Skip to main content

What's New and Release Notes 25.2

Resolved Issues in 25.2.40-VEN

Issue

Fix Description

E-137139

VEN service now restarts as expected in the following situation

Following a workload reboot, the VEN service failed to start because a temporary controller communication error occurred while the VEN was reporting its policy status to the PCE. This issue is resolved.

E-136826

Policy Sync error is now triggered reliably in the following circumstances

In the following cases, the VEN in a proxy environment didn't report a sync error when it should have:

  • If the VEN received a policy that didn't allow communication with its configured proxy.

  • If the VEN received a policy that included an Override Deny rule explicitly denying communication with the proxy while in Enforcement Mode.

This issue is resolved. A Policy Sync error is now triggered reliably in both circumstances.

E-135946

False-Positive Firewall Tampering no longer triggered in the following circumstance

On Linux systems that use nftables, a VEN reported a false‑positive firewall‑tampering alert when the security policy included a rule allowing All Services with SecureConnect enabled. This issue is resolved.

E-135044

VEN no longer issues false tampering alerts in the following circumstances

After applying a SecureConnect policy, the VEN validates that all rules are loaded. During a race condition, the audit action may occur before the policy is done loading. In this case, the VEN misinterpreted the "still loading" state as a policy-load failure and then re-loaded the policy. This in turn caused unnecessary SecureConnect re-connections. The policy validation operation has been improved to better handle such race conditions in these circumstances.

E-130202

Compatibility Report now reports correct iptables rule count

The Compatibility Report showed an incorrect iptables rule count when the firewall platform was nftables. This issue is resolved.