Zum Inhalt springen

Cloudflare One Updates & Release Notes

319 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge Cloudflare One, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für macOS 2026.5.1155.1 (Beta)

Die neue Beta des Cloudflare One Client für macOS bringt die neue Benutzeroberfläche mit Rechtsklick-Kontextmenü und integriertem Captive-Portal-Login sowie Unterstützung für DNS-Suchsuffixe aus Geräteprofil bzw. Netzwerkrichtlinie.

A new Beta release for the macOS Cloudflare One Client is now available on the beta releases downloads page.

This release introduces the new Cloudflare One Client UI for macOS! You can expect a cleaner and more intuitive design as well as easier access to common actions and information. Here are some of the many things we have found our users appreciate:

  • Right click context menu to access the most common client actions quickly
  • Built-in captive portal login experience

Additional Changes and improvements

  • The client now applies DNS search suffixes configured in your device profile / network policy. Administrators can push a list of DNS search domains that the client appends to single-label queries, alongside any system-configured suffixes. See DNS search suffixes for details. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für Windows 2026.5.1155.1 (Beta)

Die neue Beta des Cloudflare One Client für Windows bringt die neue Benutzeroberfläche mit Rechtsklick-Kontextmenü und integriertem Captive-Portal-Login sowie Unterstützung für DNS-Suchsuffixe aus Geräteprofil bzw. Netzwerkrichtlinie.

A new Beta release for the Windows Cloudflare One Client is now available on the beta releases downloads page.

This release introduces the new Cloudflare One Client UI for Windows! You can expect a cleaner and more intuitive design as well as easier access to common actions and information. Here are some of the many things we have found our users appreciate:

  • Right click context menu to access the most common client actions quickly
  • Built-in captive portal login experience

Additional Changes and improvements

  • The client now applies DNS search suffixes configured in your device profile / network policy. Administrators can push a list of DNS search domains that the client appends to single-label queries, alongside any system-configured suffixes. See DNS search suffixes for details. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Access: Aliase für Tools und Prompts in MCP-Server-Portalen

In MCP-Server-Portalen lassen sich Tools und Prompts jetzt umbenennen und ihre Beschreibungen umschreiben, ohne den Upstream-Server zu ändern, wobei geänderte Tools mit dem Label „Modified“ gekennzeichnet werden.

When you connect third-party MCP servers through MCP server portals, you have no control over how the server author named tools or wrote descriptions. Unclear names make it harder for AI agents to select the right tool and harder for users to understand what is available.

You can now rename tools and prompts and rewrite their descriptions directly on the portal, without modifying the upstream server. For example, a tool named super_cool_tool can become search_customer_records with a description tailored to your organization.

Edit tool modal showing name and description fields for an MCP server tool

Modified tools display a Modified label in the tools list so administrators can see which tools have been customized at a glance.

Tools authorized list showing a modified label on a renamed tool

Aliases override the metadata that MCP clients receive. You can set them at two levels: …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare Mesh: Verwaltung von Hochverfügbarkeits-Replikaten

Das Cloudflare-Mesh-Dashboard zeigt für Hochverfügbarkeits-Knoten nun Details pro Replikat an, markiert das aktive Replikat und erlaubt einen manuellen Failover per Klick.

The Cloudflare Mesh dashboard now shows per-replica details for high availability nodes. You can see which replica is active, view each replica's Mesh IP and connection details, and manually trigger failover — all from the node detail page.

Mesh HA replica tabs showing active and passive replicas with per-replica Mesh IPs and a manual failover option

What's new

  • Replica tabs on the node detail page — switch between replicas to see each one's Mesh IP, edge data center, origin IP, platform, version, and uptime.
  • Active/passive badges identify which replica is currently routing traffic.
  • Manual failover — promote a passive replica to active with a single click. The previous active replica switches to standby.
  • HA badge in the overview table identifies nodes running multiple replicas.
  • Active replica IP shown in the overview table — the dashboard now resolves which replica is active and displays the correct Mesh IP.

Manual failover

To manually promote a passive replica:

  1. In the Cloudflare dashboard ↗︎, go to Networking > Mesh.
  2. Select an HA-enabled node. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Gateway: Regex per natürlicher Sprache in Cloudflare One schreiben

In Gateway-Richtlinien mit Regex-Selektoren kann man jetzt in einfacher Sprache beschreiben, was passen soll, und der Cloudflare Agent erzeugt und validiert den passenden regulären Ausdruck oder erklärt bestehende Ausdrücke.

Cloudflare Gateway policy selectors which support regular expressions can now be authored in the dashboard using natural language. When building a policy with a regex-based selector (like matches regex), you can describe what you want to match in plain English and the Cloudflare Agent will generate and validate a corresponding regular expression.

