<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Cloudflare changelogs | Cloudflare One</title><description>Cloudflare changelogs for Cloudflare One products</description><link>https://cloudflaredoc.ubitools.com/changelog/</link><item><title>Cloudflare One Client - Cloudflare One Client for Windows (version 2026.6.880.0)</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-07-21-warp-windows-ga/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-07-21-warp-windows-ga/</guid><description>&lt;p&gt;A new GA release for the Windows Cloudflare One Client is now available on the &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/&quot;&gt;stable releases downloads page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This hotfix resolves a regression that caused a large increase in DNS-over-TCP queries to fallback and internal DNS servers. The client now sends fallback DNS queries over UDP first, falling back to TCP only when a response is truncated, instead of querying both protocols in parallel.&lt;/p&gt;
</description><pubDate>Tue, 21 Jul 2026 16:55:55 GMT</pubDate><product>Cloudflare One Client</product><category>Cloudflare One Client</category></item><item><title>Cloudflare One Client - Cloudflare One Client for macOS (version 2026.6.880.0)</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-07-21-warp-macos-ga/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-07-21-warp-macos-ga/</guid><description>&lt;p&gt;A new GA release for the macOS Cloudflare One Client is now available on the &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/&quot;&gt;stable releases downloads page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This hotfix resolves a regression that caused a large increase in DNS-over-TCP queries to fallback and internal DNS servers. The client now sends fallback DNS queries over UDP first, falling back to TCP only when a response is truncated, instead of querying both protocols in parallel.&lt;/p&gt;
</description><pubDate>Tue, 21 Jul 2026 16:55:55 GMT</pubDate><product>Cloudflare One Client</product><category>Cloudflare One Client</category></item><item><title>Cloudflare One Client - Cloudflare One Client for Linux (version 2026.6.880.0)</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-07-21-warp-linux-ga/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-07-21-warp-linux-ga/</guid><description>&lt;p&gt;A new GA release for the Linux Cloudflare One Client is now available on the &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/&quot;&gt;stable releases downloads page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This hotfix resolves a regression that caused a large increase in DNS-over-TCP queries to fallback and internal DNS servers. The client now sends fallback DNS queries over UDP first, falling back to TCP only when a response is truncated, instead of querying both protocols in parallel.&lt;/p&gt;
</description><pubDate>Tue, 21 Jul 2026 16:50:41 GMT</pubDate><product>Cloudflare One Client</product><category>Cloudflare One Client</category></item><item><title>Access - 针对明文 HTTP 私有应用程序的基于浏览器的登录</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-07-20-http-private-apps-l7-auth/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-07-20-http-private-apps-l7-auth/</guid><description>&lt;p&gt;Cloudflare Access 现在对通过端口 &lt;code&gt;80&lt;/code&gt; 上的明文 HTTP 提供服务的&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/access-controls/applications/non-http/self-hosted-private-app/&quot;&gt;私有应用程序&lt;/a&gt;使用标准的基于浏览器的登录流程。&lt;/p&gt;
&lt;p&gt;以前，明文 HTTP 私有应用程序会回退到与 SSH、RDP 和其他非 HTTP 协议相同的会话流程：用户会从 Cloudflare One Client 收到一个“需要身份验证（Authentication required）”弹窗，然后必须选择该通知以打开浏览器并登录。现在，访问 HTTP 私有应用程序的用户会直接在浏览器中看到 Access 登录页面，并在成功后收到标准的 Access &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/access-controls/applications/http-apps/authorization-cookie/application-token/&quot;&gt;应用程序令牌（application token）&lt;/a&gt;。&lt;/p&gt;
&lt;p&gt;这使得 HTTP 体验与 HTTPS 应用程序（开启了 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/http-policies/tls-decryption/&quot;&gt;Gateway TLS 解密&lt;/a&gt;）保持一致。无需更改配置。仍然需要 Cloudflare One Client 将流量路由到私有网络，但它不再管理 HTTP 应用程序的 Access 会话。&lt;/p&gt;
&lt;p&gt;其他非 HTTP 协议（SSH、RDP、任意 TCP/UDP）继续使用 Cloudflare One Client 通知流程。&lt;/p&gt;</description><pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate><product>Access</product><category>Access</category></item><item><title>Gateway - Gateway HTTP 策略的新请求头控制选项</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-07-17-http-request-header-manipulation/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-07-17-http-request-header-manipulation/</guid><description>&lt;p&gt;Cloudflare Gateway 现在支持在&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/http-policies/#allow&quot;&gt;允许策略&lt;/a&gt;上进行高级请求头控制。管理员可以使用静态值或动态变量来添加、重写或删除匹配请求上的请求头。&lt;/p&gt;
&lt;div tabindex=&quot;-1&quot; class=&quot;heading-wrapper level-h4&quot;&gt;&lt;h4 id=&quot;请求头操作&quot;&gt;请求头操作&lt;/h4&gt;&lt;a class=&quot;anchor-link&quot; href=&quot;#请求头操作&quot;&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;anchor-icon&quot;&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 24 24&quot;&gt;&lt;path fill=&quot;currentcolor&quot; d=&quot;m12.11 15.39-3.88 3.88a2.52 2.52 0 0 1-3.5 0 2.47 2.47 0 0 1 0-3.5l3.88-3.88a1 1 0 0 0-1.42-1.42l-3.88 3.89a4.48 4.48 0 0 0 6.33 6.33l3.89-3.88a1 1 0 1 0-1.42-1.42Zm8.58-12.08a4.49 4.49 0 0 0-6.33 0l-3.89 3.88a1 1 0 0 0 1.42 1.42l3.88-3.88a2.52 2.52 0 0 1 3.5 0 2.47 2.47 0 0 1 0 3.5l-3.88 3.88a1 1 0 1 0 1.42 1.42l3.88-3.89a4.49 4.49 0 0 0 0-6.33ZM8.83 15.17a1 1 0 0 0 1.1.22 1 1 0 0 0 .32-.22l4.92-4.92a1 1 0 0 0-1.42-1.42l-4.92 4.92a1 1 0 0 0 0 1.42Z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;p&gt;使用“允许”（Allow）操作的 Gateway HTTP 策略在 &lt;code&gt;rule_settings&lt;/code&gt; 中支持三种操作：&lt;/p&gt;
&lt;div class=&quot;table-scroll&quot; tabindex=&quot;0&quot; role=&quot;region&quot; aria-label=&quot;Table&quot;&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;操作&lt;/th&gt;
&lt;th&gt;API 字段&lt;/th&gt;
&lt;th&gt;行为&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;添加&lt;/td&gt;
&lt;td&gt;&lt;code&gt;add_headers&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;向请求头追加值。保留现有值。&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;重写&lt;/td&gt;
&lt;td&gt;&lt;code&gt;set_headers&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;替换请求头的值。如果请求头不存在，则创建它。&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;删除&lt;/td&gt;
&lt;td&gt;&lt;code&gt;delete_headers&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;从请求中移除该请求头。&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;p&gt;Gateway 按以下顺序应用操作：首先删除，然后重写，最后添加。&lt;/p&gt;
&lt;div tabindex=&quot;-1&quot; class=&quot;heading-wrapper level-h4&quot;&gt;&lt;h4 id=&quot;动态变量&quot;&gt;动态变量&lt;/h4&gt;&lt;a class=&quot;anchor-link&quot; href=&quot;#动态变量&quot;&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;anchor-icon&quot;&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 24 24&quot;&gt;&lt;path fill=&quot;currentcolor&quot; d=&quot;m12.11 15.39-3.88 3.88a2.52 2.52 0 0 1-3.5 0 2.47 2.47 0 0 1 0-3.5l3.88-3.88a1 1 0 0 0-1.42-1.42l-3.88 3.89a4.48 4.48 0 0 0 6.33 6.33l3.89-3.88a1 1 0 1 0-1.42-1.42Zm8.58-12.08a4.49 4.49 0 0 0-6.33 0l-3.89 3.88a1 1 0 0 0 1.42 1.42l3.88-3.88a2.52 2.52 0 0 1 3.5 0 2.47 2.47 0 0 1 0 3.5l-3.88 3.88a1 1 0 1 0 1.42 1.42l3.88-3.89a4.49 4.49 0 0 0 0-6.33ZM8.83 15.17a1 1 0 0 0 1.1.22 1 1 0 0 0 .32-.22l4.92-4.92a1 1 0 0 0-1.42-1.42l-4.92 4.92a1 1 0 0 0 0 1.42Z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;p&gt;请求头的值可以包含使用 &lt;code&gt;@{...}&lt;/code&gt; 语法的动态变量。Gateway 会在请求时根据身份、设备和网络上下文解析变量。&lt;/p&gt;
&lt;div class=&quot;table-scroll&quot; tabindex=&quot;0&quot; role=&quot;region&quot; aria-label=&quot;Table&quot;&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;变量&lt;/th&gt;
&lt;th&gt;说明&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;@{identity.email}&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;来自身份提供商的用户电子邮件&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;@{identity.name}&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;来自身份提供商的用户显示名称&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;@{identity.id}&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Cloudflare 身份 UUID&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;@{identity.groups}&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;身份提供商群组成员身份&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;@{identity.SAML}&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;SAML 属性（如果配置了）&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;@{identity.OIDC}&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;OIDC 声明（如果配置了）&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;@{source.ip}&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;连接的源 IP&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;@{destination.ip}&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;请求的目的 IP&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;@{device.id}&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Cloudflare One 客户端设备 UUID&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;@{device.posture}&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;设备状态检查结果（JSON 字符串）&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;p&gt;您可以在单个请求头值中混合使用静态文本和动态变量。例如，&lt;code&gt;user-@{identity.email}&lt;/code&gt; 会解析为 &lt;code&gt;user-jdoe@example.com&lt;/code&gt;。&lt;/p&gt;
&lt;p&gt;有关更多信息，请参阅&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/http-policies/tenant-control/&quot;&gt;自定义请求头&lt;/a&gt;。&lt;/p&gt;</description><pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate><product>Gateway</product><category>Gateway</category></item><item><title>Access, Cloudflare One - 用于基于浏览器的 RDP 的批量打印 PDF</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-07-16-rdp-bulk-print/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-07-16-rdp-bulk-print/</guid><description>&lt;p&gt;在基于浏览器的 RDP 会话中，用户现在可以将多个 PDF 文件作为单个打印作业进行打印。在远程计算机上将文件复制到剪贴板，然后选择剪贴板面板中的 &lt;strong&gt;Print all PDFs（打印所有 PDF）&lt;/strong&gt;。这些文件将合并为一个 PDF 并发送到您的本地打印机。&lt;/p&gt;
&lt;img src=&quot;https://cloudflaredoc.ubitools.com/_astro/rdp-bulk-print.DT4sCcI-_Z1XuBEQ.webp&quot; alt=&quot;剪贴板面板显示针对多个选定 PDF 文件的 Print all PDFs 选项。&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;768&quot; height=&quot;432&quot;&gt;
&lt;p&gt;批量打印在基于 Chromium 的浏览器和 Firefox 中可用。欲了解更多信息，请参阅&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-browser/#print-pdfs&quot;&gt;为基于浏览器的 RDP 打印 PDF&lt;/a&gt;。&lt;/p&gt;</description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate><product>Access</product><category>Access</category><category>Cloudflare One</category></item><item><title>Gateway, DNS - 内部 DNS 现在正式发布（Generally Available）</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-07-15-internal-dns-ga/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-07-15-internal-dns-ga/</guid><description>&lt;p&gt;&lt;a href=&quot;https://cloudflaredoc.ubitools.com/dns/internal-dns/&quot;&gt;内部 DNS&lt;/a&gt; 现在已正式发布。内部 DNS 在您已用于公共 DNS、Zero Trust 和应用程序服务的同一个全球网络和控制平面上，为私有网络提供权威和递归 DNS 服务。&lt;/p&gt;
&lt;div tabindex=&quot;-1&quot; class=&quot;heading-wrapper level-h4&quot;&gt;&lt;h4 id=&quot;为什么它很重要&quot;&gt;为什么它很重要&lt;/h4&gt;&lt;a class=&quot;anchor-link&quot; href=&quot;#为什么它很重要&quot;&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;anchor-icon&quot;&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 24 24&quot;&gt;&lt;path fill=&quot;currentcolor&quot; d=&quot;m12.11 15.39-3.88 3.88a2.52 2.52 0 0 1-3.5 0 2.47 2.47 0 0 1 0-3.5l3.88-3.88a1 1 0 0 0-1.42-1.42l-3.88 3.89a4.48 4.48 0 0 0 6.33 6.33l3.89-3.88a1 1 0 1 0-1.42-1.42Zm8.58-12.08a4.49 4.49 0 0 0-6.33 0l-3.89 3.88a1 1 0 0 0 1.42 1.42l3.88-3.88a2.52 2.52 0 0 1 3.5 0 2.47 2.47 0 0 1 0 3.5l-3.88 3.88a1 1 0 1 0 1.42 1.42l3.88-3.89a4.49 4.49 0 0 0 0-6.33ZM8.83 15.17a1 1 0 0 0 1.1.22 1 1 0 0 0 .32-.22l4.92-4.92a1 1 0 0 0-1.42-1.42l-4.92 4.92a1 1 0 0 0 0 1.42Z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;整合 DNS 运营。&lt;/strong&gt; 公共和私有 DNS 运行在同一个平台上，拥有统一的 API、审计跟踪和策略设置入口。&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;简化水平分割 DNS。&lt;/strong&gt; 内部和外部解析被定义为共享区域上独立的&lt;a href=&quot;https://cloudflaredoc.ubitools.com/dns/internal-dns/dns-views/&quot;&gt;视图&lt;/a&gt;，并从单个控制平面进行管理 — 因此无需排查配置偏差。&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;将 Zero Trust 扩展到 DNS。&lt;/strong&gt; 解析器策略决定哪些用户和设备针对哪个视图进行解析，并由已经监管您其余流量的同一个 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/&quot;&gt;Gateway&lt;/a&gt; 来执行。&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;设置内部 DNS 需要三个步骤：创建区域、创建视图并定义解析器策略。&lt;/p&gt;
&lt;figure class=&quot;nb-code-figure&quot; data-nb-lang=&quot;json&quot;&gt;&lt;pre class=&quot;astro-code astro-code-themes github-light github-dark nb-shiki-c6xiwz&quot; tabindex=&quot;0&quot; data-language=&quot;json&quot; data-nb-lang=&quot;json&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;POST /zones&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;{&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt;  &quot;account&quot;&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;: {&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt;    &quot;id&quot;&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;: &lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt;&quot;&amp;lt;ACCOUNT_ID&amp;gt;&quot;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;  },&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt;  &quot;name&quot;&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;: &lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt;&quot;corp.internal&quot;&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;,&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt;  &quot;type&quot;&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;: &lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt;&quot;internal&quot;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;}&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;内部 DNS 已包含在面向企业级客户的 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/&quot;&gt;Cloudflare Gateway&lt;/a&gt; 中。要开始使用，请参阅 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/dns/internal-dns/&quot;&gt;Internal DNS documentation&lt;/a&gt;。&lt;/p&gt;</description><pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate><product>Gateway</product><category>Gateway</category><category>DNS</category></item><item><title>Data Loss Prevention - 源代码检测改进</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-07-10-source-code-detection-improvements/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-07-10-source-code-detection-improvements/</guid><description>&lt;p&gt;数据丢失防护 (DLP) 源代码检测现在专注于识别整个源代码文件的上传和下载。以前，源代码检测执行部分扫描，导致误报率较高。由于现在仅对整个源代码文件进行评估，因此嵌入在其他内容（例如聊天消息、文档或代码示例）中的代码不再被标记为源代码，从而消除了常见的误报来源。&lt;/p&gt;
&lt;p&gt;源代码检测需要至少 500 个字符来评估文件。低于此阈值的文件不会被标记，以减少噪点。此阈值过滤掉了缺乏足够上下文以进行可靠分类的小片段。&lt;/p&gt;
&lt;p&gt;启用并设置&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/data-loss-prevention/dlp-profiles/advanced-settings/#confidence-thresholds&quot;&gt;置信度级别&lt;/a&gt;以调整匹配敏感度。较高的置信度级别通过需要更强烈的信号来表明内容确实是源代码，从而减少误报。较低的置信度级别会捕获更多文件，但代价是会产生额外的噪点。&lt;/p&gt;
&lt;p&gt;源代码检测适用于 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/http-policies/&quot;&gt;Gateway HTTP 策略&lt;/a&gt;中的独立源代码文件。它不会检测嵌入在其他文件类型或有效负载（例如 &lt;code&gt;.docx&lt;/code&gt; 文件或聊天消息）中的源代码。&lt;/p&gt;
&lt;p&gt;有关更多详细信息，请参阅 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/data-loss-prevention/dlp-profiles/predefined-profiles/#source-code&quot;&gt;Source Code predefined profiles&lt;/a&gt;。&lt;/p&gt;</description><pubDate>Fri, 10 Jul 2026 00:00:00 GMT</pubDate><product>Data Loss Prevention</product><category>Data Loss Prevention</category></item><item><title>Cloudflare Tunnel, Cloudflare Tunnel for SASE, Cloudflare Mesh - Zero Trust Networks 路由终点和 Cloudflare Tunnel 连接字段将于 2026 年 10 月 5 日停用</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-07-09-tunnel-routes-and-connections-api-changes/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-07-09-tunnel-routes-and-connections-api-changes/</guid><description>&lt;p&gt;在 &lt;strong&gt;2026 年 10 月 5 日&lt;/strong&gt;，两项变更将在 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/api/resources/zero_trust/subresources/networks/&quot;&gt;Zero Trust Networks API&lt;/a&gt; 和 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/api/resources/zero_trust/subresources/tunnels/&quot;&gt;Cloudflare Tunnel API&lt;/a&gt; 中生效：移除经过 CIDR 编码的路由终点，且 tunnel list 和 get 响应将不再包含 &lt;code&gt;connections&lt;/code&gt; 字段。如果您通过 API、&lt;code&gt;cloudflared&lt;/code&gt;、Terraform 或其他集成管理私有网络路由或读取 tunnel 连接详情，请阅读以下部分中的变更说明并在移除日期之前完成迁移。&lt;/p&gt;
&lt;div tabindex=&quot;-1&quot; class=&quot;heading-wrapper level-h4&quot;&gt;&lt;h4 id=&quot;路由终点&quot;&gt;路由终点&lt;/h4&gt;&lt;a class=&quot;anchor-link&quot; href=&quot;#路由终点&quot;&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;anchor-icon&quot;&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 24 24&quot;&gt;&lt;path fill=&quot;currentcolor&quot; d=&quot;m12.11 15.39-3.88 3.88a2.52 2.52 0 0 1-3.5 0 2.47 2.47 0 0 1 0-3.5l3.88-3.88a1 1 0 0 0-1.42-1.42l-3.88 3.89a4.48 4.48 0 0 0 6.33 6.33l3.89-3.88a1 1 0 1 0-1.42-1.42Zm8.58-12.08a4.49 4.49 0 0 0-6.33 0l-3.89 3.88a1 1 0 0 0 1.42 1.42l3.88-3.88a2.52 2.52 0 0 1 3.5 0 2.47 2.47 0 0 1 0 3.5l-3.88 3.88a1 1 0 1 0 1.42 1.42l3.88-3.89a4.49 4.49 0 0 0 0-6.33ZM8.83 15.17a1 1 0 0 0 1.1.22 1 1 0 0 0 .32-.22l4.92-4.92a1 1 0 0 0-1.42-1.42l-4.92 4.92a1 1 0 0 0 0 1.42Z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;p&gt;经过 CIDR 编码的路由终点已被弃用，转而使用目前已存在的基于标准 &lt;code&gt;route_id&lt;/code&gt; 的终点。这两组终点都是通过 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/connectors/cloudflare-tunnel/&quot;&gt;Cloudflare Tunnel&lt;/a&gt; 或 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/connectors/cloudflare-mesh/&quot;&gt;Cloudflare Mesh&lt;/a&gt; 路由私有网络（API 仍将 Mesh 节点称为 &lt;code&gt;warp_connector&lt;/code&gt;）— 仅请求形状（request shape）发生了变化。&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;已弃用的终点（将于 2026 年 10 月 5 日移除）：&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;创建 tunnel 路由（CIDR 终点）：&lt;a href=&quot;https://cloudflaredoc.ubitools.com/api/resources/zero_trust/subresources/networks/subresources/routes/subresources/networks/methods/create/&quot;&gt;&lt;code&gt;POST /accounts/{account_id}/teamnet/routes/network/{ip_network_encoded}&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;更新 tunnel 路由（CIDR 终点）：&lt;a href=&quot;https://cloudflaredoc.ubitools.com/api/resources/zero_trust/subresources/networks/subresources/routes/subresources/networks/methods/edit/&quot;&gt;&lt;code&gt;PATCH /accounts/{account_id}/teamnet/routes/network/{ip_network_encoded}&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;删除 tunnel 路由（CIDR 终点）：&lt;a href=&quot;https://cloudflaredoc.ubitools.com/api/resources/zero_trust/subresources/networks/subresources/routes/subresources/networks/methods/delete/&quot;&gt;&lt;code&gt;DELETE /accounts/{account_id}/teamnet/routes/network/{ip_network_encoded}&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;替代终点：&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;创建 tunnel 路由：&lt;a href=&quot;https://cloudflaredoc.ubitools.com/api/resources/zero_trust/subresources/networks/subresources/routes/methods/create/&quot;&gt;&lt;code&gt;POST /accounts/{account_id}/teamnet/routes&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;更新 tunnel 路由：&lt;a href=&quot;https://cloudflaredoc.ubitools.com/api/resources/zero_trust/subresources/networks/subresources/routes/methods/edit/&quot;&gt;&lt;code&gt;PATCH /accounts/{account_id}/teamnet/routes/{route_id}&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;删除 tunnel 路由：&lt;a href=&quot;https://cloudflaredoc.ubitools.com/api/resources/zero_trust/subresources/networks/subresources/routes/methods/delete/&quot;&gt;&lt;code&gt;DELETE /accounts/{account_id}/teamnet/routes/{route_id}&lt;/code&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div tabindex=&quot;-1&quot; class=&quot;heading-wrapper level-h4&quot;&gt;&lt;h4 id=&quot;变更内容&quot;&gt;变更内容&lt;/h4&gt;&lt;a class=&quot;anchor-link&quot; href=&quot;#变更内容&quot;&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;anchor-icon&quot;&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 24 24&quot;&gt;&lt;path fill=&quot;currentcolor&quot; d=&quot;m12.11 15.39-3.88 3.88a2.52 2.52 0 0 1-3.5 0 2.47 2.47 0 0 1 0-3.5l3.88-3.88a1 1 0 0 0-1.42-1.42l-3.88 3.89a4.48 4.48 0 0 0 6.33 6.33l3.89-3.88a1 1 0 1 0-1.42-1.42Zm8.58-12.08a4.49 4.49 0 0 0-6.33 0l-3.89 3.88a1 1 0 0 0 1.42 1.42l3.88-3.88a2.52 2.52 0 0 1 3.5 0 2.47 2.47 0 0 1 0 3.5l-3.88 3.88a1 1 0 1 0 1.42 1.42l3.88-3.89a4.49 4.49 0 0 0 0-6.33ZM8.83 15.17a1 1 0 0 0 1.1.22 1 1 0 0 0 .32-.22l4.92-4.92a1 1 0 0 0-1.42-1.42l-4.92 4.92a1 1 0 0 0 0 1.42Z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;div class=&quot;table-scroll&quot; tabindex=&quot;0&quot; role=&quot;region&quot; aria-label=&quot;Table&quot;&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th style=&quot;text-align: left&quot;&gt;&lt;/th&gt;
