Skip to main content

Check out Interactive Visual Stories to gain hands-on experience with the SSE product features. Click here.

Skyhigh Security

Skyhigh Client 5.1.0 Windows Release Notes

About this Release  

The Skyhigh Client 5.1.0 enhances device visibility, and simplifies software deployment. This release also adds an End-to-End (E2E) health check tool to the Windows system tray and allows administrators to define a custom local proxy port via the command line. 

Release Build 

For more information about the supported Windows version, see Supported Windows Versions.

Skyhigh Client Upgrade Recommendations 

You can directly upgrade or auto-upgrade to this release from any previous Skyhigh Client 5.x.x release. You cannot directly upgrade or auto-upgrade from a Skyhigh Client Proxy 4.x.x release to a 5.x.x release. If you are running a 4.x.x release, you must follow the supported migration path before upgrading to 5.x.x. For details, see here.

What's New in This Release

This release introduces the following enhancements:

End-to-End Health Check

Skyhigh Client includes an integrated end-to-end (E2E) health check mechanism for Windows. This feature allows the client to verify connectivity and redirection status directly through the system tray, ensuring that traffic is being correctly processed by the Skyhigh SSE infrastructure. By porting and optimizing the health-check logic previously available on macOS, this update provides Windows users with real-time validation of their protection status and simplifies troubleshooting for connectivity issues.  For more details, see End to End Health Check.

Custom Local Proxy Port Selection

Skyhigh Client supports the selection of a specific local proxy port during installation via the command line. Administrators can use the LOCALPROXYPORT parameter to define a preferred port; if the specified port is unavailable, the installation will safely abort to prevent conflicts. If no port is specified, the installer will automatically persist the previously used port (for upgrades from 5.x) or select an available port within the 8080–8100 range (for upgrades from 4.x). For more details, see Configure Custom Local Proxy Ports During Skyhigh Client Installation.

For more information about the key capabilities, see Enhanced Capabilities of Skyhigh Client

Skyhigh Client 5.1.0 Resolved Issues (Windows) 

This topic highlights the resolved issues fixed during testing of the Skyhigh Client 5.1.0 for Windows.

Reference

Issue Description
MCP-12435 Updated the Skyhigh Client configuration to increase the connection timeout from 2 minutes to 15 minutes across all connections. This prevents premature disconnects and improves stability for Private Access SSH protocol sessions.
MCP-12412 Improved the client status experience when users are connected to a recognized corporate or on-premises network. The Skyhigh Client now more accurately reflects its expected operational state in these environments, reducing unnecessary error indications and providing a clearer representation of connectivity status.
MCP-12236 Skyhigh Client consolidates rapid network events using a debounce mechanism and compares the current network state against the previous known state before initiating a connectivity check. A check is triggered only when a meaningful change is detected, such as a new IP address, a modified routing entry, or an adapter state change.
MCP-12220 Skyhigh Client now correctly processes configurations containing non-English characters, such as Japanese, Korean, and German umlauts. Previously, the Service Controller could crash when encountering these characters in policy names or gateway settings due to an encoding error.
MCP-12198 Fixed an issue where bypass rules for processes, web addresses, and network ranges configured in Trellix ePO were intermittently not applied to the endpoint. This ensures that trusted applications and internal traffic correctly bypass the proxy, preventing unexpected connectivity interruptions for end-users.
MCP-12196 Fixed a cosmetic issue where the Skyhigh Client interface displayed internal POP-enhanced domain strings instead of the simplified gateway address. The UI now correctly displays the primary configured proxy domain, ensuring a clearer and more consistent experience for end-users.
MCP-12188 The Skyhigh Client now automatically clears its cache and performs a fresh DNS lookup upon any network change, ensuring seamless connectivity for users moving between different environments.
MCP-12144 The Skyhigh Client now correctly blocks IPv6 traffic only on the ports configured for redirection, allowing legitimate IPv6 traffic on other ports to bypass the proxy and connect directly.
MCP-12140 Fixed a cosmetic issue where an intermittent pop-up titled ScSytem Tray-Menulet displayed on the user's screen during network transitions or VPN connections. This update ensures a seamless background experience for end-users by suppressing internal UI notifications.
MCP-12138 The Skyhigh Client now correctly handles international character encoding when generating security tokens, ensuring seamless access to global web resources. 
MCP-12117 Resolved an issue where HTTP websites were blocked due to authentication mismatches when using on-premise gateways. The Skyhigh Client now builds authentication requests using the correct URL format, preventing authentication mismatches and allowing HTTP traffic to pass through successfully.
MCP-12085 Resolved an issue where dummy proxy settings caused connection failures by incorrectly modifying destination ports. The Skyhigh Client now correctly handles explicit proxy configurations without altering the destination port, allowing applications that rely on OS proxy settings to redirect traffic through Skyhigh Client as expected.
MCP-10607 Skyhigh Client now performs connectivity checks in the background without pausing traffic redirection, ensuring a stable and consistent web experience even on unstable or frequently changing network connections. 
MCP-10585 The Skyhigh Client now correctly limits authentication prompts to a single browser window, providing a streamlined and non-intrusive login experience for users accessing private applications.
MCP-10578 The Skyhigh Client now correctly handles SRV record queries, ensuring that domain controllers can be discovered and joined seamlessly when using Private Access.
MCP-10577 Resolved an issue where Skyhigh Client failed to send the correct logged-in username for certain Private Access applications, such as LDAP and Kerberos. This update ensures that user identity is consistently reported to the gateway, enabling successful Active Directory domain joins and authentication in environments where SAML is enabled.
MCP-9698 Skyhigh Client now correctly handles non-UTF-8 characters (such as Japanese or Chinese host names) in system headers, ensuring stable log delivery and preventing infrastructure errors in localized environments.

Behavioral Difference 

For more details, see Understand Behavioral Differences Between the Skyhigh Client and the SCP.

Known Issues and Workaround     

For the list of known issues, see Skyhigh Client Known Issues.  

  • Was this article helpful?