|
Unified Access Gateway 2512 | 16 DEC 2025
|
Unified Access Gateway appliances provide users with secure remote access to virtual desktops, internal sites, applications, and file repositories. To learn more, see Unified Access Gateway Documentation.
Omnissa Unified Access Gateway Release Notes provide information about the new features and enhancements in each release. This page contains a summary of the new capabilities, issues resolved, and known issues that are reported in each version.
What's New - 2512.1
Updates to OS package versions
- Updated security patch for OpenSSL package, which addresses CVE-2025-15467 and other vulnerabilities disclosed.
- Upon evaluation, there is no impact on Unified Access Gateway. This release includes the latest OS security patches as part of our ongoing commitment to security best practices. For more information, see Omnissa Impact - OpenSSL Security Advisory (6001266).
Tunnel
-
Geolocation Policies with Workspace ONE Tunnel is now in Limited Availability
- New geolocation-based access rules allow you to enforce access policies tailored to specific regions. This helps organizations maintain regulatory compliance and safeguard sensitive data across different locations while still enabling limited access for traveling users.
- Contact your Omnissa representative for additional details on the feature and guidance on enablement.
What's New - 2512
Unified Access Gateway 2512 provides the following new features and enhancements:
-
Support for Horizon in extra-large configuration
Unified Access Gateway now supports extra large configuration for Horizon 8 deployments and can handle up to 4000 Horizon connections. See Unified Access Gateway Sizing Options. -
Support for adding multiple TLS certificates for Internet interface
Unified Access Gateway now supports binding up to 10 TLS certificates to the Internet interface for Horizon and Web Reverse Proxy end user flows, with automatic certificate selection using SNI. For more information, see TLS/SSL certificates. -
Enhancements to
OriginHTTP Header feature
Auto generated origin list now considers URLs specified without a scheme and port as both HTTPS and HTTP, while any origin with a port is considered HTTPS only (even if it is port 80). For more information, see Mandatory Validation of Origin HTTP Header. -
Enhancements to
HostHTTP Header feature
Unified Access Gateway now validates ports (in addition to the existing validation of hostname) in theHostandX-Forwarded-Hostheaders of incoming HTTP requests against an allowed list. Previously, only hostnames were considered during validation. For more information, see Host Header Validation on Unified Access Gateway. -
Enhancements to Tunnel and Blast URLs on Horizon Settings
Added support for validatingHostheaders with port numbers, auto generated from the values specified against the Tunnel and Blast External URLs (including additional external URLs), ensuring correct matching when port is present inHostheader of the HTTP request arriving at Unified Access Gateway. For more information, see Configure Horizon Settings. -
Improvements related to deployment on Nutanix
- Added support for deployment on Nutanix 7.3.
- Enhanced PowerShell script for Nutanix with a configuration option to disable TLS certificate validation. With this, you are no longer required to follow the workaround if the Nutanix Server is not using a Trusted TLS Certificate. See PowerShell deployment to Nutanix.
-
Enhancements to periodic health check
The periodic health check interval now accepts values only greater than10seconds. Setting the interval to0is no longer supported, as this stops periodic health checks and results in Unified Access Gateway being reported as unavailable for serving requests. -
PCoIP deprecation
PCoIP is going to be deprecated from Horizon Clients in an upcoming release. Consider switching to Horizon Blast Protocol. See End of support for PCoIP in Horizon in 2025 (6000812). -
Logging and troubleshooting improvements
-
Updates to OS package versions and Java component versions
- Updated
open-vm-toolsto 12.1.5-1, which addresses CVE-2025-41244.
- Updated
-
Content Gateway
Support for Certificate-based authentication (CBA) for WebDAV repository. -
Tunnel
New server KVP to support TLS 1.3 ciphers. This is separate for the KVP to support TLS 1.2 cipher suites.- KVP:
openssl_1_3_cipher_list - Example:
- KVP:
openssl_1_3_cipher_list - Value:
TLS_AES_256_GCM_SHA384:TLS_AES_128_GCM_SHA256:TLS_AES_128_CCM_SHA256
- KVP:
- KVP:
-
Secure Email Gateway
Secure Email Gateway logs are now automatically compressed and stored in.gzformat.
Before You Begin
-
Install and Upgrade
To download the Unified Access Gateway, see the Product Download page. -
Security Scan
Owing to the OS update, special instructions are required to get accurate scan results of the operating system used by the Unified Access Gateway appliance. For more information, see Security scanning of Linux on Unified Access Gateway (UAG) version 2412 and beyond (6000738).
Resolved Issues - 2512
-
UAG-12246: When Workspace ONE Tunnel Settings are turned on, DNS resolution for configured host entries might not work as expected.
-
UAG-12430: Importing UAG settings with Workspace ONE Intelligence fails with the error
Please select a valid WS1 intelligence credentials file for import. -
UAG-12542: While deploying using PowerShell script, specifying values against blastUrls and tunnelUrls keys in
.inifile do not work. -
UAG-12244: Gray color radio button (instead of green) displayed against healthy Tunnel Settings on Admin UI.
-
ESC-63850: X.509 certificate authentication might fail with
Internal server errorunder high concurrent request load when revocation checking is enabled and CRL/OCSP endpoints exhibit slow response times. -
PPAT-20103: UEM Tunnel Dashboard does not populate data throughput widget.
Known Issues - 2512
- UAG-13054: OIDC authentication fails when launching Horizon native client from Horizon client selector landing page.
Workaround: Runadminreset --force --advancedFeature disable SamlClientLocationIdValidationthrough root console (SSH or vSphere web console). - UAG-12971: The bottom part of the background of the UAG Admin UI login page is displayed as blank when the web browser's window height is less than 1430 pixels.
Workaround: No workaround exists for this issue. - UAG-13263:
"Internal server error"when space is entered as RADIUS password on Horizon client.
Workaround: No workaround exists for this issue. - UAG-13396: Stack trace disclosure from an API, under certain conditions.
Workaround:
This issue has no functional impact. Currently, there is no workaround. - UAG-13953: When UAG SAML configuration is read through certain APIs, the system triggers false-positive
CONFIG_CHANGEaudit log entries.
Workaround: This issue has no functional impact. Currently, there is no workaround.
Documentation
Documentation for Unified Access Gateway is located at Omnissa Product Documentation.
Support Contact Information
To receive support, access Customer Connect.
For information about filing a Support Request in Customer Connect and using Cloud Services Portal, see the Knowledge Base (KB) article 6000005.
Localization
For details on Omnissa’s localization strategy, see the Knowledge Base (KB) article Announcing Omnissa Localization Support.
Was this page helpful?