<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Cloudflare changelogs | Cloudflare WAN</title><description>Cloudflare changelogs for Cloudflare WAN</description><link>https://docs.ahq.lat/changelog/</link><item><title>Cloudflare WAN, Cloudflare One - Cisco IOS XE</title><link>https://docs.ahq.lat/changelog/post/2026-06-02-cisco-ios-xe/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2026-06-02-cisco-ios-xe/</guid><description>&lt;p&gt;The Cisco IOS XE third-party integration guide for Cloudflare WAN has been updated to include:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Post Quantum Cryptography (PQC)&lt;/li&gt;
&lt;li&gt;Policy-Based Routing (PBR)&lt;/li&gt;
&lt;li&gt;IP Service Level Agreement (IP SLA)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This link will take you directly to the updated &lt;a href=&quot;https://docs.ahq.lat/cloudflare-wan/configuration/third-party/cisco-ios-xe/&quot;&gt;Cisco IOS XE&lt;/a&gt; guide.&lt;/p&gt;</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><product>Cloudflare WAN</product><category>Cloudflare WAN</category><category>Cloudflare One</category></item><item><title>Cloudflare WAN, Magic Transit - Network Analytics support for Unified Routing</title><link>https://docs.ahq.lat/changelog/post/2026-05-18-unified-routing-network-analytics/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2026-05-18-unified-routing-network-analytics/</guid><description>&lt;p&gt;&lt;a href=&quot;https://docs.ahq.lat/analytics/network-analytics/&quot;&gt;Network Analytics&lt;/a&gt; is now fully supported for accounts using &lt;a href=&quot;https://docs.ahq.lat/cloudflare-wan/reference/traffic-steering/#unified-routing-mode-beta&quot;&gt;Unified Routing&lt;/a&gt; mode. Traffic that traverses Unified Routing onramps and offramps is now visible in Network Analytics with the same dimensions and filters as traffic on the standard data plane.&lt;/p&gt;
&lt;p&gt;This closes a parity gap for customers who had moved tunnels onto Unified Routing and lost visibility into their dataplane traffic in the Network Analytics dashboard. No configuration change is required — analytics data is collected automatically for all accounts with Unified Routing enabled.&lt;/p&gt;
&lt;p&gt;For the remaining beta limitations, refer to &lt;a href=&quot;https://docs.ahq.lat/cloudflare-wan/reference/traffic-steering/#beta-limitations&quot;&gt;Traffic steering beta limitations&lt;/a&gt;.&lt;/p&gt;</description><pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate><product>Cloudflare WAN</product><category>Cloudflare WAN</category><category>Magic Transit</category></item><item><title>Cloudflare WAN, Magic Transit, Cloudflare One - New accounts assigned a single IPv4 anycast address</title><link>https://docs.ahq.lat/changelog/post/2026-05-12-single-anycast-ip-default/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2026-05-12-single-anycast-ip-default/</guid><description>&lt;p&gt;New Magic Transit and Cloudflare WAN accounts are now assigned a single IPv4 anycast address by default.&lt;/p&gt;
&lt;p&gt;Cloudflare handles failures on its network automatically by advertising your endpoint IP from multiple nodes across many globally distributed data centers. To handle failures on your network, configure two tunnels from separate routers.&lt;/p&gt;
&lt;p&gt;To request additional anycast IP addresses for your account, contact your account team.&lt;/p&gt;
&lt;p&gt;For tunnel configuration guidance, refer to &lt;a href=&quot;https://docs.ahq.lat/cloudflare-wan/configuration/how-to/configure-tunnel-endpoints/&quot;&gt;Configure tunnel endpoints&lt;/a&gt; for Cloudflare WAN or &lt;a href=&quot;https://docs.ahq.lat/magic-transit/how-to/configure-tunnel-endpoints/&quot;&gt;Configure tunnel endpoints&lt;/a&gt; for Magic Transit.&lt;/p&gt;</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate><product>Cloudflare WAN</product><category>Cloudflare WAN</category><category>Magic Transit</category><category>Cloudflare One</category></item><item><title>Cloudflare WAN, Magic Transit - NAT-T support for IKE on UDP port 500</title><link>https://docs.ahq.lat/changelog/post/2026-05-11-nat-t-port-500/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2026-05-11-nat-t-port-500/</guid><description>&lt;p&gt;Cloudflare IPsec now supports the standard NAT traversal (NAT-T) flow, where IKE begins on UDP port &lt;code&gt;500&lt;/code&gt; and switches to UDP port &lt;code&gt;4500&lt;/code&gt; after NAT is detected.&lt;/p&gt;
&lt;p&gt;Previously, devices behind NAT had to be configured to initiate IKE on UDP port &lt;code&gt;4500&lt;/code&gt; directly. Devices that started on UDP port &lt;code&gt;500&lt;/code&gt; could not complete the IKE handshake when NAT was in the path. This required custom configuration on devices such as VeloCloud SD-WAN edges, Cisco IOS-XE routers, and Juniper SRX firewalls, and was not possible on every platform.&lt;/p&gt;
&lt;p&gt;What changed:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Devices behind NAT can now initiate IKE on either UDP port &lt;code&gt;500&lt;/code&gt; or UDP port &lt;code&gt;4500&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Devices that start IKE on UDP port &lt;code&gt;500&lt;/code&gt; and switch to UDP port &lt;code&gt;4500&lt;/code&gt; after NAT detection now complete the handshake successfully.&lt;/li&gt;
&lt;li&gt;No configuration change is required on Cloudflare. The change is available for all IPsec tunnels on Cloudflare WAN and Magic Transit.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This change does not affect existing tunnels:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Tunnels using UDP port &lt;code&gt;500&lt;/code&gt; with no NAT detected continue to operate as before.&lt;/li&gt;
&lt;li&gt;Tunnels configured to start IKE on UDP port &lt;code&gt;4500&lt;/code&gt; continue to operate as before.&lt;/li&gt;