Write policy regex using natural language

To get started, select a regex-compatible selector in the Gateway policy builder and select the icon. You'll see an input field for natural language, such as "any URL starting with /api/v1" or ".com, .net, and .app hosts which contain gooogle in the host."

You can also use the tool to explain existing regular expressions. If a policy already contains a regex pattern, you can instantly generate a plain-language description.

A built-in feedback mechanism allows you to rate each interaction to help improve output quality over time. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare Tunnel führt Konnektivitäts-Vorabprüfungen beim Start aus

Ab cloudflared 2026.5.2 prüft Cloudflare Tunnel beim Start nativ DNS-Auflösung, Transport-Konnektivität auf Port 7844 und die Management-API und zeigt die Ergebnisse als Tabelle mit Pass/Warn-Status samt Hinweisen zur Behebung an.

Starting with cloudflared version 2026.5.2 ↗︎, Cloudflare Tunnel automates the entire connectivity pre-checks workflow directly inside the binary. Previously, customers had to install dig and netcat and run those commands by hand to verify their environment. Now cloudflared does it natively at startup — and surfaces actionable remediation when something is blocked.

cloudflared connectivity pre-checks output

On every cloudflared tunnel run (and cloudflared tunnel diag), the binary now natively checks:

  • DNS resolution — region1.v2.argotunnel.com and region2.v2.argotunnel.com resolve to valid Cloudflare IPs.
  • Transport connectivity — outbound UDP (QUIC) and TCP (HTTP/2) on port 7844.
  • Management API — outbound TCP/443 to api.cloudflare.com for software updates.

Results are printed in a scannable CLI table with three states:

  • ✅ Pass — the check succeeded.
  • ⚠️ Warn — a non-blocking issue, for example the Management API is unreachable so automatic updates will not work, but the tunnel will still come up. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für macOS 2026.4.1390.0 (GA)

Die stabile Version bringt die neue macOS-Oberfläche mit Kontextmenü und Captive-Portal-Login, den neuen Befehl warp-cli mdm refresh und behebt ein Verbindungshängen im Proxy-Modus.

A new GA release for the macOS Cloudflare One Client is now available on the stable releases downloads page.

This release introduces the new Cloudflare One Client UI for macOS! You can expect a cleaner and more intuitive design as well as easier access to common actions and information. Here are some of the many things we have found our users appreciate:

  • Right click context menu to access the most common client actions quickly
  • Built-in captive portal login experience

Additional Changes and improvements

  • Added a new CLI command: warp-cli mdm refresh. This command executes an immediate refresh of the Mobile Device Management (MDM) configuration file.
  • Fixed a proxy mode connection stall issue.

Known issues

  • Registration may hang at "Checking your organization configuration" due to IPC errors. A system reboot should resolve the error, allowing registration to proceed.
  • Split tunnel list configuration is not available in the new UI. Management of split tunnel entries is currently only possible via warp-cli tunnel ip and warp-cli tunnel host. UI support will be added in a future release.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für Windows 2026.4.1390.0 (GA)

Die stabile Version bringt die neue Windows-Oberfläche mit Kontextmenü und Captive-Portal-Login, den neuen Befehl warp-cli mdm refresh und behebt ein Verbindungshängen im Proxy-Modus; bekannte Probleme betreffen u. a. die WebView2-Authentifizierung.

A new GA release for the Windows Cloudflare One Client is now available on the stable releases downloads page.

This release introduces the new Cloudflare One Client UI for Windows! You can expect a cleaner and more intuitive design as well as easier access to common actions and information. Here are some of the many things we have found our users appreciate:

  • Right click context menu to access the most common client actions quickly
  • Built-in captive portal login experience

Additional Changes and improvements

  • Added a new CLI command: warp-cli mdm refresh. This command executes an immediate refresh of the Mobile Device Management (MDM) configuration file.
  • Fixed a proxy mode connection stall issue.

Known issues

  • Registration authentication for devices via the integrated WebView2 browser is unavailable in this version as a temporary measure. As a result, the client will utilize the default browser on the device to complete the authentication process.
  • An error indicating that Microsoft Edge can't read and write to its data directory may be displayed during captive portal login; this error is benign and can be dismissed.
  • Registration may hang at "Checking your organization configuration" due to IPC errors. A system reboot should resolve the error, allowing registration to proceed. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für Linux 2026.4.1390.0 (GA)

Die stabile Version bringt die neue Linux-Oberfläche, den Befehl warp-cli mdm refresh, offiziellen RHEL-9-Support für Cloudflare-Mesh-Knoten und behebt ein Verbindungshängen im Proxy-Modus.

