Zum Inhalt springen

Cloudflare One Updates & Release Notes

319 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge Cloudflare One, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

DEX unterstützt EU Customer Metadata Boundary

Alle DEX-Logs sind nun mit der Customer Metadata Boundary (CMB) für die EU kompatibel, sodass sie bei aktivierter Option nicht außerhalb der EU gespeichert werden, im Dashboard dann aber nicht angezeigt werden und per LogPush exportiert werden müssen.

Digital Experience Monitoring (DEX) provides visibility into WARP device connectivity and performance to any internal or external application.

Now, all DEX logs are fully compatible with Cloudflare's Customer Metadata Boundary (CMB) setting for the 'EU' (European Union), which ensures that DEX logs will not be stored outside the 'EU' when the option is configured.

If a Cloudflare One customer using DEX enables CMB 'EU', they will not see any DEX data in the Cloudflare One dashboard. Customers can ingest DEX data via LogPush, and build their own analytics and dashboards.

If a customer enables CMB in their account, they will see the following message in the Digital Experience dashboard: "DEX data is unavailable because Customer Metadata Boundary configuration is on. Use Cloudflare LogPush to export DEX datasets."

Digital Experience Monitoring message when Customer Metadata Boundary for the EU is enabled

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Access: Vereinfachte Clientless-Browser-Isolation für private Apps

Die neue Einstellung „Allow clientless access“ erleichtert den clientlosen Zugriff auf interne Anwendungen ohne öffentliches DNS, sodass dafür kein separates Bookmark mit präfixierter Clientless-Web-Isolation-URL mehr nötig ist.

A new Allow clientless access setting makes it easier to connect users without a device client to internal applications, without using public DNS.

Allow clientless access setting in the Cloudflare One dashboard

Previously, to provide clientless access to a private hostname or IP without a published application, you had to create a separate bookmark application pointing to a prefixed Clientless Web Isolation URL (for example, https://<your-teamname>.cloudflareaccess.com/browser/https://10.0.0.1/). This bookmark was visible to all users in the App Launcher, regardless of whether they had access to the underlying application. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Access: Richtlinien für Bookmark-Anwendungen

Für Bookmark-Anwendungen lassen sich nun Access-Richtlinien zuweisen, damit Nutzer im App Launcher nur Bookmarks sehen, auf die sie laut Identität, Geräte-Posture und anderen Regeln Zugriff haben; ohne Richtlinie bleibt das Bookmark für alle sichtbar.

You can now assign Access policies to bookmark applications. This lets you control which users see a bookmark in the App Launcher based on identity, device posture, and other policy rules.

Previously, bookmark applications were visible to all users in your organization. With policy support, you can now:

  • Tailor the App Launcher to each user — Users only see the applications they have access to, reducing clutter and preventing accidental clicks on irrelevant resources.
  • Restrict visibility of sensitive bookmarks — Limit who can view bookmarks to internal tools or partner resources based on group membership, identity provider, or device posture.

Bookmarks support all Access policy configurations except purpose justification, temporary authentication, and application isolation. If no policy is assigned, the bookmark remains visible to all users (maintaining backwards compatibility).

For more information, refer to Add bookmarks.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Umbenennung von Cloudflare-One-Netzwerkprodukten

Cloudflare benennt mehrere Netzwerkprodukte um, etwa Magic WAN in Cloudflare WAN, Magic Firewall in Cloudflare Network Firewall und Magic Network Monitoring in Network Flow, wobei Funktionen, Konfigurationen und Abrechnung unverändert bleiben.

We are updating naming related to some of our Networking products to better clarify their place in the Zero Trust and Secure Access Service Edge (SASE) journey.

We are retiring some older brand names in favor of names that describe exactly what the products do within your network. We are doing this to help customers build better, clearer mental models for comprehensive SASE architecture delivered on Cloudflare.

What's changing

  • Magic WAN → Cloudflare WAN
  • Magic WAN IPsec → Cloudflare IPsec
  • Magic WAN GRE → Cloudflare GRE
  • Magic WAN Connector → Cloudflare One Appliance
  • Magic Firewall → Cloudflare Network Firewall
  • Magic Network Monitoring → Network Flow
  • Magic Cloud Networking → Cloudflare One Multi-cloud Networking

No action is required by you — all functionality, existing configurations, and billing will remain exactly the same.

