Zum Inhalt springen

Cloudflare One Updates & Release Notes

319 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge Cloudflare One, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

DNS-Filterung für private Netzwerk-Onramps mit Gateway

Magic-WAN- und WARP-Connector-Nutzer können DNS-Verkehr nun über die gemeinsamen Resolver-IPs 172.64.36.1 und 172.64.36.2 sicher zum Gateway-Resolver leiten, ohne das öffentliche Internet zu nutzen, und dabei Source Internal IP in Resolver-Richtlinien verwenden.

Magic WAN and WARP Connector users can now securely route their DNS traffic to the Gateway resolver without exposing traffic to the public Internet.

Routing DNS traffic to the Gateway resolver allows DNS resolution and filtering for traffic coming from private networks while preserving source internal IP visibility. This ensures Magic WAN users have full integration with our Cloudflare One features, including Internal DNS and hostname-based policies.

To configure DNS filtering, change your Magic WAN or WARP Connector DNS settings to use Cloudflare's shared resolver IPs, 172.64.36.1 and 172.64.36.2. Once you configure DNS resolution and filtering, you can use Source Internal IP as a traffic selector in your resolver policies for routing private DNS traffic to your Internal DNS.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare WAN: Benutzerdefinierte IKE ID für IPsec-Tunnel

Magic-WAN-Kunden können für IPsec-Tunnel nun per API eine benutzerdefinierte IKE ID festlegen, was zusammen mit VeloCloud-SD-WAN-Geräten eine Hochverfügbarkeitskonfiguration ermöglicht.

Now, Magic WAN customers can configure a custom IKE ID for their IPsec tunnels. Customers that are using Magic WAN and a VeloCloud SD-WAN device together can utilize this new feature to create a high availability configuration.

This feature is available via API only. Customers can read the Magic WAN documentation to learn more about the Custom IKE ID feature and the API call to configure it.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Bidirektionale Tunnel-Health-Checks funktionieren mit allen Magic On-Ramps

Bei einer Hochverfügbarkeitskonfiguration besteht ein bidirektionaler Health Check nun, wenn das Antwortpaket über einen beliebigen Tunnel zurückkommt und nicht mehr nur über denselben Tunnel wie das Hinpaket.

All bidirectional tunnel health check return packets are accepted by any Magic on-ramp.

Previously, when a Magic tunnel had a bidirectional health check configured, the bidirectional health check would pass when the return packets came back to Cloudflare over the same tunnel that was traversed by the forward packets.

There are SD-WAN devices, like VeloCloud, that do not offer controls to steer traffic over one tunnel versus another in a high availability tunnel configuration.

Now, when a Magic tunnel has a bidirectional health check configured, the bidirectional health check will pass when the return packet traverses over any tunnel in a high availability configuration.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Tunnel- und Networks-API liefert ab 1. Dezember 2025 keine gelöschten Ressourcen mehr

Ab dem 1. Dezember 2025 geben die List-Endpunkte der Cloudflare Tunnel API und der Zero Trust Networks API standardmäßig keine gelöschten Tunnel, Routen, Subnetze und virtuellen Netzwerke mehr zurück, und wer is_deleted=false bereits setzt, muss nichts tun.

Starting December 1, 2025, list endpoints for the Cloudflare Tunnel API and Zero Trust Networks API will no longer return deleted tunnels, routes, subnets and virtual networks by default. This change makes the API behavior more intuitive by only returning active resources unless otherwise specified.

No action is required if you already explicitly set is_deleted=false or if you only need to list active resources.

This change affects the following API endpoints:

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Überarbeitete Email-security-Rollen

Die Email-security-Rollen wurden granularer gefasst und haben keinen Lese- oder Schreibzugriff mehr auf andere Zero-Trust-Produkte, sodass für DLP oder RBI nun die Rolle Cloudflare Zero Trust nötig ist.

To provide more granular controls, we refined the existing roles for Email security and launched a new Email security role as well.

All Email security roles no longer have read or write access to any of the other Zero Trust products:

  • Email Configuration Admin
  • Email Integration Admin
  • Email security Read Only
  • Email security Analyst
  • Email security Policy Admin
  • Email security Reporting

To configure Data Loss Prevention (DLP) or Remote Browser Isolation (RBI), you now need to be an admin for the Zero Trust dashboard with the Cloudflare Zero Trust role. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

WARP Diagnostic AI Analyzer in der Beta für alle Nutzer

Der neue KI-basierte WARP diagnostic analyzer steht als Beta im Cloudflare One Dashboard bereit und wertet WARP-Diagnoseprotokolle aus, um Auswirkungen, auffällige Ereignisse und empfohlene Schritte zur Behebung von Verbindungsproblemen zu nennen.