&lt;th style=&quot;text-align: left&quot;&gt;已弃用（CIDR 编码路径）&lt;/th&gt;
&lt;th style=&quot;text-align: left&quot;&gt;替代方案&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style=&quot;text-align: left&quot;&gt;路由标识符&lt;/td&gt;
&lt;td style=&quot;text-align: left&quot;&gt;路径中经过 URL 编码的 CIDR (&lt;code&gt;/network/{ip_network_encoded}&lt;/code&gt;)&lt;/td&gt;
&lt;td style=&quot;text-align: left&quot;&gt;路径中的 &lt;code&gt;route_id&lt;/code&gt;（创建时 &lt;code&gt;network&lt;/code&gt; 移动到请求体中）&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;text-align: left&quot;&gt;创建&lt;/td&gt;
&lt;td style=&quot;text-align: left&quot;&gt;&lt;code&gt;POST .../teamnet/routes/network/{ip_network_encoded}&lt;/code&gt;&lt;/td&gt;
&lt;td style=&quot;text-align: left&quot;&gt;请求体中包含 &lt;code&gt;network&lt;/code&gt; 和 &lt;code&gt;tunnel_id&lt;/code&gt; 的 &lt;code&gt;POST .../teamnet/routes&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;text-align: left&quot;&gt;更新&lt;/td&gt;
&lt;td style=&quot;text-align: left&quot;&gt;&lt;code&gt;PATCH .../teamnet/routes/network/{ip_network_encoded}&lt;/code&gt;&lt;/td&gt;
&lt;td style=&quot;text-align: left&quot;&gt;&lt;code&gt;PATCH .../teamnet/routes/{route_id}&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;text-align: left&quot;&gt;删除&lt;/td&gt;
&lt;td style=&quot;text-align: left&quot;&gt;&lt;code&gt;DELETE .../teamnet/routes/network/{ip_network_encoded}&lt;/code&gt;&lt;/td&gt;
&lt;td style=&quot;text-align: left&quot;&gt;&lt;code&gt;DELETE .../teamnet/routes/{route_id}&lt;/code&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;div tabindex=&quot;-1&quot; class=&quot;heading-wrapper level-h4&quot;&gt;&lt;h4 id=&quot;需要采取的行动&quot;&gt;需要采取的行动&lt;/h4&gt;&lt;a class=&quot;anchor-link&quot; href=&quot;#需要采取的行动&quot;&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;anchor-icon&quot;&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 24 24&quot;&gt;&lt;path fill=&quot;currentcolor&quot; d=&quot;m12.11 15.39-3.88 3.88a2.52 2.52 0 0 1-3.5 0 2.47 2.47 0 0 1 0-3.5l3.88-3.88a1 1 0 0 0-1.42-1.42l-3.88 3.89a4.48 4.48 0 0 0 6.33 6.33l3.89-3.88a1 1 0 1 0-1.42-1.42Zm8.58-12.08a4.49 4.49 0 0 0-6.33 0l-3.89 3.88a1 1 0 0 0 1.42 1.42l3.88-3.88a2.52 2.52 0 0 1 3.5 0 2.47 2.47 0 0 1 0 3.5l-3.88 3.88a1 1 0 1 0 1.42 1.42l3.88-3.89a4.49 4.49 0 0 0 0-6.33ZM8.83 15.17a1 1 0 0 0 1.1.22 1 1 0 0 0 .32-.22l4.92-4.92a1 1 0 0 0-1.42-1.42l-4.92 4.92a1 1 0 0 0 0 1.42Z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;ol&gt;
&lt;li&gt;通过调用&lt;a href=&quot;https://cloudflaredoc.ubitools.com/api/resources/zero_trust/subresources/networks/subresources/routes/methods/list/&quot;&gt;列出 tunnel 路由&lt;/a&gt;获取每个路由的 &lt;code&gt;route_id&lt;/code&gt;，或者在首次使用替代终点创建路由时从响应中读取它。&lt;/li&gt;
&lt;li&gt;更新任何直接调用经过 CIDR 编码的终点的脚本、后端服务或 CI/CD 流水线。&lt;/li&gt;
&lt;li&gt;如果您使用 &lt;code&gt;cloudflared tunnel route ip add | delete&lt;/code&gt; 命令管理路由，请将 &lt;code&gt;cloudflared&lt;/code&gt; 升级到&lt;a href=&quot;https://github.com/cloudflare/cloudflared/releases&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;最新版本&lt;span class=&quot;external-link&quot;&gt; ↗&lt;/span&gt;&lt;/a&gt;。&lt;/li&gt;
&lt;li&gt;如果您使用 Terraform 管理路由，请确保您使用的是最新版本的 &lt;a href=&quot;https://registry.terraform.io/providers/cloudflare/cloudflare/latest/docs/resources/zero_trust_tunnel_cloudflared_route&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;&lt;code&gt;cloudflare_zero_trust_tunnel_cloudflared_route&lt;/code&gt;&lt;span class=&quot;external-link&quot;&gt; ↗&lt;/span&gt;&lt;/a&gt; 资源以及 &lt;a href=&quot;https://registry.terraform.io/providers/cloudflare/cloudflare/latest/docs&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Cloudflare Terraform 提供商&lt;span class=&quot;external-link&quot;&gt; ↗&lt;/span&gt;&lt;/a&gt;。&lt;/li&gt;
&lt;/ol&gt;
&lt;figure class=&quot;nb-code-figure&quot; data-nb-lang=&quot;bash&quot;&gt;&lt;pre class=&quot;astro-code astro-code-themes github-light github-dark nb-shiki-c6xiwz&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot; data-nb-lang=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-21nrsd&quot;&gt;# Before: create a route by URL-encoding the CIDR into the path&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-1t8gfj&quot;&gt;curl&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt; https://api.cloudflare.com/client/v4/accounts/&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;$ACCOUNT_ID&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt;/teamnet/routes/network/172.16.0.0%2F16&lt;/span&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt;     -H&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt; &apos;Content-Type: application/json&apos;&lt;/span&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt;     -H&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt; &quot;Authorization: Bearer &lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;$CLOUDFLARE_API_TOKEN&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt;     -d&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt; &apos;{&quot;tunnel_id&quot;: &quot;&apos;&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;$TUNNEL_ID&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt;&apos;&quot;, &quot;comment&quot;: &quot;Example comment for this route.&quot;}&apos;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-21nrsd&quot;&gt;# After: create a route with the network in the request body&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-1t8gfj&quot;&gt;curl&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt; https://api.cloudflare.com/client/v4/accounts/&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;$ACCOUNT_ID&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt;/teamnet/routes&lt;/span&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt;     -H&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt; &apos;Content-Type: application/json&apos;&lt;/span&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt;     -H&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt; &quot;Authorization: Bearer &lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;$CLOUDFLARE_API_TOKEN&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt;     -d&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt; &apos;{&quot;network&quot;: &quot;172.16.0.0/16&quot;, &quot;tunnel_id&quot;: &quot;&apos;&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;$TUNNEL_ID&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt;&apos;&quot;, &quot;comment&quot;: &quot;Example comment for this route.&quot;}&apos;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-21nrsd&quot;&gt;# After: update or delete a route using its route_id&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-1t8gfj&quot;&gt;curl&lt;/span&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt; -X&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt; PATCH&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt; https://api.cloudflare.com/client/v4/accounts/&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;$ACCOUNT_ID&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt;/teamnet/routes/&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;$ROUTE_ID &lt;/span&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt;\&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt;     -H&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt; &apos;Content-Type: application/json&apos;&lt;/span&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt;     -H&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt; &quot;Authorization: Bearer &lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;$CLOUDFLARE_API_TOKEN&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt;&quot;&lt;/span&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt;     -d&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt; &apos;{&quot;comment&quot;: &quot;Updated comment for this route.&quot;}&apos;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-1t8gfj&quot;&gt;curl&lt;/span&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt; -X&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt; DELETE&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt; https://api.cloudflare.com/client/v4/accounts/&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;$ACCOUNT_ID&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt;/teamnet/routes/&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;$ROUTE_ID &lt;/span&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt;\&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt;     -H&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt; &quot;Authorization: Bearer &lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;$CLOUDFLARE_API_TOKEN&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt;&quot;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;div tabindex=&quot;-1&quot; class=&quot;heading-wrapper level-h4&quot;&gt;&lt;h4 id=&quot;cloudflare-tunnel-和-cloudflare-mesh-连接&quot;&gt;Cloudflare Tunnel 和 Cloudflare Mesh 连接&lt;/h4&gt;&lt;a class=&quot;anchor-link&quot; href=&quot;#cloudflare-tunnel-和-cloudflare-mesh-连接&quot;&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;anchor-icon&quot;&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 24 24&quot;&gt;&lt;path fill=&quot;currentcolor&quot; d=&quot;m12.11 15.39-3.88 3.88a2.52 2.52 0 0 1-3.5 0 2.47 2.47 0 0 1 0-3.5l3.88-3.88a1 1 0 0 0-1.42-1.42l-3.88 3.89a4.48 4.48 0 0 0 6.33 6.33l3.89-3.88a1 1 0 1 0-1.42-1.42Zm8.58-12.08a4.49 4.49 0 0 0-6.33 0l-3.89 3.88a1 1 0 0 0 1.42 1.42l3.88-3.88a2.52 2.52 0 0 1 3.5 0 2.47 2.47 0 0 1 0 3.5l-3.88 3.88a1 1 0 1 0 1.42 1.42l3.88-3.89a4.49 4.49 0 0 0 0-6.33ZM8.83 15.17a1 1 0 0 0 1.1.22 1 1 0 0 0 .32-.22l4.92-4.92a1 1 0 0 0-1.42-1.42l-4.92 4.92a1 1 0 0 0 0 1.42Z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;p&gt;自同一天起，将从 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/connectors/cloudflare-tunnel/&quot;&gt;Cloudflare Tunnel&lt;/a&gt; 和 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/connectors/cloudflare-mesh/&quot;&gt;Cloudflare Mesh&lt;/a&gt; 节点（&lt;code&gt;cfd_tunnel&lt;/code&gt; 和 &lt;code&gt;warp_connector&lt;/code&gt; API 资源）的 list 和 get 响应中移除 &lt;code&gt;connections&lt;/code&gt; 数组。请查询专用的连接终点，而不是从 tunnel 或节点对象中读取该字段。&lt;/p&gt;
&lt;p&gt;这会影响：&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://cloudflaredoc.ubitools.com/api/resources/zero_trust/subresources/tunnels/subresources/cloudflared/methods/list/&quot;&gt;&lt;code&gt;GET /accounts/{account_id}/cfd_tunnel&lt;/code&gt;&lt;/a&gt; — 从 &lt;code&gt;result&lt;/code&gt; 中的每个项目中移除 &lt;code&gt;connections&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://cloudflaredoc.ubitools.com/api/resources/zero_trust/subresources/tunnels/subresources/cloudflared/methods/get/&quot;&gt;&lt;code&gt;GET /accounts/{account_id}/cfd_tunnel/{tunnel_id}&lt;/code&gt;&lt;/a&gt; — 从 &lt;code&gt;result&lt;/code&gt; 中移除 &lt;code&gt;connections&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://cloudflaredoc.ubitools.com/api/resources/zero_trust/subresources/tunnels/subresources/warp_connector/methods/list/&quot;&gt;&lt;code&gt;GET /accounts/{account_id}/warp_connector&lt;/code&gt;&lt;/a&gt; — 从 &lt;code&gt;result&lt;/code&gt; 中的每个项目中移除 &lt;code&gt;connections&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://cloudflaredoc.ubitools.com/api/resources/zero_trust/subresources/tunnels/subresources/warp_connector/methods/get/&quot;&gt;&lt;code&gt;GET /accounts/{account_id}/warp_connector/{tunnel_id}&lt;/code&gt;&lt;/a&gt; — 从 &lt;code&gt;result&lt;/code&gt; 中移除 &lt;code&gt;connections&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div tabindex=&quot;-1&quot; class=&quot;heading-wrapper level-h4&quot;&gt;&lt;h4 id=&quot;需要采取的行动-1&quot;&gt;需要采取的行动&lt;/h4&gt;&lt;a class=&quot;anchor-link&quot; href=&quot;#需要采取的行动-1&quot;&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;anchor-icon&quot;&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 24 24&quot;&gt;&lt;path fill=&quot;currentcolor&quot; d=&quot;m12.11 15.39-3.88 3.88a2.52 2.52 0 0 1-3.5 0 2.47 2.47 0 0 1 0-3.5l3.88-3.88a1 1 0 0 0-1.42-1.42l-3.88 3.89a4.48 4.48 0 0 0 6.33 6.33l3.89-3.88a1 1 0 1 0-1.42-1.42Zm8.58-12.08a4.49 4.49 0 0 0-6.33 0l-3.89 3.88a1 1 0 0 0 1.42 1.42l3.88-3.88a2.52 2.52 0 0 1 3.5 0 2.47 2.47 0 0 1 0 3.5l-3.88 3.88a1 1 0 1 0 1.42 1.42l3.88-3.89a4.49 4.49 0 0 0 0-6.33ZM8.83 15.17a1 1 0 0 0 1.1.22 1 1 0 0 0 .32-.22l4.92-4.92a1 1 0 0 0-1.42-1.42l-4.92 4.92a1 1 0 0 0 0 1.42Z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;p&gt;从特定于 tunnel 的连接终点获取连接详情，而不是从 list 或 get 响应中解析。对于 Cloudflare Tunnel，请调用 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/api/resources/zero_trust/subresources/tunnels/subresources/cloudflared/subresources/connections/methods/get/&quot;&gt;&lt;code&gt;GET /accounts/{account_id}/cfd_tunnel/{tunnel_id}/connections&lt;/code&gt;&lt;/a&gt;。对于 Cloudflare Mesh，请调用 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/api/resources/zero_trust/subresources/tunnels/subresources/warp_connector/subresources/connections/methods/get/&quot;&gt;&lt;code&gt;GET /accounts/{account_id}/warp_connector/{tunnel_id}/connections&lt;/code&gt;&lt;/a&gt;。&lt;/p&gt;
&lt;figure class=&quot;nb-code-figure&quot; data-nb-lang=&quot;bash&quot;&gt;&lt;pre class=&quot;astro-code astro-code-themes github-light github-dark nb-shiki-c6xiwz&quot; tabindex=&quot;0&quot; data-language=&quot;bash&quot; data-nb-lang=&quot;bash&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-21nrsd&quot;&gt;# Before: read connections off the tunnel object&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-1t8gfj&quot;&gt;curl&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt; https://api.cloudflare.com/client/v4/accounts/&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;$ACCOUNT_ID&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt;/cfd_tunnel/&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;$TUNNEL_ID &lt;/span&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt;\&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt;     -H&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt; &quot;Authorization: Bearer &lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;$CLOUDFLARE_API_TOKEN&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt;&quot;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-21nrsd&quot;&gt;# After: query connections directly&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-1t8gfj&quot;&gt;curl&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt; https://api.cloudflare.com/client/v4/accounts/&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;$ACCOUNT_ID&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt;/cfd_tunnel/&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;$TUNNEL_ID&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt;/connections&lt;/span&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt; \&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt;     -H&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt; &quot;Authorization: Bearer &lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;$CLOUDFLARE_API_TOKEN&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt;&quot;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;
&lt;p&gt;更新任何从 tunnel list 或 get 响应中解析 &lt;code&gt;connections&lt;/code&gt; 的仪表板、监控脚本或自动化。&lt;code&gt;cloudflared&lt;/code&gt; 和 Cloudflare Terraform 提供商不读取此字段，因此它们的这一部分更新不需要做任何更改。&lt;/p&gt;
&lt;div tabindex=&quot;-1&quot; class=&quot;heading-wrapper level-h4&quot;&gt;&lt;h4 id=&quot;做出这些更改的原因&quot;&gt;做出这些更改的原因&lt;/h4&gt;&lt;a class=&quot;anchor-link&quot; href=&quot;#做出这些更改的原因&quot;&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;anchor-icon&quot;&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 24 24&quot;&gt;&lt;path fill=&quot;currentcolor&quot; d=&quot;m12.11 15.39-3.88 3.88a2.52 2.52 0 0 1-3.5 0 2.47 2.47 0 0 1 0-3.5l3.88-3.88a1 1 0 0 0-1.42-1.42l-3.88 3.89a4.48 4.48 0 0 0 6.33 6.33l3.89-3.88a1 1 0 1 0-1.42-1.42Zm8.58-12.08a4.49 4.49 0 0 0-6.33 0l-3.89 3.88a1 1 0 0 0 1.42 1.42l3.88-3.88a2.52 2.52 0 0 1 3.5 0 2.47 2.47 0 0 1 0 3.5l-3.88 3.88a1 1 0 1 0 1.42 1.42l3.88-3.89a4.49 4.49 0 0 0 0-6.33ZM8.83 15.17a1 1 0 0 0 1.1.22 1 1 0 0 0 .32-.22l4.92-4.92a1 1 0 0 0-1.42-1.42l-4.92 4.92a1 1 0 0 0 0 1.42Z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;响应更小、速度更快。&lt;/strong&gt; 具有许多连接的 Cloudflare Tunnel 和 Cloudflare Mesh 节点不再膨胀每次 list 和 get 调用 — 仅在您需要时才获取连接详情。&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;静态或标识路由的单一方式。&lt;/strong&gt; 统一使用 &lt;code&gt;route_id&lt;/code&gt; 消除了对路径中 CIDR 范围进行 URL 编码的需要，并且与 Zero Trust Networks API 中所有其他资源的寻址方式一致。&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;跨 API 的一致性。&lt;/strong&gt; 这两项变更使这些终点与 Cloudflare 针对资源标识符和嵌套详情终点的标准 REST 约定保持一致。&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;要了解更多信息，请参阅 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/api/resources/zero_trust/subresources/networks/&quot;&gt;Zero Trust Networks API&lt;/a&gt;、&lt;a href=&quot;https://cloudflaredoc.ubitools.com/api/resources/zero_trust/subresources/tunnels/&quot;&gt;Cloudflare Tunnel API&lt;/a&gt; 和&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/routes/&quot;&gt;路由&lt;/a&gt;文档。&lt;/p&gt;</description><pubDate>Thu, 09 Jul 2026 00:00:00 GMT</pubDate><product>Cloudflare Tunnel</product><category>Cloudflare Tunnel</category><category>Cloudflare Tunnel for SASE</category><category>Cloudflare Mesh</category></item><item><title>Cloudflare One, Cloudflare WAN - IPsec 降级保护 (Beta)</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-07-08-ipsec-downgrade-protection/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-07-08-ipsec-downgrade-protection/</guid><description>&lt;p&gt;Cloudflare IPsec 现在支持 &lt;a href=&quot;https://datatracker.ietf.org/doc/draft-ietf-ipsecme-ikev2-downgrade-prevention/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;&lt;code&gt;IKE_SA_INIT_FULL_TRANSCRIPT_AUTH&lt;/code&gt;&lt;span class=&quot;external-link&quot;&gt; ↗&lt;/span&gt;&lt;/a&gt; IKEv2 扩展，以防御 IPsec 隧道上的降级攻击。&lt;/p&gt;
&lt;p&gt;IKEv2 的原始身份验证设计是让每个端点仅对其自己的出网消息进行签名，而不是对完整的握手脚本进行签名。具有量子计算能力的&lt;a href=&quot;https://www.cloudflare.com/learning/security/threats/on-path-attack/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;路径上（on-path）攻击者&lt;span class=&quot;external-link&quot;&gt; ↗&lt;/span&gt;&lt;/a&gt;可以利用这一点，通过将连接降级为传统密码学，从而绕过后量子密钥交换。&lt;code&gt;IKE_SA_INIT_FULL_TRANSCRIPT_AUTH&lt;/code&gt; 扩展通过在身份验证交换期间让双方对整个握手脚本进行签名来解决此问题，从而防止攻击者在不被发现的情况下操纵协商。&lt;/p&gt;
&lt;p&gt;关键详情：&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;在 Cloudflare WAN 和 Magic Transit IPsec 隧道中提供 Beta 版。&lt;/li&gt;
&lt;li&gt;启用该功能标志后，Cloudflare 会作为响应方（responder）无条件发送 &lt;code&gt;IKE_SA_INIT_FULL_TRANSCRIPT_AUTH&lt;/code&gt; 通知。&lt;/li&gt;
&lt;li&gt;发起方（您的设备）和响应方（Cloudflare）都必须支持该扩展，降级保护才能生效。&lt;/li&gt;
&lt;li&gt;此功能目前由每个账户的功能标志控制。请联系您的账户团队将其开启。&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;请参阅&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-wan/reference/gre-ipsec-tunnels/#improved-downgrade-protection-beta&quot;&gt;降级保护&lt;/a&gt;了解更多详情。&lt;/p&gt;</description><pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate><product>Cloudflare One</product><category>Cloudflare One</category><category>Cloudflare WAN</category></item><item><title>Cloudflare One Client - Cloudflare One Client for Windows (version 2026.6.850.0)</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-07-07-warp-windows-ga/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-07-07-warp-windows-ga/</guid><description>&lt;p&gt;A new GA release for the Windows Cloudflare One Client is now available on the &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/&quot;&gt;stable releases downloads page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This hotfix addresses a Windows authentication issue in the embedded WebView2 browser. Single sign-on could fail to use the Windows primary account, causing users to be prompted for an interactive sign-in. The embedded authentication browser now allows SSO providers to use the OS primary account when available.&lt;/p&gt;
