<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Changelog | Cloudflare One</title><description>Updates to Cloudflare One</description><link>https://developers.cloudflare.com/cloudflare-one/changelog</link><item><title>DLP - Source code confidence levels</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/dlp/#source-code-confidence-levels</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/dlp/#source-code-confidence-levels</guid><description>&lt;p&gt;DLP now supports setting a confidence level for &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/policies/data-loss-prevention/dlp-profiles/predefined-profiles/#source-code&quot;&gt;source code profiles&lt;/a&gt;.&lt;/p&gt;
</description><pubDate>Thu, 23 Jan 2025 00:00:00 GMT</pubDate><product>DLP</product></item><item><title>Access - Access Applications support private hostnames/IPs and reusable Access policies.</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/access/#access-applications-support-private-hostnamesips-and-reusable-access-policies</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/access/#access-applications-support-private-hostnamesips-and-reusable-access-policies</guid><description>&lt;p&gt;Cloudflare Access self-hosted applications can now be defined by &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/applications/non-http/self-hosted-private-app/&quot;&gt;private IPs&lt;/a&gt;, &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/applications/non-http/self-hosted-private-app/&quot;&gt;private hostnames&lt;/a&gt; (on port 443) and &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/applications/configure-apps/self-hosted-public-app/&quot;&gt;public hostnames&lt;/a&gt;. Additionally, we made Access policies into their own object which can be reused across multiple applications. These updates involved significant updates to the overall Access dashboard experience. The updates will be slowly rolled out to different customer cohorts. If you are an Enterprise customer and would like early access, reach out to your account team.&lt;/p&gt;
</description><pubDate>Tue, 21 Jan 2025 00:00:00 GMT</pubDate><product>Access</product></item><item><title>Gateway - Bring your own resolver IP (BYOIP) for DNS locations</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/gateway/#bring-your-own-resolver-ip-byoip-for-dns-locations</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/gateway/#bring-your-own-resolver-ip-byoip-for-dns-locations</guid><description>&lt;p&gt;Enterprise users can now &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/agentless/dns/locations/dns-resolver-ips/#bring-your-own-dns-resolver-ip&quot;&gt;provide an IP address&lt;/a&gt; for a private DNS resolver to use with &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/agentless/dns/locations/&quot;&gt;DNS locations&lt;/a&gt;. Gateway supports bringing your own IPv4 and IPv6 addresses.&lt;/p&gt;
</description><pubDate>Wed, 08 Jan 2025 00:00:00 GMT</pubDate><product>Gateway</product></item><item><title>Digital Experience Monitoring - Remote captures</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/dex/#remote-captures</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/dex/#remote-captures</guid><description>&lt;p&gt;Admins can now collect packet captures (PCAPs) and WARP diagnostic logs from end user devices. For more information, refer to &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/insights/dex/remote-captures/&quot;&gt;Remote captures&lt;/a&gt;.&lt;/p&gt;
</description><pubDate>Thu, 19 Dec 2024 00:00:00 GMT</pubDate><product>Digital Experience Monitoring</product></item><item><title>Email Security - Email Security reclassification tab</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/email-security/#email-security-reclassification-tab</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/email-security/#email-security-reclassification-tab</guid><description>&lt;p&gt;Customers can now have more transparency about their team and user submissions. The new Reclassification tab in the Zero Trust dashboard will allow customers to have a full understanding of what submissions they have made and what the outcomes of those submissions are. &lt;/p&gt;
</description><pubDate>Thu, 19 Dec 2024 00:00:00 GMT</pubDate><product>Email Security</product></item><item><title>Email Security - Email Security expanded folder scanning</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/email-security/#email-security-expanded-folder-scanning</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/email-security/#email-security-expanded-folder-scanning</guid><description>&lt;p&gt;Microsoft 365 customers can now choose to scan all folders or just the inbox when deploying via the Graph API.&lt;/p&gt;
</description><pubDate>Thu, 19 Dec 2024 00:00:00 GMT</pubDate><product>Email Security</product></item><item><title>Cloudflare Tunnel - Tunnel diagnostic logs</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/tunnel/#tunnel-diagnostic-logs</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/tunnel/#tunnel-diagnostic-logs</guid><description>&lt;p&gt;The latest &lt;code&gt;cloudflared&lt;/code&gt; build &lt;a href=&quot;https://github.com/cloudflare/cloudflared/releases/tag/2024.12.2&quot;&gt;2024.12.2&lt;/a&gt; introduces the ability to collect all the diagnostic logs needed to troubleshoot a &lt;code&gt;cloudflared&lt;/code&gt; instance. For more information, refer to &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/troubleshoot-tunnels/diag-logs/&quot;&gt;Diagnostic logs&lt;/a&gt;.&lt;/p&gt;
</description><pubDate>Thu, 19 Dec 2024 00:00:00 GMT</pubDate><product>Cloudflare Tunnel</product></item><item><title>Zero Trust WARP Client - Cloudflare One Agent for iOS (version 1.8)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#cloudflare-one-agent-for-ios-version-18</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#cloudflare-one-agent-for-ios-version-18</guid><description>&lt;p&gt;A new GA release for the iOS Cloudflare One Agent is now available in the &lt;a href=&quot;https://apps.apple.com/us/app/cloudflare-one-agent/id6443476492&quot;&gt;iOS App Store&lt;/a&gt;. This release includes support for an exciting new capability, &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/deployment/mdm-deployment/partners/intune/#per-app-vpn-for-ios&quot;&gt;per-app VPN&lt;/a&gt;. This release also includes fixes and minor improvements.&lt;/p&gt;
&lt;p&gt;Changes and improvements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Added support for per-app VPN configuration.&lt;/li&gt;
&lt;li&gt;Fixed issue where some users could not connect unless they rotated their keys after an update.&lt;/li&gt;
&lt;li&gt;Fixed a potential crash when connecting to the tunnel.&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Thu, 19 Dec 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Zero Trust WARP Client - Cloudflare One Agent for Android (version 2.3)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#cloudflare-one-agent-for-android-version-23</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#cloudflare-one-agent-for-android-version-23</guid><description>&lt;p&gt;A new GA release for the Android Cloudflare One Agent is now available in the &lt;a href=&quot;https://play.google.com/store/apps/details?id=com.cloudflare.cloudflareoneagent&quot;&gt;Google Play Store&lt;/a&gt;. This release includes support for an exciting new capability, &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/deployment/mdm-deployment/partners/intune/#per-app-vpn-for-android&quot;&gt;per-app VPN&lt;/a&gt;. This release also includes fixes and minor improvements.&lt;/p&gt;
&lt;p&gt;Changes and improvements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Added support for per-app VPN configuration.&lt;/li&gt;
&lt;li&gt;Fixed an issue where the WARP tunnel is connected immediately when &lt;strong&gt;Auto connect&lt;/strong&gt; is greater than 0.&lt;/li&gt;
&lt;li&gt;Fixed an issue where rapidly changing service modes resulted in a crash.&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Thu, 19 Dec 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Zero Trust WARP Client - WARP client for Linux (version 2024.12.554.0)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-linux-version-2024125540</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-linux-version-2024125540</guid><description>&lt;p&gt;A new GA release for the Linux WARP client is now available in the &lt;a href=&quot;https://pkg.cloudflareclient.com/&quot;&gt;package repository&lt;/a&gt;. This release includes fixes and minor improvements.&lt;/p&gt;
&lt;p&gt;Changes and improvements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Consumers can now set the tunnel protocol using &lt;code&gt;warp-cli tunnel protocol set &amp;lt;protocol&amp;gt;&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Extended diagnostics collection time in &lt;code&gt;warp-diag&lt;/code&gt; to ensure logs are captured reliably.&lt;/li&gt;
&lt;li&gt;Improved captive portal support by disabling the firewall during captive portal login flows.&lt;/li&gt;
&lt;li&gt;Improved reliability of connection establishment logic under degraded network conditions.&lt;/li&gt;
&lt;li&gt;Improved reconnection speed when a Cloudflare server is in a degraded state.&lt;/li&gt;
&lt;li&gt;Improved captive portal detection on certain public networks.&lt;/li&gt;
&lt;li&gt;Reduced connectivity interruptions on WireGuard Split Tunnel Include mode configurations.&lt;/li&gt;
&lt;li&gt;Fixed connectivity issues switching between managed network profiles with different configured protocols.&lt;/li&gt;
&lt;li&gt;QLogs are now disabled by default and can be enabled with &lt;code&gt;warp-cli debug qlog enable&lt;/code&gt;. The QLog setting from previous releases will no longer be respected.&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Thu, 19 Dec 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Zero Trust WARP Client - WARP client for Windows (version 2024.12.554.0)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-windows-version-2024125540</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-windows-version-2024125540</guid><description>&lt;p&gt;A new GA release for the Windows WARP client is now available in the &lt;a href=&quot;https://install.appcenter.ms/orgs/cloudflare/apps/1.1.1.1-windows-1/distribution_groups/release&quot;&gt;App Center&lt;/a&gt;. This release contains improvements to support custom Gateway certificate installation in addition to the changes and improvements included in version 2024.12.492.0.&lt;/p&gt;
&lt;p&gt;Changes and improvements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Adds support for installing all available custom Gateway certificates from an account to the system store.&lt;/li&gt;
&lt;li&gt;Users can now get a list of installed certificates by running &lt;code&gt;warp-cli certs&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Known issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;DNS resolution may be broken when all of the following conditions are true:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;WARP is in Secure Web Gateway without DNS filtering (tunnel-only) mode.&lt;/li&gt;
&lt;li&gt;A custom DNS server address is configured on the primary network adapter.&lt;/li&gt;
&lt;li&gt;The custom DNS server address on the primary network adapter is changed while WARP is connected.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To work around the DNS issue, reconnect the WARP client by toggling off and back on.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Thu, 19 Dec 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Zero Trust WARP Client - WARP client for macOS (version 2024.12.554.0)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-macos-version-2024125540</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-macos-version-2024125540</guid><description>&lt;p&gt;A new GA release for the macOS WARP client is now available in the &lt;a href=&quot;https://install.appcenter.ms/orgs/cloudflare/apps/1.1.1.1-macos-1/distribution_groups/release&quot;&gt;App Center&lt;/a&gt;. This release contains improvements to support custom Gateway certificate installation in addition to the changes and improvements included in version 2024.12.492.0.&lt;/p&gt;
&lt;p&gt;Note: If using macOS Sequoia, Cloudflare recommends the use of macOS 15.2 or later. With macOS 15.2, Apple addressed several issues that may have caused the WARP client to not behave as expected when used with macOS 15.0 and 15.1.&lt;/p&gt;
&lt;p&gt;Changes and improvements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Adds support for installing all available custom Gateway certificates from an account to the system store.&lt;/li&gt;
&lt;li&gt;Users can now get a list of installed certificates by running &lt;code&gt;warp-cli certs&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Known issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;macOS Sequoia: Due to changes Apple introduced in macOS 15.0.x, the WARP client may not behave as expected. Cloudflare recommends the use of macOS 15.2 or later.&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Thu, 19 Dec 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Zero Trust WARP Client - WARP client for macOS (version 2024.12.492.0)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-macos-version-2024124920</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-macos-version-2024124920</guid><description>&lt;p&gt;A new GA release for the macOS WARP client is now available in the &lt;a href=&quot;https://install.appcenter.ms/orgs/cloudflare/apps/1.1.1.1-macos-1/distribution_groups/release&quot;&gt;App Center&lt;/a&gt;. This release contains minor fixes and improvements.&lt;/p&gt;
&lt;p&gt;Note: If using macOS Sequoia, Cloudflare recommends the use of macOS 15.2 or later. With macOS 15.2, Apple addressed several issues that may have caused the WARP client to not behave as expected when used with macOS 15.0 and 15.1.&lt;/p&gt;
&lt;p&gt;Changes and improvements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Consumers can now set the tunnel protocol using &lt;code&gt;warp-cli tunnel protocol set &amp;lt;protocol&amp;gt;&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Extended diagnostics collection time in &lt;code&gt;warp-diag&lt;/code&gt; to ensure logs are captured reliably.&lt;/li&gt;
&lt;li&gt;Improved captive portal support by disabling the firewall during captive portal login flows.&lt;/li&gt;
&lt;li&gt;Improved reliability of connection establishment logic under degraded network conditions.&lt;/li&gt;
&lt;li&gt;Improved reconnection speed when a Cloudflare server is in a degraded state.&lt;/li&gt;
&lt;li&gt;Improved captive portal detection on certain public networks.&lt;/li&gt;
&lt;li&gt;Fixed an issue where admin override displayed an incorrect override end time.&lt;/li&gt;
&lt;li&gt;Reduced connectivity interruptions on WireGuard Split Tunnel Include mode configurations.&lt;/li&gt;
&lt;li&gt;Fixed connectivity issues switching between managed network profiles with different configured protocols.&lt;/li&gt;
