Zum Inhalt springen

Cloudflare One Updates & Release Notes

319 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge Cloudflare One, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Benutzerdefinierte DHCP-Optionen auf der Cloudflare One Appliance

Wenn die Cloudflare One Appliance als DHCP-Server fungiert, lassen sich nun eigene DHCP-Optionen vom Typ text, integer, hex oder ip konfigurieren, die vor der Anwendung auf der Appliance validiert werden.

When the Cloudflare One Appliance is acting as the DHCP server for a LAN, you can now configure custom DHCP options on the leases it issues. This unlocks workflows such as PXE / iPXE boot, VoIP phone provisioning, and vendor-specific client configuration.

Each option is defined by option_number, value, and one of four value types: text, integer, hex, or ip. Configurations are validated on the appliance before being applied — invalid configurations are rejected and the underlying error is returned to the API caller, so a bad option will not disrupt the live DHCP service.

For details, refer to DHCP server options.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Quellbasiertes Breakout und Priorisierung auf der Cloudflare One Appliance

Breakout- und Priorisierungsregeln der Cloudflare One Appliance können nun zusätzlich zur Ziel-Anwendung auch nach Quelle, also nach LAN-Interface oder IP-Adresse, Bereich bzw. CIDR-Block, zugeordnet werden.

Breakout and traffic prioritization rules on the Cloudflare One Appliance can now match by source in addition to destination application. You can pin breakout or priority behavior to:

  • A source LAN interface — VLANs attached to that LAN are included automatically.
  • A source IP address, range, or CIDR block.

This is the natural way to break out a guest VLAN to the local Internet, or to prioritize traffic from a specific subnet, without enumerating destination applications.

For details, refer to Breakout traffic.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Self-Service-Bereitstellung der Cloudflare One Virtual Appliance per API

Cloudflare One Virtual Appliances und ihre Lizenzschlüssel lassen sich nun direkt per API und Terraform erstellen, rotieren und löschen, wobei der Schlüssel nur einmalig bei Erstellung oder Rotation ausgegeben wird.

You can now create, rotate, and delete Cloudflare One Virtual Appliance instances and their license keys directly via the API and Terraform.

  • Create a virtual appliance and receive a license key: POST /accounts/{account_id}/magic/connectors with device.provision_license: true.
  • Rotate the license key for an existing virtual appliance: PATCH /accounts/{account_id}/magic/connectors/{connector_id} with provision_license: true. The previous key is immediately and irrevocably revoked.
  • Delete a virtual appliance to release the associated licensed device.

The license key is returned in the response only once, at create or rotate time. Copy and store it securely.

For details, refer to Configure a Cloudflare One Virtual Appliance.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Cloudy Summaries in PhishNet für O365

PhishNet-Nutzer sehen bei der E-Mail-Untersuchung nun KI-generierte Cloudy-Zusammenfassungen, die nicht auf Kundendaten trainiert sind und für Office 365 verfügbar sind, während Gmail bis Quartalsende folgen soll.

PhishNet users can now access Cloudy summaries directly within the email investigation experience. When reviewing a message in PhishNet, users will see an AI-generated summary that provides additional context and key details about the email.

These summaries help users quickly understand the nature of a message without needing to manually parse through headers, body content, and detection signals. Cloudy surfaces the most relevant information so users can make faster, more informed decisions about suspicious emails.

These summaries are not trained on customer data. They are generated using the outputs of our existing detection models and analysis systems.

This feature is available for PhishNet with Office 365. Support for Gmail will be available by the end of the quarter.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

IPv6-CIDR-Routen für Cloudflare Mesh

Cloudflare Mesh Nodes unterstützen nun IPv6-CIDR-Routen, sodass sowohl IPv4- als auch IPv6-Subnetze beworben und IPv6-only- oder Dual-Stack-Netzwerke erreichbar gemacht werden können.

