Common Gateway Enhancements
OpsRamp Gateway Base OS Upgrade
The OpsRamp Gateway (Classic and NextGen) ISO, OVA and Cloud Images have been upgraded to use Ubuntu 26.04 LTS (Resolute Raccoon) as the underlying operating system. This update ensures you continue to receive critical security patches and maintain a fully supported platform well ahead of the April 2027 end-of-life for the previous Ubuntu 22.04 LTS baseline.
By adopting the latest LTS release, you benefit from improved security posture and long-term stability for your Gateway deployments. This upgrade includes updated ISO, OVA and Cloud images for Classic and NextGen Gateways, along with comprehensive appliance upgrade to help you transition your existing environments to the new supported OS version.
Note
Gateway application upgrades are not allowed when the operating system is nearing or has reached End of Life (EOL). This prevents a supported Gateway application version from running on the operating system that is no longer supported or is approaching EOL.Enhanced Password Management for Classic and NextGen Gateways
Strengthened gateway security by enforcing password changes for default gateway accounts on first login across Classic and NextGen Gateways. You are also required to change passwords after a gateway reset. For existing deployments, upgrades and patches enforce password changes only when default credentials are still in use, helping reduce the risk of unsecured default passwords.
Updated Gateway Network Diagnostics
The traceroute and mtr have been replaced with tracepath for secure network path and latency diagnostics from the Gateway management interface.
Java Runtime Changes in Gateway 22.0.0
Starting with Gateway 22.0.0, Java 17 is the default Java version. Java 11 has been deprecated and removed from the Gateway. See H2-2025 | OpsRamp Documentation for more details.
Gateway-Managed OTEL Upgrade
After upgrading the Gateway to version 22.0.0, you must also upgrade the Gateway-managed OTEL to 1.0.1 version.
Enhanced SNMP Trap and Varbind Synchronization
You can now perform on-demand synchronization of SNMP traps and varbind definitions from the cloud to the gateway, ensuring that your monitoring configurations are updated immediately. This enhancement reduces the previous 8-hour automatic sync interval to just minutes and introduces a delta sync mechanism that pushes only the latest changes, significantly improving data efficiency.
By navigating to the Collector Profile Details page and selecting Sync SNMP Traps and Varbinds from the Actions menu, you can ensure your gateway is always equipped with the most current trap definitions. This self-service capability allows you to onboard and tune vendor-specific SNMP traps without waiting for backend updates, providing faster time-to-value and greater control over your monitoring environment.
Automatic Gateway Connectivity Diagnostic Collection
OpsRamp now automatically runs the Gateway Connectivity Debugger when specific connectivity and TLS-related failures occur. The debugger collects diagnostic data, including TLS logs, vProbe logs, gateway service logs, network diagnostics, and RCA reports, and stores them in a dedicated auto-diagnostics directory for review and sharing with OpsRamp Support.
This enhancement simplifies troubleshooting and helps accelerate root cause analysis of gateway connectivity issues.
Alert Synchronization and Healing for Gateway Monitoring
Introduced an alert synchronization mechanism that preserves monitoring alerts when a gateway is detached from a collector profile, and a new gateway is attached. The gateway synchronizes existing monitoring alert information from the OpsRamp cloud and automatically sends heal events when previously reported alert conditions have cleared.
This enhancement helps maintain accurate monitoring alert states and prevents stale alerts after gateway profile changes.
Note
Alert synchronization and healing apply only to monitoring alerts. SNMP trap alerts, Syslog alerts, and other non-monitoring alert types are not included.Common Gateway Security Fixes
Security Enhancement for Gateway Registration Data
Enhanced the security of gateway registration and authentication data by strengthening access controls and credential protection mechanisms. This update helps reduce the risk of unauthorized access and improves overall gateway security.
Common Gateway Bug Fixes
Alert triggered with warning severity instead of critical severity
Improved alert condition evaluation to ensure that alerts are generated with the appropriate severity when multiple conditions are met. When a higher-severity condition is met, lower-severity alerts are no longer generated, resulting in more accurate alert notifications.
Improved alert sequencing and accuracy
Alert and recovery events could previously be generated out of sequence during connectivity interruptions between the Gateway and server, resulting in inaccurate alert reporting. Alert notifications and corresponding recovery events are now processed in the correct sequence, improving the accuracy and reliability of alert reporting.
Classic Gateway Enhancements
Updated Gateway Service Monitoring
Enhanced service monitoring and network diagnostics for Ubuntu 26.04 (Resolute) gateways. The legacy monit utility has been replaced with gw-monitord for improved service monitoring and automatic recovery.