&lt;li&gt;QLogs are now disabled by default and can be enabled with &lt;code&gt;warp-cli debug qlog enable&lt;/code&gt;. The QLog setting from previous releases will no longer be respected.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Known issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;macOS Sequoia: Due to changes Apple introduced in macOS 15.0.x, the WARP client may not behave as expected. Cloudflare recommends the use of macOS 15.2 or later.&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Wed, 18 Dec 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Zero Trust WARP Client - WARP client for Windows (version 2024.12.492.0)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-windows-version-2024124920</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-windows-version-2024124920</guid><description>&lt;p&gt;A new GA release for the Windows WARP client is now available in the &lt;a href=&quot;https://install.appcenter.ms/orgs/cloudflare/apps/1.1.1.1-windows-1/distribution_groups/release&quot;&gt;App Center&lt;/a&gt;. This release contains minor fixes and improvements.&lt;/p&gt;
&lt;p&gt;Changes and improvements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Consumers can now set the tunnel protocol using &lt;code&gt;warp-cli tunnel protocol set &amp;lt;protocol&amp;gt;&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Extended diagnostics collection time in &lt;code&gt;warp-diag&lt;/code&gt; to ensure logs are captured reliably.&lt;/li&gt;
&lt;li&gt;Improved captive portal support by disabling the firewall during captive portal login flows.&lt;/li&gt;
&lt;li&gt;Improved captive portal detection on certain public networks.&lt;/li&gt;
&lt;li&gt;Improved reconnection speed when a Cloudflare server is in a degraded state.&lt;/li&gt;
&lt;li&gt;Fixed an issue where WARP may fail to remove certificates from the user store in Device Information Only mode.&lt;/li&gt;
&lt;li&gt;Ensured at most one Powershell instance is opened when fetching the device serial number for posture checks.&lt;/li&gt;
&lt;li&gt;Fixed an issue to prevent the daemon from following Windows junctions created by non-admin users that could be used to delete files as SYSTEM user and potentially gain SYSTEM user privileges.&lt;/li&gt;
&lt;li&gt;Improved reliability of connection establishment logic under degraded network conditions.&lt;/li&gt;
&lt;li&gt;Fixed an issue that caused high memory usage when viewing connection statistics for extended periods of time.&lt;/li&gt;
&lt;li&gt;Improved WARP connectivity in environments with virtual interfaces from VirtualBox, VMware, and similar tools.&lt;/li&gt;
&lt;li&gt;Reduced connectivity interruptions on WireGuard Split Tunnel Include mode configurations.&lt;/li&gt;
&lt;li&gt;Fixed connectivity issues switching between managed network profiles with different configured protocols.&lt;/li&gt;
&lt;li&gt;QLogs are now disabled by default and can be enabled with &lt;code&gt;warp-cli debug qlog enable&lt;/code&gt;. The QLog setting from previous releases will no longer be respected.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Known issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;DNS resolution may be broken when all of the following conditions are true:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;WARP is in Secure Web Gateway without DNS filtering (tunnel-only) mode.&lt;/li&gt;
&lt;li&gt;A custom DNS server address is configured on the primary network adapter.&lt;/li&gt;
&lt;li&gt;The custom DNS server address on the primary network adapter is changed while WARP is connected.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To work around the DNS issue, reconnect the WARP client by toggling off and back on.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Wed, 18 Dec 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Magic Transit - BGP support for Cloudflare Network Interconnect (CNI)</title><link>https://developers.cloudflare.com/magic-transit/changelog/#bgp-support-for-cloudflare-network-interconnect-cni</link><guid isPermaLink="true">https://developers.cloudflare.com/magic-transit/changelog/#bgp-support-for-cloudflare-network-interconnect-cni</guid><description>&lt;p&gt;Magic Transit customers can now establish BGP peering over Direct CNI circuits. Customers can now dynamically exchange routes and path availability status between their router device and the Magic Transit routing table.&lt;/p&gt;
</description><pubDate>Tue, 17 Dec 2024 00:00:00 GMT</pubDate><product>Magic Transit</product></item><item><title>Magic WAN - Magic WAN Connector configurable health checks</title><link>https://developers.cloudflare.com/magic-wan/changelog/#magic-wan-connector-configurable-health-checks</link><guid isPermaLink="true">https://developers.cloudflare.com/magic-wan/changelog/#magic-wan-connector-configurable-health-checks</guid><description>&lt;p&gt;Health check rate on Magic WAN Connector IPsec tunnels are now configurable.&lt;/p&gt;
</description><pubDate>Tue, 17 Dec 2024 00:00:00 GMT</pubDate><product>Magic WAN</product></item><item><title>Magic WAN - BGP support for Cloudflare Network Interconnect (CNI)</title><link>https://developers.cloudflare.com/magic-wan/changelog/#bgp-support-for-cloudflare-network-interconnect-cni</link><guid isPermaLink="true">https://developers.cloudflare.com/magic-wan/changelog/#bgp-support-for-cloudflare-network-interconnect-cni</guid><description>&lt;p&gt;Magic WAN customers can now establish BGP peering over Direct CNI circuits. Customers can now dynamically exchange routes and path availability status between their router device and the Magic WAN table.&lt;/p&gt;
</description><pubDate>Tue, 17 Dec 2024 00:00:00 GMT</pubDate><product>Magic WAN</product></item><item><title>Cloudflare Network Interconnect - BGP support for Cloudflare Network Interconnect (CNI)</title><link>https://developers.cloudflare.com/network-interconnect/changelog/#bgp-support-for-cloudflare-network-interconnect-cni</link><guid isPermaLink="true">https://developers.cloudflare.com/network-interconnect/changelog/#bgp-support-for-cloudflare-network-interconnect-cni</guid><description>&lt;p&gt;Magic WAN and Magic Transit customers can now establish BGP peering over Direct CNI circuits. Customers can now dynamically exchange routes and path availability status between their router device and the Magic WAN or Magic Transit routing table.&lt;/p&gt;
</description><pubDate>Tue, 17 Dec 2024 00:00:00 GMT</pubDate><product>Cloudflare Network Interconnect</product></item><item><title>Zero Trust WARP Client - WARP client for Windows (version 2024.12.326.1)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-windows-version-2024123261</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-windows-version-2024123261</guid><description>&lt;p&gt;A new beta release for the Windows WARP client is now available in the &lt;a href=&quot;https://install.appcenter.ms/orgs/cloudflare/apps/1.1.1.1-windows-1/distribution_groups/release/beta&quot;&gt;App Center&lt;/a&gt;. This release includes an exciting new capability, WARP support for &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/deployment/mdm-deployment/windows-multiuser/&quot;&gt;multiple users on a shared Windows device&lt;/a&gt;. The release also contains minor fixes and improvements.&lt;/p&gt;
&lt;p&gt;Changes and improvements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Fixed connectivity issues switching between managed network profiles with different configured protocols.&lt;/li&gt;
&lt;li&gt;Added support for multiple users on shared Windows 10 and Windows 11 devices. Once a user completes the Windows login, all traffic to Cloudflare will be attributed to the currently active Windows user account. Contact your Customer Success Manager to request participation in this beta.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Known issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;DNS resolution may be broken when all of the following conditions are true:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;WARP is in Secure Web Gateway without DNS filtering (tunnel-only) mode.&lt;/li&gt;
&lt;li&gt;A custom DNS server address is configured on the primary network adapter.&lt;/li&gt;
&lt;li&gt;The custom DNS server address on the primary network adapter is changed while WARP is connected.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To work around the DNS issue, reconnect the WARP client by toggling off and back on.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Fri, 13 Dec 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Magic Cloud Networking - Download cloud onramp terraform</title><link>https://developers.cloudflare.com/magic-cloud-networking/changelog/#download-cloud-onramp-terraform</link><guid isPermaLink="true">https://developers.cloudflare.com/magic-cloud-networking/changelog/#download-cloud-onramp-terraform</guid><description>&lt;p&gt;Customers can now generate customized terraform files for building cloud network on-ramps to Magic WAN. Magic Cloud can scan and discover existing network resources and generate the required terraform files to automate cloud resource deployment using their existing infrastructure-as-code workflows for cloud automation.&lt;/p&gt;
</description><pubDate>Thu, 05 Dec 2024 00:00:00 GMT</pubDate><product>Magic Cloud Networking</product></item><item><title>Zero Trust WARP Client - WARP client for Windows (version 2024.11.688.1)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-windows-version-2024116881</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-windows-version-2024116881</guid><description>&lt;p&gt;A new beta release for the Windows WARP client is now available in the &lt;a href=&quot;https://install.appcenter.ms/orgs/cloudflare/apps/1.1.1.1-windows-1/distribution_groups/release/beta&quot;&gt;App Center&lt;/a&gt;. This release contains minor fixes and improvements.&lt;/p&gt;
&lt;p&gt;Changes and improvements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Consumers can now set the tunnel protocol using &lt;code&gt;warp-cli tunnel protocol set &amp;lt;protocol&amp;gt;&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Extended diagnostics collection time in &lt;code&gt;warp-diag&lt;/code&gt; to ensure logs are captured reliably.&lt;/li&gt;
&lt;li&gt;Improved captive portal support by disabling the firewall during captive portal login flows.&lt;/li&gt;
&lt;li&gt;Improved captive portal detection on certain public networks.&lt;/li&gt;
&lt;li&gt;Improved reconnection speed when a Cloudflare server is in a degraded state.&lt;/li&gt;
&lt;li&gt;Fixed an issue where WARP may fail to remove certificates from the user store in Device Information Only mode.&lt;/li&gt;
&lt;li&gt;Ensured at most one Powershell instance is opened when fetching the device serial number for posture checks.&lt;/li&gt;
&lt;li&gt;Fixed an issue to prevent the daemon from following Windows junctions created by non-admin users that could be used to delete files as SYSTEM user and potentially gain SYSTEM user privileges.&lt;/li&gt;
&lt;li&gt;Improved reliability of connection establishment logic under degraded network conditions.&lt;/li&gt;
&lt;li&gt;Fixed an issue that caused high memory usage when viewing connection statistics for extended periods of time.&lt;/li&gt;
&lt;li&gt;Improved WARP connectivity in environments with virtual interfaces from VirtualBox, VMware, and similar tools.&lt;/li&gt;
&lt;li&gt;Reduced connectivity interruptions on WireGuard Split Tunnel Include mode configurations.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Known issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;DNS resolution may be broken when all of the following conditions are true:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;WARP is in Secure Web Gateway without DNS filtering (tunnel-only) mode.&lt;/li&gt;
&lt;li&gt;A custom DNS server address is configured on the primary network adapter.&lt;/li&gt;
&lt;li&gt;The custom DNS server address on the primary network adapter is changed while WARP is connected.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To work around the DNS issue, reconnect the WARP client by toggling off and back on.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Thu, 05 Dec 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Zero Trust WARP Client - WARP client for macOS (version 2024.11.688.1)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-macos-version-2024116881</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-macos-version-2024116881</guid><description>&lt;p&gt;A new beta release for the macOS WARP client is now available in the &lt;a href=&quot;https://install.appcenter.ms/orgs/cloudflare/apps/1.1.1.1-macos-1/distribution_groups/release/beta&quot;&gt;App Center&lt;/a&gt;. This release contains minor fixes and improvements.&lt;/p&gt;
&lt;p&gt;Note: If using macOS Sequoia, Cloudflare recommends the use of macOS 15.1 or later. With macOS 15.1, Apple addressed several issues that may have caused the WARP client to not behave as expected when used with macOS 15.0.x.&lt;/p&gt;
&lt;p&gt;Changes and improvements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Consumers can now set the tunnel protocol using &lt;code&gt;warp-cli tunnel protocol set &amp;lt;protocol&amp;gt;&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Extended diagnostics collection time in &lt;code&gt;warp-diag&lt;/code&gt; to ensure logs are captured reliably.&lt;/li&gt;
&lt;li&gt;Improved captive portal support by disabling the firewall during captive portal login flows.&lt;/li&gt;
&lt;li&gt;Improved reliability of connection establishment logic under degraded network conditions.&lt;/li&gt;
&lt;li&gt;Improved reconnection speed when a Cloudflare server is in a degraded state.&lt;/li&gt;
&lt;li&gt;Improved captive portal detection on certain public networks.&lt;/li&gt;
&lt;li&gt;Fixed an issue where admin override displayed an incorrect override end time.&lt;/li&gt;
&lt;li&gt;Reduced connectivity interruptions on WireGuard Split Tunnel Include mode configurations.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Known issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;macOS Sequoia: Due to changes Apple introduced in macOS 15.0.x, the WARP client may not behave as expected. Cloudflare recommends the use of macOS 15.1 or later.&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Thu, 05 Dec 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Access - SCIM GA for Okta and Microsoft Entra ID</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/access/#scim-ga-for-okta-and-microsoft-entra-id</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/access/#scim-ga-for-okta-and-microsoft-entra-id</guid><description>&lt;p&gt;Cloudflare&amp;#39;s SCIM integrations with &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/identity/idp-integration/okta/#synchronize-users-and-groups&quot;&gt;Okta&lt;/a&gt; and &lt;a href=&quot;https://developers.cloudflare.com//cloudflare-one/identity/idp-integration/entra-id/#synchronize-users-and-groups&quot;&gt;Microsoft Entra ID&lt;/a&gt; (formerly AzureAD) are now out of beta and generally available (GA) for all customers. These integrations can be used for Access and Gateway policies and Zero Trust user management. Note: This GA release does not include &lt;a href=&quot;https://developers.cloudflare.com/fundamentals/setup/account/account-security/scim-setup/&quot;&gt;Dashboard SSO SCIM&lt;/a&gt; support.&lt;/p&gt;