We're excited to share a new AI feature, the WARP diagnostic analyzer ↗︎, to help you troubleshoot and resolve WARP connectivity issues faster. This beta feature is now available in the Cloudflare One dashboard ↗︎ to all users. The AI analyzer makes it easier for you to identify the root cause of client connectivity issues by parsing remote captures of WARP diagnostic logs. The WARP diagnostic analyzer provides a summary of impact that may be experienced on the device, lists notable events that may contribute to performance issues, and recommended troubleshooting steps and articles to help you resolve these issues. Refer to WARP diagnostics analyzer (beta) to learn more about how to maximize using the WARP diagnostic analyzer to troubleshoot the WARP client.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

DEX MCP Server für Digital Experience Monitoring

Für DEX gibt es einen MCP-Server, mit dem Kunden per Frage Konnektivitäts- und Leistungsdaten aus der DEX API abrufen können und der für Free-, Pay-as-you-go- und Enterprise-Konten verfügbar ist.

Digital Experience Monitoring (DEX) provides visibility into device connectivity and performance across your Cloudflare SASE deployment.

We've released an MCP server (Model Context Protocol) ↗︎ for DEX.

The DEX MCP server is an AI tool that allows customers to ask a question like, "Show me the connectivity and performance metrics for the device used by carly‌@acme.com", and receive an answer that contains data from the DEX API.

Any Cloudflare One customer using a Free, Pay-as-you-go, or Enterprise account can access the DEX MCP Server. This feature is available to everyone.

Customers can test the new DEX MCP server in less than one minute. To learn more, read the DEX MCP server documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Shadow IT: Neues SaaS-Analytics-Dashboard

Das überarbeitete Shadow-IT-Dashboard zeigt, wer welche SaaS-Anwendungen nutzt und wie viele Daten übertragen werden, und erlaubt Freigabestatus wie Unreviewed, In Review, Approved und Unapproved, die auch in Gateway-HTTP-Richtlinien verwendet werden können.

Zero Trust has significantly upgraded its Shadow IT analytics, providing you with unprecedented visibility into your organizations use of SaaS tools. With this dashboard, you can review who is using an application and volumes of data transfer to the application.

You can review these metrics against application type, such as Artificial Intelligence or Social Media. You can also mark applications with an approval status, including Unreviewed, In Review, Approved, and Unapproved designating how they can be used in your organization.

Cloudflare One Analytics Dashboards

These application statuses can also be used in Gateway HTTP policies, so you can block, isolate, limit uploads and downloads, and more based on the application status.

Both the analytics and policies are accessible in the Cloudflare Zero Trust dashboard ↗︎, empowering organizations with better visibility and control.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

CASB: Neue Integrationen für ChatGPT, Claude und Gemini

Cloudflare CASB unterstützt nun per API und ohne Agenten die Plattformen OpenAI ChatGPT, Anthropic Claude und Google Gemini mit Posture Management, DLP-Erkennung in Anhängen und GenAI-spezifischen Einblicken.

Cloudflare CASB ↗︎ now supports three of the most widely used GenAI platforms — OpenAI ChatGPT, Anthropic Claude, and Google Gemini. These API-based integrations give security teams agentless visibility into posture, data, and compliance risks across their organization’s use of generative AI.

Cloudflare CASB showing selection of new findings for ChatGPT, Claude, and Gemini integrations.

Key capabilities

  • Agentless connections — connect ChatGPT, Claude, and Gemini tenants via API; no endpoint software required
  • Posture management — detect insecure settings and misconfigurations that could lead to data exposure
  • DLP detection — identify sensitive data in uploaded chat attachments or files
  • GenAI-specific insights — surface risks unique to each provider’s capabilities

Learn more

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Zugriff auf interne MCP-Server mit Cloudflare Access steuern

Self-hosted Applications in Cloudflare Access unterstützen nun OAuth für die MCP-Server-Authentifizierung, sodass der Zugriff auf interne MCP-Server per Access-Richtlinien beschränkt werden kann, auch in Verbindung mit MCP server portals.

