Zum Inhalt springen

Cloudflare One Updates & Release Notes

319 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge Cloudflare One, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Email security: Logpush für Erkennungslogs

Erkennungslogs von Email security lassen sich nun mit Cloudflare Logpush an einen frei wählbaren Endpunkt senden, wobei gefiltert und aus über 25 Feldern ausgewählt werden kann (Enterprise und Enterprise + PhishGuard).

You can now send detection logs to an endpoint of your choice with Cloudflare Logpush.

Filter logs matching specific criteria you have set and select from over 25 fields you want to send. When creating a new Logpush job, remember to select Email security alerts as the dataset.

logpush-detections

For more information, refer to Enable detection logs.

This feature is available across these Email security packages:

  • Enterprise
  • Enterprise + PhishGuard

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Email security: Status von Email security und Area 1 prüfen

Der Betriebsstatus von Email security und Area 1 kann nun auf der Cloudflare Status page unter „Cloudflare Sites and Services“ eingesehen werden.

Concerns about performance for Email security or Area 1? You can now check the operational status of both on the Cloudflare Status page ↗︎.

For Email security, look under Cloudflare Sites and Services.

  • Dashboard is the dashboard for Cloudflare, including Email security
  • Email security (Zero Trust) is the processing of email
  • API are the Cloudflare endpoints, including the ones for Email security

For Area 1, under Cloudflare Sites and Services:

  • Area 1 - Dash is the dashboard for Cloudflare, including Email security
  • Email security (Area1) is the processing of email
  • Area 1 - API are the Area 1 endpoints

Status-page

This feature is available across these Email security packages:

  • Advantage
  • Enterprise
  • Enterprise + PhishGuard

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Email security: DLP Assist für M365

Kunden von Cloudflare Email security mit Microsoft-365-Umgebung können kostenlos eine Email-DLP-Lösung einsetzen, indem sie das Add-in installieren, eine DLP-Richtlinie anlegen und Outlook so konfigurieren, dass Banner, Warnungen vor dem Senden oder eine Zustellungsblockade ausgelöst werden.

Cloudflare Email security customers who have Microsoft 365 environments can quickly deploy an Email DLP (Data Loss Prevention) solution for free.

Simply deploy our add-in, create a DLP policy in Cloudflare, and configure Outlook to trigger behaviors like displaying a banner, alerting end users before sending, or preventing delivery entirely.

Refer to Outbound Data Loss Prevention to learn more about this feature.

In GUI alert:

DLP-Alert

Alert before sending:

DLP-Pop-up

Prevent delivery:

DLP-Blocked

This feature is available across these Email security packages:

  • Enterprise
  • Enterprise + PhishGuard

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Magic WAN Connector: Konfiguration per statischer IP

Der Magic WAN Connector lässt sich nun lokal mit statischer IP-Konfiguration einrichten, ohne dass eine DHCP-Internetverbindung nötig ist, wofür Zugriff auf den seriellen Port und ein serielles Terminalprogramm erforderlich sind.

You can now locally configure your Magic WAN Connector to work in a static IP configuration.

This local method does not require having access to a DHCP Internet connection. However, it does require being comfortable with using tools to access the serial port on Magic WAN Connector as well as using a serial terminal client to access the Connector's environment.

For more details, refer to WAN with a static IP address.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Email security: E-Mail-Links in Security Center öffnen

Links in E-Mails können nun über „Open in Security Center“ untersucht werden, um einen detaillierten Bericht mit Phishing-Scan, SSL-Zertifikatsdaten, HTTP-Daten, DNS-Einträgen und mehr zu erzeugen.

You can now investigate links in emails with Cloudflare Security Center to generate a report containing a myriad of technical details: a phishing scan, SSL certificate data, HTTP request and response data, page performance data, DNS records, what technologies and libraries the page uses, and more.

Open links in Security Center

From Investigation, go to View details, and look for the Links identified section. Select Open in Security Center next to each link. Open in Security Center allows your team to quickly generate a detailed report about the link with no risk to the analyst or your environment.