Cloudflare Mesh nodes now support IPv6 CIDR routes. You can advertise both IPv4 and IPv6 subnets through your Mesh nodes, making IPv6-only or dual-stack private networks reachable from any enrolled device.

IPv6 CIDR routes on a Mesh node in the Cloudflare dashboard

To add an IPv6 route, follow the same steps as adding an IPv4 route — enter the IPv6 CIDR (for example, fd00::/64) when configuring the route in the dashboard ↗︎ or via the API.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Post-Quantum-IPsec-Interoperabilität mit Drittanbieter-Geräten

Cloudflare IPsec unterstützt nun Post-Quantum-Schlüsselaustausch mit ML-KEM mit kompatiblen Geräten von Cisco (8000 Series mit IOS XR 26.1.1) und Fortinet (FortiOS 7.6.6 und neuer), ohne zusätzliche Lizenz.

Cloudflare IPsec now supports post-quantum key agreement with compatible third-party devices. Cisco ↗︎ and Fortinet ↗︎ are the first third-party vendors validated to interoperate with Cloudflare IPsec using ML-KEM (Module-Lattice-Based Key-Encapsulation Mechanism).

Post-quantum IPsec uses RFC 9370 ↗︎ and draft-ietf-ipsecme-ikev2-mlkem ↗︎ to negotiate hybrid key agreement during the IKEv2 IKE_INTERMEDIATE phase. This combines classical Diffie-Hellman (Group 20) with ML-KEM-768 or ML-KEM-1024 to protect against harvest-now, decrypt-later ↗︎ attacks.

Key details:

  • Compatible with Cisco 8000 Series Secure Routers with IOS XR Release 26.1.1 and Fortinet FortiOS 7.6.6 and later.
  • Uses ML-KEM-768 or ML-KEM-1024 as an additional Key Exchange to DH Group 20.
  • Follows RFC 9370 and draft-ietf-ipsecme-ikev2-mlkem standards.
  • No additional licensing required.

Post-quantum IPsec with third-party devices is now generally available with confirmed interoperability for the platforms listed above. Cloudflare intends to support interoperability with more vendors as they build out support for draft-ietf-ipsecme-ikev2-mlkem. Contact your account team to discuss support for additional vendors. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Data Classification in Cloudflare DLP

Cloudflare DLP enthält nun Data Classification, mit der Administratoren sensible Inhalte über Labels, Vorlagen und wiederverwendbare Datenklassen organisieren und in benutzerdefinierten DLP-Profilen nutzen können.

Cloudflare DLP now includes Data Classification, which lets administrators organize and label sensitive content using labels, templates, and reusable data classes.

With Data Classification, administrators can define labels such as sensitivity schemas and levels, and data tag groups and tags. Administrators can also build from Cloudflare-managed templates and create reusable data classes that combine detection entries, other data classes, sensitivity levels, and data tags.

You can then use those classifications in custom DLP profiles to identify the severity of sensitive content, understand where it exists, and apply that logic consistently across DLP profiles.

For more information, refer to Data Classification.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Neue vordefinierte DLP-Erkennungseinträge

Cloudflare DLP bietet einen erweiterten Katalog vordefinierter Erkennungseinträge, etwa für Zugangsdaten, Webhooks, Adressen, Steuer- und Ausweisnummern, Finanzdaten und Krypto-Wallets, darunter GitHub PAT, OpenAI API Key und Bitcoin Wallet.

Cloudflare DLP now includes new predefined detection entries.

The expanded catalog includes detections for specific credential types, webhooks, addresses, tax identifiers, national IDs, financial data, and crypto wallets.

Examples include GitHub PAT, OpenAI API Key, Slack Webhook, Discord Webhook, US Physical Address, and Bitcoin Wallet.