</description><pubDate>Wed, 04 Dec 2024 00:00:00 GMT</pubDate><product>Access</product></item><item><title>Zero Trust WARP Client - Custom device posture integration</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#custom-device-posture-integration</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#custom-device-posture-integration</guid><description>&lt;p&gt;WARP now supports setting up &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/identity/devices/service-providers/custom/&quot;&gt;custom device posture integrations&lt;/a&gt; using a third-party API of your choice.&lt;/p&gt;
</description><pubDate>Wed, 04 Dec 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>DLP - Profile confidence levels</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/dlp/#profile-confidence-levels</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/dlp/#profile-confidence-levels</guid><description>&lt;p&gt;DLP profiles now support setting a &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/policies/data-loss-prevention/dlp-profiles/advanced-settings/#confidence-levels&quot;&gt;confidence level&lt;/a&gt; to choose how tolerant its detections are to false positives based on the context of the detection. The higher a profile&amp;#39;s confidence level is, the less false positives will be allowed. Confidence levels include Low, Medium, or High. DLP profile confidence levels supersede &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/policies/data-loss-prevention/dlp-profiles/advanced-settings/#context-analysis&quot;&gt;context analysis&lt;/a&gt;.&lt;/p&gt;
</description><pubDate>Mon, 25 Nov 2024 00:00:00 GMT</pubDate><product>DLP</product></item><item><title>CASB - CASB and DLP with Cloud Data Extraction for AWS cloud environments</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/casb/#casb-and-dlp-with-cloud-data-extraction-for-aws-cloud-environments</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/casb/#casb-and-dlp-with-cloud-data-extraction-for-aws-cloud-environments</guid><description>&lt;p&gt;You can now use CASB to find security misconfigurations in your AWS cloud environment. You can also &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/applications/casb/casb-integrations/aws-s3/#compute-account&quot;&gt;connect your AWS compute account&lt;/a&gt; to extract and scan your S3 buckets for sensitive data while avoiding egress fees.&lt;/p&gt;
</description><pubDate>Fri, 22 Nov 2024 00:00:00 GMT</pubDate><product>CASB</product></item><item><title>Magic Cloud Networking - Import cloud resources for VMs and LBs</title><link>https://developers.cloudflare.com/magic-cloud-networking/changelog/#import-cloud-resources-for-vms-and-lbs</link><guid isPermaLink="true">https://developers.cloudflare.com/magic-cloud-networking/changelog/#import-cloud-resources-for-vms-and-lbs</guid><description>&lt;p&gt;Cloud network discovery now includes cloud native virtual machine (VM) and load-balancer (LB) resources.&lt;/p&gt;
</description><pubDate>Thu, 21 Nov 2024 00:00:00 GMT</pubDate><product>Magic Cloud Networking</product></item><item><title>Magic Cloud Networking - Export resource catalog</title><link>https://developers.cloudflare.com/magic-cloud-networking/changelog/#export-resource-catalog</link><guid isPermaLink="true">https://developers.cloudflare.com/magic-cloud-networking/changelog/#export-resource-catalog</guid><description>&lt;p&gt;Customers can export their resource catalog including all discovered resource metadata to a downloadable JSON file, suitable for offline analysis.&lt;/p&gt;
</description><pubDate>Thu, 21 Nov 2024 00:00:00 GMT</pubDate><product>Magic Cloud Networking</product></item><item><title>Gateway - Category filtering in the network policy builder</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/gateway/#category-filtering-in-the-network-policy-builder</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/gateway/#category-filtering-in-the-network-policy-builder</guid><description>&lt;p&gt;Gateway users can now create network policies with the &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/policies/gateway/network-policies/#content-categories&quot;&gt;Content Categories&lt;/a&gt; and &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/policies/gateway/network-policies/#security-risks&quot;&gt;Security Risks&lt;/a&gt; traffic selectors. This update simplifies malicious traffic blocking and streamlines network monitoring for improved security management.&lt;/p&gt;
</description><pubDate>Wed, 20 Nov 2024 00:00:00 GMT</pubDate><product>Gateway</product></item><item><title>Zero Trust WARP Client - MASQUE GA</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#masque-ga</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#masque-ga</guid><description>&lt;p&gt;MASQUE as a device tunnel protocol option is now generally available (GA). Refer to &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/configure-warp/warp-settings/#device-tunnel-protocol&quot;&gt;Device tunnel protocol&lt;/a&gt; for configuration details and minimum WARP client requirements.&lt;/p&gt;
</description><pubDate>Tue, 19 Nov 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Zero Trust WARP Client - WARP client for macOS (version 2024.11.309.0)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-macos-version-2024113090</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-macos-version-2024113090</guid><description>&lt;p&gt;A new GA release for the macOS WARP client is now available in the &lt;a href=&quot;https://install.appcenter.ms/orgs/cloudflare/apps/1.1.1.1-macos-1/distribution_groups/release&quot;&gt;App Center&lt;/a&gt;. This release contains minor fixes and improvements.&lt;/p&gt;
&lt;p&gt;Changes and improvements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Fixed an issue where SSH sessions and other application connections over TCP or UDP could drop when a device that is using MASQUE changes its primary network interface.&lt;/li&gt;
&lt;li&gt;Fixed an issue to ensure the Cloudflare root certificate (or custom certificate) is installed in the trust store if not already there.&lt;/li&gt;
&lt;li&gt;Fixed an issue with the WARP client becoming unresponsive during startup.&lt;/li&gt;
&lt;li&gt;Extended &lt;code&gt;warp-diag&lt;/code&gt; to collect system profiler firewall state as part of diagnostics.&lt;/li&gt;
&lt;li&gt;Fixed an issue with the WARP client becoming unresponsive while handling LAN inclusion.&lt;/li&gt;
&lt;li&gt;Fixed an issue where users were unable to connect with an IPC error message displayed in the UI.&lt;/li&gt;
&lt;li&gt;Fixed an issue that was preventing proper operation of DNS-over-TLS (DoT) for consumer users.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Known issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;macOS Sequoia: Due to changes Apple introduced in macOS 15.0.x, the WARP client may not behave as expected. Cloudflare recommends the use of macOS 15.1 or later.&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Mon, 18 Nov 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Zero Trust WARP Client - WARP client for Windows (version 2024.11.309.0)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-windows-version-2024113090</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-windows-version-2024113090</guid><description>&lt;p&gt;A new GA release for the Windows WARP client is now available in the &lt;a href=&quot;https://install.appcenter.ms/orgs/cloudflare/apps/1.1.1.1-windows-1/distribution_groups/release&quot;&gt;App Center&lt;/a&gt;. This release contains minor fixes and improvements.&lt;/p&gt;
&lt;p&gt;Changes and improvements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Fixed an issue where SSH sessions and other application connections over TCP or UDP could drop when a device that is using MASQUE changes its primary network interface.&lt;/li&gt;
&lt;li&gt;Fixed an issue to ensure the Cloudflare root certificate (or custom certificate) is installed in the trust store if not already there.&lt;/li&gt;
&lt;li&gt;Fixed an issue with the WARP client becoming unresponsive during startup.&lt;/li&gt;
&lt;li&gt;Extended diagnostics collection time in &lt;code&gt;warp-diag&lt;/code&gt; to ensure logs are captured reliably.&lt;/li&gt;
&lt;li&gt;Fixed an issue that was preventing proper operation of DNS-over-TLS (DoT) for consumer users.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Known issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;DNS resolution may be broken when all of the following conditions are true:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;WARP is in Secure Web Gateway without DNS filtering (tunnel-only) mode.&lt;/li&gt;
&lt;li&gt;A custom DNS server address is configured on the primary network adapter.&lt;/li&gt;
&lt;li&gt;The custom DNS server address on the primary network adapter is changed while WARP is connected.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To work around the DNS issue, reconnect the WARP client by toggling off and back on.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Mon, 18 Nov 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Zero Trust WARP Client - WARP client for Linux (version 2024.11.309.0)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-linux-version-2024113090</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-linux-version-2024113090</guid><description>&lt;p&gt;A new GA release for the Linux WARP client is now available in the &lt;a href=&quot;https://pkg.cloudflareclient.com/&quot;&gt;package repository&lt;/a&gt;. This release contains reliability improvements and general bug fixes.&lt;/p&gt;
&lt;p&gt;Changes and improvements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Fixed an issue where SSH sessions and other connections ould drop when a device that is using MASQUE changes its primary network interface.&lt;/li&gt;
&lt;li&gt;Device posture client certificate checks now support PKCS#1.&lt;/li&gt;
&lt;li&gt;Fixed an issue to ensure the Cloudflare root certificate (or custom certificate) is installed in the trust store if not already there.&lt;/li&gt;
&lt;li&gt;Reduced unnecessary log messages when &lt;code&gt;resolv.conf&lt;/code&gt; has no owner.&lt;/li&gt;
&lt;li&gt;Fixed an issue with &lt;code&gt;warp-diag&lt;/code&gt; printing benign TLS certificate errors.&lt;/li&gt;
&lt;li&gt;Fixed an issue with the WARP client becoming unresponsive during startup.&lt;/li&gt;
&lt;li&gt;Extended diagnostics collection time in &lt;code&gt;warp-diag&lt;/code&gt; to ensure logs are captured reliably.&lt;/li&gt;
&lt;li&gt;Fixed an issue that was preventing proper operation of DNS-over-TLS (DoT) for consumer users.&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Mon, 18 Nov 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>DLP - Send entire HTTP requests to a Logpush destination</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/dlp/#send-entire-http-requests-to-a-logpush-destination</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/dlp/#send-entire-http-requests-to-a-logpush-destination</guid><description>&lt;p&gt;In addition to &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/policies/data-loss-prevention/dlp-policies/logging-options/#log-the-payload-of-matched-rules&quot;&gt;logging the payload&lt;/a&gt; from HTTP requests that matched a DLP policy in Cloudflare Logs, Enterprise users can now configure a &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/policies/data-loss-prevention/dlp-policies/logging-options/#send-http-requests-to-logpush-destination&quot;&gt;Logpush job&lt;/a&gt; to send the entire HTTP request that triggered a DLP match to a storage destination. This allows long-term storage of full requests for use in forensic investigation.&lt;/p&gt;
</description><pubDate>Fri, 01 Nov 2024 00:00:00 GMT</pubDate><product>DLP</product></item><item><title>Zero Trust WARP Client - WARP client for macOS (version 2024.10.279.1)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-macos-version-2024102791</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-macos-version-2024102791</guid><description>&lt;p&gt;A new beta release for the macOS WARP client is now available in the &lt;a href=&quot;https://install.appcenter.ms/orgs/cloudflare/apps/1.1.1.1-macos/distribution_groups/beta&quot;&gt;App Center&lt;/a&gt;. This release contains minor fixes and improvements.&lt;/p&gt;
&lt;p&gt;Changes and improvements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Fixed an issue where SSH sessions and other application connections over TCP or UDP could drop when a device that is using MASQUE changes its primary network interface.&lt;/li&gt;
&lt;li&gt;Fixed an issue to ensure the Cloudflare root certificate (or custom certificate) is installed in the trust store if not already there.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Known issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Cloudflare is investigating temporary networking issues on macOS 15 (Sequoia) that affect some users and may occur on any version of the WARP client.&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Wed, 23 Oct 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Zero Trust WARP Client - WARP client for Windows (version 2024.10.279.1)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-windows-version-2024102791</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-windows-version-2024102791</guid><description>&lt;p&gt;A new beta release for the Windows WARP client is now available in the &lt;a href=&quot;https://install.appcenter.ms/orgs/cloudflare/apps/1.1.1.1-windows/distribution_groups/beta&quot;&gt;App Center&lt;/a&gt;. This release contains minor fixes and improvements.&lt;/p&gt;
&lt;p&gt;Changes and improvements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Fixed an issue where SSH sessions and other application connections over TCP or UDP could drop when a device that is using MASQUE changes its primary network interface.&lt;/li&gt;
&lt;li&gt;Fixed an issue to ensure the Cloudflare root certificate (or custom certificate) is installed in the trust store if not already there.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Known issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;DNS resolution may be broken when all of the following conditions are true:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;WARP is in Secure Web Gateway without DNS filtering (tunnel-only) mode.&lt;/li&gt;
&lt;li&gt;A custom DNS server address is configured on the primary network adapter.&lt;/li&gt;
&lt;li&gt;The custom DNS server address on the primary network adapter is changed while WARP is connected.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To work around the DNS issue, reconnect the WARP client by toggling off and back on.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Wed, 23 Oct 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Gateway - Per-account Cloudflare root certificate</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/gateway/#per-account-cloudflare-root-certificate</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/gateway/#per-account-cloudflare-root-certificate</guid><description>&lt;p&gt;Gateway users can now generate &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/user-side-certificates/&quot;&gt;unique root CAs&lt;/a&gt; for their Zero Trust account. Both generated certificate and custom certificate users must &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/user-side-certificates/#activate-a-root-certificate&quot;&gt;activate a root certificate&lt;/a&gt; to use it for inspection. Per-account certificates replace the default Cloudflare certificate, which is set to expire on 2025-02-02.&lt;/p&gt;
