Skyhigh Client Known Issues
This section lists the known issues of Skyhigh Client 5.0.0 for macOS and Windows.
Legends Used
| Fixed Build Version | ![]() |
Found Build Version | Workaround | ![]() |
Skyhigh Client 5.0.0 Known Issues (macOS)
|
Reference |
Found Build Version |
Issue Description |
|---|---|---|
| MCP-9838 | 5.0.0.804 | The Skyhigh Client for macOS does not honor the Disable Forward Private Access (UDP) policy. Consequently, UDP traffic remains routed to the Cloud Firewall regardless of this setting. |
| MCP-11786 | 5.0.0.804 | When the full ephemeral port range (49152-65535) is configured as part of PA applications, the system reboots. Workaround - Do not include the full ephemeral port range in the PA configuration. |
| MCP-11882 | 5.0.0.804 | Redirection fails intermittently with browser error. Workaround: Restart the Skyhigh Client to restore connectivity if page refresh does not work. |
| MCP-11883 | 5.0.0.804 | With the Cloud Firewall policy enabled, there is a latency upto 10-seconds noticed causing network disruption despite the tunnel maintaining a Connected status. |
| MCP-11949 | 5.0.0.804 | The file upload to Google Drive fails intermittently in slow networks while the Skyhigh Client is active. |
| MCP-12084/MCP-12086 | 5.0.0.804 | Intermittently, the Client UI reports incorrect Cloud Firewall and SWG connectivity status. |
| MCP-12091/MCP-12108 | 5.0.0.804 | The URLs containing German umlaute characters (ä, ö, ü) and non-ASCII characters, fails to load. |
| MCP-12104 | 5.0.0.804 | Occasional E2E health check failure observed upon system wake-up. Workaround: Restart the Skyhigh Client or system to recover. |
| MCP-12107 | 5.0.0.804 | The HTTP websites on default ports fail to load when connected to On-prem SWG. |
| MCP-12132 | 5.0.0.804 | The client UI displays No active host for Alternate Proxy, despite no alternate proxy being configured and the alternate redirection list being configured. |
Skyhigh Client 5.0.0 Known Issues (Windows)
|
Reference |
Found Build Version |
Issue Description |
|---|---|---|
| MCP-9706 |
Bypassing the private application domain fails because the SCP resolves the domain incorrectly. Despite the traffic policy allowing the bypass, the SCP still directs the domain to an internal 100.64.x.x address. The Client, therefore, receives the internal IP instead of the public one, which causes the connection to fail. Workaround: Make sure to avoid adding the domain to both Private Access and the Domain Bypass together. |
|
| MCP-10180 | The AD join fails with the Skyhigh Client because it cannot switch over to the primary DNS server, configured as a private application, after the Wireguard tunnel has been established. Workaround: It is recommended to avoid adding the domain to both Private Access and Domain Bypass together. |
|
| MCP-10252 |
Client Upgrade from 4.9.4.388 fails due to Syscore version mismatch.
|
|
| MCP-10266 | Registryhives missing in the Support Tool. Workaround: Make sure the destination folder name contains no blank spaces before running the Support Tool. |
|
| MCP-10311 | The Skyhigh Client fails to redirect, bypass, or block traffic on Syscore versions 25.11 and later. | |
| MCP-10468 | The Skyhigh Client does not fall back to port 8080 when the Secure Channel fallback option is enabled and ports 8081 and 443 are blocked. | |
| MCP-10469 | The Skyhigh Client continues to block traffic even when the Block on mutual authentication failure option is disabled. | |
| MCP-10470 | The Skyhigh Client fails to redirect traffic when non-standard ports are configured in a V1 policy. | |
| MCP-10471 | The Skyhigh Client becomes unresponsive during installation, and traffic is bypassed when port 8080 is in use. | |
| MCP-10475 | The Skyhigh Client fails to detect captive portals, access authentication pages, or obtain an IP address, causing unsuccessful network initialization and internet access. | |
| MCP-10528 | When using a V1 policy, the Skyhigh Client fails to bypass traffic for public IP addresses starting from 128.0.0.0. | |
| MCP-10532 | When non-standard redirection ports are configured, the Skyhigh Client may redirect traffic to port 443 instead of the configured port. | |
| MCP-10570 | After a network switch, the Skyhigh Client may fail to process web requests, which can result in connectivity interruptions. | |
| MCP-11934 | The Skyhigh Client does not bypass traffic configured in the Bypass list. Traffic is redirected to the proxy rather than bypassed. | |
| MCP-11970 | The Skyhigh Client policy enforcement may fail when gateway names contain extended ASCII or multibyte characters (for example, ã). Workaround: Use only standard English (ASCII) characters when defining the gateway name. |
|
| MCP-12140 | On Windows devices, a blank window displays intermittently . This is a cosmetic anomaly. All core client functionalities remains unaffected. | |
| HWPU-15499 | The new V2 policy is sometimes created with an empty default gateway. Workaround: It is recommended to edit the hostname manually. |


