Omnissa Workspace ONE Tunnel Tunnel Container Release Notes describe the new features and enhancements in each release. This page contains a summary of the new capabilities, issues that have been resolved, and known issues.
Omnissa Workspace ONE Tunnel Container 26.03.1
What's New
In this release, we have made a few updates containing general quality and performance improvements.
Minimum Requirements
Workspace ONE UEM Console 2410 or later
Resolved Issues
- PPAT-21660: Configuration files are not updated after Tunnel service restart.
Known Issues
We haven’t identified any notable known issues in this release. If you’re facing any problems, feel free to reach out to our support team.
Omnissa Workspace ONE Tunnel Container 26.03
What's New
New ARM64 build
Introducing a native ARM64 build, enabling support for ARM‑based systems alongside x86-64 systems.
Minimum Requirements
Workspace ONE UEM Console 2410 or later
Resolved Issues
We are always working to improve Workspace ONE Tunnel with every release. There are no major bug fixes to report.
Known Issues
We haven’t identified any notable known issues in this release. If you’re facing any problems, feel free to reach out to our support team.
Omnissa Workspace ONE Tunnel Container 25.12
What's New
-
Geolocation Policies with Workspace ONE Tunnel is now in Limited Availability
- New geolocation-based access rules allow you to enforce access policies tailored to specific regions. This helps organizations maintain regulatory compliance and safeguard sensitive data across different locations while still enabling limited access for traveling users.
- Contact your Omnissa representative for additional details on the feature and guidance on enablement.
Minimum Requirements
Workspace ONE UEM Console 2410 or later
Resolved Issues
We are always working to improve Workspace ONE Tunnel with every release. There are no major bug fixes to report.
Known Issues
We haven’t identified any notable known issues in this release. If you’re facing any problems, feel free to reach out to our support team.
Omnissa Workspace ONE Tunnel Container 25.06.1
What’s New
There are now new versions of the Tunnel server container image and the CLI tool, dux.
- Tunnel server container 25.06.1
- dux 3.0
Tunnel server container 25.06.1
Compatibility with new certificate EKU guidance
Tunnel server now supports third-party certificates that conform with the latest Extended Key Usage (EKU) guidance, specifically the removal of the Client Authentication EKU from publicly trusted TLS certificates.
- Ensures compatibility with certificates issued after October 2025, which may only include Server Authentication EKU.
- This applies to cascade-mode deployments only and does not impact existing Tunnel server functionality..
- Workspace ONE UEM support for uploading certificates with the latest Extended Key Usage (EKU) requirements is planned for a future release and will be available as a patch release for all supported Workspace UEM console versions.
Rsyslog transmission using TLS
Tunnel server now supports TLS encryption for Syslog messages and introduces support for streaming tunnel service log (tunnel.log and reporter.log) to a rsyslog server.
- Starting Tunnel server 2506, the
rsyslog_over_tcpserver KVP is now replaced with a more flexible configuration. This setting provides greater control and extensibility by supporting TLS for secure delivery in addition to TCP/UDP.- KVP:
rsyslog_transport_type - Purpose: Define the transport protocol used for forwarding service logs.
- Values:
0– UDP (default)1– TCP2– TLS (encrypted syslog over TCP)
- KVP:
Improvements to vpnreport
The vpnreport command now supports a --follow option, enabling real-time streaming of VPN report entries.
./vpnreport list --follow- Use
./vpnreport list --helpto get a list of all supported options.
Management Utility: dux 3.0
Required Step: Upgrade Tunnel container manifest
For first-time deployments, the dux init command will create a new ts.manifest.yml. If dux 2.2 or 2.3 is already in use and the Tunnel container manifest file has existing configuration details, the manifest must to be upgraded with the command dux init -u and selecting the option for Tunnel. This will back up the existing manifest file and create a new manifest file which is compatible with dux 3.0.
Once updated, review the new manifest file and validate configuration by running the dux status command. See README for more information.
OAuth Support for Workspace ONE API communication
Starting with Tunnel server 25.06.1 and dux 3.0, OAuth is the recommended authentication method for securely connecting to the Workspace ONE UEM API server for improved security and scalability. To enable OAuth, populate the corresponding fields in the ts.manifest.yml file. OAuth must also be configured in the UEM console (Groups & Settings > Configurations > OAuth Client Management).
client_id:client_secret:
Outbound Proxy Support for Workspace ONE API communication
dux 3.0 now supports configuring an outbound proxy for initial configuration download. Once configured, all subsequent communication with Workspace ONE API obeys Server Traffic Rules. The Proxy information can be provided in the new dux 3.0 manifest file. See README for more information.