</description><pubDate>Thu, 17 Oct 2024 00:00:00 GMT</pubDate><product>Gateway</product></item><item><title>Cloudflare Tunnel - Simplifed WARP Connector deployment</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/tunnel/#simplifed-warp-connector-deployment</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/tunnel/#simplifed-warp-connector-deployment</guid><description>&lt;p&gt;You can now deploy WARP Connector using a simplified, guided workflow similar to &lt;code&gt;cloudflared&lt;/code&gt; connectors. For detailed instructions, refer to the &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/private-net/warp-connector/&quot;&gt;WARP Connector documentation&lt;/a&gt;.&lt;/p&gt;
</description><pubDate>Thu, 17 Oct 2024 00:00:00 GMT</pubDate><product>Cloudflare Tunnel</product></item><item><title>Gateway - Time-based policy duration</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/gateway/#time-based-policy-duration</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/gateway/#time-based-policy-duration</guid><description>&lt;p&gt;Gateway now offers &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/policies/gateway/dns-policies/timed-policies/#time-based-policy-duration&quot;&gt;time-based DNS policy duration&lt;/a&gt;. With policy duration, you can configure a duration of time for a policy to turn on or set an exact date and time to turn a policy off.&lt;/p&gt;
</description><pubDate>Thu, 10 Oct 2024 00:00:00 GMT</pubDate><product>Gateway</product></item><item><title>Cloudflare Tunnel - Bugfix for --grace-period</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/tunnel/#bugfix-for---grace-period</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/tunnel/#bugfix-for---grace-period</guid><description>&lt;p&gt;The new &lt;code&gt;cloudflared&lt;/code&gt; build &lt;a href=&quot;https://github.com/cloudflare/cloudflared/releases/tag/2024.10.0&quot;&gt;2024.10.0&lt;/a&gt; has a bugfix related to the &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/configure-tunnels/tunnel-run-parameters/#grace-period&quot;&gt;--grace-period&lt;/a&gt; tunnel run parameter. &lt;code&gt;cloudflared&lt;/code&gt; connectors will now abide by the specified waiting period before forcefully closing connections to Cloudflare&amp;#39;s network.&lt;/p&gt;
</description><pubDate>Thu, 10 Oct 2024 00:00:00 GMT</pubDate><product>Cloudflare Tunnel</product></item><item><title>Gateway - Expanded Gateway log fields</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/gateway/#expanded-gateway-log-fields</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/gateway/#expanded-gateway-log-fields</guid><description>&lt;p&gt;Gateway now offers new fields in &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/insights/logs/gateway-logs/&quot;&gt;activity logs&lt;/a&gt; for DNS, network, and HTTP policies to provide greater insight into your users&amp;#39; traffic routed through Gateway.&lt;/p&gt;
</description><pubDate>Fri, 04 Oct 2024 00:00:00 GMT</pubDate><product>Gateway</product></item><item><title>Zero Trust WARP Client - WARP client for Linux (version 2024.9.346.0)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-linux-version-202493460</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-linux-version-202493460</guid><description>&lt;p&gt;A new GA release for the Linux WARP client is now available in the &lt;a href=&quot;https://pkg.cloudflareclient.com/&quot;&gt;package repository&lt;/a&gt;. This release contains minor fixes and minor improvements.&lt;/p&gt;
&lt;p&gt;Notable updates:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Added &lt;code&gt;target list&lt;/code&gt; to the &lt;code&gt;warp-cli&lt;/code&gt; to enhance the user experience with the &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/use-cases/ssh/ssh-infrastructure-access/&quot;&gt;Access for Infrastructure SSH&lt;/a&gt; solution.&lt;/li&gt;
&lt;li&gt;Added the ability to customize PCAP options in the &lt;code&gt;warp-cli&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Added a list of installed applications in &lt;code&gt;warp-diag&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Added a &lt;code&gt;tunnel reset mtu&lt;/code&gt; subcommand to the &lt;code&gt;warp-cli&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Added the ability for &lt;code&gt;warp-cli&lt;/code&gt; to use the team name provided in the MDM file for initial registration.&lt;/li&gt;
&lt;li&gt;Added a JSON output option to the &lt;code&gt;warp-cli&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Added the ability to execute a PCAP on multiple interfaces with &lt;code&gt;warp-cli&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Added MASQUE tunnel protocol support for the consumer version of WARP (&lt;a href=&quot;https://developers.cloudflare.com/warp-client/&quot;&gt;1.1.1.1 w/ WARP&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;Improved the performance of firewall operations when enforcing split tunnel configuration.&lt;/li&gt;
&lt;li&gt;Fixed an issue where device posture certificate checks were unexpectedly failing.&lt;/li&gt;
&lt;li&gt;Fixed an issue where the Linux GUI fails to open the browser login window when registering a new Zero Trust organization.&lt;/li&gt;
&lt;li&gt;Fixed an issue where clients using service tokens failed to retry after a network change.&lt;/li&gt;
&lt;li&gt;Fixed an issue where the client, when switching between WireGuard and MASQUE protocols, sometimes required a manual tunnel key reset.&lt;/li&gt;
&lt;li&gt;Fixed a known issue which required users to re-register when an older single configuration MDM file was deployed after deploying the newer, multiple configuration format.&lt;/li&gt;
&lt;li&gt;Deprecated &lt;code&gt;warp-cli&lt;/code&gt; commands have been removed. If you have any workflows that use the deprecated commands, update to the new commands where necessary.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Known issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Using MASQUE as the tunnel protocol may be incompatible if your organization has Regional Services is enabled.&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Thu, 03 Oct 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Zero Trust WARP Client - WARP client for Windows (version 2024.9.346.0)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-windows-version-202493460</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-windows-version-202493460</guid><description>&lt;p&gt;A new GA release for the Windows WARP client is now available in the &lt;a href=&quot;https://install.appcenter.ms/orgs/cloudflare/apps/1.1.1.1-windows-1/distribution_groups/release&quot;&gt;App Center&lt;/a&gt;. This release contains minor fixes and improvements.&lt;/p&gt;
&lt;p&gt;Notable updates:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Added &lt;code&gt;target list&lt;/code&gt; to the &lt;code&gt;warp-cli&lt;/code&gt; to enhance the user experience with the &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/use-cases/ssh/ssh-infrastructure-access/&quot;&gt;Access for Infrastructure SSH&lt;/a&gt; solution.&lt;/li&gt;
&lt;li&gt;Added &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/deployment/mdm-deployment/windows-prelogin/&quot;&gt;pre-login&lt;/a&gt; configuration details to the &lt;code&gt;warp-diag&lt;/code&gt; output.&lt;/li&gt;
&lt;li&gt;Added a &lt;code&gt;tunnel reset mtu&lt;/code&gt; subcommand to the &lt;code&gt;warp-cli&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Added a JSON output option to the &lt;code&gt;warp-cli&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Added the ability for &lt;code&gt;warp-cli&lt;/code&gt; to use the team name provided in the MDM file for initial registration.&lt;/li&gt;
&lt;li&gt;Added the ability to execute a PCAP on multiple interfaces with &lt;code&gt;warp-cli&lt;/code&gt; and &lt;code&gt;warp-dex&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Improved &lt;code&gt;warp-dex&lt;/code&gt; default interface selection for PCAPs and changed &lt;code&gt;warp-dex&lt;/code&gt; CLI output to JSON.&lt;/li&gt;
&lt;li&gt;Fixed an issue where the client, when switching between WireGuard and MASQUE protocols, sometimes required a manual tunnel key reset.&lt;/li&gt;
&lt;li&gt;Added MASQUE tunnel protocol support for the consumer version of WARP (&lt;a href=&quot;https://developers.cloudflare.com/warp-client/&quot;&gt;1.1.1.1 w/ WARP&lt;/a&gt;).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Known issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Using MASQUE as the tunnel protocol may be incompatible if your organization has Regional Services is enabled.&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Thu, 03 Oct 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Zero Trust WARP Client - WARP client for macOS (version 2024.9.346.0)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-macos-version-202493460</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-macos-version-202493460</guid><description>&lt;p&gt;A new GA release for the macOS WARP client is now available in the &lt;a href=&quot;https://install.appcenter.ms/orgs/cloudflare/apps/1.1.1.1-macos-1/distribution_groups/release&quot;&gt;App Center&lt;/a&gt;. This release contains minor fixes and improvements.&lt;/p&gt;
&lt;p&gt;All customers running macOS Ventura 13.0 and above (including Sequoia) are advised to upgrade to this release. This release fixes an incompatibility with the firewall found on macOS Sonoma 14.4 and above that could result in the firewall being disabled.&lt;/p&gt;
&lt;p&gt;Notable updates:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Added &lt;code&gt;target list&lt;/code&gt; to the &lt;code&gt;warp-cli&lt;/code&gt; to enhance the user experience with the &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/use-cases/ssh/ssh-infrastructure-access/&quot;&gt;Access for Infrastructure SSH&lt;/a&gt; solution.&lt;/li&gt;
&lt;li&gt;Added a &lt;code&gt;tunnel reset mtu&lt;/code&gt; subcommand to the &lt;code&gt;warp-cli&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Added the ability for &lt;code&gt;warp-cli&lt;/code&gt; to use the team name provided in the MDM file for initial registration.&lt;/li&gt;
&lt;li&gt;Added a JSON output option to the &lt;code&gt;warp-cli&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Added the ability to execute a PCAP on multiple interfaces with &lt;code&gt;warp-cli&lt;/code&gt; and &lt;code&gt;warp-dex&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Improved &lt;code&gt;warp-dex&lt;/code&gt; default interface selection for PCAPs and changed &lt;code&gt;warp-dex&lt;/code&gt; CLI output to JSON.&lt;/li&gt;
&lt;li&gt;Improved &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/identity/devices/warp-client-checks/application-check/&quot;&gt;application posture check&lt;/a&gt; compatibility with symbolically linked files.&lt;/li&gt;
&lt;li&gt;Fixed an issue where the client, when switching between WireGuard and MASQUE protocols, sometimes required a manual tunnel key reset.&lt;/li&gt;
&lt;li&gt;Added MASQUE tunnel protocol support for the consumer version of WARP (&lt;a href=&quot;https://developers.cloudflare.com/warp-client/&quot;&gt;1.1.1.1 w/ WARP&lt;/a&gt;).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Known issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Using MASQUE as the tunnel protocol may be incompatible if your organization has Regional Services is enabled.&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Thu, 03 Oct 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Magic Firewall - New UI improvements</title><link>https://developers.cloudflare.com/magic-firewall/changelog/#new-ui-improvements</link><guid isPermaLink="true">https://developers.cloudflare.com/magic-firewall/changelog/#new-ui-improvements</guid><description>&lt;p&gt;The dashboard now allows you to search custom rules using the rule name and/or ID. Additionally, the rule ID URL link has been added to Network Analytics. Go to &lt;strong&gt;Analytics &amp;amp; Logs&lt;/strong&gt; &amp;gt; &lt;strong&gt;Network Analytics&lt;/strong&gt; &amp;gt; &lt;strong&gt;Magic Firewall&lt;/strong&gt; &amp;gt; &lt;strong&gt;Packet sample log&lt;/strong&gt; &amp;gt; Search for &lt;strong&gt;Rule ID&lt;/strong&gt;.&lt;/p&gt;
</description><pubDate>Wed, 02 Oct 2024 00:00:00 GMT</pubDate><product>Magic Firewall</product></item><item><title>Magic Cloud Networking - Cost visibility for managed cloud configuration</title><link>https://developers.cloudflare.com/magic-cloud-networking/changelog/#cost-visibility-for-managed-cloud-configuration</link><guid isPermaLink="true">https://developers.cloudflare.com/magic-cloud-networking/changelog/#cost-visibility-for-managed-cloud-configuration</guid><description>&lt;p&gt;Customers can now see the cloud provider list price of discovered network resources and will be informed of total cost and delta cost when deploying managed configuration.&lt;/p&gt;
</description><pubDate>Tue, 01 Oct 2024 00:00:00 GMT</pubDate><product>Magic Cloud Networking</product></item><item><title>Magic Transit - Early access testing for BGP on CNI 2.0 circuits</title><link>https://developers.cloudflare.com/magic-transit/changelog/#early-access-testing-for-bgp-on-cni-20-circuits</link><guid isPermaLink="true">https://developers.cloudflare.com/magic-transit/changelog/#early-access-testing-for-bgp-on-cni-20-circuits</guid><description>&lt;p&gt;Customers can exchange routes dynamically with their Magic virtual network overlay via Direct CNI or Cloud CNI based connectivity.&lt;/p&gt;
</description><pubDate>Tue, 01 Oct 2024 00:00:00 GMT</pubDate><product>Magic Transit</product></item><item><title>Magic WAN - Early access testing for BGP on CNI 2.0 circuits</title><link>https://developers.cloudflare.com/magic-wan/changelog/#early-access-testing-for-bgp-on-cni-20-circuits</link><guid isPermaLink="true">https://developers.cloudflare.com/magic-wan/changelog/#early-access-testing-for-bgp-on-cni-20-circuits</guid><description>&lt;p&gt;Customers can exchange routes dynamically with their Magic virtual network overlay via Direct CNI or Cloud CNI based connectivity.&lt;/p&gt;
</description><pubDate>Tue, 01 Oct 2024 00:00:00 GMT</pubDate><product>Magic WAN</product></item><item><title>Cloudflare Network Interconnect - Early access testing for BGP on Direct CNI circuits</title><link>https://developers.cloudflare.com/network-interconnect/changelog/#early-access-testing-for-bgp-on-direct-cni-circuits</link><guid isPermaLink="true">https://developers.cloudflare.com/network-interconnect/changelog/#early-access-testing-for-bgp-on-direct-cni-circuits</guid><description>&lt;p&gt;Customers can exchange routes dynamically with their Magic virtual network overlay via Direct CNI or Cloud CNI based connectivity.&lt;/p&gt;