For more information, visit the Cloudflare One documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Feingranulare Berechtigungen für Access-Richtlinien und Service Tokens

Zwei neue ressourcenbezogene Rollen, Cloudflare Access policy admin und Cloudflare Access service token admin, erlauben es, Berechtigungen für einzelne Access-Richtlinien bzw. Service Tokens zu vergeben; die Funktion ist als Beta verfügbar.

Fine-grained permissions for Access policies and Access service tokens are available. These new resource-scoped roles expand the existing RBAC model, enabling administrators to grant permissions scoped to individual resources.

New roles

  • Cloudflare Access policy admin: Can edit a specific Access policy in an account.
  • Cloudflare Access service token admin: Can edit a specific Access service token in an account.

These roles complement the existing resource-scoped roles for Access applications, identity providers, and infrastructure targets.

For more information:

Note

Resource-scoped roles is currently in beta.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare WAN zeigt Anycast-IPs im Dashboard an

Cloudflare WAN zeigt beim Konfigurieren von IPsec- oder GRE-Tunneln die Anycast-IP-Adressen nun direkt im Dashboard an, sodass sie nicht mehr per API-Aufruf abgerufen werden müssen.

Cloudflare WAN now displays your Anycast IP addresses directly in the dashboard when you configure IPsec or GRE tunnels.

Previously, customers received their Anycast IPs during onboarding or had to retrieve them with an API call. The dashboard now pre-loads these addresses, reducing setup friction and preventing configuration errors.

No action is required. All Cloudflare WAN customers can see their Anycast IPs in the tunnel configuration form automatically.

For more information, refer to Configure tunnel endpoints.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Post-Quantum-Verschlüsselung für Cloudflare One Appliance

Cloudflare One Appliance 2026.2.0 unterstützt Post-Quantum-Verschlüsselung mit hybridem ML-KEM über TLS 1.3 und schützt IPsec-Datenverkehr damit gegen Harvest-now-decrypt-later-Angriffe, wobei das Update automatisch in den konfigurierten Wartungsfenstern eingespielt wird.

Cloudflare One Appliance version 2026.2.0 adds post-quantum encryption support using hybrid ML-KEM (Module-Lattice-Based Key-Encapsulation Mechanism).

The appliance now uses TLS 1.3 with hybrid ML-KEM for its connection to the Cloudflare edge. During the TLS handshake, the appliance and the edge share a symmetric secret over the TLS connection and inject it into the ESP layer of IPsec. This protects IPsec data plane traffic against harvest-now, decrypt-later attacks.

This upgrade deploys automatically to all appliances during their configured interrupt windows with no manual action required.

For more information, refer to Cloudflare One Appliance.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Email security: Verbesserte Monitoring-Seite mit Suche

Die Monitoring-Seite der Email Security bietet nun Stacked-Bar-Charts, bessere Kontraste, Suche in mehreren Widgets, klarere Statusanzeigen sowie neue Detailansichten etwa zu Dispositions pro Monat und Impersonations für alle Pakete.

We have updated the Monitoring page to provide a more streamlined and insightful experience for administrators, improving both data visualization and dashboard accessibility.

  • Enhanced Visual Layout: Optimized contrast and the introduction of stacked bar charts for clearer data visualization and trend analysis. visual-example
  • Improved Accessibility & Usability:
    • Widget Search: Added search functionality to multiple widgets, including Policies, Submitters, and Impersonation.
    • Actionable UI: All available actions are now accessible via dedicated buttons.
    • State Indicators: Improved UI states to clearly communicate loading, empty datasets, and error conditions. buttons-example
  • Granular Data Breakdowns: New views for dispositions by month, malicious email details, link actions, and impersonations. monthly-example

This applies to all Email Security packages:

  • Advantage
  • Enterprise
  • Enterprise + PhishGuard

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

BGP über GRE- und IPsec-Tunnel (Beta)

Magic-WAN- und Magic-Transit-Kunden können im Dashboard BGP-Peering über IPsec- und GRE-Tunnel-On-Ramps (Beta) einrichten, um eBGP-Sitzungen mit MD5-Authentifizierung aufzubauen und Routen dynamisch mit der Magic-Routingtabelle auszutauschen.