&lt;li&gt;NAT detection logic is unchanged.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For configuration details, refer to &lt;a href=&quot;https://docs.ahq.lat/cloudflare-wan/reference/gre-ipsec-tunnels/&quot;&gt;GRE and IPsec tunnels&lt;/a&gt;.&lt;/p&gt;</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate><product>Cloudflare WAN</product><category>Cloudflare WAN</category><category>Magic Transit</category></item><item><title>Cloudflare One Appliance, Cloudflare One, Cloudflare WAN - Custom DHCP options on Cloudflare One Appliance</title><link>https://docs.ahq.lat/changelog/post/2026-05-07-appliance-dhcp-options/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2026-05-07-appliance-dhcp-options/</guid><description>&lt;p&gt;When the Cloudflare One Appliance is acting as the DHCP server for a LAN, you can now configure custom DHCP options on the leases it issues. This unlocks workflows such as PXE / iPXE boot, VoIP phone provisioning, and vendor-specific client configuration.&lt;/p&gt;
&lt;p&gt;Each option is defined by &lt;code&gt;option_number&lt;/code&gt;, &lt;code&gt;value&lt;/code&gt;, and one of four value types: &lt;code&gt;text&lt;/code&gt;, &lt;code&gt;integer&lt;/code&gt;, &lt;code&gt;hex&lt;/code&gt;, or &lt;code&gt;ip&lt;/code&gt;. Configurations are validated on the appliance before being applied — invalid configurations are rejected and the underlying error is returned to the API caller, so a bad option will not disrupt the live DHCP service.&lt;/p&gt;
&lt;p&gt;For details, refer to &lt;a href=&quot;https://docs.ahq.lat/cloudflare-wan/configuration/appliance/network-options/dhcp/dhcp-options/&quot;&gt;DHCP server options&lt;/a&gt;.&lt;/p&gt;</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate><product>Cloudflare One Appliance</product><category>Cloudflare One Appliance</category><category>Cloudflare One</category><category>Cloudflare WAN</category></item><item><title>Cloudflare One Appliance, Cloudflare One, Cloudflare WAN - Source-based breakout and prioritization on Cloudflare One Appliance</title><link>https://docs.ahq.lat/changelog/post/2026-05-07-appliance-source-based-breakout/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2026-05-07-appliance-source-based-breakout/</guid><description>&lt;p&gt;Breakout and traffic prioritization rules on the Cloudflare One Appliance can now match by &lt;strong&gt;source&lt;/strong&gt; in addition to destination application. You can pin breakout or priority behavior to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;A source LAN interface — VLANs attached to that LAN are included automatically.&lt;/li&gt;
&lt;li&gt;A source IP address, range, or CIDR block.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This is the natural way to break out a guest VLAN to the local Internet, or to prioritize traffic from a specific subnet, without enumerating destination applications.&lt;/p&gt;
&lt;p&gt;For details, refer to &lt;a href=&quot;https://docs.ahq.lat/cloudflare-wan/configuration/appliance/network-options/application-based-policies/breakout-traffic/#breakout-by-source&quot;&gt;Breakout traffic&lt;/a&gt;.&lt;/p&gt;</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate><product>Cloudflare One Appliance</product><category>Cloudflare One Appliance</category><category>Cloudflare One</category><category>Cloudflare WAN</category></item><item><title>Cloudflare One Appliance, Cloudflare One, Cloudflare WAN - Self-serve provisioning of Cloudflare One Virtual Appliance via API</title><link>https://docs.ahq.lat/changelog/post/2026-05-07-virtual-appliance-self-serve-api/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2026-05-07-virtual-appliance-self-serve-api/</guid><description>&lt;p&gt;You can now create, rotate, and delete Cloudflare One Virtual Appliance instances and their license keys directly via the API and Terraform.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Create a virtual appliance and receive a license key: &lt;code&gt;POST /accounts/{account_id}/magic/connectors&lt;/code&gt; with &lt;code&gt;device.provision_license: true&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Rotate the license key for an existing virtual appliance: &lt;code&gt;PATCH /accounts/{account_id}/magic/connectors/{connector_id}&lt;/code&gt; with &lt;code&gt;provision_license: true&lt;/code&gt;. The previous key is immediately and irrevocably revoked.&lt;/li&gt;
&lt;li&gt;Delete a virtual appliance to release the associated licensed device.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The license key is returned in the response only once, at create or rotate time. Copy and store it securely.&lt;/p&gt;
&lt;p&gt;For details, refer to &lt;a href=&quot;https://docs.ahq.lat/cloudflare-wan/configuration/appliance/configure-virtual-appliance/&quot;&gt;Configure a Cloudflare One Virtual Appliance&lt;/a&gt;.&lt;/p&gt;</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate><product>Cloudflare One Appliance</product><category>Cloudflare One Appliance</category><category>Cloudflare One</category><category>Cloudflare WAN</category></item><item><title>Cloudflare One, Cloudflare WAN - Post-quantum IPsec interoperability with third-party devices</title><link>https://docs.ahq.lat/changelog/post/2026-04-30-ipsec-post-quantum-third-party/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2026-04-30-ipsec-post-quantum-third-party/</guid><description>&lt;p&gt;Cloudflare IPsec now supports post-quantum key agreement with compatible third-party devices. &lt;a href=&quot;https://www.cisco.com/&quot; target=&quot;_blank&quot;&gt;Cisco&lt;/a&gt; and &lt;a href=&quot;https://www.fortinet.com/&quot; target=&quot;_blank&quot;&gt;Fortinet&lt;/a&gt; are the first third-party vendors validated to interoperate with Cloudflare IPsec using ML-KEM (Module-Lattice-Based Key-Encapsulation Mechanism).&lt;/p&gt;
&lt;p&gt;Post-quantum IPsec uses &lt;a href=&quot;https://datatracker.ietf.org/doc/rfc9370/&quot; target=&quot;_blank&quot;&gt;RFC 9370&lt;/a&gt; and &lt;a href=&quot;https://datatracker.ietf.org/doc/draft-ietf-ipsecme-ikev2-mlkem/&quot; target=&quot;_blank&quot;&gt;draft-ietf-ipsecme-ikev2-mlkem&lt;/a&gt; to negotiate hybrid key agreement during the IKEv2 &lt;code&gt;IKE_INTERMEDIATE&lt;/code&gt; phase. This combines classical Diffie-Hellman (Group 20) with ML-KEM-768 or ML-KEM-1024 to protect against &lt;a href=&quot;https://en.wikipedia.org/wiki/Harvest_now,_decrypt_later&quot; target=&quot;_blank&quot;&gt;harvest-now, decrypt-later&lt;/a&gt; attacks.&lt;/p&gt;
