Release Notes : F5 Access for Windows 10 1.3

Applies To:

Show Versions Show Versions

BIG-IP APM

  • 17.1.0, 17.0.0, 16.1.4, 16.1.3, 16.1.2, 16.1.1, 16.1.0, 16.0.1, 16.0.0, 15.1.10, 15.1.9, 15.1.8, 15.1.7, 15.1.6, 15.1.5, 15.1.4, 15.1.3, 15.1.2, 15.1.1, 15.1.0, 15.0.1, 15.0.0, 14.1.5, 14.1.4, 14.1.3, 14.1.2, 14.1.0, 14.0.1, 14.0.0, 13.1.5, 13.1.4, 13.1.3, 13.1.1, 13.1.0, 13.0.1, 13.0.0, 12.1.6, 12.1.5, 12.1.4, 12.1.3, 11.6.4
Release Notes
Updated Date: 08/30/2023

Summary:

Version 1.3 of F5 Access for Windows 10 is now available. The download is available from the app store for your device.

Significant changes in this version include the following:

  • Fixed Bugs
  • Tested various scenarios for deploying F5 Access on Windows 10 using Intune.

For more information, refer to F5 Access for Windows 10: Deployment using Intune.

Contents:

User documentation for this release

Known issues in 1.3

Known Issues in 1.3

ID Number Description
586159 F5 Access fails to re-establish a VPN connection if the session is killed on the server and the option "Remember my sign-in info" is disabled. As a workaround, reboot the device.
586684 By default, the Client OS checker takes the fallback branch if F5 Access for Windows is used to establish the connection. This happens because the client platform is reported as "Windows" when F5 Access is used. As a workaround, modify the default OS checker to use the "Windows" platform ( [mcget {session.client.platform}] == "Windows"} ) and version ( [mcget {session.client.platform_version}] == "10" ) session variables to detect Windows 10 correctly.
586688 When a user puts a Windows 10 system with an active F5 Access tunnel connection to sleep, the tunnel is not closed on the BIG-IP, and the user might not be able to establish a new connection to the VPN until the existing session times out.
586928 When using F5 Access to establish a VPN connection, access to the local network is not blocked even when the network access setting is "Force All Traffic through tunnel".
586956 DNS domain suffix and DNS address space settings are treated the same when a VPN connection is established using F5 access. As a result, any DNS address space settings are added to the DNS search suffix list and any DNS domain settings are added to DNS address space list.
586976 When the setting "Force All Traffic Through Tunnel" is enabled in Network Access settings, the "DNS default domain suffix" setting is ignored.
587507 If the IP address assigned to user's device is same as the local IP address, a tunnel cannot be established. As a workaround, change the local IP address or change the lease pool address to make sure that the two networks are different.
587923 When the option "Force all Traffic Through Tunnel" is set, proxy settings for short hostnames (e.g. https://intranet) are ignored.
588162 Proxy settings that are set manually in the VPN configuration will not be used in some cases. This occurs when split tunneling is configured in Network Access settings, and on windows mobile, it occurs regardless of split or full tunneling configuration. As a workaround, use a proxy configuration on the server.
588231 A session is not deleted from the BIG-IP when the user clicks Disconnect and manual proxy settings are set in the VPN configuration. As a workaround, do not specify proxy settings in the VPN configuration on the devices. Use the Network Access VPN configuration.
588857 An F5 Access user cannot pass the access policy if the on-demand certificate authentication agent is set before the logon page agent. The logon page cannot get user credentials.
589386 IPv6 traffic destined for the split tunneling exclude address space goes through the VPN tunnel.
589390 You cannot access tunnel resources if the Client Proxy Address from the Network Access resource is an IPv6 address. As a workaround, use an IPV4 proxy server.
589493 On a system with two network interfaces, the F5 Access VPN connection fails to reconnect if the network interface that was used to establish the VPN connection is disconnected, even though the second NIC is available and working.
589532 Routes to local DNS servers are added unconditionally when the VPN connection is established, even though the "Allow Local DNS Servers" option is disabled in Network Access settings.

Fixes in 1.3

Fixes in 1.3

ID Number Description
586012 Previously, when the VPN connection is already established, and you start the F5 Access app, you could not navigate past the splash screen. This issue has been fixed.
586020 Previously, when you disconnected the VPN connection and then attempted to reconnect immediately, the VPN failed to connect. Now, you can connect without any issues.
586208 Ideally, when the "Remember my sign-in info" option is disabled, you are asked to provide credentials each time you establish a VPN connection. In F5 Access, previously if you had the "Remember my sign-in info" option disabled and if you enabled it, the credentials from a previous successful VPN connection were re-used, and you were not prompted for credentials. This issue has been fixed.
586288 Previously, when you attempted to access a backend server over a VPN connection, and the server terminated the VPN session because of an inactivity timeout, sometimes the next reconnection attempt failed. This issue has been resolved.
635518 Previously, F5 Access for Windows did not support TLS client certificates stored in TPM, and the user login failed. These certificates were detected as SmartCards, and the user was asked to insert a SmartCard. This issue has been resolved.

Supported features in 1.3

The following F5 Access for Windows 10 features are supported.

Table 1. Authentication
Feature
Username/Password
Client certificate authentication
Username/Password with client certificate authentication (dual-factor authentication)
Table 2. Tunnel
Feature
TLS 1.x
Autoconnect
IPv4 transport
VPN Autoconnect
Table 3. Split Tunneling Scope
Feature Notes
Include Subnet List of subnets to be routed through the virtual VPN adapter.
Exclude Subnet List of subnets to exclude from routing through the virtual VPN adapter.
DNSSplit List of DNS patterns to define intranet DNS name space. For example: intranet.contoso.com, *.intra.contoso.com.
DNSSuffix DNS suffix for intranet.
DNS DNS server for VPN connection.

Contacting F5 Networks

Phone: (206) 272-6888
Fax: (206) 272-6802
Web: http://support.f5.com
Email: support@f5.com

For additional information, please visit http://www.f5.com.

Additional resources

You can find additional support resources and technical documentation through a variety of sources.

F5 Networks Technical Support

Free self-service tools give you 24x7 access to a wealth of knowledge and technical support. Whether it is providing quick answers to questions, training your staff, or handling entire implementations from design to deployment, F5 services teams are ready to ensure that you get the most from your F5 technology.

AskF5

AskF5 is your storehouse for thousands of solutions to help you manage your F5 products more effectively. Whether you want to search the knowledge base periodically to research a solution, or you need the most recent news about your F5 products, AskF5 is your source.

F5 DevCentral

The F5 DevCentral community helps you get more from F5 products and technologies. You can connect with user groups, learn about the latest F5 tools, and discuss F5 products and technology.

AskF5 TechNews

Weekly HTML TechNews
The weekly TechNews HTML email includes timely information about known issues, product releases, hotfix releases, updated and new solutions, and new feature notices. To subscribe, click TechNews Subscription, complete the required fields, and click the Subscribe button. You will receive a confirmation. Unsubscribe at any time by clicking the Unsubscribe link at the bottom of the TechNews email.
Periodic plain text TechNews
F5 Networks sends a timely TechNews email any time a product or hotfix is released. (This information is always included in the next weekly HTML TechNews email.) To subscribe, send a blank email to technews-subscribe@lists.f5.com from the email address you are using to subscribe. Unsubscribe by sending a blank email to technews-unsubscribe@lists.f5.com.

Legal notices