</description><pubDate>Tue, 01 Oct 2024 00:00:00 GMT</pubDate><product>Cloudflare Network Interconnect</product></item><item><title>Gateway - File sandboxing</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/gateway/#file-sandboxing</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/gateway/#file-sandboxing</guid><description>&lt;p&gt;Gateway users on Enterprise plans can create HTTP policies with &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/policies/gateway/http-policies/file-sandboxing/&quot;&gt;file sandboxing&lt;/a&gt; to quarantine previously unseen files downloaded by your users and scan them for malware.&lt;/p&gt;
</description><pubDate>Mon, 30 Sep 2024 00:00:00 GMT</pubDate><product>Gateway</product></item><item><title>Magic WAN - Magic WAN Connector sends WARP client traffic to Internet</title><link>https://developers.cloudflare.com/magic-wan/changelog/#magic-wan-connector-sends-warp-client-traffic-to-internet</link><guid isPermaLink="true">https://developers.cloudflare.com/magic-wan/changelog/#magic-wan-connector-sends-warp-client-traffic-to-internet</guid><description>&lt;p&gt;All Magic WAN Connectors now route WARP client traffic directly to the Internet, bypassing IPsec tunneling, to prevent double encapsulation of WARP traffic.&lt;/p&gt;
</description><pubDate>Fri, 27 Sep 2024 00:00:00 GMT</pubDate><product>Magic WAN</product></item><item><title>Zero Trust WARP Client - WARP client for macOS (version 2024.8.457.0)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-macos-version-202484570</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-macos-version-202484570</guid><description>&lt;p&gt;A new GA release for the macOS WARP client is now available in the &lt;a href=&quot;https://install.appcenter.ms/orgs/cloudflare/apps/1.1.1.1-macos-1/distribution_groups/release&quot;&gt;App Center&lt;/a&gt;. This release contains minor fixes and improvements.&lt;/p&gt;
&lt;p&gt;Notable updates:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Added the ability to customize PCAP options in &lt;code&gt;warp-cli&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Added a list of installed applications in &lt;code&gt;warp-diag&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Added a summary of &lt;code&gt;warp-dex&lt;/code&gt; traceroute results in its JSON output.&lt;/li&gt;
&lt;li&gt;Improved the performance of firewall operations when enforcing Split Tunnels configuration.&lt;/li&gt;
&lt;li&gt;Fixed an issue where the DNS logs were not being cleared when the user switched configurations.&lt;/li&gt;
&lt;li&gt;Fixed an issue where clients using service tokens failed to retry after a network change.&lt;/li&gt;
&lt;li&gt;Fixed a known issue which required users to re-register when an older single configuration MDM file was deployed after deploying the newer, multiple configuration format.&lt;/li&gt;
&lt;li&gt;Fixed an issue which prevented the use of private IP ranges that overlapped with end users&amp;#39; home networks.&lt;/li&gt;
&lt;li&gt;Deprecated &lt;code&gt;warp-cli&lt;/code&gt; commands have been removed. If you have any workflows that use the deprecated commands, update to the new commands where necessary.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Known issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Cloudflare is investigating temporary networking issues on macOS 15 (Sequoia) that seem to affect some users.&lt;/li&gt;
&lt;li&gt;Using MASQUE as the tunnel protocol may be incompatible if your organization has Regional Services is enabled.&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Thu, 26 Sep 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Zero Trust WARP Client - WARP client for Windows (version 2024.8.458.0)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-windows-version-202484580</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-windows-version-202484580</guid><description>&lt;p&gt;A new GA release for the Windows WARP client is now available in the &lt;a href=&quot;https://install.appcenter.ms/orgs/cloudflare/apps/1.1.1.1-windows-1/distribution_groups/release&quot;&gt;App Center&lt;/a&gt;. This release contains minor fixes and improvements.&lt;/p&gt;
&lt;p&gt;Notable updates:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Added the ability to customize PCAP options in &lt;code&gt;warp-cli&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Added a list of installed applications in &lt;code&gt;warp-diag&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Added a summary of &lt;code&gt;warp-dex&lt;/code&gt; traceroute results in its JSON output.&lt;/li&gt;
&lt;li&gt;Improved the performance of firewall operations when enforcing Split Tunnels configuration.&lt;/li&gt;
&lt;li&gt;Reduced the time it takes for a WARP client update to complete.&lt;/li&gt;
&lt;li&gt;Fixed an issue where clients using service tokens failed to retry the initial connection when there is no network connectivity on startup.&lt;/li&gt;
&lt;li&gt;Fixed issues where incorrect DNS server addresses were being applied following reboots and network changes. Any incorrect static entries set by previous WARP versions must be manually reverted.&lt;/li&gt;
&lt;li&gt;Fixed a known issue which required users to re-register when an older single configuration MDM file was deployed after deploying the newer, multiple configuration format.&lt;/li&gt;
&lt;li&gt;Deprecated &lt;code&gt;warp-cli&lt;/code&gt; commands have been removed. If you have any workflows that use the deprecated commands, update to the new commands where necessary.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Known issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Using MASQUE as the tunnel protocol may be incompatible if your organization has Regional Services enabled.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;DNS resolution may be broken when all of the following conditions are true:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;WARP is in Secure Web Gateway without DNS filtering (tunnel-only) mode.&lt;/li&gt;
&lt;li&gt;A custom DNS server address is configured on the primary network adapter.&lt;/li&gt;
&lt;li&gt;The custom DNS server address on the primary network adapter is changed while WARP is connected.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To work around the DNS issue, reconnect the WARP client by toggling off and back on.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Thu, 26 Sep 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Magic Network Monitoring - Magic Network Monitoring free version available to all customers</title><link>https://developers.cloudflare.com/magic-network-monitoring/changelog/#magic-network-monitoring-free-version-available-to-all-customers</link><guid isPermaLink="true">https://developers.cloudflare.com/magic-network-monitoring/changelog/#magic-network-monitoring-free-version-available-to-all-customers</guid><description>&lt;p&gt;The free version of Magic Network Monitoring (MNM) is now available to everyone with a Cloudflare account by default.&lt;/p&gt;
</description><pubDate>Tue, 24 Sep 2024 00:00:00 GMT</pubDate><product>Magic Network Monitoring</product></item><item><title>Magic Firewall - New UI improvements</title><link>https://developers.cloudflare.com/magic-firewall/changelog/#new-ui-improvements</link><guid isPermaLink="true">https://developers.cloudflare.com/magic-firewall/changelog/#new-ui-improvements</guid><description>&lt;p&gt;The dashboard now displays the order number of custom rules, and improved drag and drop functionality. You can also preview rules on a side panel without leaving the current page.&lt;/p&gt;
</description><pubDate>Thu, 12 Sep 2024 00:00:00 GMT</pubDate><product>Magic Firewall</product></item><item><title>DLP - Exact Data Match multi-entry upload support</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/dlp/#exact-data-match-multi-entry-upload-support</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/dlp/#exact-data-match-multi-entry-upload-support</guid><description>&lt;p&gt;You can now upload files with &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/policies/data-loss-prevention/datasets/#upload-a-new-dataset&quot;&gt;multiple columns of data&lt;/a&gt; as Exact Data Match datasets. DLP can use each column as a separate existing detection entry.&lt;/p&gt;
</description><pubDate>Tue, 03 Sep 2024 00:00:00 GMT</pubDate><product>DLP</product></item><item><title>Cloudflare Network Interconnect - Interconnect portal displays all available locations in a list</title><link>https://developers.cloudflare.com/network-interconnect/changelog/#interconnect-portal-displays-all-available-locations-in-a-list</link><guid isPermaLink="true">https://developers.cloudflare.com/network-interconnect/changelog/#interconnect-portal-displays-all-available-locations-in-a-list</guid><description>&lt;p&gt;Customers can now see all available Direct CNI locations when searching for a Cloudflare site in the Interconnects interface.&lt;/p&gt;
</description><pubDate>Mon, 02 Sep 2024 00:00:00 GMT</pubDate><product>Cloudflare Network Interconnect</product></item><item><title>Access - Reduce automatic seat deprovisioning minimum to 1 month, down from 2 months.</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/access/#reduce-automatic-seat-deprovisioning-minimum-to-1-month-down-from-2-months</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/access/#reduce-automatic-seat-deprovisioning-minimum-to-1-month-down-from-2-months</guid><description>&lt;p&gt;Admins can now configure Zero Trust seats to &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/identity/users/seat-management/#enable-seat-expiration&quot;&gt;automatically expire&lt;/a&gt; after 1 month of user inactivity. The previous minimum was 2 months.&lt;/p&gt;
</description><pubDate>Mon, 26 Aug 2024 00:00:00 GMT</pubDate><product>Access</product></item><item><title>Zero Trust WARP Client - WARP client for macOS (version 2024.8.309.1)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-macos-version-202483091</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-macos-version-202483091</guid><description>&lt;p&gt;A new beta release for the macOS WARP client is now available in the &lt;a href=&quot;https://install.appcenter.ms/orgs/cloudflare/apps/1.1.1.1-macos/distribution_groups/beta&quot;&gt;App Center&lt;/a&gt;. This release contains minor fixes and improvements.&lt;/p&gt;
&lt;p&gt;Notable updates:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Added the ability to customize PCAP options in &lt;code&gt;warp-cli&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Added a list of installed applications in &lt;code&gt;warp-diag&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Added a summary of &lt;code&gt;warp-dex&lt;/code&gt; traceroute results in its JSON output.&lt;/li&gt;
&lt;li&gt;Improved the performance of firewall operations when enforcing Split Tunnels configuration.&lt;/li&gt;
&lt;li&gt;Fixed an issue where the DNS logs were not being cleared when the user switched configurations.&lt;/li&gt;
&lt;li&gt;Fixed a known issue which required users to re-register when an older single configuration MDM file was deployed after deploying the newer, multiple configuration format.&lt;/li&gt;
&lt;li&gt;Fixed an issue which prevented the use of private IP ranges that overlapped with end users&amp;#39; home networks.&lt;/li&gt;
&lt;li&gt;Deprecated &lt;code&gt;warp-cli&lt;/code&gt; commands have been removed. If you have any workflows that use the deprecated commands, update to the new commands where necessary.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Known issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Using MASQUE as the tunnel protocol may be incompatible if your organization has either of the following conditions:&lt;ul&gt;
&lt;li&gt;Magic WAN is enabled but does not have the latest packet flow path for WARP traffic. To check the migration status, contact your account team.&lt;/li&gt;
&lt;li&gt;Regional Services is enabled.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Mon, 26 Aug 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Zero Trust WARP Client - WARP client for Windows (version 2024.8.308.1)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-windows-version-202483081</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-windows-version-202483081</guid><description>&lt;p&gt;A new beta release for the Windows WARP client is now available in the &lt;a href=&quot;https://install.appcenter.ms/orgs/cloudflare/apps/1.1.1.1-windows/distribution_groups/beta&quot;&gt;App Center&lt;/a&gt;. This release contains minor fixes and improvements.&lt;/p&gt;
&lt;p&gt;Notable updates:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Added the ability to customize PCAP options in &lt;code&gt;warp-cli&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Added a list of installed applications in &lt;code&gt;warp-diag&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Added a summary of &lt;code&gt;warp-dex&lt;/code&gt; traceroute results in its JSON output.&lt;/li&gt;
&lt;li&gt;Improved the performance of firewall operations when enforcing Split Tunnels configuration.&lt;/li&gt;
&lt;li&gt;Reduced the time it takes for a WARP client update to complete.&lt;/li&gt;
&lt;li&gt;Fixed issues where incorrect DNS server addresses were being applied following reboots and network changes. Any incorrect static entries set by previous WARP versions must be manually reverted.&lt;/li&gt;
&lt;li&gt;Fixed a known issue which required users to re-register when an older single configuration MDM file was deployed after deploying the newer, multiple configuration format.&lt;/li&gt;
&lt;li&gt;Deprecated &lt;code&gt;warp-cli&lt;/code&gt; commands have been removed. If you have any workflows that use the deprecated commands, update to the new commands where necessary.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Known issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;p&gt;Using MASQUE as the tunnel protocol may be incompatible if your organization has either of the following conditions:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Magic WAN is enabled but does not have the latest packet flow path for WARP traffic. To check the migration status, contact your account team.&lt;/li&gt;
&lt;li&gt;Regional Services is enabled.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;p&gt;DNS resolution may be broken when all of the following conditions are true:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;WARP is in Secure Web Gateway without DNS filtering (tunnel-only) mode.&lt;/li&gt;
&lt;li&gt;A custom DNS server address is configured on the primary network adapter.&lt;/li&gt;
&lt;li&gt;The custom DNS server address on the primary network adapter is changed while WARP is connected.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To work around the DNS issue, reconnect the WARP client by toggling off and back on.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Mon, 26 Aug 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Magic Firewall - Magic Firewall Analytics Rule Log Enhancement</title><link>https://developers.cloudflare.com/magic-firewall/changelog/#magic-firewall-analytics-rule-log-enhancement</link><guid isPermaLink="true">https://developers.cloudflare.com/magic-firewall/changelog/#magic-firewall-analytics-rule-log-enhancement</guid><description>&lt;p&gt;Customers who create a rule in a disabled mode will see the rule as &lt;strong&gt;Log (rule disabled)&lt;/strong&gt;.&lt;/p&gt;
