|
Unified Access Gateway 2506 | 31 JUL 2025
|
Unified Access Gateway appliance helps enable secure remote access for virtual desktops, internal sites, applications, and file repositories users. To learn more, see Unified Access Gateway Documentation.
Omnissa Unified Access Gateway Release Notes provides information about the new features and enhancements in each release. This page contains a summary of the new capabilities, issues resolved, and known issues that are reported in each version.
What's New
Unified Access Gateway 2506 provides the following new features and enhancements:
-
Support for Device X.509 certificate and SAML authentication
Added support for Device X.509 certificate authentication (enabling mutual TLS authentication with Horizon Client) followed by SAML authentication. The feature is currently supported only on Horizon Client for Mac. For more information, see Configure Horizon Settings on Unified Access Gateway for SAML Integration and Omnissa Horizon Client for Mac Release Notes.
-
Support all source locators of VMware OVF tool
Unified Access Gateway PowerShell scripts now support the same source locators as the VMware OVF tool for vSphere deployments.
-
Enhancements to Origin HTTP Header feature
The constraints mentioned in the Additional Notes section on the previous Unified Access Gateway (2503) release are now obsolete.
- Chrome native client users do not have to add the extension.
- If Origin Check Required setting is set to false, the Re-Write Origin setting is also set to false.
- By default, the common blast and tunnel external URLs are added to the auto-allowed list. There is no need to add a URL without the port explicitly.
-
Support for deploying Unified Access Gateway with Horizon 8 on Nutanix AHV - Limited Availability
As part of Horizon 8 support for Nutanix AHV Limited Availability, administrators can deploy Unified Access Gateway on Nutanix AHV. For more information, see Omnissa Horizon 8 Release Notes and PowerShell deployment to Nutanix AHV.
-
Support for deploying Unified Access Gateway with Horizon 8 on Hyper-V
Administrators can now deploy Unified Access Gateway for Horizon 8 on Hyper-V. For more information, see PowerShell deployment to Hyper-V.
-
Support IMDSv2 metadata in AWS
Unified Access Gateway now defaults to using the IMDSv2 protocol for AWS deployments. This change aligns with AWS recommendations and enhances security compared to IMDSv1 protocol.
-
Extended server certificate validation, if enabled, can now be selectively bypassed for entitlement launches using the Horizon BLAST protocol by specifying the Horizon Connection Server thumbprint in the Connection Server URL Thumbprint setting. For more information, see Configure Horizon Settings.
-
iptables replacement
Unified Access Gateway now supports
nftablesfor network packet filtering and NAT as RHEL is set to deprecateiptables. -
AzureRM support deprecation
- Following the Microsoft announcement, PowerShell script used to deploy Unified Access Gateway on Azure no longer supports AzureRM module. For more information, see PowerShell deployment to Microsoft Azure.
-
Removed support for unmanaged disks
- Following the Microsoft announcement, Azure unmanaged disks is going to be retired by September 30, 2025. Consequently, the PowerShell scripts are updated to deploy Unified Access Gateway on Azure only with managed disks.
Note: For Unified Access Gateway versions older than 2506, administrators can migrate to managed disks using the methods mentioned in the Microsoft notice. Alternatively, administrators can upgrade to Unified Access Gateway 2506.
- Following the Microsoft announcement, Azure unmanaged disks is going to be retired by September 30, 2025. Consequently, the PowerShell scripts are updated to deploy Unified Access Gateway on Azure only with managed disks.
-
Logging improvements
-
Updates to OS package versions and Java component versions
-
Omnissa Workspace ONE Tunnel
- Improvement to
rsyslogimplementation.rsyslogsupports streaming tunnel service log (tunnel.logandreporter.log) to arsyslogserver.
Thersyslog_over_tcpKVP is now deprecated in favor of a flexible and explicit configuration. This setting provides greater control and extensibility by supporting TLS for secure delivery in addition to TCP/UDP.- KVP:
rsyslog_transport_type - Purpose: Define the transport protocol used for forwarding service logs.
- Values:
- 0 – UDP (default)
- 1 – TCP
- 2 – TLS (encrypted syslog over TCP)
- KVP:
- Improvement to
-
Content Gateway
- Enhanced support for custom values in Certificate-based authentication (CBA).
- Support for Move files operation in Network file share (NFS) repository.
Before You Begin
-
Compatibility Notes
For more information about the compatibility of Unified Access Gateway with other products, see Product Interoperability Matrix. -
Install and Upgrade
To download the Unified Access Gateway, see the Product Download page. -
Security Scan
Owing to the OS update, special instructions are required to get accurate scan results of the operating system used by the Unified Access Gateway appliance. For more information, see Security scanning of Linux on Unified Access Gateway (UAG) version 2412 and beyond (6000738).
Resolved Issues
- UAG-11798: Administrators are not notified if an error occurs while saving the network settings in the Admin UI.
- UAG-12023: If rebranded version of Horizon Client is being used, the Disable Web Client toggle on Unified Access Gateway does not work.
- UAG-11996: If the Use CRL from Certificates toggle is turned off (which is also the default behavior) on X.509 Certificate Authentication Settings, an attempt is still made to get a CRL specified in the client certificate.
- UAG-11993: When High Availability Settings are activated, the health check of a healthy Workspace ONE Content Gateway server fails.
- UAG-11962: Enabling Workspace ONE Secure Email Gateway Settings causing increased disk consumption.
Known Issues
-
ESC-63850: X.509 certificate authentication might fail with
Internal server errorunder high concurrent request load when revocation checking is enabled and CRL/OCSP endpoints exhibit slow response times.
Workaround:-
Backup the configuration file.
cp /opt/omnissa/gateway/supervisor/conf/cas.ini /opt/omnissa/gateway/supervisor/conf/cas_backup -
Add the following property:
sed -i "s|-jar|-Dcertauth.business.concurrency.factor=2000 -jar|g" /opt/omnissa/gateway/supervisor/conf/cas.ini -
Run the command:
supervisorctl reread && supervisorctl update
-
-
UAG-12430: Importing UAG settings with Workspace ONE Intelligence fails with the error
Please select a valid WS1 intelligence credentials file for import. -
UAG-12246: When Workspace ONE Tunnel Settings are turned on, DNS resolution for configured host entries might not work as expected.
Workaround:-
Set the following KVP in the Tunnel configuration.
dns_server_address_1 127.0.0.53dns_server_port 53 -
Run the command:
systemctl restart vpnd.
-
-
UAG-12971: The bottom part of the background of the UAG Admin UI login page is displayed as blank when the web browser's window height is less than 1430 pixels.
Workaround: No workaround exists for this issue. -
UAG-13263:
"Internal server error"when space is entered as RADIUS password on Horizon client.
Workaround: No workaround exists for this issue. -
UAG-13396: Stack trace disclosure from an API, under certain conditions.
Workaround:
This issue has no functional impact. Currently, there is no workaround. -
UAG-13953: When UAG SAML configuration is read through certain APIs, the system triggers false-positive
CONFIG_CHANGEaudit log entries.
Workaround: This issue has no functional impact. Currently, there is no workaround.
Documentation
Documentation for Unified Access Gateway is located at Omnissa Product Documentation.
Support Contact Information
To receive support, access Customer Connect.
For information about filing a Support Request in Customer Connect and using Cloud Services Portal, see the Knowledge Base (KB) article 6000005.
Localization
For details on Omnissa’s localization strategy, see Announcing Omnissa Localization Support.
Was this page helpful?