Support for new containerized SEG and PAC Reader
dux now supports management of new containerized Gateway services. The Secure Email Gateway (SEG) container and PAC Reader container software will be released later this year. Please refer to respective release notes when available for more information.
Improved supportability
Introducing ability to retrieve alert, access, audit, and session/flow log through dux.
-
dux list --alert: This will pull thealert.logfrom all nodes. You can pull log from a specific node by providing the node number or IP as an additional argument. This can be extended to other logs. -
dux list --allowlist -cache --n 1: This will display the current device allowlist cache for that server.
Minimum Requirements
Workspace ONE UEM Console 2402 or later
Resolved Issues
We are always working to improve Workspace ONE Tunnel with every release. There are no major bug fixes to report.
Omnissa Workspace ONE Tunnel Container 25.01
What’s New
There are now new versions of the Tunnel server container image and the Tunnel CLI tool, dux.
- Tunnel server container 25.01
- Management Utility: dux 2.3
Tunnel server container 25.01
-
Modifications to the following settings are now included in audit.log
- Server Traffic Rules
- MFA configuration
- AWCM messages
- Container service state
-
Alert log can now be sent to Rsyslog. See Tunnel documentation for further information.
-
Simplified MFA implementation. We have merged the jwt_token_expiry KVP and the mfa_session_timeout KVP into one key value pair: mfa_session_timeout
- The validity of the session token will equal the mfa_session_timeout value from the time of initial authentication. At the end of this period, any existing session will disconnect and user will have to re-authenticate.
- If there is a need to extend any existing session beyond the token expiration, you may add the mfa_graceperiod KVP.
Parameter Default Value Customizable Notes mfa_session_timeout12 hours Yes 1) Default applies if the key-value pair is missing. 2) Sessions valid for 60 mins if set to 0 mfa_graceperiodNot Defined Yes Optional; Must be a positive, non-zero value.
Management Utility: dux 2.3
- Support for dux on Windows
- Support for Podman
- Multi-Nic Support
Support for dux on Windows
-
To install Dux for Windows, download the msi installer from the url based on the architecture:
Installation Steps
- Download the MSI installer for your architecture from the URLs provided above.
- Run the MSI installer.
- Select an installation directory for Dux. The default installation directory is: C:\Program Files\Omnissa\Dux
- Follow the on-screen instructions to complete the installation.
Post-Installation Notes
-
After installation, the following directory structures will be created under the selected installation directory:
<INSTALL_DIR>\images<INSTALL_DIR>\logs -
If Dux is installed in a protected directory (e.g.,
C:\Program Files), you must run PowerShell or Command Prompt as an administrator to execute Dux commands.
Support for Podman
- This is in addition to existing Docker support
Multi-Nic Support:
- Traffic separation can be enabled by configuring a separate external network interface
- Note new field in the manifest file: multi_nic_external_ip
- The Tunnel container inherits the network configuration of the host machine.
Download Location:
RPM Package for Linux:
-
For AMD64/Intel: https://packages.omnissa.com/ws1-tunnel/dux/2.3.0.405/dux-2.3.0.405-1.x86_64.rpm
-
For ARM64/Apple Silicon: https://packages.omnissa.com/ws1-tunnel/dux/2.3.0.405/dux-2.3.0.405-1.aarch64.rpm
RPM Package for macOS:
- Use package manager - brew.
$ brew tap wsonetunnel/tunnel |
$ brew install dux |
RPM Package for Windows:
-
For AMD64/Intel: https://packages.omnissa.com/ws1-tunnel/dux/2.3.0.405/dux-windows-amd64.msi
-
For ARM64: https://packages.omnissa.com/ws1-tunnel/dux/2.3.0.405/dux-windows-arm64.msi
Minimum Requirements
Workspace ONE UEM Console 2310 or later
Resolved Issues
We are always working to improve Workspace ONE Tunnel with every release. There are no major bug fixes to report.
Known Issues
We haven’t identified any notable known issues in this release. If you’re facing any problems, feel free to reach out to our support team.
Omnissa Workspace ONE Tunnel Container 24.10
What’s New
There are now new versions of the Tunnel server container image and the Tunnel CLI tool, dux.
- Tunnel server container 24.10
- dux 2.2
Tunnel Server Container 24.10
- New alert log viewer for summarized troubleshooting
- This version introduces a new feature of the vpnreport utility for viewing issue-type events that might need customer investigation, such as unreachability to internal destinations or the Workspace ONE UEM APIs or DNS lookup failures.
