Updated Date: 07/20/2026
F5 Access version 3.2.2 for Android devices is now available. Users should install this new version from the Play Store. This release note contains information about the changes made for the current version only. Refer to the prior release note versions for additional information.
The build number for the F5 Access for Android 3.2.2 application version is 322-003.2026.0713.1411.
For a comprehensive list of documentation that is relevant to this release, refer to the following pages:
There are no new features in this release.
The following issues are fixed in this release.
| Issue ID | Description |
|---|---|
| 2386229 | Upgraded a third-party software to address known security vulnerabilities and align with the latest security improvements. |
The following are known issues in this release:
| ID Number | Description |
|---|---|
| 451826 | When F5 Access uses split tunneling for traffic, after establishing a VPN connection, all DNS queries are sent to the VPN-configured enterprise DNS server. |
| 504685 | F5 Access does not change to the Reconnecting state if the GTM server is down. Load balancing with GTM does not work. |
| 624395 | The web logon screen might disappear when you send F5 Access to the background after entering an RSA SecurID software token PIN. |
| 808509 | Downloading a client certificate or token from an HTTP URL on Android 9 fails. This is because of the improved security imposed by Android. Workaround: Use the HTTPS URL with a trusted CA to download the client certificate or token. |
| 809001 | VPN connection fails to establish with FIPS mode enabled on certain devices. Workaround: Disable the FIPS mode before establishing a VPN connection. |
| 893345 | F5 Access running on Android 10 does not send the device’s IMEI number to the APM. If MDM is configured to have a dependency on the IMEI number, it would fail. Workaround: Use MDM assigned unique device ID for identifying devices. |
| 893349 | F5 Access running on Android 10 sends incorrect wifi MAC address to the APM. Therefore, if MDM uses this address to query device compliance status from Intune, the query fails. Workaround: Use MDM assigned unique device ID for identifying devices. |
| 1782133 | When TLS 1.3 is configured in the Virtual Server SSL profile, F5 Access for Android fails to display the Key Exchange Algorithm as DTLS 1.2 in the Connection Details. Workaround: Use the TCP packet capture tools to verify the Key Exchange Algorithm. |
| 1782129 | When DTLS 1.2 is configured in the Virtual Server SSL profile, F5 Access for Android fails to display the Version as DTLS 1.2 in the Connection Details. Workaround: Use the TCP packet capture tools to verify the DTLS versions. |
| 1813229 | Users should click the Connect button to establish the VPN connection even when Always On mode is enabled. |
| 1813237 | F5 Access for Android is unable to log messages on Android 9.0 version. Workaround: Upgrade to a supported Android version, as the Android 9.0 version is no longer supported. |
| ID Number | Description |
|---|---|
| 574604 | VPN connections repeatedly fail with the Thursby smart-card reader if you do not enter the smart card unlock PIN before the 30-second timeout has expired. This is caused by a known issue in Thursby SubRosa app. Workaround: Force stop the SubRosa app, or reboot the device. |
| 597826 | F5 Access fails to read smart cards using Thursby smart card reader when running within Android for Work profile. |
| 617631 | When Always-On VPN Mode is enabled, a VPN connection is established, and a Network Access resource is configured to use split tunneling, resources from the split tunneling space can be successfully accessed using the managed application, but the managed application cannot access all resources outside of the split tunneling space. |
| 620294 | In Android 7.0 RC4, ciphers and SSLv3 are disabled for security reasons. AES ciphers must be enabled in the RSA Authentication Manager configuration for Dynamic Seed Provisioning (CT-KIP) to work on Android 7.0. For more details, see https://community.rsa.com/docs/DOC-45530. Workaround: Follow the steps in the linked article to enable non-RC4 cipher suites. |
| 634069 | In most cases, when an Always-On VPN is disabled by the DPM (Device Policy Manager), the F5 Access VPN revokes if it is currently connected. In some corner cases, if F5 Access is not connected when, for example, the DPM enables Always-On VPN, but the connection doesn’t start because of a misconfiguration, and the DPM then disables Always-On VPN, F5 Access won’t be notified, and may continue to attempt to reconnect until the device is rebooted. |
| 616957 | If Always-On VPN mode is enabled for F5 Access by an MDM, and a force stop is done, F5 Access goes into the Disconnected state, and the user loses internet access through managed apps. F5 Access does not reestablish the VPN connection automatically. Workaround: Restart the device to reestablish Always-On VPN mode. Another workaround is to disallow force stops in the MDM configuration, using DISALLOW_APPS_CONTROL. |
| 617362 | On some devices with Android 4.x, F5 Access Home screen icons might not get updated, and continue to show the older Edge Client icon. This is caused by Android issue 42921: https://code.google.com/p/android/issues/detail?id=42921 |
| 619106 | On certain Android devices, F5 Access displays two icons in the notification area when connected to VPN. This behavior is by design. |
| 629242 | The RSA SecurID software token PIN setup might timeout if you do not provide a new PIN within the RSA SecurID token interval. |
| 744854 | Samsung devices provide a way to disconnect Always-On VPN through notification. As a result, when you terminate always-on VPN, the system revokes VPN permission for F5 Access. This prevents F5 Access from establishing a VPN connection. Workaround: Uninstall and reinstall the F5 Access. |
| 748960 | There is no API to get the Chrome OS version when F5 Access for Android is running on Chrome OS. This being a Chrome issue is currently reported to Google and tracked through 881005. |
| 748962 | Always-On VPN can be turned off from the Chrome OS network settings. This action should not be allowed as it defeats the purpose of Always-On VPN. This issue is currently reported to Google and tracked through 881107. Workaround: Do not turn off Always-On VPN in the Chrome OS network settings. |
| 748963 | When adding a new VPN configuration through the Chrome OS settings, the F5 Access home screen is launched instead of the Add Configuration screen. Workaround: Navigate to the Add Configuration screen and add a new configuration. This issue is currently reported to Google and tracked through 881123. |
| 748964 | For F5 Access for Android on Chrome OS, the per-app VPN’s feature to allow/disallow apps to bypass VPN connection is reserved. As a result, the disallowed apps pass through the VPN tunnel and allowed apps are blocked through the VPN tunnel. This issue is currently reported to Google and tracked through 883529. |