Magic WAN and Magic Transit customers can use the Cloudflare dashboard to configure and manage BGP peering between their networks and their Magic routing table when using IPsec and GRE tunnel on-ramps (beta).

Using BGP peering allows customers to:

  • Automate the process of adding or removing networks and subnets.
  • Take advantage of failure detection and session recovery features.

With this functionality, customers can:

  • Establish an eBGP session between their devices and the Magic WAN / Magic Transit service when connected via IPsec and GRE tunnel on-ramps.
  • Secure the session by MD5 authentication to prevent misconfigurations.
  • Exchange routes dynamically between their devices and their Magic routing table.

For configuration details, refer to:

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

WARP-Client für Windows 2026.1.89.1 (Beta)

Die Beta-Version 2026.1.89.1 des WARP-Clients für Windows verbessert den Multi-User-Modus, deaktiviert NetBIOS over TCP/IP standardmäßig (in Geräteprofilen aktivierbar) und behebt einen Fehler bei der lokalen Netzwerkausnahme mit Timeout 0.

A new Beta release for the Windows WARP client is now available on the beta releases downloads page.

This release contains minor fixes, improvements, and new features.

Changes and improvements

  • Improvements to multi-user mode. Fixed an issue where when switching from a pre-login registration to a user registration, Mobile Device Management (MDM) configuration association could be lost.
  • Added a new feature to manage NetBIOS over TCP/IP functionality on the Windows client. NetBIOS over TCP/IP on the Windows client is now disabled by default and can be enabled in device profile settings.
  • Fixed an issue causing failure of the local network exclusion feature when configured with a timeout of 0. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

WARP-Client für macOS 2026.1.89.1 (Beta)

Die Beta-Version 2026.1.89.1 des WARP-Clients für macOS behebt einen Fehler bei der lokalen Netzwerkausnahme mit Timeout 0 und meldet Geräte-Colocation-Informationen im Dashboard genauer.

A new Beta release for the macOS WARP client is now available on the beta releases downloads page.

This release contains minor fixes and improvements.

Changes and improvements

  • Fixed an issue causing failure of the local network exclusion feature when configured with a timeout of 0.
  • Improvement for more accurate reporting of device colocation information in the Cloudflare One dashboard.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare Source IPs konfigurieren (Beta)

Im Unified Routing Mode (Beta) stammt Cloudflare-Datenverkehr zu privaten Netzwerken aus einem dedizierten privaten IPv4-Bereich (standardmäßig 100.64.0.0/12, als beliebiges /12-CIDR konfigurierbar) statt aus öffentlichen IPs, was die Berechtigung „Cloudflare One Networks Write“ erfordert.

Cloudflare source IPs are the IP addresses used by Cloudflare services (such as Load Balancing, Gateway, and Browser Isolation) when sending traffic to your private networks.

For customers using legacy mode routing, traffic to private networks is sourced from public Cloudflare IPs, which may cause IP conflicts. For customers using Unified Routing mode (beta), traffic to private networks is sourced from dedicated, non-Internet-routable private IPv4 range to ensure:

  • Symmetric routing over private network connections
  • Proper firewall state preservation
  • Private traffic stays on secure paths

Key details:

  • IPv4: Sourced from 100.64.0.0/12 by default, configurable to any /12 CIDR
  • IPv6: Sourced from 2606:4700:cf1:5000::/64 (not configurable)
  • Affected connectors: GRE, IPsec, CNI, WARP Connector, and WARP Client (Cloudflare Tunnel is not affected)

Configuring Cloudflare source IPs requires Unified Routing (beta) and the Cloudflare One Networks Write permission.

For configuration details, refer to Configure Cloudflare source IPs.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Access-Schutz für alle Zonen erzwingen

Man kann nun festlegen, dass Datenverkehr zu allen Hostnamen im Account blockiert wird, sofern keine passende Access-Anwendung existiert, wobei einzelne Hostnamen ausgenommen werden können.