</description><pubDate>Tue, 07 Jul 2026 18:35:35 GMT</pubDate><product>Cloudflare One Client</product><category>Cloudflare One Client</category></item><item><title>Access, Cloudflare One - 用于基于浏览器的 RDP 的文件传输控制（Beta）</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-07-07-rdp-file-transfer-beta/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-07-07-rdp-file-transfer-beta/</guid><description>&lt;p&gt;您现在可以为使用 Cloudflare Access 的基于浏览器的 RDP 配置文件传输控制，允许您限制用户是否可以在其本地计算机与远程 Windows 服务器之间上传或下载文件。&lt;/p&gt;
&lt;img src=&quot;https://cloudflaredoc.ubitools.com/_astro/file-transfer-policy-control.CiSEa5rr_Z1oqxAg.webp&quot; alt=&quot;Access 策略配置中的文件传输连接设置。&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1356&quot; height=&quot;692&quot;&gt;
&lt;p&gt;对于支持自带设备（BYOD）政策或使用未托管设备的第三方承包商的组织，此功能非常有用。通过限制文件传输，您可以防止敏感数据从远程会话转移到用户的个人设备。&lt;/p&gt;
&lt;div tabindex=&quot;-1&quot; class=&quot;heading-wrapper level-h4&quot;&gt;&lt;h4 id=&quot;配置选项&quot;&gt;配置选项&lt;/h4&gt;&lt;a class=&quot;anchor-link&quot; href=&quot;#配置选项&quot;&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;anchor-icon&quot;&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 24 24&quot;&gt;&lt;path fill=&quot;currentcolor&quot; d=&quot;m12.11 15.39-3.88 3.88a2.52 2.52 0 0 1-3.5 0 2.47 2.47 0 0 1 0-3.5l3.88-3.88a1 1 0 0 0-1.42-1.42l-3.88 3.89a4.48 4.48 0 0 0 6.33 6.33l3.89-3.88a1 1 0 1 0-1.42-1.42Zm8.58-12.08a4.49 4.49 0 0 0-6.33 0l-3.89 3.88a1 1 0 0 0 1.42 1.42l3.88-3.88a2.52 2.52 0 0 1 3.5 0 2.47 2.47 0 0 1 0 3.5l-3.88 3.88a1 1 0 1 0 1.42 1.42l3.88-3.89a4.49 4.49 0 0 0 0-6.33ZM8.83 15.17a1 1 0 0 0 1.1.22 1 1 0 0 0 .32-.22l4.92-4.92a1 1 0 0 0-1.42-1.42l-4.92 4.92a1 1 0 0 0 0 1.42Z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;p&gt;文件传输控制在您的 Access 应用程序中针对每个策略进行配置，与现有的&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-browser/#connection-settings&quot;&gt;文本剪贴板控制&lt;/a&gt;并列。对于每个策略，您可以选择以下选项之一：&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;允许从客户端到远程 RDP 会话&lt;/strong&gt; — 用户可以从其本地计算机上传文件到基于浏览器的 RDP 会话中。&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;允许从远程 RDP 会话到客户端&lt;/strong&gt; — 用户可以从基于浏览器的 RDP 会话下载文件到其本地计算机中。&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;允许双向&lt;/strong&gt; — 用户可以在其本地计算机与基于浏览器的 RDP 会话之间上传和下载文件。&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;禁用复制/粘贴&lt;/strong&gt; — 不允许用户在其本地计算机与基于浏览器的 RDP 会话之间传输文件。&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;默认情况下，新策略的文件传输功能是被拒绝的。对于在此功能可用之前创建的现有 Access 应用程序，文件传输依然被拒绝。&lt;/p&gt;
&lt;div tabindex=&quot;-1&quot; class=&quot;heading-wrapper level-h4&quot;&gt;&lt;h4 id=&quot;工作原理&quot;&gt;工作原理&lt;/h4&gt;&lt;a class=&quot;anchor-link&quot; href=&quot;#工作原理&quot;&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;anchor-icon&quot;&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 24 24&quot;&gt;&lt;path fill=&quot;currentcolor&quot; d=&quot;m12.11 15.39-3.88 3.88a2.52 2.52 0 0 1-3.5 0 2.47 2.47 0 0 1 0-3.5l3.88-3.88a1 1 0 0 0-1.42-1.42l-3.88 3.89a4.48 4.48 0 0 0 6.33 6.33l3.89-3.88a1 1 0 1 0-1.42-1.42Zm8.58-12.08a4.49 4.49 0 0 0-6.33 0l-3.89 3.88a1 1 0 0 0 1.42 1.42l3.88-3.88a2.52 2.52 0 0 1 3.5 0 2.47 2.47 0 0 1 0 3.5l-3.88 3.88a1 1 0 1 0 1.42 1.42l3.88-3.89a4.49 4.49 0 0 0 0-6.33ZM8.83 15.17a1 1 0 0 0 1.1.22 1 1 0 0 0 .32-.22l4.92-4.92a1 1 0 0 0-1.42-1.42l-4.92 4.92a1 1 0 0 0 0 1.42Z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;p&gt;要上传，请将文件拖入浏览器窗口，或选择 RDP 会话左侧的设置齿轮图标。要下载，请在远程会话中复制文件，然后选择设置齿轮以进行下载、将多个文件下载为 zip 包，或者将 PDF 打印到本地打印机。&lt;/p&gt;
&lt;img src=&quot;https://cloudflaredoc.ubitools.com/_astro/clipboard-side-panel.Us2RfXfs_Z1hkXRl.webp&quot; alt=&quot;显示可供传输文件的剪贴板侧边面板。&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;812&quot; height=&quot;532&quot;&gt;&lt;img src=&quot;https://cloudflaredoc.ubitools.com/_astro/remote-doc-ready-for-download-or-print-local.Dcm5hrGD_kMExI.webp&quot; alt=&quot;已准备好下载或本地打印的远程文档。&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;770&quot; height=&quot;442&quot;&gt;
&lt;p&gt;此功能处于 Beta 阶段，可在所有 Zero Trust 方案中使用。欲了解更多信息，请参阅&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-browser/#transfer-files&quot;&gt;基于浏览器的 RDP 的文件传输&lt;/a&gt;。&lt;/p&gt;</description><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate><product>Access</product><category>Access</category><category>Cloudflare One</category></item><item><title>Browser Isolation, Cloudflare One - 浏览器隔离支持授权代理端点</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-07-07-authorization-proxy-endpoint-support/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-07-07-authorization-proxy-endpoint-support/</guid><description>&lt;p&gt;&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/remote-browser-isolation/&quot;&gt;浏览器隔离&lt;/a&gt;现在支持 Gateway &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/#authorization-endpoint&quot;&gt;授权代理端点&lt;/a&gt;。您可以对通过授权代理端点路由的流量应用 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/remote-browser-isolation/isolation-policies/&quot;&gt;HTTP 隔离策略&lt;/a&gt;，方式与对来自 Cloudflare One 客户端的流量相同。&lt;/p&gt;
&lt;p&gt;此前，只有&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/#source-ip-endpoint&quot;&gt;源 IP 代理端点&lt;/a&gt;支持浏览器隔离，且仅支持非基于身份的策略。由于授权代理端点通过身份提供商对用户进行认证，您现在无需 Cloudflare One 客户端即可对 PAC 文件代理流量应用基于身份的隔离策略。&lt;/p&gt;
&lt;p&gt;如需开始，请&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/#authorization-endpoint&quot;&gt;创建授权代理端点&lt;/a&gt;并&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/remote-browser-isolation/isolation-policies/&quot;&gt;构建隔离策略&lt;/a&gt;。&lt;/p&gt;</description><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate><product>Browser Isolation</product><category>Browser Isolation</category><category>Cloudflare One</category></item><item><title>Cloudflare One Appliance, Cloudflare One, Cloudflare WAN - 在仪表板中自助注册 Cloudflare One 虚拟 Appliance</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-07-06-virtual-appliance-self-serve-ui/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-07-06-virtual-appliance-self-serve-ui/</guid><description>&lt;p&gt;您现在可以直接从仪表板注册 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-wan/configuration/appliance/&quot;&gt;Cloudflare One 虚拟 Appliance&lt;/a&gt; 并生成其许可证密钥，而无需联系您的账户团队。&lt;/p&gt;
&lt;img src=&quot;https://cloudflaredoc.ubitools.com/_astro/2026-07-06-virtual-appliance-self-serve-ui.Dn2NC_ql_1WdiRS.webp&quot; alt=&quot;从 Connectors 页面注册 Cloudflare One 虚拟 Appliance 并生成其身份验证密钥&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1800&quot; height=&quot;988&quot;&gt;
&lt;ul&gt;
&lt;li&gt;在 &lt;strong&gt;Connectors（连接器）&lt;/strong&gt; 页面上，选择 &lt;strong&gt;Add an appliance（添加设备）&lt;/strong&gt; 并选择 &lt;strong&gt;Virtual appliance（虚拟设备）&lt;/strong&gt; 以注册虚拟 Appliance 并生成其身份验证密钥。&lt;/li&gt;
&lt;li&gt;从虚拟 Appliance 连接器的菜单中，使用 &lt;strong&gt;Regenerate authentication key&lt;/strong&gt; 来轮换其密钥。先前的密钥会立即且不可逆地撤销。&lt;/li&gt;
&lt;li&gt;身份验证密钥仅显示一次——请复制并妥善保存。&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;这对现有的用于配置虚拟 Appliance 的 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-wan/configuration/appliance/configure-virtual-appliance/#register-a-virtual-appliance-and-generate-a-license-key&quot;&gt;API 和 Terraform 自助服务工作流&lt;/a&gt;进行了补充。硬件 Appliance 继续使用现有的账户团队履行工作流。&lt;/p&gt;
&lt;p&gt;有关详细信息，请参阅&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-wan/configuration/appliance/configure-virtual-appliance/&quot;&gt;配置 Cloudflare One 虚拟 Appliance&lt;/a&gt;。&lt;/p&gt;</description><pubDate>Mon, 06 Jul 2026 00:00:00 GMT</pubDate><product>Cloudflare One Appliance</product><category>Cloudflare One Appliance</category><category>Cloudflare One</category><category>Cloudflare WAN</category></item><item><title>Cloudflare Mesh, Cloudflare One - Cloudflare Mesh 的主机名路由</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-07-02-mesh-hostname-routing/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-07-02-mesh-hostname-routing/</guid><description>
&lt;p&gt;除了 CIDR 路由之外，您现在还可以向 Cloudflare Mesh 节点添加&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/connectors/cloudflare-mesh/routes/#hostname-routes&quot;&gt;主机名路由&lt;/a&gt;。&lt;/p&gt;
&lt;figure class=&quot;mesh-hostname-diagram not-content&quot; aria-label=&quot;How hostname routing works with a Cloudflare Mesh node: a client requests a hostname, Cloudflare Gateway assigns a token IP and rewrites the destination, and the Mesh node delivers the traffic to the private host&quot; data-astro-cid-7hjhdnhq&gt;&lt;ol class=&quot;flow&quot; data-astro-cid-7hjhdnhq&gt;&lt;li class=&quot;flow-step&quot; data-astro-cid-7hjhdnhq&gt;&lt;div class=&quot;node-card client-card&quot; data-astro-cid-7hjhdnhq&gt;&lt;div class=&quot;node-header&quot; data-astro-cid-7hjhdnhq&gt;&lt;span class=&quot;node-icon client-icon&quot; aria-hidden=&quot;true&quot; data-astro-cid-7hjhdnhq&gt;&lt;svg width=&quot;0.98em&quot; height=&quot;1em&quot; data-astro-cid-7hjhdnhq=&quot;true&quot; data-icon=&quot;warp-client&quot;&gt;&lt;symbol id=&quot;ai:local:warp-client&quot; viewBox=&quot;0 0 48 49&quot;&gt;&lt;path fill=&quot;currentColor&quot; d=&quot;M24 5.04a19.5 19.5 0 1 0 19.5 19.5A19.575 19.575 0 0 0 24 5.04m0 3a16.575 16.575 0 0 1 16.5 16.5 16.8 16.8 0 0 1-2.175 8.175c.302-1.125.453-2.285.45-3.45a14.775 14.775 0 0 0-29.55 0 13.2 13.2 0 0 0 .45 3.45A16.8 16.8 0 0 1 7.5 24.54 16.575 16.575 0 0 1 24 8.04m-5.25 30.6a6.974 6.974 0 1 1 10.5 0 5.25 5.25 0 0 0-10.5 0M24 24.015a9.976 9.976 0 0 0-9.975 10.05c-.024.53.026 1.06.15 1.575a11.5 11.5 0 0 1-1.95-6.375 11.775 11.775 0 0 1 23.55 0 11.47 11.47 0 0 1-1.95 6.375 5.6 5.6 0 0 0 .15-1.575A9.974 9.974 0 0 0 24 24.015M21.75 38.79A2.25 2.25 0 1 1 24 41.04a2.174 2.174 0 0 1-2.25-2.25&quot;/&gt;&lt;/symbol&gt;&lt;use href=&quot;#ai:local:warp-client&quot;&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/span&gt;&lt;a class=&quot;node-title&quot; href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/&quot; data-astro-cid-7hjhdnhq&gt;Client device&lt;/a&gt;&lt;/div&gt;&lt;p class=&quot;node-caption&quot; data-astro-cid-7hjhdnhq&gt;Requests &lt;code data-astro-cid-7hjhdnhq&gt;wiki.internal.local&lt;/code&gt;&lt;/p&gt;&lt;/div&gt;&lt;/li&gt;&lt;li class=&quot;flow-connector&quot; data-astro-cid-7hjhdnhq&gt;&lt;span class=&quot;connector-label&quot; data-astro-cid-7hjhdnhq&gt;DNS query&lt;/span&gt;&lt;span class=&quot;connector-arrow&quot; aria-hidden=&quot;true&quot; data-astro-cid-7hjhdnhq&gt;↓&lt;/span&gt;&lt;/li&gt;&lt;li class=&quot;flow-step&quot; data-astro-cid-7hjhdnhq&gt;&lt;div class=&quot;node-card gateway-card&quot; data-astro-cid-7hjhdnhq&gt;&lt;div class=&quot;node-header&quot; data-astro-cid-7hjhdnhq&gt;&lt;span class=&quot;node-icon gateway-icon&quot; aria-hidden=&quot;true&quot; data-astro-cid-7hjhdnhq&gt;&lt;svg width=&quot;1em&quot; height=&quot;1em&quot; data-astro-cid-7hjhdnhq=&quot;true&quot; data-icon=&quot;gateway&quot;&gt;&lt;symbol id=&quot;ai:local:gateway&quot; viewBox=&quot;0 0 16 16&quot;&gt;&lt;path fill=&quot;currentColor&quot; d=&quot;M15.45 7.125h-2.577V3.508l-.41-.408H3.925l-.41.41v3.08h.922V4.023h7.513v7.555H4.438v-1.553h-.923v2.065l.41.41h8.538l.41-.41V8.048H16z&quot;/&gt;&lt;path fill=&quot;currentColor&quot; d=&quot;M8.453 7.238H0l.517.87H8.97zM9.21 8.51H.755l.517.868h8.453z&quot;/&gt;&lt;/symbol&gt;&lt;use href=&quot;#ai:local:gateway&quot;&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/span&gt;&lt;a class=&quot;node-title&quot; href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/&quot; data-astro-cid-7hjhdnhq&gt;Cloudflare Gateway&lt;/a&gt;&lt;/div&gt;&lt;p class=&quot;node-caption&quot; data-astro-cid-7hjhdnhq&gt;Returns a token IP, then rewrites the destination to the real private IP.&lt;/p&gt;&lt;div class=&quot;pill-row&quot; data-astro-cid-7hjhdnhq&gt;&lt;span class=&quot;token-pill&quot; data-astro-cid-7hjhdnhq&gt;&lt;code data-astro-cid-7hjhdnhq&gt;100.80.0.0/16&lt;/code&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/li&gt;&lt;li class=&quot;flow-connector&quot; data-astro-cid-7hjhdnhq&gt;&lt;a class=&quot;connector-label&quot; href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/connectors/cloudflare-mesh/routes/#hostname-routes&quot; data-astro-cid-7hjhdnhq&gt;Hostname route&lt;/a&gt;&lt;span class=&quot;connector-arrow&quot; aria-hidden=&quot;true&quot; data-astro-cid-7hjhdnhq&gt;↓&lt;/span&gt;&lt;/li&gt;&lt;li class=&quot;flow-step&quot; data-astro-cid-7hjhdnhq&gt;&lt;div class=&quot;node-card mesh-card&quot; data-astro-cid-7hjhdnhq&gt;&lt;div class=&quot;node-header&quot; data-astro-cid-7hjhdnhq&gt;&lt;span class=&quot;node-icon mesh-icon&quot; aria-hidden=&quot;true&quot; data-astro-cid-7hjhdnhq&gt;&lt;svg width=&quot;1em&quot; height=&quot;1em&quot; data-astro-cid-7hjhdnhq=&quot;true&quot; data-icon=&quot;cloudflare-mesh&quot;&gt;&lt;symbol id=&quot;ai:local:cloudflare-mesh&quot; viewBox=&quot;0 0 32 32&quot;&gt;&lt;path fill=&quot;currentColor&quot; d=&quot;M10 6a2 2 0 1 1-4 0 2 2 0 0 1 4 0m6-2a2 2 0 1 0 0 4 2 2 0 0 0 0-4m8 4a2 2 0 1 0 0-4 2 2 0 0 0 0 4M8 11a2 2 0 1 0 0 4 2 2 0 0 0 0-4m8 0a2 2 0 1 0 0 4 2 2 0 0 0 0-4m8 0a2 2 0 1 0 0 4 2 2 0 0 0 0-4M8 18a2 2 0 1 0 0 4 2 2 0 0 0 0-4m8 0a2 2 0 1 0 0 4 2 2 0 0 0 0-4m0 7a2 2 0 1 0 0 4 2 2 0 0 0 0-4m8-7a2 2 0 1 0 0 4 2 2 0 0 0 0-4&quot;/&gt;&lt;/symbol&gt;&lt;use href=&quot;#ai:local:cloudflare-mesh&quot;&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/span&gt;&lt;a class=&quot;node-title&quot; href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/connectors/cloudflare-mesh/&quot; data-astro-cid-7hjhdnhq&gt;Mesh node&lt;/a&gt;&lt;/div&gt;&lt;p class=&quot;node-caption&quot; data-astro-cid-7hjhdnhq&gt;Forwards traffic to the host on the local network&lt;/p&gt;&lt;/div&gt;&lt;/li&gt;&lt;li class=&quot;flow-connector&quot; aria-hidden=&quot;true&quot; data-astro-cid-7hjhdnhq&gt;&lt;span class=&quot;connector-arrow&quot; data-astro-cid-7hjhdnhq&gt;↓&lt;/span&gt;&lt;/li&gt;&lt;li class=&quot;flow-step&quot; data-astro-cid-7hjhdnhq&gt;&lt;div class=&quot;node-card host-card&quot; data-astro-cid-7hjhdnhq&gt;&lt;div class=&quot;node-header&quot; data-astro-cid-7hjhdnhq&gt;&lt;span class=&quot;node-icon host-icon&quot; aria-hidden=&quot;true&quot; data-astro-cid-7hjhdnhq&gt;&lt;svg width=&quot;1em&quot; height=&quot;1em&quot; data-astro-cid-7hjhdnhq=&quot;true&quot; data-icon=&quot;dns&quot;&gt;&lt;symbol id=&quot;ai:local:dns&quot; viewBox=&quot;0 0 48 48&quot;&gt;&lt;path fill=&quot;currentColor&quot; d=&quot;M39 30.98h-2.125v-8.574H25.148v-5.449h2.102l1.25-1.25V9l-1.25-1.25h-6.738L19.262 9v6.707l1.25 1.25h2.136v5.45H11.125v8.573H9l-1.25 1.25V39L9 40.25h6.742l1.25-1.25v-6.77l-1.25-1.25h-2.117v-6.074h9.023v6.074h-2.136l-1.25 1.25V39l1.25 1.25h6.738L28.5 39v-6.77l-1.25-1.25h-2.102v-6.074h9.235v6.074h-2.121l-1.25 1.25V39l1.25 1.25H39L40.25 39v-6.77ZM21.762 10.25H26v4.238h-4.238Zm-7.27 27.5H10.25v-4.27h4.238Zm11.508 0h-4.238v-4.27H26Zm11.75 0h-4.238v-4.27h4.238Z&quot;/&gt;&lt;/symbol&gt;&lt;use href=&quot;#ai:local:dns&quot;&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/span&gt;&lt;span class=&quot;node-title&quot; data-astro-cid-7hjhdnhq&gt;Private host&lt;/span&gt;&lt;/div&gt;&lt;p class=&quot;node-caption&quot; data-astro-cid-7hjhdnhq&gt;&lt;code data-astro-cid-7hjhdnhq&gt;wiki.internal.local&lt;/code&gt; · &lt;code data-astro-cid-7hjhdnhq&gt;10.0.0.50&lt;/code&gt;&lt;/p&gt;&lt;/div&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/figure&gt;
&lt;p&gt;您可以通过将主机名的流量引导到 Mesh 节点来代替管理 IP 范围：&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;私有主机名&lt;/strong&gt;（例如 &lt;code&gt;wiki.internal.local&lt;/code&gt;）—— 通过名称访问内部应用程序，这在它具有未知或临时 IP 时非常有用。在 Mesh 上，您不需要运行 DNS 服务器；只需节点上的本地 hosts 文件条目即可，或者您可以使用 Gateway 解析器策略进行 split DNS。&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;公共主机名&lt;/strong&gt;（例如 &lt;code&gt;www.example.com&lt;/code&gt;）—— 通过该节点路由该主机名的流量，并经由该节点的公共 IP 出站。&lt;/li&gt;
&lt;/ul&gt;
&lt;a href=&quot;https://dash.cloudflare.com/?to=/:account/mesh&quot; data-nb-button class=&quot;group inline-flex w-max shrink-0 items-center justify-center rounded-full font-medium whitespace-nowrap no-underline shadow-xs transition-colors cursor-pointer select-none focus-visible:outline-2 focus-visible:outline-ring focus-visible:outline-offset-2 disabled:cursor-not-allowed disabled:opacity-50 bg-primary text-primary-foreground hover:bg-primary-hover h-9 gap-1.5 px-3 text-sm&quot; target=&quot;_blank&quot;&gt;Go to &lt;strong&gt;Mesh&lt;/strong&gt;&amp;nbsp;&amp;#8599;&lt;/a&gt;
&lt;p&gt;有关设置步骤、先决条件和 DNS 选项，请参阅&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/connectors/cloudflare-mesh/routes/#hostname-routes&quot;&gt;主机名路由&lt;/a&gt;。&lt;/p&gt;</description><pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate><product>Cloudflare Mesh</product><category>Cloudflare Mesh</category><category>Cloudflare One</category></item><item><title>Cloudflare One Client - Cloudflare One Client for Linux (version 2026.6.836.0)</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-07-01-warp-linux-ga/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-07-01-warp-linux-ga/</guid><description>&lt;p&gt;A new GA release for the Linux Cloudflare One Client is now available on the &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/&quot;&gt;stable releases downloads page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This package is the same release as 2026.6.822.0, with a fix for our RPM package. Previously the repository served a single build to every OS version, so an install could pull a dependency that isn&amp;#39;t available on that release. The repository now serves the correct build for each operating system version, so installs automatically pull the dependencies that version requires. Debian and Ubuntu were not affected.&lt;/p&gt;
&lt;p&gt;If you installed version 2026.6.822.0 on an RPM-based distribution, we recommend refreshing your repository configuration:&lt;/p&gt;
&lt;pre&gt;&lt;code class=&quot;language-bash&quot;&gt;sudo curl -fsSL https://pkg.cloudflareclient.com/cloudflare-warp-ascii.repo | sudo tee /etc/yum.repos.d/cloudflare-warp.repo
sudo dnf clean all
sudo dnf install cloudflare-warp
&lt;/code&gt;&lt;/pre&gt;
</description><pubDate>Wed, 01 Jul 2026 19:48:17 GMT</pubDate><product>Cloudflare One Client</product><category>Cloudflare One Client</category></item><item><title>Access - 修复单页应用程序的重定向 URL 片段（fragment）编码</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-07-01-spa-redirect-fragment-fix/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-07-01-spa-redirect-fragment-fix/</guid><description>&lt;p&gt;Access 现在在登录后将用户重定向回应用程序时，能够正确保留 URL 片段（fragment）字符（&lt;code&gt;/&lt;/code&gt;、&lt;code&gt;?&lt;/code&gt;、&lt;code&gt;=&lt;/code&gt;、&lt;code&gt;&amp;amp;&lt;/code&gt;、&lt;code&gt;;&lt;/code&gt;）。以前，这些字符是使用 &lt;code&gt;encodeURIComponent&lt;/code&gt; 进行编码的，这会破坏单页应用程序（SPA）使用的基于片段的路由。&lt;/p&gt;
&lt;p&gt;例如，像 &lt;code&gt;https://app.example.com/#/dashboard?tab=settings&amp;amp;view=advanced&lt;/code&gt; 这样的 SPA URL 以前在登录后会重定向到一个损坏的 URL。这现在已得到正确处理。&lt;/p&gt;
&lt;p&gt;如果您的 SPA 用户在通过 Access 进行身份验证后遇到导航损坏的问题，此修复将解决该问题，而无需进行任何配置更改。&lt;/p&gt;</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate><product>Access</product><category>Access</category></item><item><title>Access - 用于基础设施应用程序的独立 MFA</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-07-01-ssh-mfa-piv-keys/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-07-01-ssh-mfa-piv-keys/</guid><description>&lt;p&gt;&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/access-controls/applications/non-http/infrastructure-apps/&quot;&gt;Access for Infrastructure&lt;/a&gt; 现在支持使用 YubiKey PIV 密钥对 SSH 连接实施独立多因素身份验证（MFA）。这为 SSH 访问添加了基于硬件的第二因素，确保仅凭受损的设备会话不足以访问您的服务器。&lt;/p&gt;
&lt;p&gt;通过针对每个应用程序和每个策略的配置，您可以对敏感用户名（例如 &lt;code&gt;root&lt;/code&gt;）强制执行 PIV 密钥身份验证，同时对其他用户名应用不同的要求。您还可以设置 MFA 会话时长，以控制用户必须重新进行身份验证的频率。&lt;/p&gt;
&lt;div tabindex=&quot;-1&quot; class=&quot;heading-wrapper level-h4&quot;&gt;&lt;h4 id=&quot;注册&quot;&gt;注册&lt;/h4&gt;&lt;a class=&quot;anchor-link&quot; href=&quot;#注册&quot;&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;anchor-icon&quot;&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 24 24&quot;&gt;&lt;path fill=&quot;currentcolor&quot; d=&quot;m12.11 15.39-3.88 3.88a2.52 2.52 0 0 1-3.5 0 2.47 2.47 0 0 1 0-3.5l3.88-3.88a1 1 0 0 0-1.42-1.42l-3.88 3.89a4.48 4.48 0 0 0 6.33 6.33l3.89-3.88a1 1 0 1 0-1.42-1.42Zm8.58-12.08a4.49 4.49 0 0 0-6.33 0l-3.89 3.88a1 1 0 0 0 1.42 1.42l3.88-3.88a2.52 2.52 0 0 1 3.5 0 2.47 2.47 0 0 1 0 3.5l-3.88 3.88a1 1 0 1 0 1.42 1.42l3.88-3.89a4.49 4.49 0 0 0 0-6.33ZM8.83 15.17a1 1 0 0 0 1.1.22 1 1 0 0 0 .32-.22l4.92-4.92a1 1 0 0 0-1.42-1.42l-4.92 4.92a1 1 0 0 0 0 1.42Z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;p&gt;用户通过&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/access-controls/access-settings/app-launcher/&quot;&gt;应用程序启动器&lt;/a&gt;注册其 YubiKey PIV 密钥。有关注册说明和 SSH 客户端设置，请参阅&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/access-controls/access-settings/independent-mfa/#enroll-a-piv-key-for-infrastructure-apps&quot;&gt;为基础设施应用程序注册 PIV 密钥&lt;/a&gt;。&lt;/p&gt;