You can now control who within your organization has access to internal MCP servers, by putting internal MCP servers behind Cloudflare Access.

Self-hosted applications in Cloudflare Access now support OAuth for MCP server authentication. This allows Cloudflare to delegate access from any self-hosted application to an MCP server via OAuth. The OAuth access token authorizes the MCP server to make requests to your self-hosted applications on behalf of the authorized user, using that user's specific permissions and scopes.

For example, if you have an MCP server designed for internal use within your organization, you can configure Access policies to ensure that only authorized users can access it, regardless of which MCP client they use. Support for internal, self-hosted MCP servers also works with MCP server portals, allowing you to provide a single MCP endpoint for multiple MCP servers. For more on MCP server portals, read the blog post ↗︎ on the Cloudflare Blog.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Access: MCP server portals in offener Beta

MCP server portals bündeln mehrere MCP-Server hinter einem HTTP-Endpunkt, erlauben pro Portal ausgewählte Tools und Prompt-Vorlagen und protokollieren Anfragen über Cloudflare Access, derzeit als offene Beta für alle Pläne.

MCP server portal

An MCP server portal centralizes multiple Model Context Protocol (MCP) servers onto a single HTTP endpoint. Key benefits include:

  • Streamlined access to multiple MCP servers: MCP server portals support both unauthenticated MCP servers as well as MCP servers secured using any third-party or custom OAuth provider. Users log in to the portal URL through Cloudflare Access and are prompted to authenticate separately to each server that requires OAuth.
  • Customized tools per portal: Admins can tailor an MCP portal to a particular use case by choosing the specific tools and prompt templates that they want to make available to users through the portal. This allows users to access a curated set of tools and prompts — the less external context exposed to the AI model, the better the AI responses tend to be.
  • Observability: Once the user's AI agent is connected to the portal, Cloudflare Access logs the individual requests made using the tools in the portal.

This is available in an open beta for all customers across all plans! For more information check out our blog ↗︎ for this release.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

DLP: Themenbasierte Erkennung für den Schutz von KI-Prompts

DLP erkennt und analysiert Prompts an Google Gemini, ChatGPT, Claude und Perplexity, klassifiziert sie nach Inhalts- und Absichtsthemen und bietet fünf neue vordefinierte Profile.

You now have access to a comprehensive suite of capabilities to secure your organization's use of generative AI. AI prompt protection introduces four key features that work together to provide deep visibility and granular control.

  1. Prompt Detection for AI Applications

DLP can now natively detect and inspect user prompts submitted to popular AI applications, including Google Gemini, ChatGPT, Claude, and Perplexity.

  1. Prompt Analysis and Topic Classification

Our DLP engine performs deep analysis on each prompt, applying topic classification. These topics are grouped into two evaluation categories:

  • Content: PII, Source Code, Credentials and Secrets, Financial Information, and Customer Data.

  • Intent: Jailbreak attempts, requests for malicious code, or attempts to extract PII.

To help you apply these topics quickly, we have also released five new predefined profiles (for example, AI Prompt: AI Security, AI Prompt: PII) that bundle these new topics.

DLP

  1. Granular Guardrails …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Gateway: BYOIP für dedizierte Egress-IPs verfügbar

Enterprise-Gateway-Nutzer können eigene IPv4- oder IPv6-Präfixe per BYOIP als dedizierte Egress-IPs einbinden und in Egress-Richtlinien auswählen.

Enterprise Gateway users can now use Bring Your Own IP (BYOIP) for dedicated egress IPs.

Admins can now onboard and use their own IPv4 or IPv6 prefixes to egress traffic from Cloudflare, delivering greater control, flexibility, and compliance for network traffic.

Get started by following the BYOIP onboarding process. Once your IPs are onboarded, go to Gateway > Egress policies and select or create an egress policy. In Select an egress IP, choose Use dedicated egress IPs (Cloudflare or BYOIP), then select your BYOIP address from the dropdown menu.

Screenshot of a dropdown menu adding a BYOIP IPv4 address as a dedicated egress IP in a Gateway egress policy

For more information, refer to BYOIP for dedicated egress IPs.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare Access Logging unterstützt die Customer Metadata Boundary

Access-Logs berücksichtigen nun eine konfigurierte Customer Metadata Boundary, wobei sie für EU-CMB-Kunden nicht von Access gespeichert werden und im Dashboard leer erscheinen, sodass diese Logpush zur Aufbewahrung nutzen sollten.