For more details, refer to Open links.

This feature is available across these Email security packages:

  • Advantage
  • Enterprise
  • Enterprise + PhishGuard

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Gateway: Passwortgeschützte und nicht scannbare Dateien blockieren

Gateway-HTTP-Richtlinien können nun passwortgeschützte, komprimierte oder anderweitig nicht scannbare Dateien blockieren, die über die Traffic-Selektoren für Download- und Upload-Dateitypen erfasst werden, darunter passwortgeschützte Office-Dokumente, PDFs und ZIP-Archive sowie nicht scannbare ZIP-Archive.

Gateway HTTP policies can now block files that are password-protected, compressed, or otherwise unscannable.

These unscannable files are now matched with the Download and Upload File Types traffic selectors for HTTP policies:

  • Password-protected Microsoft Office document
  • Password-protected PDF
  • Password-protected ZIP archive
  • Unscannable ZIP archive

To get started inspecting and modifying behavior based on these and other rules, refer to HTTP filtering.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Data Loss Prevention: Erkennung von Quellcode-Lecks

Data Loss Prevention erkennt nun Quellcode-Lecks mit vordefinierten Prüfungen für zwölf Programmiersprachen, die per NLP validiert werden, und unterstützt Konfidenzstufen für Quellcode-Profile.

You can now detect source code leaks with Data Loss Prevention (DLP) with predefined checks against common programming languages.

The following programming languages are validated with natural language processing (NLP).

  • C
  • C++
  • C#
  • Go
  • Haskell
  • Java
  • JavaScript
  • Lua
  • Python
  • R
  • Rust
  • Swift

DLP also supports confidence level for source code profiles.

For more details, refer to DLP profiles.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Access for Infrastructure: SSH-Befehlslogs per Logpush exportieren

SSH-Befehlslogs lassen sich nun über Logpush an Speicherziele einschließlich Drittanbietern senden, verfügbar nur in Enterprise-Plänen.

Availability

Only available on Enterprise plans.

Cloudflare now allows you to send SSH command logs to storage destinations configured in Logpush, including third-party destinations. Once exported, analyze and audit the data as best fits your organization! For a list of available data fields, refer to the SSH logs dataset.

To set up a Logpush job, refer to Logpush integration.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Email security: Nutzereinreichungen eskalieren

Nach der Sichtung maschinell geprüfter Nutzereinreichungen aus Submission-Alias, PhishNet und API können diese nun zur manuellen Neuklassifizierung an das Cloudflare-Team eskaliert werden.

After you triage your users' submissions (that are machine reviewed), you can now escalate them to our team for reclassification (which are instead human reviewed). User submissions from the submission alias, PhishNet, and our API can all be escalated.

Escalate

From Reclassifications, go to User submissions. Select the three dots next to any of the user submissions, then select Escalate to create a team request for reclassification. The Cloudflare dashboard will then show you the submissions on the Team Submissions tab.

Refer to User submissions to learn more about this feature.

This feature is available across these Email security packages:

  • Advantage
  • Enterprise
  • Enterprise + PhishGuard

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Email security: Mehr Transparenz bei Phishing-Einreichungen

Im Zero-Trust-Dashboard zeigt ein neuer Tab „Reclassification“, welche Phishing-E-Mails von Teams und Nutzern eingereicht wurden und wie das Ergebnis der Prüfung ausfiel.

You now have more transparency about team and user submissions for phishing emails through a Reclassification tab in the Zero Trust dashboard.

Reclassifications happen when users or admins submit a phish to Email security. Cloudflare reviews and - in some cases - reclassifies these emails based on improvements to our machine learning models.

This new tab increases your visibility into this process, allowing you to view what submissions you have made and what the outcomes of those submissions are.

