Manual Chapter :

BIG-IP Edge Client establishes secure communications to applications and networks. It provides users with full access to IP-based applications, resources, and intranet files as if they were physically working on the office network. This release note contains information about the changes made for the current version only. Refer to the prior release note versions for additional information.

The Edge Client version 7.2.7 is now available on MyF5.com (under the APM Clients container). For download instructions, refer to the K000090258: Download F5 products from MyF5 article.

The following table contains APM client 7.2.7 versions for different operating systems:

APM Clients version BIG-IP Edge Client Windows version Mac F5 Access version Mac Edge Client version Linux version
apmclients-7270.2026.331.528-7567.0.iso 7270.2026.331.528 7270.0.0.1 7270.2026.0323.1 7270.0.0.1

Important:

  • F5 announced the discontinuation of 32-bit Linux support in the APM Edge Client Compatibility matrix. In the next major APM Clients release, F5 will remove 32-bit binaries from client ISO images. For more information, please refer to K000157971: End of technical support for BIG-IP APM network access, VPN Linux 32-bit client OS.
  • Going forward F5 Access for MacOS will be released along with APM Clients releases and introducing changes to deployment workflow and versioning. For more information on this change, refer to K000152992.

BIG-IP Edge Client version 7270 for Windows must be installed as a fresh installation. Upgrading directly from any older versions to version 7270 is not possible due to changes in signer certificates and Certificate Authority (CA) in 7.2.7 release. As a result, the F5 Component Installer Service included in the update will fail to upgrade during the transition from earlier versions. To ensure smooth functionality, it is strongly recommended to uninstall any older versions of BIG-IP Edge Client on Windows systems and perform a fresh installation of version 7270. This issue is specific to the Windows platform. BIG-IP Edge Client for Mac and other platforms or clients are not impacted and will continue to function as intended. For more information, refer to K000160684

For a comprehensive list of documentation that is relevant to this release, refer to the following pages:

Following are the new features in this release.

APM Client 7.2.7 introduces support for Post-Quantum Cryptography (PQC) cipher groups, ensuring secure VPN connectivity in alignment with emerging quantum-resistant encryption standards. The legacy cryptographic infrastructure (such as OpenSSL 1.1.1 and SChannel) is replaced with OpenSSL 3.5.0, to enable the support for TLS 1.3 and PQC-ready cipher suites, such as X25519+MLKEM768.

Following APM Clients support PQC:

  • Windows Edge Client
  • MacOS F5 Access
  • Linux CLI client
  • Windows Web Client
  • Linux Web Client

To leverage PQC support in APM Clients:

  • Upgrade Edge Client/Web Client to 7.2.7.
  • Upgrade BIG-IP APM system to 17.5.1 or later.
  • Configure the BIG-IP SSL Profiles to include PQC cipher groups, such as: X25519+MLKEM768.
  • Ensure that the end-user Default Browsers can support TLS 1.3 with PQC.

Endpoint Inspection is now supported on Ubuntu with ARM64, allowing seamless management and inspection of endpoints on Linux ARM64 platforms. This feature requires BIG-IP version 21.1 or later.
For detailed information on the additional system libraries required, refer to K000158036.

The Windows Edge Client now offers custom logging preferences, giving you enhanced control over log verbosity to improve both security and flexibility.

You can select the required log level from APM Client Log Level drop-down in General Settings while creating a connectivity profile from Access > Connectivity / VPN > Connectivity > Profiles in BIG-IP. By default, it is set to Info.

Note: If the BIG-IP Server log level is set to ERROR, WARN, or INFO, it will override the Client Log Level. The APM Client Log Level is considered only when the BIG-IP Server log level is set to DEBUG or TRACE. If they differ, the lower log level (less verbose) is applied.

Important: The changes to ServerLogLevel are applied dynamically and do not require reinstalling the Edge Client. The updated settings will automatically reflect when the client connects to the APM Virtual Server with a connectivity profile that has the Custom Logging option enabled. However, the MachineLogLevel must be manually created in the Registry Editor if detailed debug-level logging is required on the client side. For more information refer to APM Clients Documentation.