&lt;div tabindex=&quot;-1&quot; class=&quot;heading-wrapper level-h4&quot;&gt;&lt;h4 id=&quot;配置&quot;&gt;配置&lt;/h4&gt;&lt;a class=&quot;anchor-link&quot; href=&quot;#配置&quot;&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;anchor-icon&quot;&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 24 24&quot;&gt;&lt;path fill=&quot;currentcolor&quot; d=&quot;m12.11 15.39-3.88 3.88a2.52 2.52 0 0 1-3.5 0 2.47 2.47 0 0 1 0-3.5l3.88-3.88a1 1 0 0 0-1.42-1.42l-3.88 3.89a4.48 4.48 0 0 0 6.33 6.33l3.89-3.88a1 1 0 1 0-1.42-1.42Zm8.58-12.08a4.49 4.49 0 0 0-6.33 0l-3.89 3.88a1 1 0 0 0 1.42 1.42l3.88-3.88a2.52 2.52 0 0 1 3.5 0 2.47 2.47 0 0 1 0 3.5l-3.88 3.88a1 1 0 1 0 1.42 1.42l3.88-3.89a4.49 4.49 0 0 0 0-6.33ZM8.83 15.17a1 1 0 0 0 1.1.22 1 1 0 0 0 .32-.22l4.92-4.92a1 1 0 0 0-1.42-1.42l-4.92 4.92a1 1 0 0 0 0 1.42Z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;p&gt;有关设置说明，请参阅&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/access-controls/policies/mfa-requirements/#infrastructure-applications&quot;&gt;为基础设施应用程序强制执行 MFA&lt;/a&gt;。&lt;/p&gt;</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate><product>Access</product><category>Access</category></item><item><title>Gateway, Cloudflare One, Cloudflare Fundamentals - Gateway 策略和列表的新权限与角色</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-06-30-gateway-granular-permissions/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-06-30-gateway-granular-permissions/</guid><description>&lt;p&gt;您现在可以为 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/&quot;&gt;Cloudflare Gateway&lt;/a&gt; 防火墙策略和 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/reusable-components/lists/&quot;&gt;Zero Trust 列表&lt;/a&gt;分配细粒度的资源作用域角色。管理员可以委派对特定策略类型或列表管理的访问权限，而无需授予账户范围或产品范围的控制权。&lt;/p&gt;
&lt;div tabindex=&quot;-1&quot; class=&quot;heading-wrapper level-h4&quot;&gt;&lt;h4 id=&quot;新增功能&quot;&gt;新增功能&lt;/h4&gt;&lt;a class=&quot;anchor-link&quot; href=&quot;#新增功能&quot;&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;anchor-icon&quot;&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 24 24&quot;&gt;&lt;path fill=&quot;currentcolor&quot; d=&quot;m12.11 15.39-3.88 3.88a2.52 2.52 0 0 1-3.5 0 2.47 2.47 0 0 1 0-3.5l3.88-3.88a1 1 0 0 0-1.42-1.42l-3.88 3.89a4.48 4.48 0 0 0 6.33 6.33l3.89-3.88a1 1 0 1 0-1.42-1.42Zm8.58-12.08a4.49 4.49 0 0 0-6.33 0l-3.89 3.88a1 1 0 0 0 1.42 1.42l3.88-3.88a2.52 2.52 0 0 1 3.5 0 2.47 2.47 0 0 1 0 3.5l-3.88 3.88a1 1 0 1 0 1.42 1.42l3.88-3.89a4.49 4.49 0 0 0 0-6.33ZM8.83 15.17a1 1 0 0 0 1.1.22 1 1 0 0 0 .32-.22l4.92-4.92a1 1 0 0 0-1.42-1.42l-4.92 4.92a1 1 0 0 0 0 1.42Z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;p&gt;当您&lt;a href=&quot;https://cloudflaredoc.ubitools.com/fundamentals/manage-members/manage/&quot;&gt;添加成员&lt;/a&gt;或创建&lt;a href=&quot;https://cloudflaredoc.ubitools.com/fundamentals/manage-members/policies/&quot;&gt;权限策略&lt;/a&gt;时，现在可以使用以下资源作用域角色：&lt;/p&gt;
&lt;div class=&quot;table-scroll&quot; tabindex=&quot;0&quot; role=&quot;region&quot; aria-label=&quot;Table&quot;&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;角色&lt;/th&gt;
&lt;th&gt;说明&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Zero Trust Gateway Firewall Policies Admin&lt;/td&gt;
&lt;td&gt;可以查看和编辑所有 Gateway 防火墙策略，包括 DNS、HTTP 和网络策略。&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Zero Trust Gateway DNS Policies Admin&lt;/td&gt;
&lt;td&gt;可以查看和编辑 Gateway DNS 策略。&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Zero Trust Gateway HTTP Policies Admin&lt;/td&gt;
&lt;td&gt;可以查看和编辑 Gateway HTTP 策略。&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Zero Trust Gateway Network Policies Admin&lt;/td&gt;
&lt;td&gt;可以查看和编辑 Gateway 网络策略。&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Zero Trust Gateway Egress Policies Admin&lt;/td&gt;
&lt;td&gt;可以查看和编辑 Gateway 出口策略。&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Zero Trust Gateway Resolver Policies Admin&lt;/td&gt;
&lt;td&gt;可以查看和编辑 Gateway 解析器策略。&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Zero Trust Gateway Policies Admin&lt;/td&gt;
&lt;td&gt;可以查看和编辑所有 Gateway 策略。&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Zero Trust Gateway Policies Read&lt;/td&gt;
&lt;td&gt;可以查看所有 Gateway 策略。&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Zero Trust Gateway Read Only&lt;/td&gt;
&lt;td&gt;可以查看所有 Gateway 资源。&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Zero Trust DNS Locations Admin&lt;/td&gt;
&lt;td&gt;可以查看和编辑 DNS 位置。&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Zero Trust Proxy Endpoints Admin&lt;/td&gt;
&lt;td&gt;可以查看和编辑 Gateway 代理端点。&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Zero Trust Account Lists Admin&lt;/td&gt;
&lt;td&gt;可以查看和编辑所有 Gateway 和 Access 列表。&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Zero Trust Account Lists Read&lt;/td&gt;
&lt;td&gt;可以查看所有 Gateway 和 Access 列表。&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;
&lt;p&gt;这些角色允许您：&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;仅向网络工程师授予网络策略的写入权限，而不暴露 DNS 或 HTTP 策略配置。&lt;/li&gt;
&lt;li&gt;允许安全分析师以只读模式查看所有 Gateway 策略以进行审计。&lt;/li&gt;
&lt;li&gt;将列表管理委托给维护阻止和允许列表的团队，而不授予他们访问策略配置的权限。&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;您现在还可以分配 &lt;em&gt;资源作用域角色&lt;/em&gt;。这些角色是对现有账户级别角色的补充，允许您授予对特定资源（例如单个 Gateway 策略或 Cloudflare One 列表）的访问权限。&lt;strong&gt;现有的账户级别角色继续有效。&lt;/strong&gt; 拥有 &lt;code&gt;Cloudflare Gateway&lt;/code&gt; 或 &lt;code&gt;Cloudflare Zero Trust&lt;/code&gt; 角色的成员将保留对所有 Gateway 资源的完全访问权限。这确保了与现有自动化和 API 令牌的向后兼容性。&lt;/p&gt;
&lt;div tabindex=&quot;-1&quot; class=&quot;heading-wrapper level-h4&quot;&gt;&lt;h4 id=&quot;快速入门&quot;&gt;快速入门&lt;/h4&gt;&lt;a class=&quot;anchor-link&quot; href=&quot;#快速入门&quot;&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;anchor-icon&quot;&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 24 24&quot;&gt;&lt;path fill=&quot;currentcolor&quot; d=&quot;m12.11 15.39-3.88 3.88a2.52 2.52 0 0 1-3.5 0 2.47 2.47 0 0 1 0-3.5l3.88-3.88a1 1 0 0 0-1.42-1.42l-3.88 3.89a4.48 4.48 0 0 0 6.33 6.33l3.89-3.88a1 1 0 1 0-1.42-1.42Zm8.58-12.08a4.49 4.49 0 0 0-6.33 0l-3.89 3.88a1 1 0 0 0 1.42 1.42l3.88-3.88a2.52 2.52 0 0 1 3.5 0 2.47 2.47 0 0 1 0 3.5l-3.88 3.88a1 1 0 1 0 1.42 1.42l3.88-3.89a4.49 4.49 0 0 0 0-6.33ZM8.83 15.17a1 1 0 0 0 1.1.22 1 1 0 0 0 .32-.22l4.92-4.92a1 1 0 0 0-1.42-1.42l-4.92 4.92a1 1 0 0 0 0 1.42Z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;查看 Cloudflare 角色参考上的&lt;a href=&quot;https://cloudflaredoc.ubitools.com/fundamentals/manage-members/roles/#resource-scoped-roles&quot;&gt;资源作用域角色&lt;/a&gt;。&lt;/li&gt;
&lt;li&gt;了解如何&lt;a href=&quot;https://cloudflaredoc.ubitools.com/fundamentals/manage-members/policies/&quot;&gt;创建使用这些角色的权限策略&lt;/a&gt;。&lt;/li&gt;
&lt;/ul&gt;</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate><product>Gateway</product><category>Gateway</category><category>Cloudflare One</category><category>Cloudflare Fundamentals</category></item><item><title>Cloudflare One Client - Cloudflare One Client for Windows (version 2026.6.822.0)</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-06-29-warp-windows-ga/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-06-29-warp-windows-ga/</guid><description>&lt;p&gt;A new GA release for the Windows Cloudflare One Client is now available on the &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/&quot;&gt;stable releases downloads page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This release introduces multiple features from our previous beta release into stable release, including:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The client now applies DNS search suffixes configured in your &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-profiles&quot;&gt;device profile&lt;/a&gt; / &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/network-policies&quot;&gt;network policy&lt;/a&gt;. Administrators can push a list of DNS search domains that the client appends to single-label queries, alongside any system-configured suffixes. See &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/#dns-search-suffixes&quot;&gt;DNS search suffixes&lt;/a&gt; for details.&lt;/li&gt;
&lt;li&gt;Added mandatory authentication. When enabled via MDM, the Cloudflare One Client blocks all Internet traffic from the moment the machine boots until the user authenticates, closing the visibility gap on newly deployed devices and during re-authentication. See the &lt;a href=&quot;https://blog.cloudflare.com/mandatory-authentication-mfa/&quot;&gt;announcement blog&lt;/a&gt; and &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/windows-no-auth-no-internet/&quot;&gt;documentation&lt;/a&gt; for details.&lt;/li&gt;
&lt;li&gt;Upgraded security of device registration to be hardware-backed. Registration tokens can now be generated in the TPM (with TPM 2.0+) whenever it is available to provide stronger protection against device impersonation. See &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/hardware-backed-registration/&quot;&gt;Hardware-backed registration&lt;/a&gt; for details.&lt;/li&gt;
&lt;li&gt;Added a local-file signal source for Emergency Disconnect. In addition to the existing HTTPS polling mechanism, administrators can now configure WARP to monitor for a file on disk; the presence of the file triggers an emergency disconnect even if both Cloudflare and your own infrastructure are unreachable. Either signal being asserted triggers disconnect; both must be cleared for normal operation to resume.&lt;/li&gt;
&lt;li&gt;Added new warp-cli debug commands for interactive connection diagnosis. See &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/diagnostic-logs/#extra-debug-logging&quot;&gt;Extra debug logging&lt;/a&gt; for details.&lt;/li&gt;
&lt;li&gt;The local DNS proxy now supports DNSSEC passthrough. DNSSEC-signed responses are forwarded to the application intact (including DO/AD bits and RRSIG records), so applications that validate DNSSEC locally — including resolvers and the dig/drill tooling — work correctly through the client.&lt;/li&gt;
&lt;li&gt;Added a new MDM format for organization-wide settings, including a cleaner way to configure the compliance environment (e.g. FedRAMP). The previous per-configuration approach still works, but the new format is now recommended. See the updated &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/parameters/#organization_configs&quot;&gt;Cloudflare One MDM documentation&lt;/a&gt; for details.&lt;/li&gt;
&lt;li&gt;Added support for dashboard-managed client version deployments. Administrators can now upgrade or downgrade the client version on enrolled devices directly from the Zero Trust dashboard. See &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/client-version-assignments/&quot;&gt;Client version assignments&lt;/a&gt; for details.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Additional Changes and improvements&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Starting with 2026.6.822.0, the client unifies all API requests under the &lt;code&gt;api.devices.cloudflare.com&lt;/code&gt; SNI, where previously both &lt;code&gt;zero-trust-client.cloudflareclient.com&lt;/code&gt; and &lt;code&gt;notifications.cloudflareclient.com&lt;/code&gt; were used. Review &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/firewall/&quot;&gt;Cloudflare One Client with firewall&lt;/a&gt; to ensure systems that rely on SNI inspection do not block the API traffic. The behavior of previous client versions is unaffected.&lt;/li&gt;
&lt;li&gt;Client Certificate device-posture checks now support template variables (e.g. &lt;code&gt;${serial_number}&lt;/code&gt;, &lt;code&gt;${device_uuid}&lt;/code&gt;) in the Subject Alternative Name field. Previously only the Common Name field accepted variables, which broke posture rules that pinned identity to a SAN entry.&lt;/li&gt;
&lt;li&gt;Improved accessibility by using high contrast colors and more defined color boundaries when high contrast is enabled in Windows Accessibility settings.&lt;/li&gt;
&lt;li&gt;Path MTU Discovery (PMTUD) is now enabled by default.&lt;/li&gt;
&lt;li&gt;The UseWebView2 registry value (HKLM\SOFTWARE\Cloudflare\CloudflareWARP\UseWebView2 = y) is once again honored by the new GUI for authentication, so administrators who prefer the embedded WebView2 browser for sign-in can opt back in. This setting was effectively ignored in the previous release; the default browser was always used. This key is now also honored for re-authentications.&lt;/li&gt;
&lt;li&gt;Fixed a crash in the authentication browser when navigating to a site that prompts for browser permissions (microphone, camera, notifications, etc.). The same fix had previously landed for the captive-portal browser; this extends it to the auth browser.&lt;/li&gt;
&lt;li&gt;Fixed an issue in proxy mode where hostnames containing underscores (e.g. ai_app.com) were rejected, breaking apps that depend on such hostnames (notably ChatGPT sandbox apps). The local proxy now accepts underscore-containing hostnames in CONNECT requests.&lt;/li&gt;
&lt;li&gt;Fixed an issue where DNS queries would fail after the connection was idle, requiring users to retry.&lt;/li&gt;
&lt;li&gt;Fixed a high CPU issue when the device wakes from sleep.&lt;/li&gt;
&lt;li&gt;Users can now register with team names in any case format without errors.&lt;/li&gt;
&lt;li&gt;New UI fixes&lt;ul&gt;
&lt;li&gt;Fixed an issue where users with invalid MDM configurations were returned to the onboarding screen after successful authentication.&lt;/li&gt;
&lt;li&gt;Added a re-auth button and banner to the home screen so users don&amp;#39;t miss it when their session expires.&lt;/li&gt;
&lt;li&gt;Added clear error messaging when the Cloudflare certificate needs to be installed.&lt;/li&gt;
&lt;li&gt;Brought back support for pausing the tunnel when connected to user-specified Wi-Fi networks for consumer users.&lt;/li&gt;
&lt;li&gt;New client UI now surfaces Split tunnel configuration and Local Domain Fallback configuration.&lt;/li&gt;
&lt;li&gt;Added ability to configure proxy mode for consumer users.&lt;/li&gt;
&lt;li&gt;Added back the option to quit for consumer users.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Known issues&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Single sign-on in the embedded WebView2 authentication browser may fail to use the Windows primary account, prompting for an interactive sign-in.&lt;/li&gt;
&lt;li&gt;An error indicating that Microsoft Edge can&amp;#39;t read and write to its data directory may be displayed during captive portal login; this error is benign and can be dismissed.&lt;/li&gt;
&lt;li&gt;In rare cases, a registration may hang at &amp;quot;Checking your organization configuration&amp;quot; due to IPC errors. A system reboot should resolve the error, allowing registration to proceed.&lt;/li&gt;
&lt;li&gt;Windows ARM may prompt the user to close running applications while trying to install this version. Simply click &amp;quot;Ok&amp;quot; with the default highlighted option.&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Mon, 29 Jun 2026 20:05:45 GMT</pubDate><product>Cloudflare One Client</product><category>Cloudflare One Client</category></item><item><title>Cloudflare One Client - Cloudflare One Client for macOS (version 2026.6.822.0)</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-06-29-warp-macos-ga/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-06-29-warp-macos-ga/</guid><description>&lt;p&gt;A new GA release for the macOS Cloudflare One Client is now available on the &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/&quot;&gt;stable releases downloads page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This release introduces multiple features from our previous beta release into stable release, including:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The client now applies DNS search suffixes configured in your &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-profiles&quot;&gt;device profile&lt;/a&gt; / &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/network-policies&quot;&gt;network policy&lt;/a&gt;. Administrators can push a list of DNS search domains that the client appends to single-label queries, alongside any system-configured suffixes. See &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/#dns-search-suffixes&quot;&gt;DNS search suffixes&lt;/a&gt; for details.&lt;/li&gt;
&lt;li&gt;Upgraded security of device registration to be hardware-backed. Registration tokens can now be generated in the Secure Enclave whenever available to provide stronger protection against device impersonation. See &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/hardware-backed-registration/&quot;&gt;Hardware-backed registration&lt;/a&gt; for details.&lt;/li&gt;
&lt;li&gt;Added a local-file signal source for Emergency Disconnect. In addition to the existing HTTPS polling mechanism, administrators can now configure WARP to monitor for a file on disk; the presence of the file triggers an emergency disconnect even if both Cloudflare and your own infrastructure are unreachable. Either signal being asserted triggers disconnect; both must be cleared for normal operation to resume.&lt;/li&gt;
&lt;li&gt;Added new warp-cli debug commands for interactive connection diagnosis. See &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/diagnostic-logs/#extra-debug-logging&quot;&gt;Extra debug logging&lt;/a&gt; for details.&lt;/li&gt;
&lt;li&gt;The local DNS proxy now supports DNSSEC passthrough. DNSSEC-signed responses are forwarded to the application intact (including DO/AD bits and RRSIG records), so applications that validate DNSSEC locally — including resolvers and the dig/drill tooling — work correctly through the client.&lt;/li&gt;
&lt;li&gt;Added a new MDM format for organization-wide settings, including a cleaner way to configure the compliance environment (e.g. FedRAMP). The previous per-configuration approach still works, but the new format is now recommended. See the updated &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/parameters/#organization_configs&quot;&gt;Cloudflare One MDM documentation&lt;/a&gt; for details.&lt;/li&gt;
&lt;li&gt;Added support for dashboard-managed client version deployments. Administrators can now upgrade or downgrade the client version on enrolled devices directly from the Zero Trust dashboard. See &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/client-version-assignments/&quot;&gt;Client version assignments&lt;/a&gt; for details.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Additional Changes and improvements&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Starting with 2026.6.822.0, the client unifies all API requests under the &lt;code&gt;api.devices.cloudflare.com&lt;/code&gt; SNI, where previously both &lt;code&gt;zero-trust-client.cloudflareclient.com&lt;/code&gt; and &lt;code&gt;notifications.cloudflareclient.com&lt;/code&gt; were used. Review &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/firewall/&quot;&gt;Cloudflare One Client with firewall&lt;/a&gt; to ensure systems that rely on SNI inspection do not block the API traffic. The behavior of previous client versions is unaffected.&lt;/li&gt;
&lt;li&gt;Client Certificate device-posture checks now support template variables (e.g. &lt;code&gt;${serial_number}&lt;/code&gt;, &lt;code&gt;${device_uuid}&lt;/code&gt;) in the Subject Alternative Name field. Previously only the Common Name field accepted variables, which broke posture rules that pinned identity to a SAN entry.&lt;/li&gt;
&lt;li&gt;Improved accessibility by using high contrast colors and more defined color boundaries when high contrast is enabled in the macOS Display settings.&lt;/li&gt;
&lt;li&gt;Path MTU Discovery (PMTUD) is now enabled by default.&lt;/li&gt;
&lt;li&gt;Fixed the in-client captive-portal browser rendering a blank &amp;quot;Success&amp;quot; page on some airline Wi-Fi networks. The browser now more consistently loads the airline&amp;#39;s real portal page so users can complete sign-in from inside the client instead of having to open a separate browser.&lt;/li&gt;