For the full list, refer to Predefined detection entries.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

DEX-Tests für authentifizierte Ressourcen und erweiterte Konfiguration

Digital experience tests können nun durch Cloudflare Access oder Drittanbieter-Authentifizierung geschützte Anwendungen testen, wobei Secrets über Cloudflare Secret Store verwaltet werden, und bieten zusätzliche HTTP-Methoden, Header, Request-Bodys und erweiterte Einstellungen.

Digital experience tests now support testing applications protected by Cloudflare Access or third-party authentication. All authentication secrets are managed via Cloudflare Secret Store.

Digital experience tests also have enhanced configuration options including:

  • New HTTP methods (DELETE, PATCH, POST, PUT)
  • Secret Store headers, custom plain text headers, and custom request bodies
  • Advanced settings: follow redirects, response bodies, response headers, and allow untrusted certificates

Digital experience test configuration for Cloudflare Access applicationsDigital experience enhanced test configuration

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Gateway Authorization Proxy und gehostete PAC-Dateien allgemein verfügbar

Der Gateway Authorization Proxy und von Cloudflare gehostete PAC-Dateien sind nun für alle Tarife allgemein verfügbar und ermöglichen identitätsbasierte Gateway-Filterung ohne installierten Cloudflare One Client.

The Gateway Authorization Proxy and hosted PAC files are now generally available for all plan types.

Authorization proxy endpoints add an identity-aware option alongside the existing source IP proxy endpoints, using Cloudflare Access authentication to verify who a user is before applying Gateway filtering — without installing the Cloudflare One Client. Cloudflare-hosted PAC files let you create and distribute PAC files directly from Cloudflare One on Cloudflare's global network.

These features are ideal for environments where deploying a device client is not an option, such as virtual desktops (VDI) or compliance-restricted endpoints.

To get started, refer to the proxy endpoints documentation.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

DEX: Benachrichtigungen bei Internet-Ausfällen für Geräte

Digital Experience zeigt nun eine Dashboard-Benachrichtigung an, wenn ein Internet-Ausfall oder eine Traffic-Anomalie ein Cloudflare-One-Client-Gerät aufgrund von Standort oder Netzwerkverbindung betreffen könnte, basierend auf Daten von Cloudflare Radar.

Digital Experience will display a dashboard notification when an Internet outage or traffic anomaly may impact a Cloudflare One Client device based on its geographic location or network connection.

This Internet outage and traffic anomaly data is pulled from Cloudflare Radar ↗︎. All Internet outage and traffic anomaly observations can be viewed in the Radar Outage Center ↗︎.

Digital Experience Monitoring dashboard notification for Internet outage impacting Cloudflare One Client devicesDigital Experience Monitoring dashboard analytics for Internet outage impacting Cloudflare One Client devices

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

DEX: Speed-Tests vom Cloudflare One Client

IT-Teams können nun aus der Ferne Speed-Tests vom Cloudflare One Client zum Cloudflare-Netzwerkrand ausführen, die Durchsatz, Latenz, Jitter und Netzwerkqualitätswerte liefern.

IT teams can now remotely run speed tests from the Cloudflare One Client to Cloudflare's network edge.

Each speed test includes the following metrics:

  • Internet speed: download and upload throughput
  • Latency: download, upload, unloaded latency, and jitter
  • Network quality score: video streaming, webchat/real-time communication (RTC)

In the Cloudflare dashboard ↗︎, go to Zero Trust > Insights > Digital experience > Diagnostics and select Run diagnostics to use the feature today.

Cloudflare One client speed test result

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

DLP-Erkennungseinträge außerhalb von Profilen verwalten

DLP-Erkennungseinträge lassen sich nun unabhängig von einzelnen Profilen im Bereich Detection entries erstellen, anzeigen und verwalten und in benutzerdefinierten DLP-Profilen verwenden.

You can now create, view, and manage DLP detection entries outside of profiles.

Detection entries are no longer hidden inside individual profiles. Administrators can manage detection entries directly from the Detection entries section and use them in custom DLP profiles.