- The alert log can be accessed via the vpnreport command:
# ./vpnreport list --alert - The log is formatted with the following headers:
Timestamp,Type,Sess ID,Flow ID,User,Device Name,Device UDID,Address,Port
Example output:2024-10-10T10:10:10+0000,API server TCP Connection Problem,-1,0,MFAConfigManager,10.87.133.1,01178f73-5e82-c207-d34d-ac447ba26e5c,wns-1.ssdevrd.com,443
2024-10-10T10:10:10+0000,Host unreachable,10001,32,test_user,DESKTOP-Omnissa,bd17e13148ba4092a10b9951a22460a8,testwebsite.com,443
Supportability Improvements to vpnreport
- The vpnreport utility has been enhanced for better diagnostics and easier consumption. Use `./vpnreport allowlist --help` for all available options.
- Added ability to view the local allowlist cache (instead of calling UEM API) via the -cache option.
- Vpnreport may be formatted in either CSV or JSON format.
- Retain vpnreport information on a service restart.
Management Utility: dux 2.2
The download location for dux has changed.
- For AMD64/Intel: https://packages.omnissa.com/ws1-tunnel/dux/2.2.0.247/dux-2.2.0.247-1.x86_64.rpm
- For ARM64/Apple Silicon: https://packages.omnissa.com/ws1-tunnel/dux/2.2.0.247/dux-2.2.0.247-1.aarch64.rpm
Navigate to the README file for further information.
Support localhost deployment without using SSH
For organizations that do not want to leave SSH enabled for remote administration, you can choose to leverage a hypervisor’s virtual console to do administration. In most instances, it is recommended to leave ssh enabled so dux can administer multiple hosts from a single location.
To use dux locally from the same host, specify the host information as "localhost," the hostname, or the IP address under the “Tunnel Server Host(s) Information” section of the manifest.
Added exec-shell command to SSH directly into a container
To run Vpnreport, it may be required to directly interact with a Tunnel container.
A few other improvements have been added:
- Support for defining a custom SSH port in the manifest
- Dry run command now checks if the Tunnel container image is available at the right location.
- Fallback to interactive prompt for credentials on SSH authentication failure
Minimum Requirements
Workspace ONE UEM Console 2306 or later
Resolved Issues
We are always working to improve Workspace ONE Tunnel with every release. There are no major bug fixes to report.
Known Issues
We haven’t identified any notable known issues in this release. If you’re facing any problems, feel free to reach out to our support team.
Workspace ONE Container
New Features
We are excited to announce a new offering, Omnissa Workspace ONE Tunnel Container. The Workspace ONE team is updating the deployment options for Tunnel and replacing the standalone Linux Tunnel installer. This new deployment method provides significant orchestration and security improvements over the previous RPM artifact and installer, and leverages a secure container version of the Tunnel gateway software. There is no requirement for container or Kubernetes infrastructure or expertise to make use of the new tools.
The first release for the Tunnel Container supports the following:
-
Deploy multiple servers at the same time
- There is no requirement for WS1 HUB or MDM enrollment.
- Support for managed enrollment is on the roadmap.
-
Increased support and flexibility for the host, beyond RHEL 7 or Unified Access Gateway.
- Choose your Linux distribution of choice for the host OS
-
Simplified host prerequisites
-
Improved diagnostic tools for monitoring your deployment
Minimum Requirements
The following are the minimum requirements for this release.
-
Tunnel server container image
-
Cross-platform CLI (dux) for lifecycle management of Tunnel server
See the Tunnel Guide to get started.
Resolved Issues
We are always working to improve Workspace ONE Tunnel with every release. There are no major bug fixes to report.
Known Issues
We haven’t identified any notable known issues in this release. If you’re facing any problems, feel free to reach out to our support team.
Product Documentation
-
Navigate to the README file for further information.
-
See How to Deploy the Tunnel Container to get started.
Support Contact Information
To receive support, either submit a ticket through the Customer Connect portal or call your local support line. See Omnissa Support Phone Numbers (6000004) and Omnissa Customer Connect FAQs.
Download Instructions
You can download the new software from Customer Connect portal.
Instructions to download dux
- Linux and Windows: dux 3.0.0.641
- macOS: Use package manager
brew - For new install:
brew tap wsonetunnel/tunnelbrew install dux
- To update the dux version to 3.0
brew updatebrew upgrade dux
War diese Seite hilfreich?