Azure Classic Gateway support for Azure Generation 2 Virtual Machines
OpsRamp now supports the installation of Classic Gateways on Azure Generation 2 (Gen2) Virtual Machines. This enhancement allows you to leverage modern Azure VM architecture, providing a future-proof deployment path as Microsoft approaches the deprecation of Generation 1 VMs. During deployment via the Azure ARM template, you can now choose between Gen1 and Gen2 VM types, with Gen2 set as the default selection for new installations to ensure optimal performance and long-term compatibility.
Classic Gateway Security Fixes
Classic Gateway WebUI Security Improvement
Enhanced security in the Classic Gateway WebUI by removing a long-lived security cookie and tying the associated protection to the user session. This prevents it from persisting after the session ends, while preserving normal sign-in and form submission functionality.
Enhanced Validation for Proxy Configuration Settings
Enhanced validation has been implemented for Proxy Settings used in inbound and outbound restrictions. The update ensures that only properly formatted network and domain entries are accepted, helping prevent configuration errors and improving overall reliability and security.
Classic Gateway Bug Fixes
Classic Gateway Password Validation Enhancement
You can now use the hash (#) special character when updating passwords through the Classic Gateway admin UI. Previously, passwords containing # were incorrectly rejected by the password validation policy, even when they met all other complexity requirements.
This update aligns password validation with the supported character set, allowing successful password updates using any supported special character and improving the overall password management experience on Classic Gateway.
NextGen Gateway Enhancements
Enhanced Third-Party Application Communication for vProbe
OpsRamp has introduced NATS JetStream as the new communication backbone for vProbe to facilitate data exchange with third-party applications. This update replaces the deprecated NATS STAN component, providing you with a more robust and future-proof messaging system for application discovery and monitoring data. You will benefit from seamless data pipelines and improved reliability during network reconnections or gateway restarts, ensuring continuous visibility into your monitored devices without data loss.
Container Attestation and Image Trust Enforcement
Added container image attestation and policy enforcement for NextGen Gateway Kubernetes deployments. This enhancement ensures that only trusted, signed, and policy-compliant container images can run, helping protect against tampered or malicious images. Image signatures are verified automatically during deployment, with support for deny and warn enforcement modes. The feature also includes TOFV caching for secure operation in offline and air-gapped environments.
Terminal UI for Guided OpsRamp Gateway Operations
Introduced a Terminal UI for OpsRamp Gateway that simplifies common Gateway and Kubernetes administration tasks through a guided, menu-driven interface. You can use the Terminal UI to configure network and proxy settings, manage Kubernetes clusters and namespaces, install or uninstall Gateways, update Gateway configurations, view Kubernetes pods, and generate diagnostic bundles without manually entering CLI commands.
Enhanced Security Controls for NextGen Gateway Containers
OpsRamp has introduced configurable security contexts and non-root execution capabilities across all NextGen Gateway containers. This enhancement allows you to align your gateway deployments with Kubernetes security best practices by enforcing restricted privileges and non-root user execution by default.
Kubernetes Secret Support for NextGen Gateway Helm Chart
The NextGen Gateway Helm chart now supports Kubernetes Secrets for sensitive values such as vProbe registration details and proxy credentials via valueFrom.secretKeyRef. This allows secure credential management without storing plaintext values in values.yaml making Helm configurations safe to commit to Git.
The update is backward compatible with existing plaintext configurations, while giving priority to values from referenced secrets. It also adds support for imagePullSecrets, enabling secure authentication to custom image registries without storing credentials in configuration files.
Enhanced Security and Compliance with RKE2 Migration
NextGen Gateway now uses Rancher Kubernetes Engine 2 (RKE2) for new UB26 appliance deployments, replacing K3s. RKE2 is FIPS 140-2 compliant and aligned with CIS Kubernetes Benchmark hardening standards, providing a more secure, enterprise-ready Kubernetes platform while maintaining feature parity for discovery, monitoring, and application support.
This update supports both single-node and HA multi-node deployments and integrates seamlessly with the existing collector-cli and Terminal UI workflows. It also adds support for custom CIDR configurations and automated cluster health monitoring to help you deploy and manage compliant, resilient gateway environments.
Note
An appliance upgrade is required for this change to take effect.Kubernetes-Only Deployment for Collector Bootstrap Tool
OpsRamp has standardized the NextGen Gateway deployment exclusively on Kubernetes, removing support for Docker environments within the Collector Bootstrap Tool. You no longer need to manually select or specify a deployment environment during the setup process, as the bootstrap workflow now defaults to Kubernetes. This update streamlines the installation experience by eliminating Docker-specific configuration steps and CLI flags, ensuring a more focused and efficient deployment process aligned with modern infrastructure standards.