&lt;p&gt;Key details:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Compatible with Cisco 8000 Series Secure Routers with IOS XR Release 26.1.1 and Fortinet FortiOS 7.6.6 and later.&lt;/li&gt;
&lt;li&gt;Uses ML-KEM-768 or ML-KEM-1024 as an additional Key Exchange to DH Group 20.&lt;/li&gt;
&lt;li&gt;Follows RFC 9370 and draft-ietf-ipsecme-ikev2-mlkem standards.&lt;/li&gt;
&lt;li&gt;No additional licensing required.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Post-quantum IPsec with third-party devices is now generally available with confirmed interoperability for the platforms listed above. Cloudflare intends to support interoperability with more vendors as they build out support for draft-ietf-ipsecme-ikev2-mlkem. Contact your account team to discuss support for additional vendors.&lt;/p&gt;
&lt;p&gt;For supported key exchange methods and the list of validated platforms, refer to &lt;a href=&quot;https://docs.ahq.lat/cloudflare-wan/reference/gre-ipsec-tunnels/#tested-third-party-vendor-interoperability&quot;&gt;GRE and IPsec tunnels&lt;/a&gt;.&lt;/p&gt;</description><pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate><product>Cloudflare One</product><category>Cloudflare One</category><category>Cloudflare WAN</category></item><item><title>Cloudflare Network Firewall, Magic Transit, Cloudflare WAN - Country rules supported in Unified Routing</title><link>https://docs.ahq.lat/changelog/post/2026-04-21-unified-routing-geoip-country-rules/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2026-04-21-unified-routing-geoip-country-rules/</guid><description>&lt;p&gt;&lt;a href=&quot;https://docs.ahq.lat/cloudflare-network-firewall/&quot;&gt;Cloudflare Advanced Network Firewall&lt;/a&gt; Country rules are now supported for accounts using &lt;a href=&quot;https://docs.ahq.lat/cloudflare-wan/reference/traffic-steering/#unified-routing-mode-beta&quot;&gt;Unified Routing&lt;/a&gt; mode. This feature requires a Cloudflare Advanced Network Firewall subscription.&lt;/p&gt;
&lt;p&gt;You can create firewall rules that match traffic based on source or destination country to enforce geographic access policies across your network.&lt;/p&gt;
&lt;p&gt;This is the first of the Cloudflare Advanced Network Firewall features to become available in Unified Routing. Support for additional features - IP Lists, ASN Lists, Threat Intel Lists, IDS, Rate Limiting, SIP, and Managed Rulesets - is planned.&lt;/p&gt;
&lt;p&gt;For the full list of current beta limitations, refer to &lt;a href=&quot;https://docs.ahq.lat/cloudflare-wan/reference/traffic-steering/#beta-limitations&quot;&gt;Traffic steering beta limitations&lt;/a&gt;.&lt;/p&gt;</description><pubDate>Tue, 21 Apr 2026 12:00:00 GMT</pubDate><product>Cloudflare Network Firewall</product><category>Cloudflare Network Firewall</category><category>Magic Transit</category><category>Cloudflare WAN</category></item><item><title>Cloudflare One Appliance, Cloudflare One, Cloudflare WAN - Link aggregation (LACP) support for Cloudflare One Appliance</title><link>https://docs.ahq.lat/changelog/post/2026-04-07-link-aggregation-lacp-appliance/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2026-04-07-link-aggregation-lacp-appliance/</guid><description>&lt;p&gt;Cloudflare One Appliance now supports Link Aggregation Control Protocol (LACP), allowing you to bundle up to six physical LAN ports into a single logical interface. Link aggregation increases available bandwidth and eliminates single points of failure on the LAN side of the appliance.&lt;/p&gt;
&lt;p&gt;This feature is available in beta on physical appliance hardware with the latest OS. No entitlement is required.&lt;/p&gt;
&lt;p&gt;To configure a Link Aggregation Group, refer to &lt;a href=&quot;https://docs.ahq.lat/cloudflare-wan/configuration/appliance/network-options/link-aggregation/&quot;&gt;Configure link aggregation groups&lt;/a&gt;.&lt;/p&gt;</description><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate><product>Cloudflare One Appliance</product><category>Cloudflare One Appliance</category><category>Cloudflare One</category><category>Cloudflare WAN</category></item><item><title>Cloudflare One, Cloudflare WAN, Cloudflare Network Firewall, Network Flow - Cloudflare One Product Name Updates</title><link>https://docs.ahq.lat/changelog/post/2026-02-17-product-name-updates/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2026-02-17-product-name-updates/</guid><description>&lt;p&gt;We are updating naming related to some of our Networking products to better clarify their place in the Zero Trust and Secure Access Service Edge (SASE) journey.&lt;/p&gt;
&lt;p&gt;We are retiring some older brand names in favor of names that describe exactly what the products do within your network. We are doing this to help customers build better, clearer mental models for comprehensive SASE architecture delivered on Cloudflare.&lt;/p&gt;
&lt;h4&gt;What&apos;s changing&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Magic WAN&lt;/strong&gt; → &lt;strong&gt;Cloudflare WAN&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Magic WAN IPsec&lt;/strong&gt; → &lt;strong&gt;Cloudflare IPsec&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Magic WAN GRE&lt;/strong&gt; → &lt;strong&gt;Cloudflare GRE&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Magic WAN Connector&lt;/strong&gt; → &lt;strong&gt;Cloudflare One Appliance&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Magic Firewall&lt;/strong&gt; → &lt;strong&gt;Cloudflare Network Firewall&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Magic Network Monitoring&lt;/strong&gt; → &lt;strong&gt;Network Flow&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Magic Cloud Networking&lt;/strong&gt; → &lt;strong&gt;Cloudflare One Multi-cloud Networking&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;No action is required by you&lt;/strong&gt; — all functionality, existing configurations, and billing will remain exactly the same.&lt;/p&gt;
