Skip to main content

Check out Interactive Visual Stories to gain hands-on experience with the SSE product features. Click here.

Skyhigh Security

Client Proxy 4.9.3 Release Notes

About Patch Release 

The Client Proxy 4.9.3.92.1 Windows patch release includes enhancements related to the Skyhigh Client Proxy support tool and improvements to the AD group header size. It also addresses key resolved issues, including IPv4 traffic interception for private applications on configured ports and updates to the SCP About Window status. For details on all resolved issues, refer to the resolved Issues section.

The Client Proxy 4.9.3.211 macOS patch release includes enhancements related to AD group header size, end-to-end (E2E) health check and addresses key resolved issues. For details on all resolved issues, refer to the resolved Issues section. 

Release build

  • Windows -  4.9.3.92.1
  • Mac - 4.9.3.211

Enhancements

AD Group Header Size Selection

The AD Group Header Size is now configurable with two available options: 8k and 4k. The default size remains set to 8k. For more details, see Configure Group Header Size.

NOTE: Customers using multibyte characters in their AD group headers with SCP version 4.7.0 & later (till 4.9.2),  have the potential of facing issues such as failed user authentication, disrupted pop connectivity for those regions as total header size exceeds maximum header size limit. We have observed this for some customers only in the APAC region. For these customers, it is recommended to upgrade to 4.9.3 and select the AD Group Header size of 4K. For more details, see Troubleshooting AD Group Header Size.

NOTE: The default AD Header Group Size has remained 8K since Skyhigh Client Proxy version 4.7.0.

Skyhigh Client Proxy Support Tool (Windows only)

Skyhigh Client Proxy support tool supports Network Shell (netsh) to collect network traces and dependency on Wireshark has been removed. For more details, see Skyhigh Client Proxy Support Tool

NOTE: Skyhigh Client Proxy Support Tool enhancement is currently supported on the Windows platform only. 

NOTE: This patch release applies to the Windows platform only. This patch release does not support the upgrade of pre-release software versions, such as beta versions and POC builds. To install a production release of the software, you must first uninstall any pre-release versions. Upgrade work from older GA builds to the latest GA builds.

End-to-End Health Check (macOS only)

The End-to-End (E2E) health check enhancement monitors an endpoint to identify any failure scenarios in the SCP that may prevent it from securing that endpoint. This enhancement will help users detect insecure and non-compliant endpoints, enabling them to take necessary remedial actions. If a health check fails, the SCP will report the status as Not Redirecting (E2EHealthCheckFailed) and will automatically generate a Merlog. For more details, see End to End Health Check.

Resolved issues 

Reference Issue Description
MCP-5267 Alternate redirection list when selected no longer shows an error for Skyhigh Client Proxy  policy in Trellix SaaS ePO. (Windows only)
MCP-6668 Skyhigh Client Proxy now redirects traffic while using a dummy proxy IP for the primary proxy. (Windows only)
MCP-6770 This addresses the issues related to redirection faced by customers using myltubyte characters in AD Group headers. (Windows only)
MCP-6773 Skyhigh Client Proxy About Window is showing the right status when the dummy primary proxy is configured. (Windows only)
MCP-6777 The alternate proxy now redirects traffic when the primary proxy gets 500 responses for a webwasher request. (Windows only)
MCP-6978 Skyhigh Client Proxy was disconnecting from the proxy and refused to reconnect. (Windows only)
MCP-7118 The SCP incorrectly displayed a Bad Policy status due to a loop occurring when a port range ending at port 65535 was applied. This issue has now been fixed. (macOS only)
MCP-7158 Skyhigh Client Proxy intercept IPv4 PA traffic only on configured ports. 
MCP-7238 Skyhigh Client Proxy goes to a state of no redirection after a certain period of activity. (Windows only)
MCP-7345 Skyhigh Client Proxy goes to a state of no redirection after a certain period of activity. (macOS only)
MCP-7768 FMP 10.7.10 RTPP build with significant stability is now integrated into SCP 4.9.3. (macOS only)
MCP-8376 SCP sometimes fails to detect the VPN-connected state and continues redirecting traffic, even when redirection is disabled. This issue has been resolved by upgrading the deprecated Network Monitor API and to accurately detecting the VPN-connected state. (macOS only)
MCP-8457 Automatic browser tab opening for SAML login is disabled when accessing UDP PA applications, as multiple requests from these applications caused multiple tabs to open. Users should log in manually by opening the https://api.wgcs.skyhigh.cloud/ztna/dashboard url in the browser as a workaround. (macOS only) 

 

Known Issues and Workaround  

For a list of issues that are currently known, see Skyhigh Client Proxy Known Issues.

 

  • Was this article helpful?