A new GA release for the Linux Cloudflare One Client is now available on the stable releases downloads page.

This release introduces the new Cloudflare One Client UI for Linux! You can expect a cleaner and more intuitive design as well as easier access to common actions and information. Here are some of the many things we have found our users appreciate:

  • Right click context menu to access the most common client actions quickly
  • Built-in captive portal login experience

Changes and improvements

  • Added a new CLI command: warp-cli mdm refresh. This command executes an immediate refresh of the Mobile Device Management (MDM) configuration file.
  • Official support for RHEL 9 has been added for Cloudflare Mesh nodes. To install the RHEL 9 package, the Extra Packages for Enterprise Linux (EPEL) repository must be active, as it contains dependencies required for the tray icon and captive portal webview.
  • Fixed a proxy mode connection stall issue.

Known issues

  • Registration may hang at "Checking your organization configuration" due to IPC errors. A system reboot should resolve the error, allowing registration to proceed.
  • Split tunnel list configuration is not available in the new UI. Management of split tunnel entries is currently only possible via warp-cli tunnel ip and warp-cli tunnel host. UI support will be added in a future release.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Granulare Berechtigungen für Cloudflare Tunnel und Cloudflare Mesh

Berechtigungen lassen sich jetzt auf einzelne Cloudflare-Tunnel-Instanzen und Cloudflare-Mesh-Knoten beschränken, sodass Zugriff delegiert werden kann, ohne kontoweite Kontrolle über das private Netzwerk zu gewähren.

You can now scope Cloudflare permissions to individual Cloudflare Tunnel instances and Cloudflare Mesh nodes. Administrators can delegate access to specific Tunnels or Mesh nodes without granting account-wide control over private networking.

What is new

When you add a member or create a permission policy, the resource picker now lists Cloudflare Tunnel instances and Cloudflare Mesh nodes as scopable resource types. You can:

  • Grant a read-only role on a single Cloudflare Tunnel instance to a support operator for log streaming and diagnostics — without exposing other Tunnels or destructive actions.
  • Grant a write role on a specific Cloudflare Mesh node to an application team — without giving them access to the rest of your private network.
  • Scope a single policy to one or many Tunnels and Mesh nodes at once.

How it works

Granular permissions are a parallel layer to existing account-level roles — they do not replace them. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Access: Cloudflare als Identitätsanbieter und Kontomitglieder-Selektor

Cloudflare Access unterstützt Cloudflare selbst als Identitätsanbieter, der für neue Zero-Trust-Konten den One-time PIN als Standard ersetzt, und bietet zusätzlich einen Selektor für Cloudflare-Kontomitglieder sowie die Option, die Anmeldung auf Kontomitglieder zu beschränken.

Cloudflare Access now supports using Cloudflare itself as an identity provider. If you publish an Access application and select Cloudflare as the login method, users can sign in with their existing Cloudflare account — no one-time PINs, no third-party IdP configuration, and no shared email inboxes. Authentication is backed by Cloudflare's own account security (including multi-factor authentication), making it both simpler to set up and more secure than OTP-based login for most use cases.

Cloudflare is now the default identity provider for all newly created Zero Trust accounts, replacing One-time PIN.

This also enables two new capabilities:

  • Cloudflare Account Member selector — A new policy selector that matches users based on their membership in a Cloudflare account. You can target the current account or specify a different account ID for cross-account access scenarios.
  • Restrict to account members — An identity provider configuration option that limits authentication to users who are members of your Cloudflare account.

To get started, add Cloudflare as an identity provider in your Zero Trust settings.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

CASB unterstützt die Claude Compliance API

Cloudflare CASB bindet die Claude Compliance API an und meldet Sicherheitsbefunde zu öffentlichen Projekten, Projektanhängen, Chat-Dateien, Chat-Nachrichten und Artifacts, die gegen DLP-Richtlinien verstoßen.

Cloudflare CASB now integrates with the Claude Compliance API ↗︎. This enhancement gives security teams visibility into Claude usage patterns, admin activity, and compliance-relevant events across their organization.

The Claude Compliance API provides structured access to audit logs and administrative actions within Claude Enterprise and Claude Platform. Cloudflare CASB ingests this data to surface security findings that help organizations enhance their security posture and enforce AI governance.