</description><pubDate>Fri, 16 Aug 2024 00:00:00 GMT</pubDate><product>Magic Firewall</product></item><item><title>Zero Trust WARP Client - WARP client for Linux (version 2024.6.497.0)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-linux-version-202464970</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-linux-version-202464970</guid><description>&lt;p&gt;A new GA release for the Linux WARP client is now available in the &lt;a href=&quot;https://pkg.cloudflareclient.com/&quot;&gt;package repository&lt;/a&gt;. This release includes some exciting new features. It also includes additional fixes and minor improvements.&lt;/p&gt;
&lt;p&gt;New features:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The WARP client now supports operation on Ubuntu 24.04.&lt;/li&gt;
&lt;li&gt;Admins can now elect to have ZT WARP clients connect using the MASQUE protocol; this setting is in Device Profiles. Note: before MASQUE can be used, the global setting for Override local interface IP must be enabled. For more detail, refer to &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/configure-warp/warp-settings/#device-tunnel-protocol&quot;&gt;Device tunnel protocol&lt;/a&gt;. This feature will be rolled out to customers in stages over approximately the next month.&lt;/li&gt;
&lt;li&gt;The Device Posture &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/identity/devices/warp-client-checks/client-certificate/&quot;&gt;client certificate check&lt;/a&gt; has been substantially enhanced. The primary enhancement is the ability to check for client certificates that have unique common names, made unique by the inclusion of the device serial number or host name (for example, CN = &lt;code&gt;123456.mycompany&lt;/code&gt;, where 123456 is the device serial number).&lt;/li&gt;
&lt;li&gt;TCP MSS clamping is now used where necessary to meet the MTU requirements of the tunnel interface. This will be especially helpful in Docker use cases.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Warning:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu 16.04 and 18.04 are not supported by this version of the client.&lt;/li&gt;
&lt;li&gt;This is the last GA release that will be supporting older, deprecated &lt;code&gt;warp-cli&lt;/code&gt; commands. There are two methods to identify these commands. One, when used in this release, the command will work but will also return a deprecation warning. And two, the deprecated commands do not appear in the output of &lt;code&gt;warp-cli -h&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Known issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;There are certain known limitations preventing the use of the MASQUE tunnel protocol in certain scenarios. Do not use the MASQUE tunnel protocol if:&lt;ul&gt;
&lt;li&gt;A Magic WAN integration is on the account and does not have the latest packet flow path for WARP traffic. To check the migration status, contact your account team.&lt;/li&gt;
&lt;li&gt;Your account has Regional Services enabled.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;The Linux client GUI does not yet support all GUI features found in the Windows and macOS clients. Future releases of the Linux client will be adding these GUI features.&lt;/li&gt;
&lt;li&gt;The Zero Trust team name is not visible in the GUI if you upgraded from the previous GA release using an MDM tool.&lt;/li&gt;
&lt;li&gt;Sometimes the WARP icon will remain gray (disconnected state) while in dark mode.&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Thu, 15 Aug 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Magic Cloud Networking - GCP on-ramps</title><link>https://developers.cloudflare.com/magic-cloud-networking/changelog/#gcp-on-ramps</link><guid isPermaLink="true">https://developers.cloudflare.com/magic-cloud-networking/changelog/#gcp-on-ramps</guid><description>&lt;p&gt;Magic Cloud Networking supports Google Cloud Platform.&lt;/p&gt;
</description><pubDate>Wed, 14 Aug 2024 00:00:00 GMT</pubDate><product>Magic Cloud Networking</product></item><item><title>Email Security - Email Security is live</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/email-security/#email-security-is-live</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/email-security/#email-security-is-live</guid><description>&lt;p&gt;Email Security is now live under Zero Trust.&lt;/p&gt;
</description><pubDate>Tue, 06 Aug 2024 00:00:00 GMT</pubDate><product>Email Security</product></item><item><title>Email Security - Microsoft Graph API deployment.</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/email-security/#microsoft-graph-api-deployment</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/email-security/#microsoft-graph-api-deployment</guid><description>&lt;p&gt;Customers using Microsoft Office 365 can set up Email Security via Microsoft Graph API.&lt;/p&gt;
</description><pubDate>Tue, 06 Aug 2024 00:00:00 GMT</pubDate><product>Email Security</product></item><item><title>Cloudflare Tunnel - cloudflared builds available in GitHub for Apple silicon</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/tunnel/#cloudflared-builds-available-in-github-for-apple-silicon</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/tunnel/#cloudflared-builds-available-in-github-for-apple-silicon</guid><description>&lt;p&gt;macOS users can now download &lt;code&gt;cloudflared-arm64.pkg&lt;/code&gt; directly from &lt;a href=&quot;https://github.com/cloudflare/cloudflared/releases&quot;&gt;GitHub&lt;/a&gt;, in addition to being available via Homebrew.&lt;/p&gt;
</description><pubDate>Tue, 06 Aug 2024 00:00:00 GMT</pubDate><product>Cloudflare Tunnel</product></item><item><title>Gateway - UK NCSC indicator feed publicly available in Gateway</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/gateway/#uk-ncsc-indicator-feed-publicly-available-in-gateway</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/gateway/#uk-ncsc-indicator-feed-publicly-available-in-gateway</guid><description>&lt;p&gt;Gateway users on any plan can now use the &lt;a href=&quot;https://developers.cloudflare.com/security-center/indicator-feeds/#publicly-available-feeds&quot;&gt;PDNS threat intelligence feed&lt;/a&gt; provided by the UK National Cyber Security Centre (NCSC) in DNS policies.&lt;/p&gt;
</description><pubDate>Tue, 30 Jul 2024 00:00:00 GMT</pubDate><product>Gateway</product></item><item><title>Zero Trust WARP Client - WARP client for macOS (version 2024.6.474.0)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-macos-version-202464740</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-macos-version-202464740</guid><description>&lt;p&gt;A new GA release for the macOS WARP client is now available in the &lt;a href=&quot;https://install.appcenter.ms/orgs/cloudflare/apps/1.1.1.1-macos-1/distribution_groups/release&quot;&gt;App Center&lt;/a&gt;. This release contains fixes to improve the client; no new features are included.&lt;/p&gt;
&lt;p&gt;Notable updates:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Fixed an issue which caused alternate network detection to fail if the beacon host was using TLS 1.2 without TLS Extended Master Secret (EMS) enabled.&lt;/li&gt;
&lt;li&gt;Improved the stability of device profile switching based on alternate network detection.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Known issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;If a user has an MDM file configured to support multiple profiles (for the &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/deployment/mdm-deployment/switch-organizations/&quot;&gt;switch configurations&lt;/a&gt; feature), and then changes to an MDM file configured for a single profile, the WARP client may not connect. The workaround is to use the &lt;code&gt;warp-cli registration delete&lt;/code&gt; command to clear the registration, and then re-register the client.&lt;/li&gt;
&lt;li&gt;There are certain known limitations preventing the use of the MASQUE tunnel protocol in certain scenarios. Do not use the MASQUE tunnel protocol if:&lt;ul&gt;
&lt;li&gt;A Magic WAN integration is on the account and does not have the latest packet flow path for WARP traffic. Please check migration status with your account team.&lt;/li&gt;
&lt;li&gt;Your account has Regional Services enabled.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Tue, 30 Jul 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Zero Trust WARP Client - WARP client for Windows (version 2024.6.473.0)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-windows-version-202464730</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-windows-version-202464730</guid><description>&lt;p&gt;A new GA release for the Windows WARP client is now available in the &lt;a href=&quot;https://install.appcenter.ms/orgs/cloudflare/apps/1.1.1.1-windows-1/distribution_groups/release&quot;&gt;App Center&lt;/a&gt;. This release contains fixes to improve the client; no new features are included.&lt;/p&gt;
&lt;p&gt;Notable updates:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Fixed an issue which caused alternate network detection to fail if the beacon host was using TLS 1.2 without TLS Extended Master Secret (EMS) enabled.&lt;/li&gt;
&lt;li&gt;Improved the stability of device profile switching based on alternate network detection.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Known issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;If a user has an MDM file configured to support multiple profiles (for the &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/deployment/mdm-deployment/switch-organizations/&quot;&gt;switch configurations&lt;/a&gt; feature), and then changes to an MDM file configured for a single profile, the WARP client may not connect. The workaround is to use the &lt;code&gt;warp-cli registration delete&lt;/code&gt; command to clear the registration, and then re-register the client.&lt;/li&gt;
&lt;li&gt;There are certain known limitations preventing the use of the MASQUE tunnel protocol in certain scenarios. Do not use the MASQUE tunnel protocol if:&lt;ul&gt;
&lt;li&gt;A Magic WAN integration is on the account and does not have the latest packet flow path for WARP traffic. Please check migration status with your account team.&lt;/li&gt;
&lt;li&gt;Your account has Regional Services enabled.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Tue, 30 Jul 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Magic WAN - Updates to High Availability on the Magic WAN Connector</title><link>https://developers.cloudflare.com/magic-wan/changelog/#updates-to-high-availability-on-the-magic-wan-connector</link><guid isPermaLink="true">https://developers.cloudflare.com/magic-wan/changelog/#updates-to-high-availability-on-the-magic-wan-connector</guid><description>&lt;p&gt;The High Availability feature on Magic WAN Connector now supports additional failover conditions, DHCP lease syncing, and staggered upgrades.&lt;/p&gt;
</description><pubDate>Wed, 17 Jul 2024 00:00:00 GMT</pubDate><product>Magic WAN</product></item><item><title>Gateway - Gateway DNS filter non-authenticated queries</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/gateway/#gateway-dns-filter-non-authenticated-queries</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/gateway/#gateway-dns-filter-non-authenticated-queries</guid><description>&lt;p&gt;Gateway users can now select which endpoints to use for a given DNS location. Available endpoints include IPv4, IPv6, DNS over HTTPS (DoH), and DNS over TLS (DoT). Users can protect each configured endpoint by specifying allowed source networks. Additionally, for the DoH endpoint, users can filter  traffic based on source networks and/or authenticate user identity tokens.&lt;/p&gt;
</description><pubDate>Sun, 14 Jul 2024 00:00:00 GMT</pubDate><product>Gateway</product></item><item><title>Magic Cloud Networking - Closed beta launch</title><link>https://developers.cloudflare.com/magic-cloud-networking/changelog/#closed-beta-launch</link><guid isPermaLink="true">https://developers.cloudflare.com/magic-cloud-networking/changelog/#closed-beta-launch</guid><description>&lt;p&gt;The Magic Cloud Networking closed beta release is available, with the managed cloud on-ramps feature.&lt;/p&gt;
</description><pubDate>Mon, 01 Jul 2024 00:00:00 GMT</pubDate><product>Magic Cloud Networking</product></item><item><title>Zero Trust WARP Client - WARP client for macOS (version 2024.6.416.0)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-macos-version-202464160</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-macos-version-202464160</guid><description>&lt;p&gt;A new GA release for the macOS WARP client is now available in the &lt;a href=&quot;https://install.appcenter.ms/orgs/cloudflare/apps/1.1.1.1-macos-1/distribution_groups/release&quot;&gt;App Center&lt;/a&gt;. This release includes some exciting new features. It also includes additional fixes and minor improvements.&lt;/p&gt;
&lt;p&gt;New features:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Admins can now elect to have ZT WARP clients connect using the MASQUE protocol; this setting is in Device Profiles. Note: before MASQUE can be used, the global setting for Override local interface IP must be enabled. For more detail, refer to &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/configure-warp/warp-settings/#device-tunnel-protocol&quot;&gt;Device tunnel protocol&lt;/a&gt;. This feature will be rolled out to customers in stages over approximately the next month.&lt;/li&gt;
&lt;li&gt;The Device Posture &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/identity/devices/warp-client-checks/client-certificate/&quot;&gt;client certificate check&lt;/a&gt; has been substantially enhanced. The primary enhancement is the ability to check for client certificates that have unique common names, made unique by the inclusion of the device serial number or host name (for example, CN = &lt;code&gt;123456.mycompany&lt;/code&gt;, where 123456 is the device serial number).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Additional changes and improvements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a known issue where the certificate was not always properly left behind in &lt;code&gt;/Library/Application Support/Cloudflare/installed_cert.pem&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Fixed an issue where re-auth notifications were not cleared from the UI when the user switched configurations.&lt;/li&gt;
