently supported only on Horizon Client for Mac. For more information, see Configure Horizon Settings on Unified Access Gateway for SAML Integration and Omnissa Horizon Client for Mac Release Notes.

  • Support all source locators of VMware OVF tool

    Unified Access Gateway PowerShell scripts now support the same source locators as the VMware OVF tool for vSphere deployments.

  • Enhancements to Origin HTTP Header feature

    The constraints mentioned in the Additional Notes section on the previous Unified Access Gateway (2503) release are now obsolete.

    • Chrome native client users do not have to add the extension.
    • If Origin Check Required setting is set to false, the Re-Write Origin setting is also set to false.
    • By default, the common blast and tunnel external URLs are added to the auto-allowed list. There is no need to add a URL without the port explicitly.
  • Support for deploying Unified Access Gateway with Horizon 8 on Nutanix AHV - Limited Availability

    As part of Horizon 8 support for Nutanix AHV Limited Availability, administrators can deploy Unified Access Gateway on Nutanix AHV. For more information, see Omnissa Horizon 8 Release Notes and PowerShell deployment to Nutanix AHV.

  • Support for deploying Unified Access Gateway with Horizon 8 on Hyper-V

    Administrators can now deploy Unified Access Gateway for Horizon 8 on Hyper-V. For more information, see PowerShell deployment to Hyper-V.

  • Support IMDSv2 metadata in AWS

    Unified Access Gateway now defaults to using the IMDSv2 protocol for AWS deployments. This change aligns with AWS recommendations and enhances security compared to IMDSv1 protocol.

  • Extended server certificate validation, if enabled, can now be selectively bypassed for entitlement launches using the Horizon BLAST protocol by specifying the Horizon Connection Server thumbprint in the Connection Server URL Thumbprint setting. For more information, see Configure Horizon Settings.

  • iptables replacement

    Unified Access Gateway now supports nftables for network packet filtering and NAT as RHEL is set to deprecate iptables.

  • AzureRM support deprecation

  • Removed support for unmanaged disks

    • Following the Microsoft announcement, Azure unmanaged disks is going to be retired by September 30, 2025. Consequently, the PowerShell scripts are updated to deploy Unified Access Gateway on Azure only with managed disks.
      Note: For Unified Access Gateway versions older than 2506, administrators can migrate to managed disks using the methods mentioned in the Microsoft notice. Alternatively, administrators can upgrade to Unified Access Gateway 2506.
  • Logging improvements

  • Updates to OS package versions and Java component versions

  • Omnissa Workspace ONE Tunnel

    • Improvement to rsyslog implementation. rsyslog supports streaming tunnel service log (tunnel.log and reporter.log) to a rsyslog server.
      The rsyslog_over_tcp KVP is now deprecated in favor of a flexible and explicit configuration. This setting provides greater control and extensibility by supporting TLS for secure delivery in addition to TCP/UDP.
      • KVP: rsyslog_transport_type
      • Purpose: Define the transport protocol used for forwarding service logs.
      • Values:
        • 0 – UDP (default)
        • 1 – TCP
        • 2 – TLS (encrypted syslog over TCP)
  • Content Gateway

    • Enhanced support for custom values in Certificate-based authentication (CBA).
    • Support for Move files operation in Network file share (NFS) repository.

Before You Begin

Resolved Issues

  • UAG-11798: Administrators are not notified if an error occurs while saving the network settings in the Admin UI.
  • UAG-12023: If rebranded version of Horizon Client is being used, the Disable Web Client toggle on Unified Access Gateway does not work.
  • UAG-11996: If the Use CRL from Certificates toggle is turned off (which is also the default behavior) on X.509 Certificate Authentication Settings, an attempt is still made to get a CRL specified in the client certificate.
  • UAG-11993: When High Availability Settings are activated, the health check of a healthy Workspace ONE Content Gateway server fails.
  • UAG-11962: Enabling Workspace ONE Secure Email Gateway Settings causing increased disk consumption.

Known Issues

  • ESC-63850: X.509 certificate authentication might fail with Internal server error under high concurrent request load when revocation checking is enabled and CRL/OCSP endpoints exhibit slow response times.


    Workaround:

    1. Backup the configuration file.

      cp /opt/omnissa/gateway/supervisor/conf/cas.ini /opt/omnissa/gateway/supervisor/conf/cas_backup

    2. Add the following property:

      sed -i "s|-jar|-Dcertauth.business.concurrency.factor=2000 -jar|g" /opt/omnissa/gateway/supervisor/conf/cas.ini

    3. Run the command:

      supervisorctl reread && supervisorctl update

  • UAG-12430: Importing UAG settings with Workspace ONE Intelligence fails with the error Please select a valid WS1 intelligence credentials file for import.

  • UAG-12246: When Workspace ONE Tunnel Settings are turned on, DNS resolution for configured host entries might not work as expected.


    Workaround:

    1. Set the following KVP in the Tunnel configuration.

      dns_server_address_1 127.0.0.53

      dns_server_port 53

    2. Run the command: systemctl restart vpnd.

  • UAG-12971: The bottom part of the background of the UAG Admin UI login page is displayed as blank when the web browser's window height is less than 1430 pixels.
    Workaround: No workaround exists for this issue.

  • UAG-13263: "Internal server error" when space is entered as RADIUS password on Horizon client.
    Workaround: No workaround exists for this issue.

  • UAG-13396: Stack trace disclosure from an API, under certain conditions.
    Workaround:
    This issue has no functional impact. Currently, there is no workaround.

  • UAG-13953: When UAG SAML configuration is read through certain APIs, the system triggers false-positive CONFIG_CHANGE audit log entries.
    Workaround: This issue has no functional impact. Currently, there is no workaround.

Documentation

Documentation for Unified Access Gateway is located at Omnissa Product Documentation.

Support Contact Information

To receive support, access Customer Connect.

For information about filing a Support Request in Customer Connect and using Cloud Services Portal, see the Knowledge Base (KB) article 6000005.

Localization

For details on Omnissa’s localization strategy, see Announcing Omnissa Localization Support.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…