Key capabilities

Starting today, security teams can scan for security findings across the following assets:

  • Public projects — Projects set to public visibility
  • Project attachment — Files and documents added to projects that violate DLP policies
  • Chat files — User-uploaded and provider-generated files that violate DLP policies
  • Chat messages — User prompts and provider responses that violate DLP policies
  • Artifacts — Provider-generated documents and files that violate DLP policies

Learn more

…

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Network Analytics unterstützt Unified Routing

Network Analytics ist nun für Konten im Unified-Routing-Modus vollständig unterstützt, sodass Datenverkehr über Unified-Routing-Onramps und -Offramps mit denselben Dimensionen und Filtern sichtbar ist, ohne dass eine Konfiguration nötig ist.

Network Analytics is now fully supported for accounts using Unified Routing mode. Traffic that traverses Unified Routing onramps and offramps is now visible in Network Analytics with the same dimensions and filters as traffic on the standard data plane.

This closes a parity gap for customers who had moved tunnels onto Unified Routing and lost visibility into their dataplane traffic in the Network Analytics dashboard. No configuration change is required — analytics data is collected automatically for all accounts with Unified Routing enabled.

For the remaining beta limitations, refer to Traffic steering beta limitations.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Überarbeitete Access-Anmeldeseite

Die Access-Anmeldeseite und die OTP-Seite haben ein neues Design mit einer einheitlichen Authentifizierungskarte, konsistenten Buttons, besserer mobiler Darstellung und Dark-Mode-Unterstützung.

The Access login page and one-time password (OTP) page now feature a refreshed design that improves visual consistency, user trust, and mobile responsiveness.

Before:

Screenshot of the previous Access login page

After:

Screenshot of the updated Access login page

The updated login experience includes:

  • Unified authentication card - All sign-in options (identity provider buttons, email input, OTP) now appear in a single card with consistent styling, replacing the previous multi-section layout.
  • Consistent button styling - Identity provider buttons use a uniform size and layout for easier scanning and selection.
  • Better mobile experience - Responsive layout improvements ensure the login page renders correctly on phones and tablets.
  • Dark mode support - The login page now supports dark mode.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Neue Konten erhalten standardmäßig eine einzelne IPv4-Anycast-Adresse

Neue Magic-Transit- und Cloudflare-WAN-Konten bekommen standardmäßig eine einzelne IPv4-Anycast-Adresse, und weitere Adressen können über das Account-Team angefragt werden.

New Magic Transit and Cloudflare WAN accounts are now assigned a single IPv4 anycast address by default.

Cloudflare handles failures on its network automatically by advertising your endpoint IP from multiple nodes across many globally distributed data centers. To handle failures on your network, configure two tunnels from separate routers.

To request additional anycast IP addresses for your account, contact your account team.

For tunnel configuration guidance, refer to Configure tunnel endpoints for Cloudflare WAN or Configure tunnel endpoints for Magic Transit.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Gateway-Firewall-Richtlinien per natürlicher Sprache erstellen

Für DNS-, HTTP- und Netzwerk-Firewall-Richtlinien in Cloudflare Gateway kann man über „Create with AI“ das gewünschte Ergebnis in einfacher Sprache beschreiben, woraufhin eine vollständige Regel im Policy Builder zur Prüfung erscheint.

Cloudflare Gateway now supports natural language policy creation for DNS, HTTP, and Network firewall policies. Administrators can describe the outcome they want in plain language, and Cloudflare will generate a complete policy rule that populates the policy builder form.

Create with AI button on the Gateway firewall policies page

To create a policy with natural language, select Create with AI on any Gateway firewall policy tab. Choose a policy type, describe what the policy should do, and a fully configured rule will appear in the policy builder for review. You can edit any field before saving, or re-generate with a different prompt.

The generated policy incorporates your account context - including lists, DLP profiles, applications, and device posture checks - so that references to your existing resources resolve automatically.

A built-in feedback mechanism allows you to rate each generated policy and provide optional comments, which Cloudflare uses to improve output quality over time. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für Windows 2026.4.1350.0 (GA)

Die stabile Version bringt die neue Windows-Oberfläche mit Kontextmenü und Captive-Portal-Login sowie den neuen Befehl warp-cli mdm refresh; bekannte Probleme betreffen u. a. die WebView2-Authentifizierung.

A new GA release for the Windows Cloudflare One Client is now available on the stable releases downloads page.

This release introduces the new Cloudflare One Client UI for Windows! You can expect a cleaner and more intuitive design as well as easier access to common actions and information. Here are some of the many things we have found our users appreciate:

  • Right click context menu to access the most common client actions quickly
  • Built-in captive portal login experience

Additional Changes and improvements

  • Added a new CLI command: warp-cli mdm refresh. This command executes an immediate refresh of the Mobile Device Management (MDM) configuration file.

