Skyhigh Client 5.1.0 Windows Release Notes
About this Release
The Skyhigh Client 5.1.0 enhances device visibility, and simplifies software deployment. This release also adds an End-to-End (E2E) health check tool to the Windows system tray and allows administrators to define a custom local proxy port via the command line.
Release Build
- Build Version: Skyhigh Client 5.1.0.369
- Supported Processor Architecture: x86_64
For more information about the supported Windows version, see Supported Windows Versions.
Skyhigh Client Upgrade Recommendations
You can directly upgrade or auto-upgrade to this release from any previous Skyhigh Client 5.x.x release. You cannot directly upgrade or auto-upgrade from a Skyhigh Client Proxy 4.x.x release to a 5.x.x release. If you are running a 4.x.x release, you must follow the supported migration path before upgrading to 5.x.x. For details, see here.
What's New in This Release
This release introduces the following enhancements:
End-to-End Health Check
Skyhigh Client includes an integrated end-to-end (E2E) health check mechanism for Windows. This feature allows the client to verify connectivity and redirection status directly through the system tray, ensuring that traffic is being correctly processed by the Skyhigh SSE infrastructure. By porting and optimizing the health-check logic previously available on macOS, this update provides Windows users with real-time validation of their protection status and simplifies troubleshooting for connectivity issues. For more details, see End to End Health Check.
Custom Local Proxy Port Selection
Skyhigh Client supports the selection of a specific local proxy port during installation via the command line. Administrators can use the LOCALPROXYPORT parameter to define a preferred port; if the specified port is unavailable, the installation will safely abort to prevent conflicts. If no port is specified, the installer will automatically persist the previously used port (for upgrades from 5.x) or select an available port within the 8080–8100 range (for upgrades from 4.x). For more details, see Configure Custom Local Proxy Ports During Skyhigh Client Installation.
For more information about the key capabilities, see Enhanced Capabilities of Skyhigh Client.
Skyhigh Client 5.1.0 Resolved Issues (Windows)
This topic highlights the resolved issues fixed during testing of the Skyhigh Client 5.1.0 for Windows.
|
Reference |
Issue Description |
|---|---|
| MCP-12435 | Updated the Skyhigh Client configuration to increase the connection timeout from 2 minutes to 15 minutes across all connections. This prevents premature disconnects and improves stability for Private Access SSH protocol sessions. |
| MCP-12412 | Improved the client status experience when users are connected to a recognized corporate or on-premises network. The Skyhigh Client now more accurately reflects its expected operational state in these environments, reducing unnecessary error indications and providing a clearer representation of connectivity status. |
| MCP-12236 | Skyhigh Client consolidates rapid network events using a debounce mechanism and compares the current network state against the previous known state before initiating a connectivity check. A check is triggered only when a meaningful change is detected, such as a new IP address, a modified routing entry, or an adapter state change. |
| MCP-12220 | Skyhigh Client now correctly processes configurations containing non-English characters, such as Japanese, Korean, and German umlauts. Previously, the Service Controller could crash when encountering these characters in policy names or gateway settings due to an encoding error. |
| MCP-12198 | Fixed an issue where bypass rules for processes, web addresses, and network ranges configured in Trellix ePO were intermittently not applied to the endpoint. This ensures that trusted applications and internal traffic correctly bypass the proxy, preventing unexpected connectivity interruptions for end-users. |
| MCP-12196 | Fixed a cosmetic issue where the Skyhigh Client interface displayed internal POP-enhanced domain strings instead of the simplified gateway address. The UI now correctly displays the primary configured proxy domain, ensuring a clearer and more consistent experience for end-users. |
| MCP-12188 | The Skyhigh Client now automatically clears its cache and performs a fresh DNS lookup upon any network change, ensuring seamless connectivity for users moving between different environments. |
| MCP-12144 | The Skyhigh Client now correctly blocks IPv6 traffic only on the ports configured for redirection, allowing legitimate IPv6 traffic on other ports to bypass the proxy and connect directly. |
| MCP-12140 | Fixed a cosmetic issue where an intermittent pop-up titled ScSytem Tray-Menulet displayed on the user's screen during network transitions or VPN connections. This update ensures a seamless background experience for end-users by suppressing internal UI notifications. |
| MCP-12138 | The Skyhigh Client now correctly handles international character encoding when generating security tokens, ensuring seamless access to global web resources. |
| MCP-12117 | Resolved an issue where HTTP websites were blocked due to authentication mismatches when using on-premise gateways. The Skyhigh Client now builds authentication requests using the correct URL format, preventing authentication mismatches and allowing HTTP traffic to pass through successfully. |
| MCP-12085 | Resolved an issue where dummy proxy settings caused connection failures by incorrectly modifying destination ports. The Skyhigh Client now correctly handles explicit proxy configurations without altering the destination port, allowing applications that rely on OS proxy settings to redirect traffic through Skyhigh Client as expected. |
| MCP-10607 | Skyhigh Client now performs connectivity checks in the background without pausing traffic redirection, ensuring a stable and consistent web experience even on unstable or frequently changing network connections. |
| MCP-10585 | The Skyhigh Client now correctly limits authentication prompts to a single browser window, providing a streamlined and non-intrusive login experience for users accessing private applications. |
| MCP-10578 | The Skyhigh Client now correctly handles SRV record queries, ensuring that domain controllers can be discovered and joined seamlessly when using Private Access. |
| MCP-10577 | Resolved an issue where Skyhigh Client failed to send the correct logged-in username for certain Private Access applications, such as LDAP and Kerberos. This update ensures that user identity is consistently reported to the gateway, enabling successful Active Directory domain joins and authentication in environments where SAML is enabled. |
| MCP-9698 | Skyhigh Client now correctly handles non-UTF-8 characters (such as Japanese or Chinese host names) in system headers, ensuring stable log delivery and preventing infrastructure errors in localized environments. |
Behavioral Difference
For more details, see Understand Behavioral Differences Between the Skyhigh Client and the SCP.
Known Issues and Workaround
For the list of known issues, see Skyhigh Client Known Issues.