Use the Reclassification area to review submitted phishing emails

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare Tunnel: Diagnose-Logs mit cloudflared 2024.12.2

Der neue cloudflared-Build 2024.12.2 kann alle für die Fehlersuche nötigen Diagnose-Logs einer lokal laufenden Instanz sammeln und in einer cloudflared-diag-Datei ausgeben.

The latest cloudflared build 2024.12.2 ↗︎ introduces the ability to collect all the diagnostic logs needed to troubleshoot a cloudflared instance.

A diagnostic report collects data from a single instance of cloudflared running on the local machine and outputs it to a cloudflared-diag file.

For more information, refer to Diagnostic logs.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

BGP-Peering über Direct CNI für Magic WAN und Magic Transit

Kunden von Magic WAN und Magic Transit können im Cloudflare-Dashboard BGP-Peering über Direct-CNI-On-Ramps einrichten, einschließlich eBGP-Sitzung, MD5-Authentifizierung und dynamischem Routenaustausch mit der Magic-Routing-Tabelle.

Magic WAN and Magic Transit customers can use the Cloudflare dashboard to configure and manage BGP peering between their networks and their Magic routing table when using a Direct CNI on-ramp.

Using BGP peering allows customers to:

  • Automate the process of adding or removing networks and subnets.
  • Take advantage of failure detection and session recovery features.

With this functionality, customers can:

  • Establish an eBGP session between their devices and the Magic WAN / Magic Transit service when connected via CNI.
  • Secure the session by MD5 authentication to prevent misconfigurations.
  • Exchange routes dynamically between their devices and their Magic routing table.

Refer to Magic WAN BGP peering or Magic Transit BGP peering to learn more about this feature and how to set it up.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Multi-Cloud Networking: Angepasste Terraform-Dateien für Cloud-On-Ramps

Magic Cloud kann bestehende Netzwerkressourcen erkennen und angepasste Terraform-Dateien für On-Ramps zu Magic WAN erzeugen, die sich prüfen oder in eigenen Infrastructure-as-Code-Pipelines einsetzen lassen.

You can now generate customized terraform files for building cloud network on-ramps to Magic WAN.

Magic Cloud can scan and discover existing network resources and generate the required terraform files to automate cloud resource deployment using their existing infrastructure-as-code workflows for cloud automation.

You might want to do this to:

  • Review the proposed configuration for an on-ramp before deploying it with Cloudflare.
  • Deploy the on-ramp using your own infrastructure-as-code pipeline instead of deploying it with Cloudflare.

For more details, refer to Set up with Terraform.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

CASB: Sicherheitsfehlkonfigurationen in AWS finden

CASB findet nun Sicherheitsfehlkonfigurationen in AWS-Umgebungen und kann über ein verbundenes Compute-Konto S3-Buckets ohne Egress-Gebühren auf sensible Daten scannen.

You can now use CASB to find security misconfigurations in your AWS cloud environment using Data Loss Prevention.

You can also connect your AWS compute account to extract and scan your S3 buckets for sensitive data while avoiding egress fees. CASB will scan any objects that exist in the bucket at the time of configuration.

To connect a compute account to your AWS integration:

  1. In Cloudflare One ↗︎, go to Cloud & SaaS findings > Integrations.
  2. Find and select your AWS integration.
  3. Select Open connection instructions.
  4. Follow the instructions provided to connect a new compute account.
  5. Select Refresh.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Browser Isolation: Bessere Unterstützung nicht-englischer Tastaturen

Im isolierten Browser lassen sich nun Sprachen mit Diakritika sowie zeichenbasierte Schriften wie Chinesisch, Japanisch und Koreanisch direkt eingeben, ohne Inhalte aus einem lokalen Browser kopieren zu müssen.

You can now type in languages that use diacritics (like á or ç) and character-based scripts (such as Chinese, Japanese, and Korean) directly within the remote browser. The isolated browser now properly recognizes non-English keyboard input, eliminating the need to copy and paste content from a local browser or device.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Email security: Logpush für Nutzeraktionen

Nutzeraktionslogs von Email security können nun per Cloudflare Logpush an einen frei wählbaren Endpunkt gesendet werden, indem man den Datensatz „Audit logs“ wählt und nach ResourceType beginnend mit email_security filtert.