You can now require Cloudflare Access protection for all hostnames in your account. When enabled, traffic to any hostname that does not have a matching Access application is automatically blocked.

This deny-by-default approach prevents accidental exposure of internal resources to the public Internet. If a developer deploys a new application or creates a DNS record without configuring an Access application, the traffic is blocked rather than exposed.

Require Cloudflare Access protection in the dashboard

How it works

  • Blocked by default: Traffic to all hostnames in the account is blocked unless an Access application exists for that hostname.
  • Explicit access required: To allow traffic, create an Access application with an Allow or Bypass policy.
  • Hostname exemptions: You can exempt specific hostnames from this requirement.

To turn on this feature, refer to Require Access protection.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Neue granulare API-Token-Berechtigungen für Access

Drei neue API-Token-Berechtigungen für Cloudflare Access (Organizations Revoke, Population Read und Population Write) ermöglichen feinere Kontrolle beim Widerrufen von Sitzungen sowie beim Lesen und Schreiben synchronisierter SCIM-Nutzer und -Gruppen.

Three new API token permissions are available for Cloudflare Access, giving you finer-grained control when building automations and integrations:

  • Access: Organizations Revoke — Grants the ability to revoke user sessions in a Zero Trust organization. Use this permission when you need a token that can terminate active sessions without broader write access to organization settings.
  • Access: Population Read — Grants read access to the SCIM users and groups synced from an identity provider to Cloudflare Access. Use this permission for tokens that only need to read synced user and group data.
  • Access: Population Write — Grants write access to the SCIM users and groups synced from an identity provider to Cloudflare Access. Use this permission for tokens that need to create or modify synced user and group data.

These permissions are scoped at the account level and can be combined with existing Access permissions.

For a full list of available permissions, refer to API token permissions.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Neue Navigation für Network Services im Dashboard

Das Menü „Network Services“ ist nach Lösungen statt Produktnamen gegliedert, mit neuer Overview-Seite, Konfiguration unter Routes und Connectors sowie Analysen unter Insights, während Konfigurationen und Funktionen unverändert bleiben.

The Network Services menu structure in Cloudflare's dashboard has been updated to reflect solutions and capabilities instead of product names. This will make it easier for you to find what you need and better reflects how our services work together.

Your existing configurations will remain the same, and you will have access to all of the same features and functionality.

The changes visible in your dashboard may vary based on the products you use. Overall, changes relate to Magic Transit ↗︎, Magic WAN ↗︎, and Magic Firewall ↗︎.

Summary of changes:

  • A new Overview page provides access to the most common tasks across Magic Transit and Magic WAN.
  • Product names have been removed from top-level navigation.
  • Magic Transit and Magic WAN configuration is now organized under Routes and Connectors. For example, you will find IP Prefixes under Routes, and your GRE/IPsec Tunnels under Connectors.
  • Magic Firewall policies are now called Firewall Policies.
  • Magic WAN Connectors and Connector On-Ramps are now referenced in the dashboard as Appliances and Appliance profiles. They can be found under Connectors > Appliances.
  • Network analytics, network health, and real-time analytics are now available under Insights. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

CrowdStrike-Gerätescores im User Risk Scoring

Das User Risk Scoring bietet für Organisationen mit CrowdStrike-Integration zwei neue Verhaltensweisen, die den Risikoscore eines Nutzers automatisch erhöhen, wenn das Gerät von CrowdStrike einen niedrigen oder mittleren ZTA-Score meldet.

Cloudflare One has expanded its [User Risk Scoring] (/cloudflare-one/insights/risk-score/) capabilities by introducing two new behaviors for organizations using the [CrowdStrike integration] (/cloudflare-one/integrations/service-providers/crowdstrike/).

Administrators can now automatically escalate the risk score of a user if their device matches specific CrowdStrike Zero Trust Assessment (ZTA) score ranges. This allows for more granular security policies that respond dynamically to the health of the endpoint.