&lt;li&gt;Fixed a macOS firewall rule that allowed all UDP traffic to go outside the tunnel. Relates to TunnelVision (&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2024-3661&quot;&gt;CVE-2024-3661&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;Fixed an issue that could cause the Cloudflare WARP menu bar application to disappear when switching configurations.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Warning:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;This is the last GA release that will be supporting older, deprecated &lt;code&gt;warp-cli&lt;/code&gt; commands. There are two methods to identify these commands. One, when used in this release, the command will work but will also return a deprecation warning. And two, the deprecated commands do not appear in the output of &lt;code&gt;warp-cli -h&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Known issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;If a user has an MDM file configured to support multiple profiles (for the &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/deployment/mdm-deployment/switch-organizations/&quot;&gt;switch configurations&lt;/a&gt; feature), and then changes to an MDM file configured for a single profile, the WARP client may not connect. The workaround is to use the &lt;code&gt;warp-cli registration delete&lt;/code&gt; command to clear the registration, and then re-register the client.&lt;/li&gt;
&lt;li&gt;There are certain known limitations preventing the use of the MASQUE tunnel protocol in certain scenarios. Do not use the MASQUE tunnel protocol if:&lt;ul&gt;
&lt;li&gt;A Magic WAN integration is on the account and does not have the latest packet flow path for WARP traffic. Please check migration status with your account team.&lt;/li&gt;
&lt;li&gt;Your account has Regional Services enabled.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Fri, 28 Jun 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Zero Trust WARP Client - WARP client for Windows (version 2024.6.415.0)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-windows-version-202464150</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-windows-version-202464150</guid><description>&lt;p&gt;A new GA release for the Windows WARP client is now available in the &lt;a href=&quot;https://install.appcenter.ms/orgs/cloudflare/apps/1.1.1.1-windows-1/distribution_groups/release&quot;&gt;App Center&lt;/a&gt;. This release includes some exciting new features. It also includes additional fixes and minor improvements.&lt;/p&gt;
&lt;p&gt;New features:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Admins can now elect to have ZT WARP clients connect using the MASQUE protocol; this setting is in Device Profiles. Note: before MASQUE can be used, the global setting for Override local interface IP must be enabled. For more detail, refer to &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/configure-warp/warp-settings/#device-tunnel-protocol&quot;&gt;Device tunnel protocol&lt;/a&gt;. This feature will be rolled out to customers in stages over approximately the next month.&lt;/li&gt;
&lt;li&gt;The ZT WARP client on Windows devices can now connect before the user completes their Windows login. This &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/deployment/mdm-deployment/windows-prelogin/&quot;&gt;Windows pre-login capability&lt;/a&gt; allows for connecting to on-premise Active Directory and/or similar resources necessary to complete the Windows login.&lt;/li&gt;
&lt;li&gt;The Device Posture &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/identity/devices/warp-client-checks/client-certificate/&quot;&gt;client certificate check&lt;/a&gt; has been substantially enhanced. The primary enhancement is the ability to check for client certificates that have unique common names, made unique by the inclusion of the device serial number or host name (for example, CN = &lt;code&gt;123456.mycompany&lt;/code&gt;, where 123456 is the device serial number).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Additional changes and improvements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Added a new &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/troubleshooting/client-errors/#cf_failed_read_system_dns_config&quot;&gt;Unable to Connect message&lt;/a&gt; to the UI to help in troubleshooting.&lt;/li&gt;
&lt;li&gt;The upgrade window now uses international date formats.&lt;/li&gt;
&lt;li&gt;Made a change to ensure DEX tests are not running when the tunnel is not up due to the device going to or waking from sleep. This is specific to devices using the S3 power model.&lt;/li&gt;
&lt;li&gt;Fixed a known issue where the certificate was not always properly left behind in &lt;code&gt;%ProgramData%\Cloudflare\installed_cert.pem&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Fixed an issue where ICMPv6 Neighbor Solicitation messages were being incorrectly sent on the WARP tunnel.&lt;/li&gt;
&lt;li&gt;Fixed an issue where a silent upgrade was causing certain files to be deleted if the target upgrade version is the same as the current version.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Warning:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;This is the last GA release that will be supporting older, deprecated &lt;code&gt;warp-cli&lt;/code&gt; commands. There are two methods to identify these commands. One, when used in this release, the command will work but will also return a deprecation warning. And two, the deprecated commands do not appear in the output of &lt;code&gt;warp-cli -h&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Known issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;If a user has an MDM file configured to support multiple profiles (for the &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/deployment/mdm-deployment/switch-organizations/&quot;&gt;switch configurations&lt;/a&gt; feature), and then changes to an MDM file configured for a single profile, the WARP client may not connect. The workaround is to use the &lt;code&gt;warp-cli registration delete&lt;/code&gt; command to clear the registration, and then re-register the client.&lt;/li&gt;
&lt;li&gt;There are certain known limitations preventing the use of the MASQUE tunnel protocol in certain scenarios. Do not use the MASQUE tunnel protocol if:&lt;ul&gt;
&lt;li&gt;A Magic WAN integration is on the account and does not have the latest packet flow path for WARP traffic. Please check migration status with your account team.&lt;/li&gt;
&lt;li&gt;Your account has Regional Services enabled.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Fri, 28 Jun 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Zero Trust WARP Client - Cloudflare One Agent for iOS (version 1.4)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#cloudflare-one-agent-for-ios-version-14</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#cloudflare-one-agent-for-ios-version-14</guid><description>&lt;p&gt;A new GA release for the iOS Cloudflare One Agent is now available in the &lt;a href=&quot;https://apps.apple.com/us/app/cloudflare-one-agent/id6443476492&quot;&gt;iOS App Store&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Notable updates:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Fixed an issue with endpoint IP settings in MDM files&lt;/li&gt;
&lt;li&gt;Cleaned up some erroneous links&lt;/li&gt;
&lt;li&gt;Updated the Terms of Service&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Thu, 27 Jun 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Gateway - Gateway DNS policy setting to ignore CNAME category matches</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/gateway/#gateway-dns-policy-setting-to-ignore-cname-category-matches</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/gateway/#gateway-dns-policy-setting-to-ignore-cname-category-matches</guid><description>&lt;p&gt;Gateway now offers the ability to selectively ignore CNAME domain categories in DNS policies via the &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/policies/gateway/domain-categories/#ignore-cname-domain-categories&quot;&gt;&lt;strong&gt;Ignore CNAME domain categories&lt;/strong&gt; setting&lt;/a&gt; in the policy builder and the &lt;a href=&quot;https://developers.cloudflare.com/api/resources/zero_trust/subresources/gateway/subresources/rules/methods/create/&quot;&gt;&lt;code&gt;ignore_cname_category_matches&lt;/code&gt; setting&lt;/a&gt; in the API.&lt;/p&gt;
</description><pubDate>Tue, 25 Jun 2024 00:00:00 GMT</pubDate><product>Gateway</product></item><item><title>Magic WAN - ICMP support for traffic sourced from private IPs</title><link>https://developers.cloudflare.com/magic-wan/changelog/#icmp-support-for-traffic-sourced-from-private-ips</link><guid isPermaLink="true">https://developers.cloudflare.com/magic-wan/changelog/#icmp-support-for-traffic-sourced-from-private-ips</guid><description>&lt;p&gt;Magic WAN will now support ICMP traffic sourced from private IPs going to the Internet via Gateway.&lt;/p&gt;
</description><pubDate>Sun, 23 Jun 2024 00:00:00 GMT</pubDate><product>Magic WAN</product></item><item><title>Risk score - Okta risk exchange</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/risk-score/#okta-risk-exchange</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/risk-score/#okta-risk-exchange</guid><description>&lt;p&gt;You can now &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/insights/risk-score/#send-risk-score-to-okta&quot;&gt;exchange user risk scores&lt;/a&gt; with Okta to inform SSO-level policies.&lt;/p&gt;
</description><pubDate>Mon, 17 Jun 2024 00:00:00 GMT</pubDate><product>Risk score</product></item><item><title>Risk score - SentinelOne signal ingestion</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/risk-score/#sentinelone-signal-ingestion</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/risk-score/#sentinelone-signal-ingestion</guid><description>&lt;p&gt;You can now configure a &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/insights/risk-score/#predefined-risk-behaviors&quot;&gt;predefined risk behavior&lt;/a&gt; to evaluate user risk score using device posture attributes from the &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/identity/devices/service-providers/sentinelone/&quot;&gt;SentinelOne integration&lt;/a&gt;.&lt;/p&gt;
</description><pubDate>Fri, 14 Jun 2024 00:00:00 GMT</pubDate><product>Risk score</product></item><item><title>Access - Scalability improvements to the App Launcher</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/access/#scalability-improvements-to-the-app-launcher</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/access/#scalability-improvements-to-the-app-launcher</guid><description>&lt;p&gt;Applications now load more quickly for customers with a large number of applications or complex policies.&lt;/p&gt;
</description><pubDate>Thu, 06 Jun 2024 00:00:00 GMT</pubDate><product>Access</product></item><item><title>Magic WAN - Application based prioritization</title><link>https://developers.cloudflare.com/magic-wan/changelog/#application-based-prioritization</link><guid isPermaLink="true">https://developers.cloudflare.com/magic-wan/changelog/#application-based-prioritization</guid><description>&lt;p&gt;The Magic WAN Connector can now prioritize traffic on a per-application basis.&lt;/p&gt;
</description><pubDate>Wed, 05 Jun 2024 00:00:00 GMT</pubDate><product>Magic WAN</product></item><item><title>CASB - Atlassian Bitbucket integration</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/casb/#atlassian-bitbucket-integration</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/casb/#atlassian-bitbucket-integration</guid><description>&lt;p&gt;You can now scan your Bitbucket Cloud workspaces for a variety of contextualized security issues such as source code exposure, admin misconfigurations, and more.&lt;/p&gt;
</description><pubDate>Mon, 03 Jun 2024 00:00:00 GMT</pubDate><product>CASB</product></item><item><title>Magic WAN - WARP virtual IP addresses</title><link>https://developers.cloudflare.com/magic-wan/changelog/#warp-virtual-ip-addresses</link><guid isPermaLink="true">https://developers.cloudflare.com/magic-wan/changelog/#warp-virtual-ip-addresses</guid><description>&lt;p&gt;Customers using Gateway to filter traffic to Magic WAN destinations will now see traffic from Cloudflare egressing with WARP virtual IP addresses (CGNAT range), rather than public Cloudflare IP addresses. This simplifies configuration and improves visibility for customers.&lt;/p&gt;
</description><pubDate>Fri, 31 May 2024 00:00:00 GMT</pubDate><product>Magic WAN</product></item><item><title>CASB - Data-at-rest DLP for Box and Dropbox</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/casb/#data-at-rest-dlp-for-box-and-dropbox</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/casb/#data-at-rest-dlp-for-box-and-dropbox</guid><description>&lt;p&gt;You can now scan your &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/applications/casb/casb-integrations/box/#data-loss-prevention-optional&quot;&gt;Box&lt;/a&gt; and &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/applications/casb/casb-integrations/dropbox/#data-loss-prevention-optional&quot;&gt;Dropbox&lt;/a&gt; files for DLP matches.&lt;/p&gt;
</description><pubDate>Thu, 23 May 2024 00:00:00 GMT</pubDate><product>CASB</product></item><item><title>DLP - Data-at-rest DLP for Box and Dropbox</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/dlp/#data-at-rest-dlp-for-box-and-dropbox</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/dlp/#data-at-rest-dlp-for-box-and-dropbox</guid><description>&lt;p&gt;You can now scan your &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/applications/casb/casb-integrations/box/#data-loss-prevention-optional&quot;&gt;Box&lt;/a&gt; and &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/applications/casb/casb-integrations/dropbox/#data-loss-prevention-optional&quot;&gt;Dropbox&lt;/a&gt; files for DLP matches.&lt;/p&gt;
</description><pubDate>Thu, 23 May 2024 00:00:00 GMT</pubDate><product>DLP</product></item><item><title>Zero Trust WARP Client - WARP client for Windows (version 2024.5.310.1)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-windows-version-202453101</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-windows-version-202453101</guid><description>&lt;p&gt;A new beta release for the Windows WARP client is now available in the &lt;a href=&quot;https://install.appcenter.ms/orgs/cloudflare/apps/1.1.1.1-windows/distribution_groups/beta&quot;&gt;App Center&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Notable updates:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Added a new &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/troubleshooting/client-errors/#cf_failed_read_system_dns_config&quot;&gt;Unable to Connect message&lt;/a&gt; to the UI to help in troubleshooting.&lt;/li&gt;
&lt;li&gt;In the upgrade window, a change was made to use international date formats to resolve an issue with localization.&lt;/li&gt;
&lt;li&gt;Made a change to ensure DEX tests are not running when the tunnel is not up due to the device going to or waking from sleep. This is specific to devices using the S3 power model.&lt;/li&gt;