&lt;p&gt;For more information, visit the &lt;a href=&quot;https://docs.ahq.lat/cloudflare-one/&quot;&gt;Cloudflare One documentation&lt;/a&gt;.&lt;/p&gt;</description><pubDate>Tue, 17 Feb 2026 00:00:00 GMT</pubDate><product>Cloudflare One</product><category>Cloudflare One</category><category>Cloudflare WAN</category><category>Cloudflare Network Firewall</category><category>Network Flow</category></item><item><title>Cloudflare WAN - Anycast IPs displayed on the dashboard</title><link>https://docs.ahq.lat/changelog/post/2026-02-12-anycast-ips-on-dashboard/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2026-02-12-anycast-ips-on-dashboard/</guid><description>&lt;p&gt;Cloudflare WAN now displays your Anycast IP addresses directly in the dashboard when you configure IPsec or GRE tunnels.&lt;/p&gt;
&lt;p&gt;Previously, customers received their Anycast IPs during onboarding or had to retrieve them with an API call. The dashboard now pre-loads these addresses, reducing setup friction and preventing configuration errors.&lt;/p&gt;
&lt;p&gt;No action is required. All Cloudflare WAN customers can see their Anycast IPs in the tunnel configuration form automatically.&lt;/p&gt;
&lt;p&gt;For more information, refer to &lt;a href=&quot;https://docs.ahq.lat/cloudflare-wan/configuration/how-to/configure-tunnel-endpoints/&quot;&gt;Configure tunnel endpoints&lt;/a&gt;.&lt;/p&gt;</description><pubDate>Thu, 12 Feb 2026 00:00:00 GMT</pubDate><product>Cloudflare WAN</product><category>Cloudflare WAN</category></item><item><title>Cloudflare One Appliance, Cloudflare One, Cloudflare WAN - Post-quantum encryption support for Cloudflare One Appliance</title><link>https://docs.ahq.lat/changelog/post/2026-02-11-appliance-post-quantum-encryption/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2026-02-11-appliance-post-quantum-encryption/</guid><description>&lt;p&gt;Cloudflare One Appliance version 2026.2.0 adds &lt;a href=&quot;https://docs.ahq.lat/ssl/post-quantum-cryptography/&quot;&gt;post-quantum encryption&lt;/a&gt; support using hybrid ML-KEM (Module-Lattice-Based Key-Encapsulation Mechanism).&lt;/p&gt;
&lt;p&gt;The appliance now uses TLS 1.3 with hybrid ML-KEM for its connection to the Cloudflare edge. During the TLS handshake, the appliance and the edge share a symmetric secret over the TLS connection and inject it into the ESP layer of IPsec. This protects IPsec data plane traffic against harvest-now, decrypt-later attacks.&lt;/p&gt;
&lt;p&gt;This upgrade deploys automatically to all appliances during their configured interrupt windows with no manual action required.&lt;/p&gt;
&lt;p&gt;For more information, refer to &lt;a href=&quot;https://docs.ahq.lat/cloudflare-wan/configuration/appliance/&quot;&gt;Cloudflare One Appliance&lt;/a&gt;.&lt;/p&gt;</description><pubDate>Wed, 11 Feb 2026 00:00:00 GMT</pubDate><product>Cloudflare One Appliance</product><category>Cloudflare One Appliance</category><category>Cloudflare One</category><category>Cloudflare WAN</category></item><item><title>Cloudflare WAN, Magic Transit, Cloudflare One - BGP over GRE and IPsec tunnels</title><link>https://docs.ahq.lat/changelog/post/2026-01-30-bgp-over-tunnels/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2026-01-30-bgp-over-tunnels/</guid><description>&lt;p&gt;Magic WAN and Magic Transit customers can use the Cloudflare dashboard to configure and manage BGP peering between their networks and their Magic routing table when using IPsec and GRE tunnel on-ramps (beta).&lt;/p&gt;
&lt;p&gt;Using BGP peering allows customers to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Automate the process of adding or removing networks and subnets.&lt;/li&gt;
&lt;li&gt;Take advantage of failure detection and session recovery features.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;With this functionality, customers can:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Establish an eBGP session between their devices and the Magic WAN / Magic Transit service when connected via IPsec and GRE tunnel on-ramps.&lt;/li&gt;
&lt;li&gt;Secure the session by MD5 authentication to prevent misconfigurations.&lt;/li&gt;
&lt;li&gt;Exchange routes dynamically between their devices and their Magic routing table.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For configuration details, refer to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.ahq.lat/cloudflare-wan/configuration/how-to/configure-routes/#configure-bgp-routes&quot;&gt;Configure BGP routes for Magic WAN&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.ahq.lat/magic-transit/how-to/configure-routes/#configure-bgp-routes&quot;&gt;Configure BGP routes for Magic Transit&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description><pubDate>Fri, 30 Jan 2026 00:00:00 GMT</pubDate><product>Cloudflare WAN</product><category>Cloudflare WAN</category><category>Magic Transit</category><category>Cloudflare One</category></item><item><title>Cloudflare One, Cloudflare WAN - Configure Cloudflare source IPs (beta)</title><link>https://docs.ahq.lat/changelog/post/2026-01-27-configure-cloudflare-source-ips/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2026-01-27-configure-cloudflare-source-ips/</guid><description>&lt;p&gt;Cloudflare source IPs are the IP addresses used by Cloudflare services (such as Load Balancing, Gateway, and Browser Isolation) when sending traffic to your private networks.&lt;/p&gt;
&lt;p&gt;For customers using legacy mode routing, traffic to private networks is sourced from public Cloudflare IPs, which may cause IP conflicts. For customers using Unified Routing mode (beta), traffic to private networks is sourced from dedicated, non-Internet-routable private IPv4 range to ensure:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Symmetric routing over private network connections&lt;/li&gt;
&lt;li&gt;Proper firewall state preservation&lt;/li&gt;
&lt;li&gt;Private traffic stays on secure paths&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Key details:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;IPv4&lt;/strong&gt;: Sourced from &lt;code&gt;100.64.0.0/12&lt;/code&gt; by default, configurable to any &lt;code&gt;/12&lt;/code&gt; CIDR&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;IPv6&lt;/strong&gt;: Sourced from &lt;code&gt;2606:4700:cf1:5000::/64&lt;/code&gt; (not configurable)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Affected connectors&lt;/strong&gt;: GRE, IPsec, CNI, WARP Connector, and WARP Client (Cloudflare Tunnel is not affected)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Configuring Cloudflare source IPs requires Unified Routing (beta) and the &lt;code&gt;Cloudflare One Networks Write&lt;/code&gt; permission.&lt;/p&gt;