For more information, refer to Configure detection entries.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Neues vordefiniertes DLP-Profil für PII-Datensätze

Cloudflare DLP enthält ein neues vordefiniertes Profil „Personally Identifiable Information (PII) Record“, das nur anschlägt, wenn mindestens drei verschiedene Erkennungseinträge in unmittelbarer Nähe gefunden werden, um Fehlalarme zu verringern.

Cloudflare DLP now includes a new predefined profile designed to detect PII records that contain multiple types of personal data: Personally Identifiable Information (PII) Record.

Most predefined and custom DLP profiles match when any enabled detection entry matches. The Personally Identifiable Information (PII) Record profile is different. It only matches when at least three unique detection entries are found in close proximity, which reduces false positives from standalone values that may not represent a real PII record.

Detection entries included in the profile:

  • AU Passport Number
  • American Express Card Number
  • Diners Club Card Number
  • US Driver's License Number
  • Email Address
  • Full Name
  • US Mailing Address
  • Mastercard Card Number
  • US Individual Tax Identification Number (ITIN)
  • US Passport Number
  • US Phone Number
  • Union Pay Card Number
  • United States SSN Numeric Detection
  • Visa Card Number

For more information, refer to predefined DLP profiles.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Network Session Logs für alle On-Ramps verfügbar

Zero Trust Network Session Logs werden nun für den gesamten über Cloudflare Gateway geleiteten Verkehr erzeugt, auch von Proxy-Endpunkten (PAC-Dateien) und Browser-Isolation-Egress, was bei Nutzung dieser On-Ramps zu höherem Log-Volumen führen kann.

Zero Trust Network Session Logs are now generated for all traffic proxied through Cloudflare Gateway, regardless of on-ramp type. This includes traffic from proxy endpoints (PAC files) and Browser Isolation egress — on-ramps that previously did not generate session logs.

Customers who already consume the zero_trust_network_sessions dataset via Logpush or Log Explorer may see increased log volume if they use these on-ramps.

For field definitions, refer to Zero Trust Network Session Logs. For traffic analysis, refer to Network session analytics.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

AAGUID-Beschränkungen und AMR-Abgleich für Access Independent MFA

Independent MFA in Cloudflare Access unterstützt nun die Beschränkung von Authentifikatoren per AAGUID sowie einen AMR-Abgleich, der die MFA-Abfrage überspringt, wenn der Identity Provider bereits eine gleichwertige MFA durchgeführt hat.

Independent MFA in Cloudflare Access now supports two additional organization-level controls:

  • Restrict authenticators by AAGUID — Limit enrollment to a specific set of WebAuthn authenticators using their AAGUID ↗︎. This is useful for organizations that require FIPS-validated security keys or company-issued hardware. AAGUIDs are managed through a new List type.
  • AMR matching — Skip the independent MFA prompt when the identity provider has already performed an equivalent MFA. Access reads the amr claim defined in RFC 8176 ↗︎ and matches supported values such as hwk, otp, and fpt to the authenticator types allowed on the application or policy. This prevents users from having to complete MFA twice when their identity provider already enforces it. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Country-Regeln der Network Firewall im Unified Routing

Country-Regeln der Cloudflare Advanced Network Firewall werden nun für Konten im Unified-Routing-Modus unterstützt, erfordern ein Advanced-Network-Firewall-Abonnement und sind das erste Feature, das dort verfügbar wird.

Cloudflare Advanced Network Firewall Country rules are now supported for accounts using Unified Routing mode. This feature requires a Cloudflare Advanced Network Firewall subscription.

You can create firewall rules that match traffic based on source or destination country to enforce geographic access policies across your network.

This is the first of the Cloudflare Advanced Network Firewall features to become available in Unified Routing. Support for additional features - IP Lists, ASN Lists, Threat Intel Lists, IDS, Rate Limiting, SIP, and Managed Rulesets - is planned.