&lt;li&gt;Fixed a known issue where the certificate was not always properly left behind in &lt;code&gt;%ProgramData%\Cloudflare\installed_cert.pem&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Fixed an issue where ICMPv6 Neighbor Solicitation messages were being incorrectly sent on the WARP tunnel.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Known issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;If a user has an MDM file configured to support multiple profiles (for the switch configurations feature), and then changes to an MDM file configured for a single profile, the WARP client may not connect. The workaround is to use the &lt;code&gt;warp-cli registration delete&lt;/code&gt; command to clear the registration, and then re-register the client.&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Wed, 22 May 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Zero Trust WARP Client - WARP client for macOS (version 2024.5.287.1)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-macos-version-202452871</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-macos-version-202452871</guid><description>&lt;p&gt;A new beta release for the macOS WARP client is now available in the &lt;a href=&quot;https://install.appcenter.ms/orgs/cloudflare/apps/1.1.1.1-macos/distribution_groups/beta&quot;&gt;App Center&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Notable updates:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a known issue where the certificate was not always properly left behind in &lt;code&gt;/Library/Application Support/Cloudflare/installed_cert.pem&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Fixed an issue so that the reauth notification is cleared from the UI when the user switches configurations.&lt;/li&gt;
&lt;li&gt;Fixed an issue by correcting the WARP client setting of macOS firewall rules. This relates to TunnelVision (&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2024-3661&quot;&gt;CVE-2024-3661&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;Fixed an issue that could cause the Cloudflare WARP menu bar application to disappear when switching configurations.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Known issues:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;If a user has an MDM file configured to support multiple profiles (for the switch configurations feature), and then changes to an MDM file configured for a single profile, the WARP client may not connect. The workaround is to use the &lt;code&gt;warp-cli registration delete&lt;/code&gt; command to clear the registration, and then re-register the client.&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Tue, 21 May 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Digital Experience Monitoring - Last seen ISP</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/dex/#last-seen-isp</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/dex/#last-seen-isp</guid><description>&lt;p&gt;Admins can view the last ISP seen for a device by going to &lt;strong&gt;My Team&lt;/strong&gt; &amp;gt; &lt;strong&gt;Devices&lt;/strong&gt;. Requires setting up a &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/insights/dex/tests/traceroute/&quot;&gt;traceroute test&lt;/a&gt;.&lt;/p&gt;
</description><pubDate>Mon, 20 May 2024 00:00:00 GMT</pubDate><product>Digital Experience Monitoring</product></item><item><title>Digital Experience Monitoring - DEX alerts</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/dex/#dex-alerts</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/dex/#dex-alerts</guid><description>&lt;p&gt;Admins can now set &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/insights/dex/notifications/&quot;&gt;DEX alerts&lt;/a&gt; using &lt;a href=&quot;https://developers.cloudflare.com/notifications/&quot;&gt;Cloudflare Notifications&lt;/a&gt;. Three new DEX alert types:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Device connectivity anomaly&lt;/li&gt;
&lt;li&gt;Test latency&lt;/li&gt;
&lt;li&gt;Test low availability&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Mon, 13 May 2024 00:00:00 GMT</pubDate><product>Digital Experience Monitoring</product></item><item><title>Zero Trust WARP Client - Cloudflare One Agent for Android (version 1.7)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#cloudflare-one-agent-for-android-version-17</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#cloudflare-one-agent-for-android-version-17</guid><description>&lt;p&gt;A new GA release for the Android Cloudflare One Agent is now available in the &lt;a href=&quot;https://play.google.com/store/apps/details?id=com.cloudflare.cloudflareoneagent&quot;&gt;Google Play Store&lt;/a&gt;. This release fixes an issue where the user was not prompted to select the client certificate in the browser during Access registration.&lt;/p&gt;
</description><pubDate>Fri, 10 May 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Zero Trust WARP Client - Crowdstrike posture checks for online status</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#crowdstrike-posture-checks-for-online-status</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#crowdstrike-posture-checks-for-online-status</guid><description>&lt;p&gt;Two new Crowdstrike attributes, &lt;em&gt;Last Seen&lt;/em&gt; and &lt;em&gt;State&lt;/em&gt;, are now available to be used as selectors in the &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/identity/devices/service-providers/crowdstrike/&quot;&gt;Crowdstrike service provider integration&lt;/a&gt;.&lt;/p&gt;
</description><pubDate>Thu, 09 May 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Zero Trust WARP Client - WARP client for macOS (version 2024.3.444.0)</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-macos-version-202434440</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/warp/#warp-client-for-macos-version-202434440</guid><description>&lt;p&gt;A new GA release for the macOS WARP client is now available in the &lt;a href=&quot;https://install.appcenter.ms/orgs/cloudflare/apps/1.1.1.1-macos-1/distribution_groups/release&quot;&gt;App Center&lt;/a&gt;. This releases fixes an issue with how the WARP client sets macOS firewall rules and addresses the TunnelVision (&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2024-3661&quot;&gt;CVE-2024-3661&lt;/a&gt;) vulnerability.&lt;/p&gt;
</description><pubDate>Wed, 08 May 2024 00:00:00 GMT</pubDate><product>Zero Trust WARP Client</product></item><item><title>Access - Add option to bypass CORS to origin server</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/access/#add-option-to-bypass-cors-to-origin-server</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/access/#add-option-to-bypass-cors-to-origin-server</guid><description>&lt;p&gt;Access admins can &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/identity/authorization-cookie/cors/#bypass-options-requests-to-origin&quot;&gt;defer all CORS enforcement to their origin server&lt;/a&gt; for specific Access applications.&lt;/p&gt;
</description><pubDate>Sun, 28 Apr 2024 00:00:00 GMT</pubDate><product>Access</product></item><item><title>CASB - Export CASB findings to CSV</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/casb/#export-casb-findings-to-csv</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/casb/#export-casb-findings-to-csv</guid><description>&lt;p&gt;You can now export all top-level CASB findings or every instance of your findings to CSV.&lt;/p&gt;
</description><pubDate>Tue, 16 Apr 2024 00:00:00 GMT</pubDate><product>CASB</product></item><item><title>DLP - Optical character recognition</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/dlp/#optical-character-recognition</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/dlp/#optical-character-recognition</guid><description>&lt;p&gt;DLP can now &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/policies/data-loss-prevention/dlp-profiles/advanced-settings/#optical-character-recognition-ocr&quot;&gt;detect sensitive data&lt;/a&gt; in jpeg, jpg, and png files. This helps companies prevent the leak of sensitive data in images, such as screenshots.&lt;/p&gt;
</description><pubDate>Tue, 16 Apr 2024 00:00:00 GMT</pubDate><product>DLP</product></item><item><title>Access - Zero Trust User identity audit logs</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/access/#zero-trust-user-identity-audit-logs</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/access/#zero-trust-user-identity-audit-logs</guid><description>&lt;p&gt;All user identity changes via SCIM or Authentication events are logged against a user&amp;#39;s registry identity.&lt;/p&gt;
</description><pubDate>Mon, 15 Apr 2024 00:00:00 GMT</pubDate><product>Access</product></item><item><title>Gateway - Gateway file type control improvements</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/gateway/#gateway-file-type-control-improvements</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/gateway/#gateway-file-type-control-improvements</guid><description>&lt;p&gt;Gateway now offers a more extensive, categorized &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/policies/gateway/http-policies/#download-and-upload-file-types&quot;&gt;list of files&lt;/a&gt; to control uploads and downloads.&lt;/p&gt;
</description><pubDate>Fri, 05 Apr 2024 00:00:00 GMT</pubDate><product>Gateway</product></item><item><title>Browser Isolation - Removed third-party cookie dependencies</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/browser-isolation/#removed-third-party-cookie-dependencies</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/browser-isolation/#removed-third-party-cookie-dependencies</guid><description>&lt;p&gt;Removed dependency on third-party cookies in the isolated browser, fixing an issue that previously caused intermittent disruptions for users maintaining multi-site, cross-tab sessions in the isolated browser.&lt;/p&gt;
</description><pubDate>Thu, 21 Mar 2024 00:00:00 GMT</pubDate><product>Browser Isolation</product></item><item><title>Access - Access for SaaS OIDC Support</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/access/#access-for-saas-oidc-support</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/access/#access-for-saas-oidc-support</guid><description>&lt;p&gt;Access for SaaS applications can be setup with OIDC as an authentication method. OIDC and SAML 2.0 are now both fully supported.&lt;/p&gt;
</description><pubDate>Thu, 22 Feb 2024 00:00:00 GMT</pubDate><product>Access</product></item><item><title>Access - WARP as an identity source for Access</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/access/#warp-as-an-identity-source-for-access</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/access/#warp-as-an-identity-source-for-access</guid><description>&lt;p&gt;Allow users to log in to Access applications with their WARP session identity. Users need to reauthenticate based on default session durations. WARP authentication identity must be turned on in your device enrollment permissions and can be enabled on a per application basis.&lt;/p&gt;
</description><pubDate>Thu, 22 Feb 2024 00:00:00 GMT</pubDate><product>Access</product></item><item><title>Magic WAN - Network segmentation</title><link>https://developers.cloudflare.com/magic-wan/changelog/#network-segmentation</link><guid isPermaLink="true">https://developers.cloudflare.com/magic-wan/changelog/#network-segmentation</guid><description>&lt;p&gt;You can define policies in your Connector to either allow traffic to flow between your LANs without it leaving your local premises or to forward it via the Cloudflare network where you can add additional security features.&lt;/p&gt;
</description><pubDate>Tue, 23 Jan 2024 00:00:00 GMT</pubDate><product>Magic WAN</product></item><item><title>Access - Unique Entity IDs in Access for SaaS</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/access/#unique-entity-ids-in-access-for-saas</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/access/#unique-entity-ids-in-access-for-saas</guid><description>&lt;p&gt;All new Access for SaaS applications have unique Entity IDs. This allows for multiple integrations with the same SaaS provider if required. The unique Entity ID has the application audience tag appended. Existing apps are unchanged.&lt;/p&gt;
</description><pubDate>Wed, 20 Dec 2023 00:00:00 GMT</pubDate><product>Access</product></item><item><title>Access - Default relay state support in Access for SaaS</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/access/#default-relay-state-support-in-access-for-saas</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/access/#default-relay-state-support-in-access-for-saas</guid><description>&lt;p&gt;Allows Access admins to set a default relay state on Access for SaaS apps.&lt;/p&gt;
</description><pubDate>Fri, 15 Dec 2023 00:00:00 GMT</pubDate><product>Access</product></item><item><title>Access - App launcher supports tags and filters</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/access/#app-launcher-supports-tags-and-filters</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/access/#app-launcher-supports-tags-and-filters</guid><description>&lt;p&gt;Access admins can now tag applications and allow users to filter by those tags in the App Launcher.&lt;/p&gt;
</description><pubDate>Fri, 15 Sep 2023 00:00:00 GMT</pubDate><product>Access</product></item><item><title>Access - App launcher customization</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/access/#app-launcher-customization</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/access/#app-launcher-customization</guid><description>&lt;p&gt;Allow Access admins to configure the App Launcher page within Zero Trust.&lt;/p&gt;
</description><pubDate>Fri, 15 Sep 2023 00:00:00 GMT</pubDate><product>Access</product></item><item><title>Access - View active Access user identities in the dashboard and API</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/access/#view-active-access-user-identities-in-the-dashboard-and-api</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/access/#view-active-access-user-identities-in-the-dashboard-and-api</guid><description>&lt;p&gt;Access admins can now view the full contents of a user&amp;#39;s identity and device information for all active application sessions.&lt;/p&gt;
</description><pubDate>Fri, 15 Sep 2023 00:00:00 GMT</pubDate><product>Access</product></item><item><title>Access - Custom OIDC claims for named IdPs</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/access/#custom-oidc-claims-for-named-idps</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/access/#custom-oidc-claims-for-named-idps</guid><description>&lt;p&gt;Access admins can now add custom claims to the existing named IdP providers. Previously this was locked to the generic OIDC provider.&lt;/p&gt;
</description><pubDate>Fri, 08 Sep 2023 00:00:00 GMT</pubDate><product>Access</product></item><item><title>Access - Azure AD authentication contexts</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/access/#azure-ad-authentication-contexts</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/access/#azure-ad-authentication-contexts</guid><description>&lt;p&gt;Support Azure AD authentication contexts directly in Access policies.&lt;/p&gt;
</description><pubDate>Wed, 02 Aug 2023 00:00:00 GMT</pubDate><product>Access</product></item><item><title>Access - Custom block pages for Access applications</title><link>https://developers.cloudflare.com/cloudflare-one/changelog/access/#custom-block-pages-for-access-applications</link><guid isPermaLink="true">https://developers.cloudflare.com/cloudflare-one/changelog/access/#custom-block-pages-for-access-applications</guid><description>&lt;p&gt;Allow Access admins to customize the block pages presented by Access to end users.&lt;/p&gt;
</description><pubDate>Fri, 23 Jun 2023 00:00:00 GMT</pubDate><product>Access</product></item></channel></rss>