&lt;p&gt;For configuration details, refer to &lt;a href=&quot;https://docs.ahq.lat/cloudflare-wan/configuration/how-to/configure-cloudflare-source-ips/&quot;&gt;Configure Cloudflare source IPs&lt;/a&gt;.&lt;/p&gt;</description><pubDate>Tue, 27 Jan 2026 00:00:00 GMT</pubDate><product>Cloudflare One</product><category>Cloudflare One</category><category>Cloudflare WAN</category></item><item><title>Magic Transit, Cloudflare Network Firewall, Cloudflare WAN, Network Flow - Network Services navigation update</title><link>https://docs.ahq.lat/changelog/post/2026-01-15-networking-navigation-update/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2026-01-15-networking-navigation-update/</guid><description>&lt;p&gt;The Network Services menu structure in Cloudflare&apos;s dashboard has been updated to reflect solutions and capabilities instead of product names. This will make it easier for you to find what you need and better reflects how our services work together.&lt;/p&gt;
&lt;p&gt;Your existing configurations will remain the same, and you will have access to all of the same features and functionality.&lt;/p&gt;
&lt;p&gt;The changes visible in your dashboard may vary based on the products you use. Overall, changes relate to &lt;a href=&quot;https://docs.ahq.lat/magic-transit/&quot; target=&quot;_blank&quot;&gt;Magic Transit&lt;/a&gt;, &lt;a href=&quot;https://docs.ahq.lat/magic-wan/&quot; target=&quot;_blank&quot;&gt;Magic WAN&lt;/a&gt;, and &lt;a href=&quot;https://docs.ahq.lat/cloudflare-network-firewall/&quot; target=&quot;_blank&quot;&gt;Magic Firewall&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Summary of changes:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;A new &lt;strong&gt;Overview&lt;/strong&gt; page provides access to the most common tasks across Magic Transit and Magic WAN.&lt;/li&gt;
&lt;li&gt;Product names have been removed from top-level navigation.&lt;/li&gt;
&lt;li&gt;Magic Transit and Magic WAN configuration is now organized under &lt;strong&gt;Routes&lt;/strong&gt; and &lt;strong&gt;Connectors&lt;/strong&gt;. For example, you will find IP Prefixes under &lt;strong&gt;Routes&lt;/strong&gt;, and your GRE/IPsec Tunnels under &lt;strong&gt;Connectors.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Magic Firewall policies are now called &lt;strong&gt;Firewall Policies.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Magic WAN Connectors and Connector On-Ramps are now referenced in the dashboard as &lt;strong&gt;Appliances&lt;/strong&gt; and &lt;strong&gt;Appliance profiles.&lt;/strong&gt; They can be found under &lt;strong&gt;Connectors &gt; Appliances.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Network analytics, network health, and real-time analytics are now available under &lt;strong&gt;Insights.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Packet Captures are found under &lt;strong&gt;Insights &gt; Diagnostics.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;You can manage your Sites from &lt;strong&gt;Insights &gt; Network health.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;You can find Magic Network Monitoring under &lt;strong&gt;Insights &gt; Network flow&lt;/strong&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you would like to provide feedback, complete &lt;a href=&quot;https://forms.gle/htWyjRsTjw1usdis5&quot; target=&quot;_blank&quot;&gt;this form&lt;/a&gt;. You can also find these details in the January 7, 2026 email titled &lt;strong&gt;[FYI] Upcoming Network Services Dashboard Navigation Update&lt;/strong&gt;.&lt;/p&gt;
&lt;starlight-image-zoom-zoomable&gt;&lt;img src=&quot;https://docs.ahq.lat/_astro/networking-overview-and-navigation.CeMgEFaZ_Z20HKl.webp&quot; alt=&quot;Networking Navigation&quot;&gt;&lt;/starlight-image-zoom-zoomable&gt;</description><pubDate>Thu, 15 Jan 2026 00:00:00 GMT</pubDate><product>Magic Transit</product><category>Magic Transit</category><category>Cloudflare Network Firewall</category><category>Cloudflare WAN</category><category>Network Flow</category></item><item><title>Cloudflare One Appliance, Cloudflare One, Cloudflare WAN - Breakout traffic visibility via NetFlow</title><link>https://docs.ahq.lat/changelog/post/2025-12-31-connector-breakout-traffic-netflow/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2025-12-31-connector-breakout-traffic-netflow/</guid><description>&lt;p&gt;Magic WAN Connector now exports NetFlow data for breakout traffic to Magic Network Monitoring (MNM), providing visibility into traffic that bypasses Cloudflare&apos;s security filtering.&lt;/p&gt;
&lt;p&gt;This feature allows you to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Monitor breakout traffic statistics in the Cloudflare dashboard.&lt;/li&gt;
&lt;li&gt;View traffic patterns for applications configured to bypass Cloudflare.&lt;/li&gt;
&lt;li&gt;Maintain visibility across all traffic passing through your Magic WAN Connector.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For more information, refer to &lt;a href=&quot;https://docs.ahq.lat/cloudflare-wan/analytics/netflow-analytics/&quot;&gt;NetFlow statistics&lt;/a&gt;.&lt;/p&gt;</description><pubDate>Wed, 31 Dec 2025 00:00:00 GMT</pubDate><product>Cloudflare One Appliance</product><category>Cloudflare One Appliance</category><category>Cloudflare One</category><category>Cloudflare WAN</category></item><item><title>Cloudflare One, Cloudflare WAN - Automatic Return Routing (Beta)</title><link>https://docs.ahq.lat/changelog/post/2025-11-06-automatic-return-routing-beta/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2025-11-06-automatic-return-routing-beta/</guid><description>&lt;p&gt;Magic WAN now supports Automatic Return Routing (ARR), allowing customers to configure Magic on-ramps (IPsec/GRE/CNI) to learn the return path for traffic flows without requiring static routes.&lt;/p&gt;