You can now send user action logs for Email security to an endpoint of your choice with Cloudflare Logpush.

Filter logs matching specific criteria you have set or select from multiple fields you want to send. For all users, we will log the date and time, user ID, IP address, details about the message they accessed, and what actions they took.

When creating a new Logpush job, remember to select Audit logs as the dataset and filter by:

  • Field: "ResourceType"
  • Operator: "starts with"
  • Value: "email_security".

Logpush-user-actions

For more information, refer to Enable user action logs.

This feature is available across all Email security packages:

  • Enterprise
  • Enterprise + PhishGuard

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Network Firewall: Suche nach Custom Rules per Name oder ID

Im Magic-Firewall-Dashboard lassen sich benutzerdefinierte Regeln nun nach Regelname und/oder ID suchen, und in Network Analytics wurde zusätzlich ein Link zur Regel-ID ergänzt.

The Magic Firewall dashboard now allows you to search custom rules using the rule name and/or ID.

  1. Log into the Cloudflare dashboard ↗︎ and select your account.
  2. Go to Analytics & Logs > Network Analytics.
  3. Select Magic Firewall.
  4. Add a filter for Rule ID.

Search for firewall rules with rule IDs

Additionally, the rule ID URL link has been added to Network Analytics.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Access for Infrastructure: SSH ohne langlebige Zugangsdaten

SSH mit Access for Infrastructure nutzt kurzlebige SSH-Zertifikate von Cloudflare statt langlebiger Schlüssel und ermöglicht Multi-Faktor-Authentifizierung, feingranulare Richtlinien sowie Access- und Befehlslogs, während native SSH-Clients ohne Änderungen weiter funktionieren.

Organizations can now eliminate long-lived credentials from their SSH setup and enable strong multi-factor authentication for SSH access, similar to other Access applications, all while generating access and command logs.

SSH with Access for Infrastructure uses short-lived SSH certificates from Cloudflare, eliminating SSH key management and reducing the security risks associated with lost or stolen keys. It also leverages a common deployment model for Cloudflare One customers: WARP-to-Tunnel.

SSH with Access for Infrastructure enables you to:

  • Author fine-grained policy to control who may access your SSH servers, including specific ports, protocols, and SSH users.
  • Monitor infrastructure access with Access and SSH command logs, supporting regulatory compliance and providing visibility in case of security breach.
  • Preserve your end users' workflows. SSH with Access for Infrastructure supports native SSH clients and does not require any modifications to users’ SSH configs.

Example of an infrastructure Access application …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Risk Scores mit Okta austauschen

Cloudflare One kann Benutzer-Risk-Scores nun an Okta senden, damit sie für SSO-Richtlinien genutzt werden können; dazu wird in Cloudflare One die Option „Send risk score to Okta“ aktiviert und in Okta ein Shared-Signals-Stream mit der Well-known-URL angelegt.

Beyond the controls in Zero Trust, you can now exchange user risk scores with Okta to inform SSO-level policies.

First, configure Cloudflare One to send user risk scores to Okta.

  1. Set up the Okta SSO integration.
  2. In the Cloudflare dashboard ↗︎, go to Zero Trust > Integrations > Identity providers.
  3. In Your identity providers, locate your Okta integration and select Edit.
  4. Turn on Send risk score to Okta.
  5. Select Save.
  6. Upon saving, Cloudflare One will display the well-known URL for your organization. Copy the value.

Next, configure Okta to receive your risk scores.

  1. On your Okta admin dashboard, go to Security > Device Integrations.
  2. Go to Receive shared signals, then select Create stream.
  3. Name your integration. In Set up integration with, choose Well-known URL.
  4. In Well-known URL, enter the well-known URL value provided by Cloudflare One.
  5. Select Create.

Originalquelle(öffnet in neuem Tab)Problem melden