SWG 12.2.x Known Issues and Workaround
Known Issues and Workarounds
| Fix Version | Found Version | Description |
|---|---|---|
| 12.2.23 | Issue: A race condition in the SSL Tap feature can cause the mwg-core process to restart (crash) when SSL Tap is used together with HTTP/2. This issue does not affect users who do not use SSL Tap. Workaround: If an upgrade to 12.2.23 is required, disable HTTP/2 using the Proxy Control event. |
|
| 12.2.19 | 12.2.17 | Issue: In certain scenarios, file uploads result in a 502 proxy error during HTTP/2 POST requests when the message size exceeds 65 KB. Workaround: Disable HTTP/2 to avoid the issue. |
|
- |
12.2.13 |
Issue: On KVM VM, kernel upgrade from 12.2.12 to 12.2.13 fails. Workaround: Follow the steps below for workaround
For details, see TSWS-13308 |
|
12.2.11 |
12.2.10 |
Issue: In the latest SWG release 12.2.10, a save operation post addition or updates to the below configuration items might fail with an error message popup being displayed in UI. NOTE: If you intend to change configuration values for any of the following fields, Skyhigh recommends not upgrading to 12.2.10. Central Management: Date and Time |
|
12.2.15 |
12.2.8 |
Issue: If the following conditions are met in your environment:
Then upgrading to any later version will cause HAProxy to fail to start. Workaround: The best practice is to add the Director as a scanner. |
|
12.2.10 |
12.2.8 |
Issue: HA proxy service is not running after upgrading to SWG 12.2.8 and 11.2.22 This is an issue with the latest Haproxy version 2.9.3. Workaround: 1) If the customer has not upgraded to the affected version then they can go to backend and do "haproxy -c -f /etc/haproxy/haproxy.cfg" and check if they have any warnings
|
| - | 12.2.6 | Issue:
Applications that use long-lived HTTP streaming responses, such as Server-Sent Events (SSE), may fail when accessed through Skyhigh Secure Web Gateway with HTTPS scanning enabled. These applications keep response streams open and do not send a terminating end-of-data signal. As a result, the gateway cannot complete content processing, which may disrupt application functionality. Workaround: Bypass HTTPS scanning for the affected application traffic to allow streaming connections to function correctly. |