&lt;p&gt;Key benefits:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Route-less mode&lt;/strong&gt;: Static or dynamic routes are optional when using ARR.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Overlapping IP space support&lt;/strong&gt;: Traffic originating from customer sites can use overlapping private IP ranges.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Symmetric routing&lt;/strong&gt;: Return traffic is guaranteed to use the same connection as the original on-ramp.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This feature is currently in beta and requires the new Unified Routing mode (beta).&lt;/p&gt;
&lt;p&gt;For configuration details, refer to &lt;a href=&quot;https://docs.ahq.lat/cloudflare-wan/configuration/how-to/configure-routes/#configure-automatic-return-routing-beta&quot;&gt;Configure Automatic Return Routing&lt;/a&gt;.&lt;/p&gt;</description><pubDate>Thu, 06 Nov 2025 00:00:00 GMT</pubDate><product>Cloudflare One</product><category>Cloudflare One</category><category>Cloudflare WAN</category></item><item><title>Cloudflare One Appliance, Cloudflare One, Cloudflare WAN - Designate WAN link for breakout traffic</title><link>https://docs.ahq.lat/changelog/post/2025-11-06-connector-designate-wan-link-breakout/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2025-11-06-connector-designate-wan-link-breakout/</guid><description>&lt;p&gt;Magic WAN Connector now allows you to designate a specific WAN port for breakout traffic, giving you deterministic control over the egress path for latency-sensitive applications.&lt;/p&gt;
&lt;p&gt;With this feature, you can:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Pin breakout traffic for specific applications to a preferred WAN port.&lt;/li&gt;
&lt;li&gt;Ensure critical traffic (such as Zoom or Teams) always uses your fastest or most reliable connection.&lt;/li&gt;
&lt;li&gt;Benefit from automatic failover to standard WAN port priority if the preferred port goes down.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This is useful for organizations with multiple ISP uplinks who need predictable egress behavior for performance-sensitive traffic.&lt;/p&gt;
&lt;p&gt;For configuration details, refer to &lt;a href=&quot;https://docs.ahq.lat/cloudflare-wan/configuration/appliance/network-options/application-based-policies/breakout-traffic/#designate-wan-ports-for-breakout-apps&quot;&gt;Designate WAN ports for breakout apps&lt;/a&gt;.&lt;/p&gt;</description><pubDate>Thu, 06 Nov 2025 00:00:00 GMT</pubDate><product>Cloudflare One Appliance</product><category>Cloudflare One Appliance</category><category>Cloudflare One</category><category>Cloudflare WAN</category></item><item><title>Gateway, Cloudflare WAN, Cloudflare Tunnel for SASE - DNS filtering for private network onramps</title><link>https://docs.ahq.lat/changelog/post/2025-09-11-dns-filtering-for-private-network-onramps/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2025-09-11-dns-filtering-for-private-network-onramps/</guid><description>&lt;p&gt;&lt;a href=&quot;https://docs.ahq.lat/cloudflare-wan/zero-trust/cloudflare-gateway/#dns-filtering&quot;&gt;Magic WAN&lt;/a&gt; and &lt;a href=&quot;https://docs.ahq.lat/cloudflare-one/networks/connectors/cloudflare-mesh/routes/#dns-filtering&quot;&gt;WARP Connector&lt;/a&gt; users can now securely route their DNS traffic to the Gateway resolver without exposing traffic to the public Internet.&lt;/p&gt;
&lt;p&gt;Routing DNS traffic to the Gateway resolver allows DNS resolution and filtering for traffic coming from private networks while preserving source internal IP visibility. This ensures Magic WAN users have full integration with our Cloudflare One features, including &lt;a href=&quot;https://docs.ahq.lat/cloudflare-one/traffic-policies/resolver-policies/#internal-dns&quot;&gt;Internal DNS&lt;/a&gt; and &lt;a href=&quot;https://docs.ahq.lat/cloudflare-one/traffic-policies/egress-policies/#selector-prerequisites&quot;&gt;hostname-based policies&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;To configure DNS filtering, change your Magic WAN or WARP Connector DNS settings to use Cloudflare&apos;s shared resolver IPs, &lt;code&gt;172.64.36.1&lt;/code&gt; and &lt;code&gt;172.64.36.2&lt;/code&gt;. Once you configure DNS resolution and filtering, you can use &lt;em&gt;Source Internal IP&lt;/em&gt; as a traffic selector in your &lt;a href=&quot;https://docs.ahq.lat/cloudflare-one/traffic-policies/resolver-policies/&quot;&gt;resolver policies&lt;/a&gt; for routing private DNS traffic to your &lt;a href=&quot;https://docs.ahq.lat/dns/internal-dns/&quot;&gt;Internal DNS&lt;/a&gt;.&lt;/p&gt;</description><pubDate>Thu, 11 Sep 2025 00:00:00 GMT</pubDate><product>Gateway</product><category>Gateway</category><category>Cloudflare WAN</category><category>Cloudflare Tunnel for SASE</category></item><item><title>Cloudflare WAN - Custom IKE ID for IPsec Tunnels</title><link>https://docs.ahq.lat/changelog/post/2025-09-08-custom-ike-id-ipsec-tunnels/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2025-09-08-custom-ike-id-ipsec-tunnels/</guid><description>&lt;p&gt;Now, Magic WAN customers can configure a custom IKE ID for their IPsec tunnels. Customers that are using Magic WAN and a VeloCloud SD-WAN device together can utilize this new feature to create a high availability configuration.&lt;/p&gt;
&lt;p&gt;This feature is available via API only. Customers can read the Magic WAN documentation to learn more about the &lt;a href=&quot;https://docs.ahq.lat/cloudflare-wan/configuration/common-settings/custom-ike-id-ipsec/&quot;&gt;Custom IKE ID feature and the API call to configure it&lt;/a&gt;.&lt;/p&gt;</description><pubDate>Mon, 08 Sep 2025 00:00:00 GMT</pubDate><product>Cloudflare WAN</product><category>Cloudflare WAN</category></item><item><title>Cloudflare WAN - Bidirectional tunnel health checks are compatible with all Magic on-ramps</title><link>https://docs.ahq.lat/changelog/post/2025-09-05-bidirectional-health-check-any-on-ramp/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2025-09-05-bidirectional-health-check-any-on-ramp/</guid><description>&lt;p&gt;All bidirectional tunnel health check return packets are accepted by any Magic on-ramp.&lt;/p&gt;