Network Performance Management compatibility
NextGen Gateway 22.0.0 requires Network Performance Management (NPM) 4.0.0 or later to maintain monitoring capabilities. While NPM 3.0.0 remains supported on earlier gateway versions, it is not compatible with Gateway 22.0.0. Because NPM 4.0.0 is backward compatible with earlier versions and supports Gateway 22.0.0 seamlessly, you can upgrade your NPM collector in advance to ensure a smooth transition when you move to the latest gateway version.
Caution
- For Gateway 22.0.0, if you switch the VM to another VM, reconfigure the NodePort settings on the new VM.
- Re-enable the Load Balancer (LB) Controller and Third-Party App settings on the applicable nodes.
Classic Apps Enhancements
Chassis Information in UCS Alert Descriptions
Introduced parent hierarchy details, specifically the chassis name, in alert descriptions for Cisco UCS compute blade metrics. This enhancement ensures that you can immediately identify the physical location of a blade server directly from the alert, eliminating the need to manually cross-reference inventory data and improving response times for hardware-related issues.
Ping Monitoring Timeout Configuration
Introduced a new configuration parameter for Ping Monitoring that allows you to configure timeout values directly through the user interface. This enhancement, available in the updated Ping Monitor - G2 - v2 template, eliminates the need for manual backend configuration changes when managing large numbers of devices on a Windows gateway. By optimizing internal execution paths and batching devices with identical configurations, this update ensures reliable monitoring data collection and prevents devices from incorrectly entering an unknown state due to command timeouts.
Added Support VMware vSAN Virtual Machine Read/Write Latency Metrics at Cluster Level
Introduced support for VMware vSAN virtual machine latency metrics at the cluster level. You can now monitor vmware_vsan_virtual_machine_latencyRead and vmware_vsan_virtual_machine_latencyWrite data directly on cluster devices that contain virtual machines as components. This enhancement provides you with deeper visibility into storage performance and latency trends across your vSAN environment, enabling more effective troubleshooting and resource management.
Datastore Cluster Visibility for VMware Datastores
OpsRamp now displays the Datastore Cluster name (Storage DRS cluster) for each VMware datastore. This enhancement provides you with improved visibility and contextual understanding by aligning the OpsRamp resource view with your vCenter organizational structure.
By surfacing this metadata, you can more efficiently manage large-scale VMware environments, perform faster impact analysis, and streamline troubleshooting. This update also enables better reporting and filtering capabilities, allowing you to group and identify resources based on their operational ownership and cluster assignments.
Enable Instance-Specific Credential Mapping for Sybase Database Monitoring
You can now specify credential names along with database instance and port details in configuration parameters. This enhancement enables instance-specific credential mapping, ensuring that each Sybase instance uses the correct credentials for authentication and helping prevent failed logins and account lockouts in multi-instance environments.
Improve WLAN Controller Discovery Reliability
Enhanced WLAN Controller Discovery by querying one OID per request instead of multiple OIDs in a single request. This improvement supports devices that do not respond to multi-OID requests, helping ensure more reliable discovery and data collection.
Support Alternative IP Ping Monitoring
Introduced the Alternative IP Ping Monitoring adapter, enabling you to monitor additional IP addresses beyond a device’s primary IP address. You can configure alternative IPs as template parameters and collect packet loss and response time (RTA) metrics for each configured IP, helping ensure visibility into the availability and performance of multi-IP environments.
Display Datastore Cluster Information for VMware Datastores
Added support to display the Datastore Cluster (Storage DRS cluster) name in the custom attributes of VMware datastores. This enhancement helps you easily identify the datastore cluster associated with a datastore and improves visibility into VMware storage configurations.
Enhance Syslog Parsing for RFC Compliance
Enhanced syslog parsing to align with RFC 3164 and RFC 5424 specifications. This update improves timestamp, priority, and structured data validation while providing more reliable handling of short, malformed, and standards-compliant syslog messages.
Added VMware Cluster CPU and Memory Utilization Metrics Without Failover Capacity
Added support for the vmware_cluster_cpu_utilization_percentage_excluding_failover and vmware_cluster_mem_utilization_percentage_excluding_failover metrics, providing CPU and memory utilization values that exclude failover-reserved capacity for more accurate cluster utilization reporting.