&lt;li&gt;Fixed an issue in proxy mode where hostnames containing underscores (e.g. ai_app.com) were rejected, breaking apps that depend on such hostnames (notably ChatGPT sandbox apps). The local proxy now accepts underscore-containing hostnames in CONNECT requests.&lt;/li&gt;
&lt;li&gt;Fixed an issue where DNS queries would fail after the connection was idle, requiring users to retry.&lt;/li&gt;
&lt;li&gt;Users can now register with team names in any case format without errors.&lt;/li&gt;
&lt;li&gt;New UI fixes&lt;ul&gt;
&lt;li&gt;Fixed an issue where users with invalid MDM configurations were returned to the onboarding screen after successful authentication.&lt;/li&gt;
&lt;li&gt;Added a re-auth button and banner to the home screen so users don&amp;#39;t miss it when their session expires.&lt;/li&gt;
&lt;li&gt;Added clear error messaging when the Cloudflare certificate needs to be installed.&lt;/li&gt;
&lt;li&gt;Brought back support for pausing the tunnel when connected to user-specified Wi-Fi networks for consumer users.&lt;/li&gt;
&lt;li&gt;New client UI now surfaces Split tunnel configuration and Local Domain Fallback configuration.&lt;/li&gt;
&lt;li&gt;Added ability to configure proxy mode for consumer users.&lt;/li&gt;
&lt;li&gt;Added back the option to quit for consumer users.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Known issues&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Registration may hang at &amp;quot;Checking your organization configuration&amp;quot; due to IPC errors. A system reboot should resolve the error, allowing registration to proceed.&lt;/li&gt;
&lt;li&gt;When deploying with Microsoft Intune, the client may be repeatedly reinstalled because Intune adds the client&amp;#39;s embedded framework bundles to its install-detection list, and those frameworks cannot be detected as installed on their own. See &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/known-limitations/#repeated-reinstalls-on-macos-with-microsoft-intune&quot;&gt;Repeated reinstalls on macOS with Microsoft Intune&lt;/a&gt; for the workaround.&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Mon, 29 Jun 2026 20:05:45 GMT</pubDate><product>Cloudflare One Client</product><category>Cloudflare One Client</category></item><item><title>Cloudflare One Client - Cloudflare One Client for Linux (version 2026.6.822.0)</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-06-29-warp-linux-ga/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-06-29-warp-linux-ga/</guid><description>&lt;p&gt;A new GA release for the Linux Cloudflare One Client is now available on the &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/&quot;&gt;stable releases downloads page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This release introduces multiple features from our previous beta release into stable release, including:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The client now applies DNS search suffixes configured in your &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-profiles&quot;&gt;device profile&lt;/a&gt; / &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/network-policies&quot;&gt;network policy&lt;/a&gt;. Administrators can push a list of DNS search domains that the client appends to single-label queries, alongside any system-configured suffixes. See &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/#dns-search-suffixes&quot;&gt;DNS search suffixes&lt;/a&gt; for details.&lt;/li&gt;
&lt;li&gt;Upgraded security of device registration to be hardware-backed. Registration tokens can now be generated in the TPM (with TPM 2.0+) whenever it is available to provide stronger protection against device impersonation. See &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/hardware-backed-registration/&quot;&gt;Hardware-backed registration&lt;/a&gt; for details.&lt;/li&gt;
&lt;li&gt;Added a local-file signal source for Emergency Disconnect. In addition to the existing HTTPS polling mechanism, administrators can now configure WARP to monitor for a file on disk; the presence of the file triggers an emergency disconnect even if both Cloudflare and your own infrastructure are unreachable. Either signal being asserted triggers disconnect; both must be cleared for normal operation to resume.&lt;/li&gt;
&lt;li&gt;Added new warp-cli debug commands for interactive connection diagnosis. See &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/diagnostic-logs/#extra-debug-logging&quot;&gt;Extra debug logging&lt;/a&gt; for details.&lt;/li&gt;
&lt;li&gt;The local DNS proxy now supports DNSSEC passthrough. DNSSEC-signed responses are forwarded to the application intact (including DO/AD bits and RRSIG records), so applications that validate DNSSEC locally — including resolvers and the dig/drill tooling — work correctly through the client.&lt;/li&gt;
&lt;li&gt;Added a new MDM format for organization-wide settings, including a cleaner way to configure the compliance environment (e.g. FedRAMP). The previous per-configuration approach still works, but the new format is now recommended. See the updated &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/parameters/#organization_configs&quot;&gt;Cloudflare One MDM documentation&lt;/a&gt; for details.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Additional changes and improvements&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Starting with 2026.6.822.0, the client unifies all API requests under the &lt;code&gt;api.devices.cloudflare.com&lt;/code&gt; SNI, where previously both &lt;code&gt;zero-trust-client.cloudflareclient.com&lt;/code&gt; and &lt;code&gt;notifications.cloudflareclient.com&lt;/code&gt; were used. Review &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/firewall/&quot;&gt;Cloudflare One Client with firewall&lt;/a&gt; to ensure systems that rely on SNI inspection do not block the API traffic. The behavior of previous client versions is unaffected.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/connectors/cloudflare-mesh/&quot;&gt;Cloudflare Mesh&lt;/a&gt; functionality using the Cloudflare One Client is now supported on RHEL 9 and 10.&lt;/li&gt;
&lt;li&gt;Cloudflare Mesh now supports &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/connectors/cloudflare-mesh/routes/#hostname-routes&quot;&gt;hostname-based routing&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Client Certificate device-posture checks now support template variables (e.g. &lt;code&gt;${serial_number}&lt;/code&gt;, &lt;code&gt;${device_uuid}&lt;/code&gt;) in the Subject Alternative Name field. Previously only the Common Name field accepted variables, which broke posture rules that pinned identity to a SAN entry.&lt;/li&gt;
&lt;li&gt;Improved accessibility by using high contrast colors and more defined color boundaries when high contrast is enabled in the system display settings.&lt;/li&gt;
&lt;li&gt;Path MTU Discovery (PMTUD) is now enabled by default.&lt;/li&gt;
&lt;li&gt;Fixed the in-client captive-portal browser rendering a blank &amp;quot;Success&amp;quot; page on some airline Wi-Fi networks. The browser now more consistently loads the airline&amp;#39;s real portal page so users can complete sign-in from inside the client instead of having to open a separate browser.&lt;/li&gt;
&lt;li&gt;Fixed an issue in proxy mode where hostnames containing underscores (e.g. ai_app.com) were rejected, breaking apps that depend on such hostnames (notably ChatGPT sandbox apps). The local proxy now accepts underscore-containing hostnames in CONNECT requests.&lt;/li&gt;
&lt;li&gt;Fixed an issue where DNS queries would fail after the connection was idle, requiring users to retry.&lt;/li&gt;
&lt;li&gt;Fixed an issue where some Debian releases experienced inaccurate version reporting for posture checks.&lt;/li&gt;
&lt;li&gt;Users can now register with team names in any case format without errors.&lt;/li&gt;
&lt;li&gt;New UI fixes&lt;ul&gt;
&lt;li&gt;Fixed an issue where users with invalid MDM configurations were returned to the onboarding screen after successful authentication.&lt;/li&gt;
&lt;li&gt;Added a re-auth button and banner to the home screen so users don&amp;#39;t miss it when their session expires.&lt;/li&gt;
&lt;li&gt;Added clear error messaging when the Cloudflare certificate needs to be installed.&lt;/li&gt;
&lt;li&gt;Brought back support for pausing the tunnel when connected to user-specified Wi-Fi networks for consumer users.&lt;/li&gt;
&lt;li&gt;New client UI now surfaces Split tunnel configuration and Local Domain Fallback configuration.&lt;/li&gt;
&lt;li&gt;Added ability to configure proxy mode for consumer users.&lt;/li&gt;
&lt;li&gt;Added back the option to quit for consumer users.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For RHEL deployments, this release introduces a dependency on the &lt;a href=&quot;https://docs.fedoraproject.org/en-US/epel/&quot;&gt;Extra Packages for Enterprise Linux&lt;/a&gt; repository (EPEL). The EPEL repository provides packages that support the captive portal detection’s in-app browser authentication and system tray icon. See &lt;a href=&quot;https://docs.fedoraproject.org/en-US/epel/getting-started/&quot;&gt;Getting started with EPEL&lt;/a&gt; for instructions on enabling EPEL.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Known issues&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Registration may hang at &amp;quot;Checking your organization configuration&amp;quot; due to IPC errors. A system reboot should resolve the error, allowing registration to proceed.&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Mon, 29 Jun 2026 19:21:09 GMT</pubDate><product>Cloudflare One Client</product><category>Cloudflare One Client</category></item><item><title>Cloudflare One, Access - MCP 服务端门户支持 Service token</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-06-26-mcp-portal-service-tokens/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-06-26-mcp-portal-service-tokens/</guid><description>&lt;p&gt;您现在可以使用 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/access-controls/service-credentials/service-tokens/&quot;&gt;Access service token&lt;/a&gt; 将自主 Agent 和机器人连接到 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/access-controls/ai-controls/mcp-portals/&quot;&gt;MCP 服务端门户&lt;/a&gt;。Service token 会话可以通过门户访问上游 MCP 服务端，而无需基于浏览器的 OAuth 流程。&lt;/p&gt;
&lt;p&gt;要进行此设置：&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;将与您的 service token 匹配的 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/access-controls/policies/#service-auth&quot;&gt;Service Auth 策略&lt;/a&gt;添加到门户的 Access 应用程序。&lt;/li&gt;
&lt;li&gt;将与相同 token 匹配的 Service Auth 策略添加到每个关联的 MCP 服务端的 Access 应用程序。&lt;/li&gt;
&lt;li&gt;将每个关联服务端的 **Require user auth（需要用户身份验证）**关闭（&lt;code&gt;on_behalf: false&lt;/code&gt;），以便门户使用管理员凭证，而不是每个用户的 OAuth 授权。&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;机器人使用 &lt;code&gt;CF-Access-Client-Id&lt;/code&gt; 和 &lt;code&gt;CF-Access-Client-Secret&lt;/code&gt; 请求头进行连接，并可以看到其获得授权的每个关联服务端中的工具。仍然需要每个用户 OAuth 的服务端将被排除在 service token 会话之外，因为 service token 无法完成每个用户的 OAuth 授权。&lt;/p&gt;
&lt;p&gt;有关逐步设置，请参阅&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/access-controls/ai-controls/mcp-portals/#connect-with-a-service-token&quot;&gt;使用 service token 进行连接&lt;/a&gt;。&lt;/p&gt;</description><pubDate>Fri, 26 Jun 2026 00:00:00 GMT</pubDate><product>Cloudflare One</product><category>Cloudflare One</category><category>Access</category></item><item><title>Cloudflare One Client - Cloudflare One Client for macOS (version 2026.6.782.1)</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-06-24-warp-macos-beta/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-06-24-warp-macos-beta/</guid><description>&lt;p&gt;A new Beta release for the macOS Cloudflare One Client is now available on the &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/beta-releases/&quot;&gt;beta releases downloads page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This beta release introduces upgraded security of device registration to be hardware-backed. Registration tokens can now be generated in the Secure Enclave whenever available to provide stronger protection against device impersonation.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Additional changes and improvements&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;This release also introduces multiple fixes and improvements including:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Improved accessibility by using high contrast colors and more defined color boundaries when high contrast is enabled in the macOS Display settings.&lt;/li&gt;
&lt;li&gt;Path MTU Discovery (PMTUD) is now enabled by default.&lt;/li&gt;
&lt;li&gt;Fixed an issue where DNS queries would fail after the connection was idle, requiring users to retry.&lt;/li&gt;
&lt;li&gt;Users can now register with team names in any case format without errors.&lt;/li&gt;
&lt;li&gt;New UI fixes&lt;ul&gt;
&lt;li&gt;Fixed an issue where users with invalid MDM configurations were returned to the onboarding screen after successful authentication.&lt;/li&gt;
&lt;li&gt;Added a re-auth button and banner to the home screen so users don&amp;#39;t miss it when their session expires.&lt;/li&gt;
&lt;li&gt;Added clear error messaging when the Cloudflare certificate needs to be installed.&lt;/li&gt;
&lt;li&gt;Brought back support for pausing the tunnel when connected to user-specified Wi-Fi networks for consumer users.&lt;/li&gt;
&lt;li&gt;New client UI now surfaces Split tunnel configuration and Local Domain Fallback configuration.&lt;/li&gt;
&lt;li&gt;Added ability to configure proxy mode for consumer users.&lt;/li&gt;
&lt;li&gt;Added back the option to quit for consumer users.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Known issues&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Registration may hang at &amp;quot;Checking your organization configuration&amp;quot; due to IPC errors. A system reboot should resolve the error, allowing registration to proceed.&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Wed, 24 Jun 2026 18:35:32 GMT</pubDate><product>Cloudflare One Client</product><category>Cloudflare One Client</category></item><item><title>Data Localization Suite - 针对 Regional Services 的 Regionalized IP Bindings</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-06-23-regionalized-ip-bindings/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-06-23-regionalized-ip-bindings/</guid><description>&lt;p&gt;Regional Services 现在支持 &lt;strong&gt;Regionalized IP Bindings&lt;/strong&gt;，让您能够针对通过 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/byoip/&quot;&gt;Bring Your Own IP (BYOIP)&lt;/a&gt; 引入 Cloudflare 的前缀在 IP 层实现流量区域化。&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://cloudflaredoc.ubitools.com/data-localization/regional-services/regional-hostnames/&quot;&gt;Regional Hostnames&lt;/a&gt; 是按主机名对流量进行区域化，而 Regionalized IP Bindings 允许您将来自前缀之一的 CIDR 绑定（binding）到某个区域 —— 这非常适合地址映射部署以及任何您通过 IP 而非主机名寻址的服务。然后，Cloudflare 会在 TLS 终止后，仅在该区域的数据中心内处理发往这些地址的流量。&lt;/p&gt;
&lt;p&gt;Regionalized IP Bindings 需要 Regional Services 和 Regional Services for BYOIP 的授权。请联系您的账户团队以启用它们。&lt;/p&gt;
&lt;p&gt;要开始使用，请参阅 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/data-localization/regional-services/ip-bindings/&quot;&gt;Regionalized IP Bindings&lt;/a&gt;。&lt;/p&gt;</description><pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate><product>Data Localization Suite</product><category>Data Localization Suite</category></item><item><title>Cloudflare Mesh, Cloudflare Tunnel, Cloudflare WAN, Cloudflare One - 在仪表板中通过单页面管理您的所有路由</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-06-19-unified-routes-page/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-06-19-unified-routes-page/</guid><description>
&lt;p&gt;Cloudflare 仪表板中的 **Routes（路由）**页面现在在单个表格中显示您所有连接器的路由——包括 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/connectors/cloudflare-mesh/&quot;&gt;Cloudflare Mesh&lt;/a&gt; 和 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/tunnel/&quot;&gt;Cloudflare Tunnel&lt;/a&gt; 路由，以及 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-wan/&quot;&gt;Cloudflare WAN&lt;/a&gt; 和 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/magic-transit/&quot;&gt;Magic Transit&lt;/a&gt; 静态路由，而不是每个产品分别显示独立的路由视图。&lt;/p&gt;
&lt;img src=&quot;https://cloudflaredoc.ubitools.com/_astro/2026-06-19-unified-routes.B3igBY20_Z1awHp.webp&quot; alt=&quot;Cloudflare 仪表板中统一的 Routes 页面，在单个表格中显示各个连接器的路由&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1800&quot; height=&quot;948&quot;&gt;
&lt;p&gt;在统一的 Routes 页面中，您可以：&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;通过交互式地图可视化您的网络&lt;/strong&gt;，该地图显示了您的目的地如何流向您的连接器——包括由多个连接器提供相同前缀服务的等价多路径（ECMP）路由。选择一个节点以过滤表格以显示其后面的路由。&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;在单个表格中查看每条路由&lt;/strong&gt;，及其目的地、类型、连接器、优先级和来源，并进行过滤或排序以找到您需要的内容。&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;创建、编辑和删除路由&lt;/strong&gt;（支持任何受支持的类型），而无需离开页面。添加 Cloudflare WAN 或 Magic Transit 静态路由时，您现在可以通过&lt;strong&gt;连接器名称&lt;/strong&gt;选择下一跳，而无需输入其 IP。&lt;/li&gt;
&lt;li&gt;在专用选项卡中&lt;strong&gt;管理&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/virtual-networks/&quot;&gt;虚拟网络&lt;/a&gt;&lt;/strong&gt;。&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;测试路由&lt;/strong&gt;，以便在提交更改之前查看目的地解析为哪个连接器和下一跳。&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;要找到它，请前往仪表板侧边栏中的 &lt;strong&gt;Networking（网络）&lt;/strong&gt; &amp;gt; &lt;strong&gt;Routes（路由）&lt;/strong&gt;。&lt;/p&gt;
&lt;a href=&quot;https://dash.cloudflare.com/?to=/:account/magic-networks/routes&quot; data-nb-button class=&quot;group inline-flex w-max shrink-0 items-center justify-center rounded-full font-medium whitespace-nowrap no-underline shadow-xs transition-colors cursor-pointer select-none focus-visible:outline-2 focus-visible:outline-ring focus-visible:outline-offset-2 disabled:cursor-not-allowed disabled:opacity-50 bg-primary text-primary-foreground hover:bg-primary-hover h-9 gap-1.5 px-3 text-sm&quot; target=&quot;_blank&quot;&gt;Go to &lt;strong&gt;Routes&lt;/strong&gt;&amp;nbsp;&amp;#8599;&lt;/a&gt;
&lt;p&gt;您现有的路由、API 和配置保持不变——这是一个将它们聚集在一个地方的仪表板体验。了解如何&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/routes/add-routes/&quot;&gt;添加路由&lt;/a&gt;和&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/virtual-networks/&quot;&gt;管理虚拟网络&lt;/a&gt;。&lt;/p&gt;</description><pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate><product>Cloudflare Mesh</product><category>Cloudflare Mesh</category><category>Cloudflare Tunnel</category><category>Cloudflare WAN</category><category>Cloudflare One</category></item><item><title>Cloudflare One, Access - Cloudflare 身份提供商现在是新账户的默认选择</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-06-18-cloudflare-idp-default/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-06-18-cloudflare-idp-default/</guid><description>&lt;p&gt;当您创建新的 Zero Trust 组织时，Cloudflare 现在会将 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/integrations/identity-providers/cloudflare/&quot;&gt;Cloudflare 身份提供商&lt;/a&gt;添加为您的默认登录方式。先前，新的组织会以 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/integrations/identity-providers/one-time-pin/&quot;&gt;一次性 PIN 码 (OTP)&lt;/a&gt; 开始。&lt;/p&gt;
&lt;p&gt;使用 Cloudflare 身份提供商，您的用户将使用其现有的 Cloudflare 账户凭证进行身份验证，并且身份验证仅限于您账户的成员。您仍然可以在需要时随时添加 OTP 或连接任何&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/integrations/identity-providers/&quot;&gt;第三方身份提供商&lt;/a&gt;。&lt;/p&gt;
&lt;p&gt;此更改仅适用于新创建的账户。现有组织将保留其已配置的登录方式。如果您想在现有账户中使用 Cloudflare 身份提供商，则必须将其启用。&lt;/p&gt;</description><pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate><product>Cloudflare One</product><category>Cloudflare One</category><category>Access</category></item><item><title>Data Loss Prevention - 为 AI 提示词保护定义自定义主题</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-06-11-custom-ai-prompt-topics/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-06-11-custom-ai-prompt-topics/</guid><description>&lt;p&gt;您现在可以为 AI 提示词保护定义自定义主题。预定义的 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/data-loss-prevention/detection-entries/configure-detection-entries/#ai-prompt-topics&quot;&gt;AI 提示词主题&lt;/a&gt;涵盖了常见的生命周期和意图类别，例如 PII、源代码和越狱（jailbreak）尝试。自定义主题允许您检测未包含在预定义类别中的独特或专有概念。&lt;/p&gt;
&lt;p&gt;您用自然语言描述一个自定义主题，Cloudflare DLP 会根据上下文（而非特定关键字）检测提示词是否与该主题匹配。例如，描述机密合并讨论的主题会与对该交易进行释义的提示词相匹配，即使该提示词从未包含“合并”一词或涉及的公司名称。要检测诸如内部代号或产品标识符之类的字面值，请改用&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/data-loss-prevention/detection-entries/configure-detection-entries/#custom-wordlist-datasets&quot;&gt;自定义单词列表或模式条目&lt;/a&gt;。&lt;/p&gt;