This feature requires BIG-IP version 21.1 or later.

Windows Edge Client can now automatically upgrade the F5 Machine Tunnel Service when a newer version is available on BIG-IP, and the auto-upgrade feature is enabled. Additionally, if the Machine Tunnel service is running before the upgrade, it continues to run after the upgrade completes without affecting existing VPN configuration settings.

This feature requires BIG-IP changes tracked as part of https://techdocs.f5.com/kb/en-us/products/big-ip_ltm/releasenotes/related/relnote-supplement-bigip-17-5-1-4.html#A2141337-1 and shipped in BIG-IP 17.5.1.4 release.

The following are the fixes in this release:

ID Number Component Description
1403777 Windows Edge Client Fixed the issue of Network Access Client power management options not working as expected.

Following are the Known Issues.

ID Number Description
2251413 On macOS Edge Client, the UI continues to display the status as “Connecting” even after the VPN connection is successfully established.
Workaround: Disconnect and reconnect from Edge Client.
2224925 When the client machine has multiple valid certificates for client certificate inspection, the Windows Edge Client will prompt the user with a dialog box to select a certificate from the list of matching certificates each time a VPN session is initiated.
2162537 Microsoft’s Trident engine (Embedded Browser) does not support PQC MLKEM ciphers. As a result, any HTTPS requests initiated by Trident will not use PQC MLKEM ciphers during the TLS handshake. This affects the following scenarios:
Edge Client: When configured to use the embedded browser for user authentication, all HTTPS requests initiated from the Trident engine will not support PQC ciphers. This limitation is limited to authentication (using the embedded browser). To overcome this limitation, system’s Default Web Browser can be configured for user authentication.
Web VPN: Web VPN uses Trident to render the VPN connectivity UI. UI related HTML file requests (/vdesk/resource_all_info.eui, webtop_resource_inner.eui) and subsequent requests such as CSS or JS files and timeoutagent-i.php initiated by the Trident engine will not use PQC ciphers.
Windows Pre-Logon: Similar to Edge Client, when Pre-Logon uses the embedded browser for user authentication, HTTPS requests from this engine will not support PQC ciphers.
Note: These limitations do not affect the Machine Tunnel client. VPN tunnel establishment of all the Windows Clients is unaffected by the Trident limitation.
2230065 Upgrading from older versions of Edge Client for Windows to version 7270 may fail. You must completely uninstall the existing version before installing version 7270. For more information, refer to https://my.f5.com/manage/s/article/K000160684
1079621 When the application is moved to the trash, the respective application F5 EPI or F5 VPN directory is getting deleted from the following path: /Applications/F5 Endpoint Inspector.app/Contents/Resources/ Whereas, the respective application specific (F5 EPI or F5 VPN) folder is not getting deleted from the following path: /Users/<username>/Library/Applications Support/F5 EPI The plist file of the respective application is not deleted from the following path: /Users/<username>/Library/Launchagents/ Workaround: If you are running MacOS Version 12.2 or later 1. Upgrade to the latest build and verify the applications are recent: /Applications/F5\ VPN.app /Applications/F5\ Endpoint\ Inspector.app 2. Delete the following LaunchAgents: ~/Library/LaunchAgents/com.f5.f5epihelper.plist ~/Library/LaunchAgents/com.f5.f5epihelper.plist 3. Delete the following python scripts: ~/Library/Application\ Support/F5\ VPN/uninstall.py ~/Library/Application\ Support/F5\ EPI/uninstall.py 4. Reboot the device to remove the Launch agents in memory.
1082821 When trying to establish a VPN connection using a browser, it does not work with TLS 1.3 on all versions of macOS. Workaround: Enable other versions of TLS to allow the browser to fallback to any other versions of TLS protocol.
1082825 When trying to establish a VPN connection using a browser, it does not work with TLS 1.3 on Linux. Workaround: Enable other versions of TLS to allow the browser to fallback to any other versions of TLS protocol.