Support Windows Endpoint Monitoring from Linux Gateways
Added Python and PowerShell monitoring support for Windows devices from Linux gateways using SSH credentials, enabling RSE monitoring in Linux-to-Windows environments.
Improve Ping Monitoring Efficiency on Windows Gateways
Optimized ping monitoring execution on Windows gateways by grouping devices with identical configurations and improving snapshot processing. This enhancement reduces monitoring overhead and helps avoid timeout adjustments when monitoring large numbers of devices.
Display DNS Names for VMware vCenter Resources
Added support to display DNS names in VMware vCenter resource attributes, improving visibility and consistency between discovery and resource details.
Classic Apps Bug Fixes
SNMPv3 AES-256c Privacy Protocol Support
OpsRamp now supports the AES-256c privacy protocol for SNMPv3 device discovery and communication. This enhancement ensures that you can successfully discover and manage network devices, such as Cisco IOS XE systems, that require the AES-256c encryption standard for secure data transmission. Previously, discovery might fail with timeout or security level errors when this specific protocol was configured.
Improved Hex-to-String Conversion for SNMP Dynamic Metrics
The SNMP “Hex To String” data type conversion has been enhanced to ensure cleaner string outputs for dynamic metrics. Previously, converting fixed-length SNMP OctetString responses could include trailing null bytes or non-printable characters, which caused regex-based alert conditions to fail.
With this update, the gateway now automatically trims trailing null bytes and non-printable characters during the conversion process. This ensures that you receive a clean string value, allowing regex alert thresholds to match correctly and preventing false-positive alerts.
Improved CIM Alerting for Invalid Credentials
Introduced an enhancement to CIM monitoring to prevent unnecessary heal alerts when invalid credentials are assigned. This update ensures that you no longer receive repetitive critical and heal alert cycles during monitoring polls, providing a more accurate and stable alerting experience.
Improved RFC 5424 Syslog Ingestion
Fixed an issue where RFC 5424 syslog messages containing nonUTC timezone offsets were not ingested correctly into Log Explorer when forwarded through the Gateway-managed OTel Collector. Timezone offsets are now correctly converted to UTC, ensuring logs from devices in different time zones are successfully ingested and displayed with accurate timestamps. RFC 3164 syslog messages and RFC 5424 messages using UTC timestamps were not affected.
vSAN Performance Optimization
Improved VMware vSAN monitoring performance for large-scale environments that use multiple gateways to monitor the same vCenter. Previously, excessive monitoring requests could increase vCenter resource consumption, contribute to service instability, and trigger request throttling in heavily distributed deployments.
This update optimizes vSAN data collection by improving how monitoring requests are processed, reducing the load placed on vCenter while maintaining monitoring coverage. As a result, you can more efficiently monitor large VMware environments, improve vCenter stability, and scale vSAN monitoring across distributed sites with reduced performance impact.
Improved VMware CIM Credential Alert Messaging
Corrected VMware CIM alert subjects to accurately indicate when no CIM credentials are attached to an ESXi host discovered outside VMware integrations, improving troubleshooting and alert clarity.
SDK Enhancements
Enhanced SNMP Trap and Device Definition Synchronization
You can now benefit from faster and more efficient synchronization of SNMP trap and device type definitions between the cloud and the gateway. This update introduces on-demand synchronization and a new delta sync mechanism that pushes only the latest changes, significantly reducing data transfer and ensuring your gateway is always up to date with the most recent definitions.
These improvements allow you to onboard and tune vendor-specific SNMP traps more quickly, providing immediate visibility into your device monitoring without waiting for lengthy automatic sync cycles.
Updates for Upcoming Release
Removal of Legacy Dell Storage and CyberArk Classic App Integrations
Beginning with OpsRamp Gateway 22.1.0, the following Classic App integrations will be removed and will no longer be supported:
- Dell VNX
- Dell VNXe
- Dell CLARiiON
- CyberArk
See H2-2025 | OpsRamp Documentation and H1-2026 | OpsRamp Documentation for more details.
Impact on Existing Customers
Existing installations of the Dell VNX, Dell VNXe, Dell CLARiiON, and CyberArk Classic App integrations will continue to function on OpsRamp Gateway versions up to 22.0.0.
After upgrading to OpsRamp Gateway 22.1.0 or later, all installed Dell VNX, Dell VNXe, Dell CLARiiON, and CyberArk Classic App integrations will no longer function.
Customers using any of these integrations should identify and transition to alternative monitoring or integration solutions before upgrading to Gateway 22.1.0 or later.