Cloudflare Access logs now support the Customer Metadata Boundary (CMB). If you have configured the CMB for your account, all Access logging will respect that configuration.

Note

For EU CMB customers, the logs will not be stored by Access and will appear as empty in the dashboard. EU CMB customers should utilize Logpush to retain their Access logging, if desired.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Email security: Erweiterte Email Link Isolation

Bei MX- oder Inline-Bereitstellung lässt sich Email Link Isolation nun auf alle Links einer bestimmten Disposition anwenden, verfügbar in den Paketen Enterprise und Enterprise + PhishGuard.

When you deploy MX or Inline, not only can you apply email link isolation to suspicious links in all emails (including benign), you can now also apply email link isolation to all links of a specified disposition. This provides more flexibility in controlling user actions within emails.

For example, you may want to deliver suspicious messages but isolate the links found within them so that users who choose to interact with the links will not accidentally expose your organization to threats. This means your end users are more secure than ever before.

Expanded Email Link Isolation Configuration

To isolate all links within a message based on the disposition, select Settings > Link Actions > View and select Configure. As with other other links you isolate, an interstitial will be provided to warn users that this site has been isolated and the link will be recrawled live to evaluate if there are any changes in our threat intel. Learn more about this feature on Configure link actions ↗︎.

This feature is available across these Email security packages:

  • Enterprise
  • Enterprise + PhishGuard

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare WAN: Terraform-V5-Unterstützung für Tunnel und Routen

Die Terraform-Provider-Ressourcen für Cloudflare WAN Tunnel und Routen unterstützen nun Terraform Provider Version 5.

The Cloudflare Terraform provider resources for Cloudflare WAN tunnels and routes now support Terraform provider version 5. Customers using infrastructure-as-code workflows can manage their tunnel and route configuration with the latest provider version.

For more information, refer to the Cloudflare Terraform provider documentation ↗︎.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Magic Transit und Magic WAN: Health-Check-Daten mit CMB EU kompatibel

Kunden mit aktiviertem CMB EU können nun GRE-, IPsec- und CNI-Health-Check- sowie Traffic-Volumen-Daten im Dashboard und per API abrufen, da die GraphQL-Endpunkte magicTransitTunnelHealthChecksAdaptiveGroups und magicTransitTunnelTrafficAdaptiveGroups kompatibel sind.

Today, we are excited to announce that all Magic Transit and Magic WAN customers with CMB EU (Customer Metadata Boundary - Europe) enabled in their account will be able to access GRE, IPsec, and CNI health check and traffic volume data in the Cloudflare dashboard and via API.

This ensures that all Magic Transit and Magic WAN customers with CMB EU enabled will be able to access all Magic Transit and Magic WAN features.

Specifically, these two GraphQL endpoints are now compatible with CMB EU:

  • magicTransitTunnelHealthChecksAdaptiveGroups
  • magicTransitTunnelTrafficAdaptiveGroups

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Gateway: Neue Kategorie „Scam“ unter Security Threats

Unter den Security Threats gibt es die neue Kategorie Scam (ID 191) für betrügerische Websites und Maschen, mit der entsprechende Domains markiert werden.

We have introduced a new Security Threat category called Scam. Relevant domains are marked with the Scam category. Scam typically refers to fraudulent websites and schemes designed to trick victims into giving away money or personal information.

New category added

Parent ID

Parent Name

Category ID

Category Name

21

Security Threats

191

Scam

Refer to Gateway domain categories to learn more.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Gateway: HTTP-Filterung auf allen Ports in offener Beta

Gateway kann HTTP-Filterung nun auf alle proxied HTTP-Anfragen und nicht nur auf die Ports 80 und 443 anwenden, aktivierbar über Settings > Network > Firewall mit „Inspect on all ports“.

Gateway can now apply HTTP filtering to all proxied HTTP requests, not just traffic on standard HTTP (80) and HTTPS (443) ports. This means all requests can now be filtered by A/V scanning, file sandboxing, Data Loss Prevention (DLP), and more.

You can turn this setting on by going to Settings > Network > Firewall and choosing Inspect on all ports.

HTTP Inspection on all ports setting

To learn more, refer to Inspect on all ports (Beta).

Originalquelle(öffnet in neuem Tab)Problem melden