Known issues

  • Registration authentication for devices via the integrated WebView2 browser is unavailable in this version as a temporary measure. As a result, the client will utilize the default browser on the device to complete the authentication process.
  • An error indicating that Microsoft Edge can't read and write to its data directory may be displayed during captive portal login; this error is benign and can be dismissed.
  • Registration may hang at "Checking your organization configuration" due to IPC errors. A system reboot should resolve the error, allowing registration to proceed. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für macOS 2026.4.1350.0 (GA)

Die stabile Version bringt die neue macOS-Oberfläche mit Kontextmenü und Captive-Portal-Login sowie den neuen Befehl warp-cli mdm refresh; die Split-Tunnel-Konfiguration ist in der neuen Oberfläche noch nicht verfügbar.

A new GA release for the macOS Cloudflare One Client is now available on the stable releases downloads page.

This release introduces the new Cloudflare One Client UI for macOS! You can expect a cleaner and more intuitive design as well as easier access to common actions and information. Here are some of the many things we have found our users appreciate:

  • Right click context menu to access the most common client actions quickly
  • Built-in captive portal login experience

Additional Changes and improvements

  • Added a new CLI command: warp-cli mdm refresh. This command executes an immediate refresh of the Mobile Device Management (MDM) configuration file.

Known issues

  • Registration may hang at "Checking your organization configuration" due to IPC errors. A system reboot should resolve the error, allowing registration to proceed.
  • Split tunnel list configuration is not available in the new UI. Management of split tunnel entries is currently only possible via warp-cli tunnel ip and warp-cli tunnel host. UI support will be added in a future release.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudflare One Client für Linux 2026.4.1350.0 mit neuer Oberfläche

Das GA-Release des Cloudflare One Client für Linux bringt eine neue Benutzeroberfläche mit Kontextmenü und integriertem Captive-Portal-Login, den neuen CLI-Befehl warp-cli mdm refresh sowie offizielle RHEL-9-Unterstützung für Cloudflare Mesh Nodes.

A new GA release for the Linux Cloudflare One Client is now available on the stable releases downloads page.

This release introduces the new Cloudflare One Client UI for Linux! You can expect a cleaner and more intuitive design as well as easier access to common actions and information. Here are some of the many things we have found our users appreciate:

  • Right click context menu to access the most common client actions quickly
  • Built-in captive portal login experience

Changes and improvements

  • Added a new CLI command: warp-cli mdm refresh. This command executes an immediate refresh of the Mobile Device Management (MDM) configuration file.
  • Official support for RHEL 9 has been added for Cloudflare Mesh nodes. To install the RHEL 9 package, the Extra Packages for Enterprise Linux (EPEL) repository must be active, as it contains dependencies required for the tray icon and captive portal webview.

Known issues

  • Registration may hang at "Checking your organization configuration" due to IPC errors. A system reboot should resolve the error, allowing registration to proceed.
  • Split tunnel list configuration is not available in the new UI. Management of split tunnel entries is currently only possible via warp-cli tunnel ip and warp-cli tunnel host. UI support will be added in a future release.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

NAT-T-Unterstützung für IKE auf UDP-Port 500

Cloudflare IPsec unterstützt nun den Standard-NAT-T-Ablauf, bei dem IKE auf UDP-Port 500 beginnt und nach NAT-Erkennung auf Port 4500 wechselt, ohne dass Änderungen an der Cloudflare-Konfiguration nötig sind und ohne Auswirkungen auf bestehende Tunnel.

Cloudflare IPsec now supports the standard NAT traversal (NAT-T) flow, where IKE begins on UDP port 500 and switches to UDP port 4500 after NAT is detected.

Previously, devices behind NAT had to be configured to initiate IKE on UDP port 4500 directly. Devices that started on UDP port 500 could not complete the IKE handshake when NAT was in the path. This required custom configuration on devices such as VeloCloud SD-WAN edges, Cisco IOS-XE routers, and Juniper SRX firewalls, and was not possible on every platform.

What changed:

  • Devices behind NAT can now initiate IKE on either UDP port 500 or UDP port 4500.
  • Devices that start IKE on UDP port 500 and switch to UDP port 4500 after NAT detection now complete the handshake successfully.
  • No configuration change is required on Cloudflare. The change is available for all IPsec tunnels on Cloudflare WAN and Magic Transit.

This change does not affect existing tunnels:

  • Tunnels using UDP port 500 with no NAT detected continue to operate as before.
  • Tunnels configured to start IKE on UDP port 4500 continue to operate as before.
  • NAT detection logic is unchanged.

For configuration details, refer to GRE and IPsec tunnels.

Originalquelle(öffnet in neuem Tab)Problem melden