For the full list of current beta limitations, refer to Traffic steering beta limitations.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Network-session-analytics-Dashboard in Cloudflare One

Cloudflare One enthält ein neues Network-session-analytics-Dashboard, das Sitzungszahl, übertragene Bytes, Nutzer, geografische Verteilung, Protokolle und Gründe für Verbindungsabbrüche des Netzwerkverkehrs sichtbar macht.

The new Network session analytics dashboard is now available in Cloudflare One. This dashboard provides visibility into your network traffic patterns, helping you understand how traffic flows through your Cloudflare One infrastructure.

Cloudflare One Network Session Analytics

What you can do with Network session analytics

  • Analyze geographic distribution: View a world map showing where your network traffic originates, with a list of top locations by session count.
  • Monitor key metrics: Track session count, total bytes transferred, and unique users.
  • Identify connection issues: Analyze connection close reasons to troubleshoot network problems.
  • Review protocol usage: See which network protocols (TCP, UDP, ICMP) are most used.

Dashboard features

  • Summary metrics: Session count, bytes total, and unique users
  • Traffic by location: World map visualization and location list with top traffic sources
  • Top protocols: Breakdown of TCP, UDP, ICMP, and ICMPv6 traffic
  • Connection close reasons: Insights into why sessions terminated (client closed, origin closed, timeouts, errors)

How to access …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Access: Startseite und Abmelden für MCP-Server-Portale

MCP server portals zeigen im Browser nun eine Startseite mit Portalname, MCP-Endpoint-URL und Verbindungsanleitungen für verschiedene Clients, und angemeldete Nutzer können sich per „Sign out“ abmelden, wodurch Portal-OAuth-Freigaben widerrufen werden.

MCP server portals display a homepage when users visit the portal domain in a browser.

MCP server portal homepage showing connection status and setup instructions

The homepage shows:

  • The portal name and organization branding
  • The MCP endpoint URL with a copy button
  • Per-client connection instructions for Claude Desktop, Workers AI Playground, OpenCode, Windsurf, and other MCP clients

Authenticated users see their email address and a Sign out button. Selecting Sign out revokes all portal-level OAuth grants, deletes upstream server OAuth states, and redirects through Cloudflare Access logout. A confirmation page shows a summary of the revoked sessions.

For more information, refer to MCP server portals.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Cloudflare One von Cloudflare

Access: Unabhängige MFA für Access-Anwendungen

Cloudflare Access unterstützt nun unabhängige Multi-Faktor-Authentifizierung per Authenticator-App, Sicherheitsschlüssel oder Biometrie, die sich auf Organisations-, Anwendungs- und Policy-Ebene festlegen lässt, während Infrastructure-Anwendungen noch nicht unterstützt werden.

Cloudflare Access now supports independent multi-factor authentication (MFA), allowing you to enforce MFA requirements without relying on your identity provider (IdP). With per-application and per-policy configuration, you can enforce stricter authentication methods like hardware security keys on sensitive applications without requiring them across your entire organization. This reduces the risk of MFA fatigue for your broader user population while adding additional security where it matters most.

This feature also addresses common gaps in IdP-based MFA, such as inconsistent MFA policies across different identity providers or the need for additional security layers beyond what the IdP provides.

Independent MFA supports the following authenticator types:

  • Authenticator application — Time-based one-time passwords (TOTP) using apps like Google Authenticator, Microsoft Authenticator, or Authy.
  • Security key — Hardware security keys such as YubiKeys.
  • Biometrics — Built-in device authenticators including Apple Touch ID, Apple Face ID, and Windows Hello.

Note

Infrastructure applications do not yet support independent MFA.

Configuration levels

You can configure MFA requirements at three levels:

Level

Description

Organization

Enforce MFA by default for all applications in your account.

Application

Require or turn off MFA for a specific application.

Policy …

Originalquelle(öffnet in neuem Tab)Problem melden