&lt;p&gt;自定义主题与预定义的 AI 提示词主题运行相同的&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/http-policies/#granular-controls&quot;&gt;应用程序精细控制&lt;/a&gt;路径。自定义主题适用于 ChatGPT、Google Gemini、Perplexity 和 Claude。&lt;/p&gt;
&lt;div tabindex=&quot;-1&quot; class=&quot;heading-wrapper level-h4&quot;&gt;&lt;h4 id=&quot;创建自定义-ai-提示词主题&quot;&gt;创建自定义 AI 提示词主题&lt;/h4&gt;&lt;a class=&quot;anchor-link&quot; href=&quot;#创建自定义-ai-提示词主题&quot;&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;anchor-icon&quot;&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 24 24&quot;&gt;&lt;path fill=&quot;currentcolor&quot; d=&quot;m12.11 15.39-3.88 3.88a2.52 2.52 0 0 1-3.5 0 2.47 2.47 0 0 1 0-3.5l3.88-3.88a1 1 0 0 0-1.42-1.42l-3.88 3.89a4.48 4.48 0 0 0 6.33 6.33l3.89-3.88a1 1 0 1 0-1.42-1.42Zm8.58-12.08a4.49 4.49 0 0 0-6.33 0l-3.89 3.88a1 1 0 0 0 1.42 1.42l3.88-3.88a2.52 2.52 0 0 1 3.5 0 2.47 2.47 0 0 1 0 3.5l-3.88 3.88a1 1 0 1 0 1.42 1.42l3.88-3.89a4.49 4.49 0 0 0 0-6.33ZM8.83 15.17a1 1 0 0 0 1.1.22 1 1 0 0 0 .32-.22l4.92-4.92a1 1 0 0 0-1.42-1.42l-4.92 4.92a1 1 0 0 0 0 1.42Z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;ol&gt;
&lt;li&gt;在 &lt;a href=&quot;https://dash.cloudflare.com/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Cloudflare 仪表板&lt;span class=&quot;external-link&quot;&gt; ↗&lt;/span&gt;&lt;/a&gt;中，转到 &lt;strong&gt;Zero Trust&lt;/strong&gt; &amp;gt; &lt;strong&gt;Data loss prevention（数据防泄露）&lt;/strong&gt; &amp;gt; &lt;strong&gt;Detection entries（检测条目）&lt;/strong&gt;。&lt;/li&gt;
&lt;li&gt;选择 &lt;strong&gt;AI prompt topics（AI 提示词主题）&lt;/strong&gt;，然后选择 &lt;strong&gt;Custom Prompt Topic（自定义提示词主题）&lt;/strong&gt;。&lt;/li&gt;
&lt;li&gt;用自然语言描述主题。具体说明您想要检测的概念。例如，描述未发布的产品路线图细节或机密的客户合同条款。&lt;/li&gt;
&lt;li&gt;将此检测条目添加到现有的 DLP 配置文件中，或&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/data-loss-prevention/dlp-profiles/#build-a-custom-profile&quot;&gt;创建一个新的 DLP 配置文件&lt;/a&gt;。&lt;/li&gt;
&lt;li&gt;在 Gateway HTTP 策略中使用该配置文件，以记录或阻断与该主题相匹配的提示词。&lt;/li&gt;
&lt;/ol&gt;
&lt;aside role=&quot;note&quot; aria-label=&quot;说明&quot; class=&quot;aside-card flex items-start gap-3 rounded-lg px-4 py-3 my-4&quot; style=&quot;--_c: var(--nb-info); --_t: var(--nb-info-muted);&quot; data-astro-cid-znle5jil&gt;&lt;span class=&quot;flex h-[1.375em] shrink-0 items-center&quot; aria-hidden=&quot;true&quot; data-astro-cid-znle5jil&gt;&lt;svg width=&quot;1em&quot; height=&quot;1em&quot; class=&quot;h-[1em] w-[1em]&quot; data-astro-cid-znle5jil=&quot;true&quot; data-icon=&quot;ph:info&quot;&gt;&lt;symbol id=&quot;ai:ph:info&quot; viewBox=&quot;0 0 256 256&quot;&gt;&lt;path fill=&quot;currentColor&quot; d=&quot;M128 24a104 104 0 1 0 104 104A104.11 104.11 0 0 0 128 24m0 192a88 88 0 1 1 88-88a88.1 88.1 0 0 1-88 88m16-40a8 8 0 0 1-8 8a16 16 0 0 1-16-16v-40a8 8 0 0 1 0-16a16 16 0 0 1 16 16v40a8 8 0 0 1 8 8m-32-92a12 12 0 1 1 12 12a12 12 0 0 1-12-12&quot;/&gt;&lt;/symbol&gt;&lt;use href=&quot;#ai:ph:info&quot;&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/span&gt;&lt;div class=&quot;flex min-w-0 flex-1 flex-col gap-0.5&quot; data-astro-cid-znle5jil&gt;&lt;p class=&quot;m-0 text-base leading-snug font-semibold&quot; data-astro-cid-znle5jil&gt;说明&lt;/p&gt;&lt;div class=&quot;aside-card-body text-sm leading-normal&quot; data-astro-cid-znle5jil&gt;&lt;p&gt;将描述写成一个要分类的概念，而不是关键字列表。例如，描述“内部财务预测和未发布的收入数字”，而不是列出特定的文档名称。&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/aside&gt;
&lt;p&gt;有关更多详细信息，请参阅 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/data-loss-prevention/detection-entries/configure-detection-entries/#ai-prompt-topics&quot;&gt;AI prompt topics&lt;/a&gt;。&lt;/p&gt;</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate><product>Data Loss Prevention</product><category>Data Loss Prevention</category></item><item><title>Gateway, Cloudflare Mesh, Workers VPC - 使用 Gateway 策略过滤 Workers 的公共互联网流量</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-06-05-gateway-egress/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-06-05-gateway-egress/</guid><description>
&lt;p&gt;使用 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/workers-vpc/configuration/vpc-networks/&quot;&gt;VPC 网络（VPC Network）&lt;/a&gt; 绑定（binding）与 &lt;code&gt;network_id: &quot;cf1:network&quot;&lt;/code&gt; 的 Workers 现在可以通过 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/&quot;&gt;Cloudflare Gateway&lt;/a&gt; 出口到公共互联网目标。这意味着您现有的 Zero Trust 流量策略 —— DNS、HTTP、网络和出口（egress）—— 将延伸到源自您的 Workers 的流量，就像今天对 WARP 用户所做的那样。&lt;/p&gt;
&lt;figure class=&quot;vpc-egress-diagram not-content&quot; aria-label=&quot;Workers VPC public Internet egress through Cloudflare Mesh and Cloudflare Gateway&quot; data-astro-cid-lmo6yva7&gt;&lt;ol class=&quot;flow&quot; data-astro-cid-lmo6yva7&gt;&lt;li class=&quot;flow-step&quot; data-astro-cid-lmo6yva7&gt;&lt;div class=&quot;node-card worker-card&quot; data-astro-cid-lmo6yva7&gt;&lt;div class=&quot;node-header&quot; data-astro-cid-lmo6yva7&gt;&lt;span class=&quot;node-icon worker-icon&quot; aria-hidden=&quot;true&quot; data-astro-cid-lmo6yva7&gt;&lt;svg width=&quot;0.98em&quot; height=&quot;1em&quot; data-astro-cid-lmo6yva7=&quot;true&quot; data-icon=&quot;workers&quot;&gt;&lt;symbol id=&quot;ai:local:workers&quot; viewBox=&quot;0 0 48 49&quot;&gt;&lt;path fill=&quot;currentColor&quot; d=&quot;m18.63 37.418-9.645-12.9 9.592-12.533-1.852-2.527L5.917 23.595l-.015 1.808 10.86 14.542z&quot;/&gt;&lt;path fill=&quot;currentColor&quot; d=&quot;M21.997 6.503h-3.712l13.387 18.3-13.072 17.7h3.735L35.4 24.81z&quot;/&gt;&lt;path fill=&quot;currentColor&quot; d=&quot;M29.175 6.503h-3.758l13.598 18.082-13.598 17.918h3.765l12.908-17.01v-1.808z&quot;/&gt;&lt;/symbol&gt;&lt;use href=&quot;#ai:local:workers&quot;&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/span&gt;&lt;a class=&quot;node-title&quot; href=&quot;https://cloudflaredoc.ubitools.com/workers/&quot; data-astro-cid-lmo6yva7&gt;Worker&lt;/a&gt;&lt;/div&gt;&lt;p class=&quot;node-caption&quot; data-astro-cid-lmo6yva7&gt;Calls &lt;code data-astro-cid-lmo6yva7&gt;env.EGRESS.fetch()&lt;/code&gt;&lt;/p&gt;&lt;/div&gt;&lt;/li&gt;&lt;li class=&quot;flow-connector&quot; data-astro-cid-lmo6yva7&gt;&lt;a class=&quot;connector-label&quot; href=&quot;https://cloudflaredoc.ubitools.com/workers-vpc/&quot; data-astro-cid-lmo6yva7&gt;VPC binding&lt;/a&gt;&lt;span class=&quot;connector-arrow&quot; aria-hidden=&quot;true&quot; data-astro-cid-lmo6yva7&gt;↓&lt;/span&gt;&lt;/li&gt;&lt;li class=&quot;flow-step&quot; data-astro-cid-lmo6yva7&gt;&lt;div class=&quot;node-card mesh-card&quot; data-astro-cid-lmo6yva7&gt;&lt;div class=&quot;node-header&quot; data-astro-cid-lmo6yva7&gt;&lt;span class=&quot;node-icon mesh-icon&quot; aria-hidden=&quot;true&quot; data-astro-cid-lmo6yva7&gt;&lt;svg width=&quot;1em&quot; height=&quot;1em&quot; data-astro-cid-lmo6yva7=&quot;true&quot; data-icon=&quot;cloudflare-mesh&quot;&gt;&lt;symbol id=&quot;ai:local:cloudflare-mesh&quot; viewBox=&quot;0 0 32 32&quot;&gt;&lt;path fill=&quot;currentColor&quot; d=&quot;M10 6a2 2 0 1 1-4 0 2 2 0 0 1 4 0m6-2a2 2 0 1 0 0 4 2 2 0 0 0 0-4m8 4a2 2 0 1 0 0-4 2 2 0 0 0 0 4M8 11a2 2 0 1 0 0 4 2 2 0 0 0 0-4m8 0a2 2 0 1 0 0 4 2 2 0 0 0 0-4m8 0a2 2 0 1 0 0 4 2 2 0 0 0 0-4M8 18a2 2 0 1 0 0 4 2 2 0 0 0 0-4m8 0a2 2 0 1 0 0 4 2 2 0 0 0 0-4m0 7a2 2 0 1 0 0 4 2 2 0 0 0 0-4m8-7a2 2 0 1 0 0 4 2 2 0 0 0 0-4&quot;/&gt;&lt;/symbol&gt;&lt;use href=&quot;#ai:local:cloudflare-mesh&quot;&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/span&gt;&lt;a class=&quot;node-title&quot; href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/connectors/cloudflare-mesh/&quot; data-astro-cid-lmo6yva7&gt;Cloudflare Mesh&lt;/a&gt;&lt;/div&gt;&lt;p class=&quot;node-caption&quot; data-astro-cid-lmo6yva7&gt;Bind via &lt;a class=&quot;inline-pill mesh-pill&quot; href=&quot;https://cloudflaredoc.ubitools.com/workers-vpc/configuration/vpc-networks/&quot; data-astro-cid-lmo6yva7&gt;&lt;code data-astro-cid-lmo6yva7&gt;cf1:network&lt;/code&gt;&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;&lt;/li&gt;&lt;li class=&quot;flow-connector&quot; aria-hidden=&quot;true&quot; data-astro-cid-lmo6yva7&gt;&lt;span class=&quot;connector-arrow&quot; data-astro-cid-lmo6yva7&gt;↓&lt;/span&gt;&lt;/li&gt;&lt;li class=&quot;flow-step&quot; data-astro-cid-lmo6yva7&gt;&lt;div class=&quot;node-card gateway-card&quot; data-astro-cid-lmo6yva7&gt;&lt;div class=&quot;node-header&quot; data-astro-cid-lmo6yva7&gt;&lt;span class=&quot;node-icon gateway-icon&quot; aria-hidden=&quot;true&quot; data-astro-cid-lmo6yva7&gt;&lt;svg width=&quot;1em&quot; height=&quot;1em&quot; data-astro-cid-lmo6yva7=&quot;true&quot; data-icon=&quot;gateway&quot;&gt;&lt;symbol id=&quot;ai:local:gateway&quot; viewBox=&quot;0 0 16 16&quot;&gt;&lt;path fill=&quot;currentColor&quot; d=&quot;M15.45 7.125h-2.577V3.508l-.41-.408H3.925l-.41.41v3.08h.922V4.023h7.513v7.555H4.438v-1.553h-.923v2.065l.41.41h8.538l.41-.41V8.048H16z&quot;/&gt;&lt;path fill=&quot;currentColor&quot; d=&quot;M8.453 7.238H0l.517.87H8.97zM9.21 8.51H.755l.517.868h8.453z&quot;/&gt;&lt;/symbol&gt;&lt;use href=&quot;#ai:local:gateway&quot;&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/span&gt;&lt;a class=&quot;node-title&quot; href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/&quot; data-astro-cid-lmo6yva7&gt;Cloudflare Gateway&lt;/a&gt;&lt;/div&gt;&lt;p class=&quot;node-caption&quot; data-astro-cid-lmo6yva7&gt;Policies applied:&lt;/p&gt;&lt;div class=&quot;pill-row&quot; data-astro-cid-lmo6yva7&gt;&lt;a class=&quot;policy-pill&quot; href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/dns-policies/&quot; data-astro-cid-lmo6yva7&gt;DNS&lt;/a&gt;&lt;a class=&quot;policy-pill&quot; href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/http-policies/&quot; data-astro-cid-lmo6yva7&gt;HTTP&lt;/a&gt;&lt;a class=&quot;policy-pill&quot; href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/network-policies/&quot; data-astro-cid-lmo6yva7&gt;Network&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/li&gt;&lt;li class=&quot;flow-connector&quot; aria-hidden=&quot;true&quot; data-astro-cid-lmo6yva7&gt;&lt;span class=&quot;connector-arrow&quot; data-astro-cid-lmo6yva7&gt;↓&lt;/span&gt;&lt;/li&gt;&lt;li class=&quot;flow-step&quot; data-astro-cid-lmo6yva7&gt;&lt;div class=&quot;node-card internet-card&quot; data-astro-cid-lmo6yva7&gt;&lt;div class=&quot;node-header&quot; data-astro-cid-lmo6yva7&gt;&lt;span class=&quot;node-icon internet-icon&quot; aria-hidden=&quot;true&quot; data-astro-cid-lmo6yva7&gt;↗&lt;/span&gt;&lt;span class=&quot;node-title&quot; data-astro-cid-lmo6yva7&gt;Public Internet&lt;/span&gt;&lt;/div&gt;&lt;p class=&quot;node-caption&quot; data-astro-cid-lmo6yva7&gt;Any public hostname or IP&lt;/p&gt;&lt;/div&gt;&lt;/li&gt;&lt;/ol&gt;&lt;a class=&quot;logs-card&quot; href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/insights/logs/dashboard-logs/gateway-logs/&quot; aria-label=&quot;Gateway logs&quot; data-astro-cid-lmo6yva7&gt;&lt;span class=&quot;logs-title&quot; data-astro-cid-lmo6yva7&gt;Gateway logs&lt;/span&gt;&lt;span class=&quot;logs-pills&quot; data-astro-cid-lmo6yva7&gt;&lt;span class=&quot;logs-pill&quot; data-astro-cid-lmo6yva7&gt;DNS&lt;/span&gt;&lt;span class=&quot;logs-pill&quot; data-astro-cid-lmo6yva7&gt;HTTP&lt;/span&gt;&lt;span class=&quot;logs-pill&quot; data-astro-cid-lmo6yva7&gt;Network&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/figure&gt;
&lt;p&gt;您默认获得的内容：&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;可见性。&lt;/strong&gt; Worker 出口流量与您的其他流量一起显示在 Gateway &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/dns-policies/&quot;&gt;DNS&lt;/a&gt;、&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/http-policies/&quot;&gt;HTTP&lt;/a&gt; 和 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/network-policies/&quot;&gt;网络&lt;/a&gt; 日志中，以便您可以审计您的 Workers 在何时调用了什么。&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;强制执行。&lt;/strong&gt; 任何其选择器与 Worker 请求相匹配的现有 Gateway 策略都将适用 —— 包括允许/阻止列表、DNS 类别过滤和 HTTP 目标规则。如果您已经为您的员工屏蔽了某个类别，您的 Workers 将继承该屏蔽。&lt;/li&gt;
&lt;/ul&gt;
&lt;div data-nb-tabs data-nb-sync-key=&quot;wranglerConfig&quot; class&gt;&lt;div class=&quot;relative flex border-b border-border&quot; role=&quot;tablist&quot; data-nb-tabs-list&gt;&lt;span class=&quot;bg-primary pointer-events-none absolute -bottom-px h-0.5 rounded-t-sm transition-[left,width] duration-200 ease-out&quot; data-nb-tabs-indicator aria-hidden=&quot;true&quot;&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;mt-3&quot;&gt;&lt;div role=&quot;tabpanel&quot; data-nb-tabs-content data-nb-tab-label=&quot;wrangler.jsonc&quot; class&gt;&lt;figure class=&quot;nb-code-figure&quot; data-nb-lang=&quot;jsonc&quot;&gt;&lt;pre class=&quot;astro-code astro-code-themes github-light github-dark nb-shiki-c6xiwz&quot; tabindex=&quot;0&quot; data-language=&quot;jsonc&quot; data-nb-lang=&quot;jsonc&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;{&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt;	&quot;vpc_networks&quot;&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;: [&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;		{&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt;			&quot;binding&quot;&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;: &lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt;&quot;EGRESS&quot;&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;,&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt;			&quot;network_id&quot;&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;: &lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt;&quot;cf1:network&quot;&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;,&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt;			&quot;remote&quot;&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;: &lt;/span&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt;true&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;,&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;		},&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;	],&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;}&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;&lt;/div&gt;&lt;div role=&quot;tabpanel&quot; data-nb-tabs-content data-nb-tab-label=&quot;wrangler.toml&quot; class&gt;&lt;figure class=&quot;nb-code-figure&quot; data-nb-lang=&quot;toml&quot;&gt;&lt;pre class=&quot;astro-code astro-code-themes github-light github-dark nb-shiki-c6xiwz&quot; tabindex=&quot;0&quot; data-language=&quot;toml&quot; data-nb-lang=&quot;toml&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;[[&lt;/span&gt;&lt;span class=&quot;nb-shiki-1t8gfj&quot;&gt;vpc_networks&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;]]&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;binding = &lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt;&quot;EGRESS&quot;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;network_id = &lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt;&quot;cf1:network&quot;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;remote = &lt;/span&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt;true&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;script type=&quot;module&quot; src=&quot;https://cloudflaredoc.ubitools.com/Users/jt.gui/workspace/astro/cloudflare-docs/src/components/ui/tabs/Tabs.astro?astro&amp;type=script&amp;index=0&amp;lang.ts&quot;&gt;&lt;/script&gt;&lt;div&gt;&lt;div data-nb-tabs data-nb-sync-key=&quot;workersExamples&quot; class&gt;&lt;div class=&quot;relative flex border-b border-border&quot; role=&quot;tablist&quot; data-nb-tabs-list&gt;&lt;span class=&quot;bg-primary pointer-events-none absolute -bottom-px h-0.5 rounded-t-sm transition-[left,width] duration-200 ease-out&quot; data-nb-tabs-indicator aria-hidden=&quot;true&quot;&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;mt-3&quot;&gt;&lt;div role=&quot;tabpanel&quot; data-nb-tabs-content data-nb-tab-label=&quot;JavaScript&quot; class&gt;&lt;figure class=&quot;nb-code-figure&quot; data-nb-lang=&quot;js&quot;&gt;&lt;pre class=&quot;astro-code astro-code-themes github-light github-dark nb-shiki-c6xiwz&quot; tabindex=&quot;0&quot; data-language=&quot;js&quot; data-nb-lang=&quot;js&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-21nrsd&quot;&gt;// Egress to a public destination — subject to your Gateway policies and logged&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-1itgoe&quot;&gt;const&lt;/span&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt; response&lt;/span&gt;&lt;span class=&quot;nb-shiki-1itgoe&quot;&gt; =&lt;/span&gt;&lt;span class=&quot;nb-shiki-1itgoe&quot;&gt; await&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt; env.&lt;/span&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt;EGRESS&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nb-shiki-1t8gfj&quot;&gt;fetch&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt;&quot;https://api.example.com/data&quot;&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;);&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;&lt;/div&gt;&lt;div role=&quot;tabpanel&quot; data-nb-tabs-content data-nb-tab-label=&quot;TypeScript&quot; class&gt;&lt;figure class=&quot;nb-code-figure&quot; data-nb-lang=&quot;ts&quot;&gt;&lt;pre class=&quot;astro-code astro-code-themes github-light github-dark nb-shiki-c6xiwz&quot; tabindex=&quot;0&quot; data-language=&quot;ts&quot; data-nb-lang=&quot;ts&quot;&gt;&lt;code&gt;&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-21nrsd&quot;&gt;// Egress to a public destination — subject to your Gateway policies and logged&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;line&quot;&gt;&lt;span class=&quot;nb-shiki-1itgoe&quot;&gt;const&lt;/span&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt; response&lt;/span&gt;&lt;span class=&quot;nb-shiki-1itgoe&quot;&gt; =&lt;/span&gt;&lt;span class=&quot;nb-shiki-1itgoe&quot;&gt; await&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt; env.&lt;/span&gt;&lt;span class=&quot;nb-shiki-dzsirb&quot;&gt;EGRESS&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;nb-shiki-1t8gfj&quot;&gt;fetch&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;nb-shiki-mdbnqw&quot;&gt;&quot;https://api.example.com/data&quot;&lt;/span&gt;&lt;span class=&quot;nb-shiki-140thh&quot;&gt;);&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/figure&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;
&lt;p&gt;有关配置选项，请参阅 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/workers-vpc/configuration/vpc-networks/&quot;&gt;VPC 网络（VPC Networks）&lt;/a&gt;。有关策略编写，请参阅 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/&quot;&gt;Cloudflare Gateway 流量策略&lt;/a&gt;。&lt;/p&gt;</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><product>Gateway</product><category>Gateway</category><category>Cloudflare Mesh</category><category>Workers VPC</category></item><item><title>Access - 通过 IdP 联合跨账户共享身份提供商</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-06-04-idp-federation/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-06-04-idp-federation/</guid><description>&lt;p&gt;Cloudflare Access 现在支持 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/integrations/identity-providers/idp-federation/&quot;&gt;IdP 联合&lt;/a&gt;，这允许组织在多个 Cloudflare 账户之间共享单个身份提供商。&lt;/p&gt;
&lt;p&gt;无需在每个账户中分别配置相同的 IdP（例如 Okta 或 Entra ID），您只需在源账户中配置一次，然后与组织中的其他账户共享它。每个接收方账户都会获得一个只读的 IdP 连接，该连接通过一个桥接（bridge）—— 源账户中一个代理跨账户登录的隐藏应用程序 —— 将身份验证路由回源账户。最终用户使用其现有的 IdP 凭据登录，而每个账户的 Access 策略评估生成的身份就和任何其他 IdP 登录一样。&lt;/p&gt;
&lt;p&gt;关键功能：&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;一个 IdP，多个账户&lt;/strong&gt; — 配置一次您的 IdP，并将其共享给您组织中的所有账户。&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;生命周期管理&lt;/strong&gt; — 随着账户加入或离开您的 Cloudflare 组织，它们的 IdP 连接会自动预配和删除 —— 无需手动清理。&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;不可变的接收方连接&lt;/strong&gt; — 接收方账户中的 IdP 连接不能被意外修改或删除。&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;要开始使用，请参阅 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/integrations/identity-providers/idp-federation/&quot;&gt;IdP 联合&lt;/a&gt;。&lt;/p&gt;</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate><product>Access</product><category>Access</category></item><item><title>Access - 身份提供商的 SAML 断言加密</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-06-03-saml-assertion-encryption/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-06-03-saml-assertion-encryption/</guid><description>&lt;p&gt;Cloudflare Access 现在支持身份提供商集成的 SAML 断言（assertion）加密。开启后，您的身份提供商会在通过用户浏览器发送 SAML 断言之前，使用 Cloudflare 管理的证书对其进行加密。只有 Access 可以解密这些断言，从而在 TLS 终止后也能保护敏感的身份数据。&lt;/p&gt;