1084369 Optimized tunnels are not supported on ARM64-based Windows 10 and Windows 11 systems. When Optimized tunnels are used, the tunnel connection fails without user notification. Workaround: In some cases, use a static app tunnel to establish a tunnel connection.
1194381 An intermittent issue is observed when Edge Client on Windows fails to reconnect if the LAN cable is unplugged when the system is asleep. Workaround 1: Add the Virtual Server FQDN to the stonewall exclusion list on BIG-IP. Workaround 2: The LAN cable should be unplugged from the Windows system prior to hibernation if the user does not want to continue with LAN connectivity after coming out of hibernation. Workaround 3: If step 1 is missed or skipped, and faces the Edge Client reconnect issue after coming out of hibernation then the Ethernet cable must be plugged into the Ethernet port on the Windows system. If there is no Ethernet cable, restart the Edge Client application.
1239253 Web F5 VPN will not be launched if certain versions of Ubuntu on ARM64 do not have the /lib/aarch64-linux-gnu/libpcre16.so.3 library installed. Workaround: Users who want to use web F5 VPN on certain versions of Ubuntu running on ARM64 which do not have /lib/aarch64-linux-gnu/libpcre16.so.3 should install libpcre16-3 using one of the following commands. sudo apt install libpcre16-3 or sudo apt-get install libpcre16-3
1295133 Edge Client users are prompted to install the Endpoint Inspection (EPI) helper applications on macOS 13.3. Workaround: Preinstalling the latest EPI helper application would resolve the issue. For more information on the deployment process, refer to the Install the latest Edge Client on MacOS end devices section of the K000133476 article. For more details on the user experience changes, refer to the K000133622 article.
1324053-1 Users experience a one-time issue on Windows and MacOS as Edge Client configuration settings which were defined in the client.f5c are overwritten with the settings defined in the config.f5c when the auto-upgrade is enabled. This issue would not be seen when users upgrade from APM Clients 7.2.4.3 version to the future versions. Workaround: Administrators can define the desired configuration, especially the APM virtual server list in the config.f5c before the upgrade so that the Edge Client Installer copies the settings to the client.f5c file. Generally, the config.f5c file is available in the following directory path: Windows: C:\ProgramData\F5 Networks\Secure Access Client or C:\Program Files (x86)\F5 VPN MacOS: /Library/Application Support/F5Networks
1581041 The Show IP configuration and Show routing table buttons do not work for the F5 VPN window on the Mac Platform after the QT upgrade of APM clients. You can use the following command line tools to view the network configurations: /sbin/ifconfig /usr/sbin/netstat -rn /usr/sbin/scutil –dns
1615801 If the VPN connection is made from Windows 11 machines with WebVPN or Edge Client with Default Browser Authentication enabled, BIG-IP shows the wrong session.client.platform value.
1628533-1 Windows Logon Credentials feature does not work in Windows 11 24H2. Users cannot connect to Edge Client automatically as the prompt is displayed to specify the credentials.
1678473 Auto-upgrades of Windows Clients (Web EPI, Web VPN, and Edge Client) without Component Installer service fails. Workaround: 1) Re-install the Windows Clients (or) 2) Upgrade to 7248 GA build (apmclients-7248.2024.910.609-6452.0.iso) before upgrading to 725x or later.
1697301 On a Windows 10 machine, unable to establish VPN Connection with EdgeClient, WebVPN, Machine Tunnel, and Custom Dialer using TLS1.3. Workaround: 1. Upgrade Windows 10 to Windows 11 or 2. Establish a VPN connection with TLS1.2
2047741 Starting with Windows Edge Client 7.2.6, the network port icon previously shown in multiple Edge Client windows and as the application icon in the Windows Start menu has been replaced with the default F5 icon. This default icon cannot be changed, as customization is not currently supported for the icon.