&lt;p&gt;Previously, when a Magic tunnel had a bidirectional health check configured, the bidirectional health check would pass when the return packets came back to Cloudflare over the same tunnel that was traversed by the forward packets.&lt;/p&gt;
&lt;p&gt;There are SD-WAN devices, like VeloCloud, that do not offer controls to steer traffic over one tunnel versus another in a high availability tunnel configuration.&lt;/p&gt;
&lt;p&gt;Now, when a Magic tunnel has a bidirectional health check configured, the bidirectional health check will pass when the return packet traverses over any tunnel in a high availability configuration.&lt;/p&gt;</description><pubDate>Fri, 05 Sep 2025 00:00:00 GMT</pubDate><product>Cloudflare WAN</product><category>Cloudflare WAN</category></item><item><title>Cloudflare WAN - Terraform V5 support for tunnels and routes</title><link>https://docs.ahq.lat/changelog/post/2025-07-31-terraform-v5-tunnels-routes/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2025-07-31-terraform-v5-tunnels-routes/</guid><description>&lt;p&gt;The Cloudflare Terraform provider resources for Cloudflare WAN tunnels and routes now support Terraform provider version 5. Customers using infrastructure-as-code workflows can manage their tunnel and route configuration with the latest provider version.&lt;/p&gt;
&lt;p&gt;For more information, refer to the &lt;a href=&quot;https://registry.terraform.io/providers/cloudflare/cloudflare/latest/docs&quot; target=&quot;_blank&quot;&gt;Cloudflare Terraform provider documentation&lt;/a&gt;.&lt;/p&gt;</description><pubDate>Thu, 31 Jul 2025 00:00:00 GMT</pubDate><product>Cloudflare WAN</product><category>Cloudflare WAN</category></item><item><title>Magic Transit, Cloudflare WAN - Magic Transit and Magic WAN health check data is fully compatible with the CMB EU setting.</title><link>https://docs.ahq.lat/changelog/post/2025-07-30-mt-mwan-health-check-cmb-eu/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2025-07-30-mt-mwan-health-check-cmb-eu/</guid><description>&lt;p&gt;Today, we are excited to announce that all Magic Transit and Magic WAN customers with CMB EU (&lt;a href=&quot;https://docs.ahq.lat/data-localization/metadata-boundary/&quot;&gt;Customer Metadata Boundary - Europe&lt;/a&gt;) enabled in their account will be able to access GRE, IPsec, and CNI health check and traffic volume data in the Cloudflare dashboard and via API.&lt;/p&gt;
&lt;p&gt;This ensures that all Magic Transit and Magic WAN customers with CMB EU enabled will be able to access all Magic Transit and Magic WAN features.&lt;/p&gt;
&lt;p&gt;Specifically, these two GraphQL endpoints are now compatible with CMB EU:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;magicTransitTunnelHealthChecksAdaptiveGroups&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;magicTransitTunnelTrafficAdaptiveGroups&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;</description><pubDate>Wed, 30 Jul 2025 00:00:00 GMT</pubDate><product>Magic Transit</product><category>Magic Transit</category><category>Cloudflare WAN</category></item><item><title>Cloudflare One Appliance, Cloudflare One, Cloudflare WAN - Virtual Cloudflare One Appliance with KVM support (open beta)</title><link>https://docs.ahq.lat/changelog/post/2025-07-21-virtual-appliance-kvm-proxmox/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2025-07-21-virtual-appliance-kvm-proxmox/</guid><description>&lt;p&gt;The KVM-based virtual Cloudflare One Appliance is now in open beta with official support for Proxmox VE.&lt;/p&gt;
&lt;p&gt;Customers can deploy the virtual appliance on KVM hypervisors to connect branch or data center networks to Cloudflare WAN without dedicated hardware.&lt;/p&gt;
&lt;p&gt;For setup instructions, refer to &lt;a href=&quot;https://docs.ahq.lat/cloudflare-wan/configuration/appliance/configure-virtual-appliance/&quot;&gt;Configure a virtual Cloudflare One Appliance&lt;/a&gt;.&lt;/p&gt;</description><pubDate>Mon, 21 Jul 2025 00:00:00 GMT</pubDate><product>Cloudflare One Appliance</product><category>Cloudflare One Appliance</category><category>Cloudflare One</category><category>Cloudflare WAN</category></item><item><title>Cloudflare One Appliance, Cloudflare One, Cloudflare WAN - Cloudflare One Appliance supports multiple DNS server IPs</title><link>https://docs.ahq.lat/changelog/post/2025-04-30-appliance-multiple-dns-servers/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2025-04-30-appliance-multiple-dns-servers/</guid><description>&lt;p&gt;Cloudflare One Appliance DHCP server settings now support specifying multiple DNS server IP addresses in the DHCP pool.&lt;/p&gt;
&lt;p&gt;Previously, customers could only configure a single DNS server per DHCP pool. With this update, you can specify multiple DNS servers to provide redundancy for clients at branch locations.&lt;/p&gt;
&lt;p&gt;For configuration details, refer to &lt;a href=&quot;https://docs.ahq.lat/cloudflare-wan/configuration/appliance/network-options/dhcp/dhcp-server/&quot;&gt;DHCP server&lt;/a&gt;.&lt;/p&gt;</description><pubDate>Wed, 30 Apr 2025 00:00:00 GMT</pubDate><product>Cloudflare One Appliance</product><category>Cloudflare One Appliance</category><category>Cloudflare One</category><category>Cloudflare WAN</category></item><item><title>Cloudflare One Appliance, Cloudflare One, Cloudflare WAN - Configure your Magic WAN Connector to connect via static IP assignment</title><link>https://docs.ahq.lat/changelog/post/2025-02-14-local-console-access/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2025-02-14-local-console-access/</guid><description>&lt;p&gt;You can now locally configure your &lt;a href=&quot;https://docs.ahq.lat/cloudflare-wan/configuration/appliance/&quot;&gt;Magic WAN Connector&lt;/a&gt; to work in a static IP configuration.&lt;/p&gt;
&lt;p&gt;This local method does not require having access to a DHCP Internet connection. However, it does require being comfortable with using tools to access the serial port on Magic WAN Connector as well as using a serial terminal client to access the Connector&apos;s environment.&lt;/p&gt;