&lt;p&gt;如果没有加密，SAML 断言将以明文传输，并且可能会被浏览器扩展或客户端恶意软件看到。&lt;/p&gt;
&lt;img src=&quot;https://cloudflaredoc.ubitools.com/_astro/saml-encryption.J5jmiYv8_ZkhXFT.webp&quot; alt=&quot;身份提供商配置中的 SAML 加密切换开关&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1698&quot; height=&quot;344&quot;&gt;
&lt;p&gt;SAML 加密包括内置的证书生命周期管理：&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;自动生成证书&lt;/strong&gt;：当您为身份提供商开启 SAML 加密时，Access 会生成一个加密证书。&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;证书轮换&lt;/strong&gt;：无停机轮换证书。之前的证书在过期前保持有效，为您留出时间来更新 IdP。&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;PEM 导出&lt;/strong&gt;：复制 PEM 格式的证书以便手动上传到您的 IdP，或者将您的 IdP 指向 SAML 元数据端点以进行自动检索。&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;要开始使用，请参阅&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/integrations/identity-providers/generic-saml/#encrypt-saml-assertions&quot;&gt;加密 SAML 断言&lt;/a&gt;。&lt;/p&gt;</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><product>Access</product><category>Access</category></item><item><title>Cloudflare WAN, Cloudflare One - Cisco IOS XE</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-06-02-cisco-ios-xe/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-06-02-cisco-ios-xe/</guid><description>&lt;p&gt;用于 Cloudflare WAN 的 Cisco IOS XE 第三方集成指南已更新，包含以下内容：&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;后量子密码学 (PQC)&lt;/li&gt;
&lt;li&gt;策略路由 (PBR)&lt;/li&gt;
&lt;li&gt;IP 服务水平协议 (IP SLA)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;此链接将直接带您进入已更新的 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-wan/configuration/third-party/cisco-ios-xe/&quot;&gt;Cisco IOS XE&lt;/a&gt; 指南。&lt;/p&gt;</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><product>Cloudflare WAN</product><category>Cloudflare WAN</category><category>Cloudflare One</category></item><item><title>Cloudflare One Client - Cloudflare One Client for macOS (version 2026.5.1155.1)</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-05-29-warp-macos-beta/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-05-29-warp-macos-beta/</guid><description>&lt;p&gt;A new Beta release for the macOS Cloudflare One Client is now available on the &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/beta-releases/&quot;&gt;beta releases downloads page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This release introduces the new Cloudflare One Client UI for macOS! You can expect a cleaner and more intuitive design as well as easier access to common actions and information. Here are some of the many things we have found our users appreciate:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Right click context menu to access the most common client actions quickly&lt;/li&gt;
&lt;li&gt;Built-in captive portal login experience&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Additional Changes and improvements&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The client now applies DNS search suffixes configured in your &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-profiles&quot;&gt;device profile&lt;/a&gt; / &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/network-policies&quot;&gt;network policy&lt;/a&gt;. Administrators can push a list of DNS search domains that the client appends to single-label queries, alongside any system-configured suffixes. See &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/#dns-search-suffixes&quot;&gt;DNS search suffixes&lt;/a&gt; for details.&lt;/li&gt;
&lt;li&gt;Administrators can now control which virtual networks (VNETs) are available to which users via WARP device profile settings in the Zero Trust dashboard. Previously, every VNET in the organization was visible to every device; you can now scope the VNET picker per profile so users only see the networks relevant to them. See &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/#vnet-availability&quot;&gt;VNET availability&lt;/a&gt; for details.&lt;/li&gt;
&lt;li&gt;Added a local-file signal source for Emergency Disconnect. In addition to the existing HTTPS polling mechanism, administrators can now configure WARP to monitor for a file on disk; the presence of the file triggers an emergency disconnect even if both Cloudflare and your own infrastructure are unreachable. Either signal being asserted triggers disconnect; both must be cleared for normal operation to resume.&lt;/li&gt;
&lt;li&gt;Added new warp-cli debug commands for interactive connection diagnosis. See &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/diagnostic-logs/#extra-debug-logging&quot;&gt;Extra debug logging&lt;/a&gt; for details.&lt;/li&gt;
&lt;li&gt;The local DNS proxy now supports DNSSEC passthrough. DNSSEC-signed responses are forwarded to the application intact (including DO/AD bits and RRSIG records), so applications that validate DNSSEC locally — including resolvers and the dig/drill tooling — work correctly through the client.&lt;/li&gt;
&lt;li&gt;Added a new MDM format for organization-wide settings, including a cleaner way to configure the compliance environment (e.g. FedRAMP). The previous per-configuration approach still works, but the new format is now recommended. See the updated &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/parameters/#organization_configs&quot;&gt;Cloudflare One MDM documentation&lt;/a&gt; for details.&lt;/li&gt;
&lt;li&gt;Client Certificate device-posture checks now support template variables (e.g. &lt;code&gt;${serial_number}&lt;/code&gt;, &lt;code&gt;${device_uuid}&lt;/code&gt;) in the Subject Alternative Name field, matching what the documentation has always claimed. Previously only the Common Name field accepted variables, which broke posture rules that pinned identity to a SAN entry.&lt;/li&gt;
&lt;li&gt;Fixed the in-client captive-portal browser rendering a blank &amp;quot;Success&amp;quot; page on some airline Wi-Fi networks (United inflight Wi-Fi was the reported case). The browser now reliably loads the airline&amp;#39;s real portal page so users can complete sign-in from inside the client instead of having to open a separate browser.&lt;/li&gt;
&lt;li&gt;Fixed an issue in proxy mode where hostnames containing underscores (e.g. ai_app.com) were rejected, breaking apps that depend on such hostnames (notably ChatGPT sandbox apps). The local proxy now accepts underscore-containing hostnames in CONNECT requests.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Known issues&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Registration may hang at &amp;quot;Checking your organization configuration&amp;quot; due to IPC errors. A system reboot should resolve the error, allowing registration to proceed.&lt;/li&gt;
&lt;li&gt;Split tunnel list configuration is not available in the new UI. Management of split tunnel entries is currently only possible via &lt;code&gt;warp-cli tunnel ip&lt;/code&gt; and &lt;code&gt;warp-cli tunnel host&lt;/code&gt;. UI support will be added in a future release.&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Fri, 29 May 2026 00:55:38 GMT</pubDate><product>Cloudflare One Client</product><category>Cloudflare One Client</category></item><item><title>Cloudflare One Client - Cloudflare One Client for Windows (version 2026.5.1155.1)</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-05-29-warp-windows-beta/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-05-29-warp-windows-beta/</guid><description>&lt;p&gt;A new Beta release for the Windows Cloudflare One Client is now available on the &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/beta-releases/&quot;&gt;beta releases downloads page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This release introduces the new Cloudflare One Client UI for Windows! You can expect a cleaner and more intuitive design as well as easier access to common actions and information. Here are some of the many things we have found our users appreciate:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Right click context menu to access the most common client actions quickly&lt;/li&gt;
&lt;li&gt;Built-in captive portal login experience&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Additional Changes and improvements&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The client now applies DNS search suffixes configured in your &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-profiles&quot;&gt;device profile&lt;/a&gt; / &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/network-policies&quot;&gt;network policy&lt;/a&gt;. Administrators can push a list of DNS search domains that the client appends to single-label queries, alongside any system-configured suffixes. See &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/#dns-search-suffixes&quot;&gt;DNS search suffixes&lt;/a&gt; for details.&lt;/li&gt;
&lt;li&gt;Administrators can now control which virtual networks (VNETs) are available to which users via WARP device profile settings in the Zero Trust dashboard. Previously, every VNET in the organization was visible to every device; you can now scope the VNET picker per profile so users only see the networks relevant to them. See &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/#vnet-availability&quot;&gt;VNET availability&lt;/a&gt; for details.&lt;/li&gt;
&lt;li&gt;Added mandatory authentication. When enabled via MDM, the Cloudflare One Client blocks all Internet traffic from the moment the machine boots until the user authenticates, closing the visibility gap on newly deployed devices and during re-authentication. See the &lt;a href=&quot;https://blog.cloudflare.com/mandatory-authentication-mfa/&quot;&gt;announcement blog&lt;/a&gt; and &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/windows-no-auth-no-internet/&quot;&gt;documentation&lt;/a&gt; for details.&lt;/li&gt;
&lt;li&gt;Added a local-file signal source for Emergency Disconnect. In addition to the existing HTTPS polling mechanism, administrators can now configure WARP to monitor for a file on disk; the presence of the file triggers an emergency disconnect even if both Cloudflare and your own infrastructure are unreachable. Either signal being asserted triggers disconnect; both must be cleared for normal operation to resume.&lt;/li&gt;
&lt;li&gt;Added new warp-cli debug commands for interactive connection diagnosis. See &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/diagnostic-logs/#extra-debug-logging&quot;&gt;Extra debug logging&lt;/a&gt; for details.&lt;/li&gt;
&lt;li&gt;The local DNS proxy now supports DNSSEC passthrough. DNSSEC-signed responses are forwarded to the application intact (including DO/AD bits and RRSIG records), so applications that validate DNSSEC locally — including resolvers and the dig/drill tooling — work correctly through the client.&lt;/li&gt;
&lt;li&gt;Added a new MDM format for organization-wide settings, including a cleaner way to configure the compliance environment (e.g. FedRAMP). The previous per-configuration approach still works, but the new format is now recommended. See the updated &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/parameters/#organization_configs&quot;&gt;Cloudflare One MDM documentation&lt;/a&gt; for details.&lt;/li&gt;
&lt;li&gt;Client Certificate device-posture checks now support template variables (e.g. &lt;code&gt;${serial_number}&lt;/code&gt;, &lt;code&gt;${device_uuid}&lt;/code&gt;) in the Subject Alternative Name field, matching what the documentation has always claimed. Previously only the Common Name field accepted variables, which broke posture rules that pinned identity to a SAN entry.&lt;/li&gt;
&lt;li&gt;The UseWebView2 registry value (HKLM\SOFTWARE\Cloudflare\CloudflareWARP\UseWebView2 = y) is once again honored by the new GUI for authentication, so administrators who prefer the embedded WebView2 browser for sign-in can opt back in. This setting was effectively ignored in the previous release; the default browser was always used. This key is now also honored for re-authentications.&lt;/li&gt;
&lt;li&gt;Fixed a crash in the authentication browser when navigating to a site that prompts for browser permissions (microphone, camera, notifications, etc.). The same fix had previously landed for the captive-portal browser; this extends it to the auth browser.&lt;/li&gt;
&lt;li&gt;Fixed an issue in proxy mode where hostnames containing underscores (e.g. ai_app.com) were rejected, breaking apps that depend on such hostnames (notably ChatGPT sandbox apps). The local proxy now accepts underscore-containing hostnames in CONNECT requests.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Known issues&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;An error indicating that Microsoft Edge can&amp;#39;t read and write to its data directory may be displayed during captive portal login; this error is benign and can be dismissed.&lt;/li&gt;
&lt;li&gt;Registration may hang at &amp;quot;Checking your organization configuration&amp;quot; due to IPC errors. A system reboot should resolve the error, allowing registration to proceed.&lt;/li&gt;
&lt;li&gt;Split tunnel list configuration is not available in the new UI. Management of Split Tunnel entries is currently only possible via &lt;code&gt;warp-cli tunnel ip&lt;/code&gt; and &lt;code&gt;warp-cli tunnel host&lt;/code&gt;. UI support will be added in a future release.&lt;/li&gt;
&lt;li&gt;Windows ARM may prompt the user to close running applications while trying to install this version. Simply click “Ok” with the default highlighted option.&lt;/li&gt;
&lt;li&gt;DNS resolution may be broken when the following conditions are all true:&lt;ul&gt;
&lt;li&gt;The client is in Secure Web Gateway without DNS filtering (tunnel-only) mode.&lt;/li&gt;
&lt;li&gt;A custom DNS server address is configured on the primary network adapter.&lt;/li&gt;
&lt;li&gt;The custom DNS server address on the primary network adapter is changed while the client is connected.&lt;br&gt;To work around this issue, please reconnect the client by selecting &amp;quot;disconnect&amp;quot; and then &amp;quot;connect&amp;quot; in the client user interface.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Fri, 29 May 2026 00:55:37 GMT</pubDate><product>Cloudflare One Client</product><category>Cloudflare One Client</category></item><item><title>Access - 用于 MCP 服务器门户的工具和提示词别名</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-05-28-mcp-portal-tool-prompt-aliases/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-05-28-mcp-portal-tool-prompt-aliases/</guid><description>&lt;p&gt;当您通过 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/access-controls/ai-controls/mcp-portals/&quot;&gt;MCP 服务器门户&lt;/a&gt;连接第三方 MCP 服务器时，您无法控制服务器作者如何命名工具或编写描述。不明确的名称使 AI 代理更难选择正确的工具，也使用户更难理解可用内容。&lt;/p&gt;
&lt;p&gt;您现在可以直接在门户上&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/access-controls/ai-controls/mcp-portals/#rename-tools-and-prompts-with-aliases&quot;&gt;重命名工具和提示词&lt;/a&gt;并重写其描述，而无需修改上游服务器。例如，名为 &lt;code&gt;super_cool_tool&lt;/code&gt; 的工具可以变成 &lt;code&gt;search_customer_records&lt;/code&gt;，并配有专门针对您组织定制的描述。&lt;/p&gt;
&lt;img src=&quot;https://cloudflaredoc.ubitools.com/_astro/portal-edit-tool-modal.DrxORhBl_Z1NtRnj.webp&quot; alt=&quot;显示 MCP 服务器工具的名称和描述字段的编辑工具模态框&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1640&quot; height=&quot;1144&quot;&gt;
&lt;p&gt;修改后的工具会在工具列表中显示 **Modified（已修改）**标签，以便管理员一眼就能看出哪些工具被自定义过。&lt;/p&gt;
&lt;img src=&quot;https://cloudflaredoc.ubitools.com/_astro/portal-tools-authorized-modified.B674Xvip_12xxcK.webp&quot; alt=&quot;在重命名的工具上显示已修改标签的授权工具列表&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1862&quot; height=&quot;700&quot;&gt;
&lt;p&gt;别名会覆盖 MCP 客户端接收到的元数据。您可以在两个层级设置它们：&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;针对每个门户&lt;/strong&gt;：仅在特定门户内适用。优先级高于服务器级别的别名。&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;针对每个服务器&lt;/strong&gt;：适用于所有使用该服务器的门户。&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;您可以随时重置别名以恢复原始的上游名称。&lt;/p&gt;
&lt;p&gt;欲了解更多信息，请参阅&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/access-controls/ai-controls/mcp-portals/#rename-tools-and-prompts-with-aliases&quot;&gt;工具和提示词别名&lt;/a&gt;。&lt;/p&gt;</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate><product>Access</product><category>Access</category></item><item><title>Cloudflare Mesh, Cloudflare One - Cloudflare Mesh 高可用性副本管理</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-05-28-mesh-ha-replica-ui/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-05-28-mesh-ha-replica-ui/</guid><description>&lt;p&gt;&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/connectors/cloudflare-mesh/&quot;&gt;Cloudflare Mesh&lt;/a&gt; 仪表板现在显示&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/connectors/cloudflare-mesh/high-availability/&quot;&gt;高可用性&lt;/a&gt;节点的单副本详情。您可以查看哪个副本是活动状态，查看每个副本的 Mesh IP 和连接详情，并手动触发故障转移——这一切都可以从节点详情页面完成。&lt;/p&gt;
&lt;img src=&quot;https://cloudflaredoc.ubitools.com/_astro/mesh-ha-replicas.Dvf1GMmQ_Z2i6nGi.webp&quot; alt=&quot;Mesh HA 副本选项卡，显示具有单副本 Mesh IP 的活动和备用副本，以及手动故障转移选项&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1800&quot; height=&quot;1155&quot;&gt;
&lt;div tabindex=&quot;-1&quot; class=&quot;heading-wrapper level-h4&quot;&gt;&lt;h4 id=&quot;新增功能&quot;&gt;新增功能&lt;/h4&gt;&lt;a class=&quot;anchor-link&quot; href=&quot;#新增功能&quot;&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;anchor-icon&quot;&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 24 24&quot;&gt;&lt;path fill=&quot;currentcolor&quot; d=&quot;m12.11 15.39-3.88 3.88a2.52 2.52 0 0 1-3.5 0 2.47 2.47 0 0 1 0-3.5l3.88-3.88a1 1 0 0 0-1.42-1.42l-3.88 3.89a4.48 4.48 0 0 0 6.33 6.33l3.89-3.88a1 1 0 1 0-1.42-1.42Zm8.58-12.08a4.49 4.49 0 0 0-6.33 0l-3.89 3.88a1 1 0 0 0 1.42 1.42l3.88-3.88a2.52 2.52 0 0 1 3.5 0 2.47 2.47 0 0 1 0 3.5l-3.88 3.88a1 1 0 1 0 1.42 1.42l3.88-3.89a4.49 4.49 0 0 0 0-6.33ZM8.83 15.17a1 1 0 0 0 1.1.22 1 1 0 0 0 .32-.22l4.92-4.92a1 1 0 0 0-1.42-1.42l-4.92 4.92a1 1 0 0 0 0 1.42Z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;节点详情页面上的&lt;strong&gt;副本选项卡&lt;/strong&gt;——在副本之间切换以查看每个副本的 Mesh IP、边缘数据中心、源站 IP、平台、版本和运行时间。&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;活动/备用（Active/passive）徽章&lt;/strong&gt;，用于识别当前正在路由流量的副本。&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;手动故障转移&lt;/strong&gt;——只需单击一下即可将备用副本提升为活动状态。先前的活动副本将切换为备用（standby）状态。&lt;/li&gt;
&lt;li&gt;概览表中的 &lt;strong&gt;HA 徽章&lt;/strong&gt;，用于识别运行多个副本的节点。&lt;/li&gt;
&lt;li&gt;概览表中显示的&lt;strong&gt;活动副本 IP&lt;/strong&gt;——仪表板现在会解析出哪个副本处于活动状态并显示正确的 Mesh IP。&lt;/li&gt;
&lt;/ul&gt;
&lt;div tabindex=&quot;-1&quot; class=&quot;heading-wrapper level-h4&quot;&gt;&lt;h4 id=&quot;手动故障转移&quot;&gt;手动故障转移&lt;/h4&gt;&lt;a class=&quot;anchor-link&quot; href=&quot;#手动故障转移&quot;&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;anchor-icon&quot;&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 24 24&quot;&gt;&lt;path fill=&quot;currentcolor&quot; d=&quot;m12.11 15.39-3.88 3.88a2.52 2.52 0 0 1-3.5 0 2.47 2.47 0 0 1 0-3.5l3.88-3.88a1 1 0 0 0-1.42-1.42l-3.88 3.89a4.48 4.48 0 0 0 6.33 6.33l3.89-3.88a1 1 0 1 0-1.42-1.42Zm8.58-12.08a4.49 4.49 0 0 0-6.33 0l-3.89 3.88a1 1 0 0 0 1.42 1.42l3.88-3.88a2.52 2.52 0 0 1 3.5 0 2.47 2.47 0 0 1 0 3.5l-3.88 3.88a1 1 0 1 0 1.42 1.42l3.88-3.89a4.49 4.49 0 0 0 0-6.33ZM8.83 15.17a1 1 0 0 0 1.1.22 1 1 0 0 0 .32-.22l4.92-4.92a1 1 0 0 0-1.42-1.42l-4.92 4.92a1 1 0 0 0 0 1.42Z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;p&gt;要手动提升备用副本：&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;在 &lt;a href=&quot;https://dash.cloudflare.com/?to=/:account/mesh&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Cloudflare 仪表板&lt;span class=&quot;external-link&quot;&gt; ↗&lt;/span&gt;&lt;/a&gt;中，前往 &lt;strong&gt;Networking（网络）&lt;/strong&gt; &amp;gt; &lt;strong&gt;Mesh&lt;/strong&gt;。&lt;/li&gt;
&lt;li&gt;选择启用了 HA 的节点。&lt;/li&gt;
&lt;li&gt;选择备用副本选项卡。&lt;/li&gt;
&lt;li&gt;选择 &lt;strong&gt;Promote to active（提升为活动）&lt;/strong&gt; 并确认。&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;流量会立即重定向到提升后的副本。有关故障转移行为的详情，请参阅&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/connectors/cloudflare-mesh/high-availability/&quot;&gt;高可用性&lt;/a&gt;。&lt;/p&gt;</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate><product>Cloudflare Mesh</product><category>Cloudflare Mesh</category><category>Cloudflare One</category></item><item><title>Cloudflare One, Gateway - 在 Cloudflare One 中使用自然语言编写正则表达式 (regex)</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-05-27-cloudy-regex-assistance/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-05-27-cloudy-regex-assistance/</guid><description>&lt;p&gt;支持正则表达式的 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/&quot;&gt;Cloudflare Gateway&lt;/a&gt; 策略选择器现在可以在仪表板中使用自然语言编写。当使用基于正则表达式的选择器（例如 &lt;code&gt;matches regex&lt;/code&gt;）构建&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/expression-syntax/&quot;&gt;策略&lt;/a&gt;时，您可以用简明英语描述您想要匹配的内容，Cloudflare Agent 将生成并验证相应的正则表达式。&lt;/p&gt;