New risk behaviors The following risk scoring behaviors are now available:

  • CrowdStrike low device score: Automatically increases a user's risk score when the connected device reports a "Low" score from CrowdStrike.
  • CrowdStrike medium device score: Automatically increases a user's risk score when the connected device reports a "Medium" score from CrowdStrike.

These scores are derived from [CrowdStrike device posture attributes] (/cloudflare-one/integrations/service-providers/crowdstrike/#device-posture-attributes), including OS signals and sensor configurations.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

WARP Connector per Ping auf LAN-IP prüfen

Ab Version 2025.10.186.0 antwortet der WARP Connector auf Datenverkehr an seine eigene LAN-IP, sodass sich die Erreichbarkeit direkt nach der Installation per ping prüfen lässt.

We have made it easier to validate connectivity when deploying WARP Connector as part of your software-defined private network.

You can now ping the WARP Connector host directly on its LAN IP address immediately after installation. This provides a fast, familiar way to confirm that the Connector is online and reachable within your network before testing access to downstream services.

Starting with version 2025.10.186.0, WARP Connector responds to traffic addressed to its own LAN IP, giving you immediate visibility into Connector reachability.

Learn more about deploying WARP Connector and building private network connectivity with Cloudflare One.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

WARP-Client für Windows 2025.10.186.0 (GA)

Die GA-Version 2025.10.186.0 des WARP-Clients für Windows bringt unter anderem die Steuerung der WARP-Konnektivität aller Geräte per externem Signal (Emergency Disconnect) und einen neuen Device-Posture-Check für Antivirus.

A new GA release for the Windows WARP client is now available on the stable releases downloads page.

This release contains minor fixes, improvements, and new features. New features include the ability to manage WARP client connectivity for all devices in your fleet using an external signal, and a new WARP client device posture check for Antivirus.

Changes and improvements

  • Added a new feature to manage WARP client connectivity for all devices using an external signal. This feature allows administrators to send a global signal from an on-premises HTTPS endpoint that force disconnects or reconnects all WARP clients in an account based on configuration set on the endpoint. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

WARP client für macOS 2025.10.186.0 (GA)

Der macOS WARP client 2025.10.186.0 ist als GA-Release verfügbar, ermöglicht die Steuerung der WARP-Verbindung aller Geräte per externem Signal, behebt Local Domain Fallback ohne konfigurierten Fallback-Server und unterstützt im Proxy mode nun transparentes HTTP-Proxying.

A new GA release for the macOS WARP client is now available on the stable releases downloads page.

This release contains minor fixes, improvements, and new features, including the ability to manage WARP client connectivity for all devices in your fleet using an external signal.

Changes and improvements

  • The Local Domain Fallback feature has been fixed for devices running WARP client version 2025.4.929.0 and newer. Previously, these devices could experience failures with Local Domain Fallback unless a fallback server was explicitly configured. This configuration is no longer a requirement for the feature to function correctly.
  • Proxy mode now supports transparent HTTP proxying in addition to CONNECT-based proxying. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

WARP client für Linux 2025.10.186.0 (GA)

Der Linux WARP client 2025.10.186.0 ist als GA-Release verfügbar, erlaubt die Steuerung der WARP-Verbindung per externem Signal und behebt Local Domain Fallback ohne konfigurierten Fallback-Server; zudem muss der öffentliche Schlüssel für Linux-Pakete, falls vor dem 12. September 2025 installiert, aktualisiert werden.

A new GA release for the Linux WARP client is now available on the stable releases downloads page.

This release contains minor fixes, improvements, and new features, including the ability to manage WARP client connectivity for all devices in your fleet using an external signal.

WARP client version 2025.8.779.0 introduced an updated public key for Linux packages. The public key must be updated if it was installed before September 12, 2025 to ensure the repository remains functional after December 4, 2025. Instructions to make this update are available at pkg.cloudflareclient.com.

Changes and improvements

  • The Local Domain Fallback feature has been fixed for devices running WARP client version 2025.4.929.0 and newer. Previously, these devices could experience failures with Local Domain Fallback unless a fallback server was explicitly configured. This configuration is no longer a requirement for the feature to function correctly. …

Originalquelle(öffnet in neuem Tab)Problem melden