&lt;p&gt;For more details, refer to &lt;a href=&quot;https://docs.ahq.lat/cloudflare-wan/configuration/appliance/configure-hardware-appliance/#bootstrap-via-serial-console&quot;&gt;WAN with a static IP address&lt;/a&gt;.&lt;/p&gt;</description><pubDate>Fri, 14 Feb 2025 00:00:00 GMT</pubDate><product>Cloudflare One Appliance</product><category>Cloudflare One Appliance</category><category>Cloudflare One</category><category>Cloudflare WAN</category></item><item><title>Magic Transit, Cloudflare WAN, Network Interconnect - Establish BGP peering over Direct CNI circuits</title><link>https://docs.ahq.lat/changelog/post/2024-12-17-bgp-support-cni/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2024-12-17-bgp-support-cni/</guid><description>&lt;p&gt;Magic WAN and Magic Transit customers can use the Cloudflare dashboard to configure and manage BGP peering between their networks and their Magic routing table when using a Direct CNI on-ramp.&lt;/p&gt;
&lt;p&gt;Using BGP peering allows customers to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Automate the process of adding or removing networks and subnets.&lt;/li&gt;
&lt;li&gt;Take advantage of failure detection and session recovery features.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;With this functionality, customers can:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Establish an eBGP session between their devices and the Magic WAN / Magic Transit service when connected via CNI.&lt;/li&gt;
&lt;li&gt;Secure the session by MD5 authentication to prevent misconfigurations.&lt;/li&gt;
&lt;li&gt;Exchange routes dynamically between their devices and their Magic routing table.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Refer to &lt;a href=&quot;https://docs.ahq.lat/cloudflare-wan/configuration/how-to/configure-routes/#configure-bgp-routes&quot;&gt;Magic WAN BGP peering&lt;/a&gt; or &lt;a href=&quot;https://docs.ahq.lat/magic-transit/how-to/configure-routes/#configure-bgp-routes&quot;&gt;Magic Transit BGP peering&lt;/a&gt; to learn more about this feature and how to set it up.&lt;/p&gt;</description><pubDate>Tue, 17 Dec 2024 00:00:00 GMT</pubDate><product>Magic Transit</product><category>Magic Transit</category><category>Cloudflare WAN</category><category>Network Interconnect</category></item><item><title>Access, Browser Isolation, CASB, Cloudflare Tunnel for SASE, Digital Experience Monitoring, Data Loss Prevention, Email security, Gateway, Multi-Cloud Networking, Cloudflare Network Firewall, Network Flow, Magic Transit, Cloudflare WAN, Network Interconnect, Risk Score, Cloudflare One Client - Explore product updates for Cloudflare One</title><link>https://docs.ahq.lat/changelog/post/2024-06-16-cloudflare-one/</link><guid isPermaLink="true">https://docs.ahq.lat/changelog/post/2024-06-16-cloudflare-one/</guid><description>&lt;p&gt;Welcome to your new home for product updates on &lt;a href=&quot;https://docs.ahq.lat/cloudflare-one/&quot;&gt;Cloudflare One&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Our &lt;a href=&quot;https://docs.ahq.lat/changelog/&quot;&gt;new changelog&lt;/a&gt; lets you read about changes in much more depth, offering in-depth examples, images, code samples, and even gifs.&lt;/p&gt;
&lt;p&gt;If you are looking for older product updates, refer to the following locations.&lt;/p&gt;
&lt;details&gt; &lt;summary&gt;&lt;p&gt;Older product updates&lt;/p&gt;
&lt;/summary&gt; &lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.ahq.lat/cloudflare-one/changelog/access/&quot;&gt;Access&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.ahq.lat/cloudflare-one/changelog/browser-isolation/&quot;&gt;Browser Isolation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.ahq.lat/cloudflare-one/changelog/casb/&quot;&gt;CASB&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.ahq.lat/cloudflare-one/changelog/tunnel/&quot;&gt;Cloudflare Tunnel&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.ahq.lat/cloudflare-one/changelog/dlp/&quot;&gt;Data Loss Prevention&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.ahq.lat/cloudflare-one/changelog/dex/&quot;&gt;Digital Experience Monitoring&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.ahq.lat/cloudflare-one/changelog/email-security/&quot;&gt;Email security&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.ahq.lat/cloudflare-one/changelog/gateway/&quot;&gt;Gateway&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.ahq.lat/multi-cloud-networking/changelog/&quot;&gt;Multi-Cloud Networking&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.ahq.lat/cloudflare-network-firewall/changelog/&quot;&gt;Cloudflare Network Firewall&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.ahq.lat/network-flow/changelog/&quot;&gt;Magic Network Monitoring&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.ahq.lat/magic-transit/changelog/&quot;&gt;Magic Transit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.ahq.lat/cloudflare-wan/changelog/&quot;&gt;Magic WAN&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.ahq.lat/network-interconnect/changelog/&quot;&gt;Network Interconnect&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.ahq.lat/cloudflare-one/changelog/risk-score/&quot;&gt;Risk score&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.ahq.lat/changelog/cloudflare-one-client/&quot;&gt;Cloudflare One Client&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt; &lt;/details&gt;</description><pubDate>Sun, 16 Jun 2024 00:00:00 GMT</pubDate><product>Access</product><category>Access</category><category>Browser Isolation</category><category>CASB</category><category>Cloudflare Tunnel for SASE</category><category>Digital Experience Monitoring</category><category>Data Loss Prevention</category><category>Email security</category><category>Gateway</category><category>Multi-Cloud Networking</category><category>Cloudflare Network Firewall</category><category>Network Flow</category><category>Magic Transit</category><category>Cloudflare WAN</category><category>Network Interconnect</category><category>Risk Score</category><category>Cloudflare One Client</category></item></channel></rss>