&lt;img src=&quot;https://cloudflaredoc.ubitools.com/_astro/gateway-regex-ai-generation.CtJ0S6FS_Z1WVe4K.webp&quot; alt=&quot;使用自然语言编写策略正则表达式&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1000&quot; height=&quot;638&quot;&gt;
&lt;p&gt;要开始使用，请在 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/&quot;&gt;Gateway 策略构建器&lt;/a&gt;中选择兼容正则表达式的选择器，然后选择该图标。您将看到一个用于输入自然语言的字段，例如“以 /api/v1 开头的任何 URL”或“主机中包含 &lt;code&gt;gooogle&lt;/code&gt; 的 .com、.net 和 .app 主机”。&lt;/p&gt;
&lt;p&gt;您还可以使用该工具来解释现有的正则表达式。如果策略中已包含正则表达式模式，您可以立即生成通俗易懂的语言描述。&lt;/p&gt;
&lt;p&gt;内置的反馈机制允许您对每次交互进行评分，以帮助随着时间推移提高输出质量。&lt;/p&gt;
&lt;p&gt;有关更多信息，请参阅 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/&quot;&gt;Cloudflare One 防火墙策略&lt;/a&gt;，并期待很快在&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/data-loss-prevention/&quot;&gt;数据防泄露（DLP）配置文件&lt;/a&gt;中支持相同的功能。&lt;/p&gt;</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate><product>Cloudflare One</product><category>Cloudflare One</category><category>Gateway</category></item><item><title>Cloudflare Tunnel, Cloudflare Tunnel for SASE - Cloudflare Tunnel 现在在启动时运行连接性预检查</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-05-27-cloudflared-connectivity-prechecks/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-05-27-cloudflared-connectivity-prechecks/</guid><description>&lt;p&gt;从 &lt;a href=&quot;https://github.com/cloudflare/cloudflared/releases&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;&lt;code&gt;cloudflared&lt;/code&gt; 版本 2026.5.2&lt;span class=&quot;external-link&quot;&gt; ↗&lt;/span&gt;&lt;/a&gt; 开始，&lt;a href=&quot;https://cloudflaredoc.ubitools.com/tunnel/&quot;&gt;Cloudflare Tunnel&lt;/a&gt; 直接在二进制文件内部自动执行整个&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/connectors/cloudflare-tunnel/troubleshoot-tunnels/connectivity-prechecks/&quot;&gt;连接性预检查工作流程&lt;/a&gt;。以前，客户必须安装 &lt;code&gt;dig&lt;/code&gt; 和 &lt;code&gt;netcat&lt;/code&gt; 并手动运行这些命令来验证其环境。现在 &lt;code&gt;cloudflared&lt;/code&gt; 在启动时以原生方式执行此操作 — 并在某些内容被阻止时提供可操作的修正提示。&lt;/p&gt;
&lt;img src=&quot;https://cloudflaredoc.ubitools.com/_astro/cloudflared-connectivity-prechecks.DRwN6tGe_c1XGu.webp&quot; alt=&quot;cloudflared 连接性预检查输出&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;1800&quot; height=&quot;1012&quot;&gt;
&lt;p&gt;在每次运行 &lt;code&gt;cloudflared tunnel run&lt;/code&gt;（以及 &lt;code&gt;cloudflared tunnel diag&lt;/code&gt;）时，二进制文件现在都会原生检查：&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;DNS 解析&lt;/strong&gt; — &lt;code&gt;region1.v2.argotunnel.com&lt;/code&gt; 和 &lt;code&gt;region2.v2.argotunnel.com&lt;/code&gt; 解析为有效的 Cloudflare IP。&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;传输连接性&lt;/strong&gt; — 端口 &lt;code&gt;7844&lt;/code&gt; 上的出站 &lt;code&gt;UDP (QUIC)&lt;/code&gt; 和 &lt;code&gt;TCP (HTTP/2)&lt;/code&gt;。&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Management API&lt;/strong&gt; — 发往 &lt;code&gt;api.cloudflare.com&lt;/code&gt; 的出站 &lt;code&gt;TCP/443&lt;/code&gt;，用于软件更新。&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;结果将以可扫描的 CLI 表格形式打印，包含以下三种状态：&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;✅ &lt;strong&gt;通过&lt;/strong&gt; — 检查成功。&lt;/li&gt;
&lt;li&gt;⚠️ &lt;strong&gt;警告&lt;/strong&gt; — 非阻塞问题，例如 Management API 无法访问，因此自动更新将无法工作，但 Tunnel 仍会启动。&lt;/li&gt;
&lt;li&gt;❌ &lt;strong&gt;失败&lt;/strong&gt; — 阻塞问题，并附有具体的修正提示（例如 &lt;code&gt;Allow outbound UDP on port 7844&lt;/code&gt;）。&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;如果 DNS 无法解析，或者端口 7844 上的 UDP 和 TCP &lt;strong&gt;双双&lt;/strong&gt;失败，&lt;code&gt;cloudflared&lt;/code&gt; 将提前退出并报告失败，而不是在不透明的 &lt;code&gt;failed to dial&lt;/code&gt; 错误中循环。&lt;/p&gt;
&lt;p&gt;现在每次启动都会自动运行预检查，这还能捕获诸如通宵防火墙策略变更之类的问题退化 — 无需记得重新运行故障排除指南。&lt;/p&gt;
&lt;p&gt;要获取这一新行为，请将 &lt;code&gt;cloudflared&lt;/code&gt; 升级到版本 &lt;code&gt;2026.5.2&lt;/code&gt; 或更高版本。欲了解更多细节，请参阅&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/connectors/cloudflare-tunnel/troubleshoot-tunnels/connectivity-prechecks/&quot;&gt;连接性预检查文档&lt;/a&gt;。&lt;/p&gt;</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate><product>Cloudflare Tunnel</product><category>Cloudflare Tunnel</category><category>Cloudflare Tunnel for SASE</category></item><item><title>Cloudflare One Client - Cloudflare One Client for macOS (version 2026.4.1390.0)</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-05-26-warp-macos-ga/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-05-26-warp-macos-ga/</guid><description>&lt;p&gt;A new GA release for the macOS Cloudflare One Client is now available on the &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/&quot;&gt;stable releases downloads page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This release introduces the new Cloudflare One Client UI for macOS! You can expect a cleaner and more intuitive design as well as easier access to common actions and information. Here are some of the many things we have found our users appreciate:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Right click context menu to access the most common client actions quickly&lt;/li&gt;
&lt;li&gt;Built-in captive portal login experience&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Additional Changes and improvements&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Added a new CLI command: warp-cli mdm refresh. This command executes an immediate refresh of the Mobile Device Management (MDM) configuration file.&lt;/li&gt;
&lt;li&gt;Fixed a proxy mode connection stall issue.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Known issues&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Registration may hang at &amp;quot;Checking your organization configuration&amp;quot; due to IPC errors. A system reboot should resolve the error, allowing registration to proceed.&lt;/li&gt;
&lt;li&gt;Split tunnel list configuration is not available in the new UI. Management of split tunnel entries is currently only possible via &lt;code&gt;warp-cli tunnel ip&lt;/code&gt; and &lt;code&gt;warp-cli tunnel host&lt;/code&gt;. UI support will be added in a future release.&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Tue, 26 May 2026 22:26:01 GMT</pubDate><product>Cloudflare One Client</product><category>Cloudflare One Client</category></item><item><title>Cloudflare One Client - Cloudflare One Client for Windows (version 2026.4.1390.0)</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-05-26-warp-windows-ga/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-05-26-warp-windows-ga/</guid><description>&lt;p&gt;A new GA release for the Windows Cloudflare One Client is now available on the &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/&quot;&gt;stable releases downloads page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This release introduces the new Cloudflare One Client UI for Windows! You can expect a cleaner and more intuitive design as well as easier access to common actions and information. Here are some of the many things we have found our users appreciate:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Right click context menu to access the most common client actions quickly&lt;/li&gt;
&lt;li&gt;Built-in captive portal login experience&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Additional Changes and improvements&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Added a new CLI command: warp-cli mdm refresh. This command executes an immediate refresh of the Mobile Device Management (MDM) configuration file.&lt;/li&gt;
&lt;li&gt;Fixed a proxy mode connection stall issue.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Known issues&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Registration authentication for devices via the integrated WebView2 browser is unavailable in this version as a temporary measure. As a result, the client will utilize the default browser on the device to complete the authentication process.&lt;/li&gt;
&lt;li&gt;An error indicating that Microsoft Edge can&amp;#39;t read and write to its data directory may be displayed during captive portal login; this error is benign and can be dismissed.&lt;/li&gt;
&lt;li&gt;Registration may hang at &amp;quot;Checking your organization configuration&amp;quot; due to IPC errors. A system reboot should resolve the error, allowing registration to proceed.&lt;/li&gt;
&lt;li&gt;Split tunnel list configuration is not available in the new UI. Management of Split Tunnel entries is currently only possible via &lt;code&gt;warp-cli tunnel ip&lt;/code&gt; and &lt;code&gt;warp-cli tunnel host&lt;/code&gt;. UI support will be added in a future release.&lt;/li&gt;
&lt;li&gt;Windows ARM may prompt the user to close running applications while trying to install this version. Simply click “Ok” with the default highlighted option.&lt;/li&gt;
&lt;li&gt;DNS resolution may be broken when the following conditions are all true:&lt;ul&gt;
&lt;li&gt;The client is in Secure Web Gateway without DNS filtering (tunnel-only) mode.&lt;/li&gt;
&lt;li&gt;A custom DNS server address is configured on the primary network adapter.&lt;/li&gt;
&lt;li&gt;The custom DNS server address on the primary network adapter is changed while the client is connected.&lt;br&gt;To work around this issue, please reconnect the client by selecting &amp;quot;disconnect&amp;quot; and then &amp;quot;connect&amp;quot; in the client user interface.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Tue, 26 May 2026 22:26:00 GMT</pubDate><product>Cloudflare One Client</product><category>Cloudflare One Client</category></item><item><title>Cloudflare One Client - Cloudflare One Client for Linux (version 2026.4.1390.0)</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-05-26-warp-linux-ga/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-05-26-warp-linux-ga/</guid><description>&lt;p&gt;A new GA release for the Linux Cloudflare One Client is now available on the &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/&quot;&gt;stable releases downloads page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This release introduces the new Cloudflare One Client UI for Linux! You can expect a cleaner and more intuitive design as well as easier access to common actions and information. Here are some of the many things we have found our users appreciate:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Right click context menu to access the most common client actions quickly&lt;/li&gt;
&lt;li&gt;Built-in captive portal login experience&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Changes and improvements&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Added a new CLI command: warp-cli mdm refresh. This command executes an immediate refresh of the Mobile Device Management (MDM) configuration file.&lt;/li&gt;
&lt;li&gt;Official support for RHEL 9 has been added for Cloudflare Mesh nodes. To install the RHEL 9 package, the Extra Packages for Enterprise Linux (EPEL) repository must be active, as it contains dependencies required for the tray icon and captive portal webview.&lt;/li&gt;
&lt;li&gt;Fixed a proxy mode connection stall issue.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Known issues&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Registration may hang at &amp;quot;Checking your organization configuration&amp;quot; due to IPC errors. A system reboot should resolve the error, allowing registration to proceed.&lt;/li&gt;
&lt;li&gt;Split tunnel list configuration is not available in the new UI. Management of split tunnel entries is currently only possible via &lt;code&gt;warp-cli tunnel ip&lt;/code&gt; and &lt;code&gt;warp-cli tunnel host&lt;/code&gt;. UI support will be added in a future release.&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Tue, 26 May 2026 20:32:41 GMT</pubDate><product>Cloudflare One Client</product><category>Cloudflare One Client</category></item><item><title>Cloudflare Fundamentals, Cloudflare One, Cloudflare Tunnel for SASE, Cloudflare Tunnel, Cloudflare Mesh - Cloudflare Tunnel 和 Cloudflare Mesh 的细粒度权限</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-05-21-tunnel-mesh-granular-permissions/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-05-21-tunnel-mesh-granular-permissions/</guid><description>&lt;p&gt;您现在可以将 Cloudflare 权限范围限定为单个 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/tunnel/&quot;&gt;Cloudflare Tunnel&lt;/a&gt; 实例和 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/connectors/cloudflare-mesh/&quot;&gt;Cloudflare Mesh&lt;/a&gt; 节点。管理员可以委派对特定 Tunnel 或 Mesh 节点的访问权限，而无需授予对整个账户中私有网络的控制权。&lt;/p&gt;
&lt;div tabindex=&quot;-1&quot; class=&quot;heading-wrapper level-h4&quot;&gt;&lt;h4 id=&quot;新增功能&quot;&gt;新增功能&lt;/h4&gt;&lt;a class=&quot;anchor-link&quot; href=&quot;#新增功能&quot;&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;anchor-icon&quot;&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 24 24&quot;&gt;&lt;path fill=&quot;currentcolor&quot; d=&quot;m12.11 15.39-3.88 3.88a2.52 2.52 0 0 1-3.5 0 2.47 2.47 0 0 1 0-3.5l3.88-3.88a1 1 0 0 0-1.42-1.42l-3.88 3.89a4.48 4.48 0 0 0 6.33 6.33l3.89-3.88a1 1 0 1 0-1.42-1.42Zm8.58-12.08a4.49 4.49 0 0 0-6.33 0l-3.89 3.88a1 1 0 0 0 1.42 1.42l3.88-3.88a2.52 2.52 0 0 1 3.5 0 2.47 2.47 0 0 1 0 3.5l-3.88 3.88a1 1 0 1 0 1.42 1.42l3.88-3.89a4.49 4.49 0 0 0 0-6.33ZM8.83 15.17a1 1 0 0 0 1.1.22 1 1 0 0 0 .32-.22l4.92-4.92a1 1 0 0 0-1.42-1.42l-4.92 4.92a1 1 0 0 0 0 1.42Z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;p&gt;当您&lt;a href=&quot;https://cloudflaredoc.ubitools.com/fundamentals/manage-members/manage/&quot;&gt;添加成员&lt;/a&gt;或创建&lt;a href=&quot;https://cloudflaredoc.ubitools.com/fundamentals/manage-members/policies/&quot;&gt;权限策略&lt;/a&gt;时，资源选择器现在将 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/tunnel/&quot;&gt;Cloudflare Tunnel&lt;/a&gt; 实例和 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/connectors/cloudflare-mesh/&quot;&gt;Cloudflare Mesh&lt;/a&gt; 节点列为可限定范围的资源类型。您可以：&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;向支持操作人员授予对单个 Cloudflare Tunnel 实例的只读角色，以进行日志流传输和诊断，而不会暴露其他 Tunnel 或允许破坏性操作。&lt;/li&gt;
&lt;li&gt;向应用程序团队授予对特定 Cloudflare Mesh 节点的写入角色，而无需让他们访问私有网络的其余部分。&lt;/li&gt;
&lt;li&gt;将单个策略的范围同时限定为一个或多个 Tunnel 以及 Mesh 节点。&lt;/li&gt;
&lt;/ul&gt;
&lt;div tabindex=&quot;-1&quot; class=&quot;heading-wrapper level-h4&quot;&gt;&lt;h4 id=&quot;工作原理&quot;&gt;工作原理&lt;/h4&gt;&lt;a class=&quot;anchor-link&quot; href=&quot;#工作原理&quot;&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;anchor-icon&quot;&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 24 24&quot;&gt;&lt;path fill=&quot;currentcolor&quot; d=&quot;m12.11 15.39-3.88 3.88a2.52 2.52 0 0 1-3.5 0 2.47 2.47 0 0 1 0-3.5l3.88-3.88a1 1 0 0 0-1.42-1.42l-3.88 3.89a4.48 4.48 0 0 0 6.33 6.33l3.89-3.88a1 1 0 1 0-1.42-1.42Zm8.58-12.08a4.49 4.49 0 0 0-6.33 0l-3.89 3.88a1 1 0 0 0 1.42 1.42l3.88-3.88a2.52 2.52 0 0 1 3.5 0 2.47 2.47 0 0 1 0 3.5l-3.88 3.88a1 1 0 1 0 1.42 1.42l3.88-3.89a4.49 4.49 0 0 0 0-6.33ZM8.83 15.17a1 1 0 0 0 1.1.22 1 1 0 0 0 .32-.22l4.92-4.92a1 1 0 0 0-1.42-1.42l-4.92 4.92a1 1 0 0 0 0 1.42Z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;p&gt;细粒度权限是与现有账户级别角色平行的层，它们不会取代后者。&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;现现的账户级别角色继续有效。&lt;/strong&gt; 拥有 &lt;code&gt;Cloudflare Access&lt;/code&gt; 或 &lt;code&gt;Cloudflare Zero Trust&lt;/code&gt; 的成员将保留对账户中每个 Tunnel 和 Mesh 节点的写入访问权限。这确保了与现有自动化和令牌的向后兼容性。&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;细粒度权限是累加的。&lt;/strong&gt; 对于针对特定 Tunnel 或 Mesh 节点的任何 API 请求，如果主体具有账户级别角色&lt;strong&gt;或&lt;/strong&gt;该资源的细粒度权限，则将授予访问权限。&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;资源枚举是感知授权的。&lt;/strong&gt; 列表端点（&lt;code&gt;GET /accounts/{id}/cfd_tunnel&lt;/code&gt;，&lt;code&gt;GET /accounts/{id}/warp_connector&lt;/code&gt;）仅返回主体至少具有只读访问权限的资源。&lt;/li&gt;
&lt;/ul&gt;
&lt;div tabindex=&quot;-1&quot; class=&quot;heading-wrapper level-h4&quot;&gt;&lt;h4 id=&quot;开始使用&quot;&gt;开始使用&lt;/h4&gt;&lt;a class=&quot;anchor-link&quot; href=&quot;#开始使用&quot;&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;anchor-icon&quot;&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 24 24&quot;&gt;&lt;path fill=&quot;currentcolor&quot; d=&quot;m12.11 15.39-3.88 3.88a2.52 2.52 0 0 1-3.5 0 2.47 2.47 0 0 1 0-3.5l3.88-3.88a1 1 0 0 0-1.42-1.42l-3.88 3.89a4.48 4.48 0 0 0 6.33 6.33l3.89-3.88a1 1 0 1 0-1.42-1.42Zm8.58-12.08a4.49 4.49 0 0 0-6.33 0l-3.89 3.88a1 1 0 0 0 1.42 1.42l3.88-3.88a2.52 2.52 0 0 1 3.5 0 2.47 2.47 0 0 1 0 3.5l-3.88 3.88a1 1 0 1 0 1.42 1.42l3.88-3.89a4.49 4.49 0 0 0 0-6.33ZM8.83 15.17a1 1 0 0 0 1.1.22 1 1 0 0 0 .32-.22l4.92-4.92a1 1 0 0 0-1.42-1.42l-4.92 4.92a1 1 0 0 0 0 1.42Z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;ul&gt;
&lt;li&gt;配置 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/tunnel/advanced/granular-permissions/&quot;&gt;Cloudflare Tunnel 的细粒度权限&lt;/a&gt;。&lt;/li&gt;
&lt;li&gt;配置 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/networks/connectors/granular-permissions/&quot;&gt;Cloudflare One 中 Cloudflare Tunnel 和 Cloudflare Mesh 的细粒度权限&lt;/a&gt;。&lt;/li&gt;
&lt;li&gt;查看 Cloudflare 角色参考上的&lt;a href=&quot;https://cloudflaredoc.ubitools.com/fundamentals/manage-members/roles/#resource-scoped-roles&quot;&gt;资源范围角色&lt;/a&gt;。&lt;/li&gt;
&lt;/ul&gt;</description><pubDate>Thu, 21 May 2026 00:00:00 GMT</pubDate><product>Cloudflare Fundamentals</product><category>Cloudflare Fundamentals</category><category>Cloudflare One</category><category>Cloudflare Tunnel for SASE</category><category>Cloudflare Tunnel</category><category>Cloudflare Mesh</category></item><item><title>Access - Cloudflare 作为身份提供商和账户成员资格选择器</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-05-19-cloudflare-as-identity-provider/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-05-19-cloudflare-as-identity-provider/</guid><description>&lt;p&gt;Cloudflare Access 现在支持将 Cloudflare 本身用作&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/integrations/identity-providers/cloudflare/&quot;&gt;身份提供商&lt;/a&gt;。如果您发布了 Access 应用程序并选择 Cloudflare 作为登录方法，用户可以使用其现有的 Cloudflare 账户登录——无需一次性 PIN，无需第三方 IdP 配置，也无需共享电子邮件收件箱。身份验证由 Cloudflare 自身的账户安全性（包括多因素身份验证）提供支持，因此在大多数用例中，它比基于 OTP 的登录更易于设置且更安全。&lt;/p&gt;
&lt;p&gt;Cloudflare 现在是&lt;strong&gt;所有新创建的 Zero Trust 账户的默认身份提供商&lt;/strong&gt;，取代了一次性 PIN（One-time PIN）。&lt;/p&gt;
&lt;p&gt;这还启用了两个新功能：&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Cloudflare 账户成员选择器（Cloudflare Account Member selector）&lt;/strong&gt; — 一种新的&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/access-controls/policies/#cloudflare-access-selectors&quot;&gt;策略选择器&lt;/a&gt;，根据用户在 Cloudflare 账户中的成员资格来进行匹配。您可以针对当前账户，也可以为跨账户访问场景指定不同的账户 ID。&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Restrict to account members（限制为账户成员）&lt;/strong&gt; — 一种身份提供商配置选项，将身份验证限制为属于您 Cloudflare 账户成员的用户。&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;要开始使用，请在您的 Zero Trust 设置中将 Cloudflare 添加为&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/integrations/identity-providers/cloudflare/&quot;&gt;身份提供商&lt;/a&gt;。&lt;/p&gt;</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><product>Access</product><category>Access</category></item><item><title>CASB - CASB 新增对 Claude Compliance API 的支持</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-05-19-casb-claude-compliance-api/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-05-19-casb-claude-compliance-api/</guid><description>&lt;p&gt;&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/integrations/cloud-and-saas/anthropic/&quot;&gt;Cloudflare CASB&lt;/a&gt; 现已与 &lt;a href=&quot;https://support.claude.com/en/articles/13015708-access-the-compliance-api&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;Claude Compliance API&lt;span class=&quot;external-link&quot;&gt; ↗&lt;/span&gt;&lt;/a&gt; 集成。此增强功能为安全团队提供了对其组织内 Claude 使用模式、管理员活动和合规相关事件的可见性。&lt;/p&gt;
&lt;p&gt;Claude Compliance API 提供对 Claude Enterprise 和 Claude Platform 内审计日志及管理操作的结构化访问。Cloudflare CASB 摄取这些数据，以呈现帮助组织增强安全态势并执行 AI 治理的安全发现结果。&lt;/p&gt;
&lt;div tabindex=&quot;-1&quot; class=&quot;heading-wrapper level-h4&quot;&gt;&lt;h4 id=&quot;主要功能&quot;&gt;主要功能&lt;/h4&gt;&lt;a class=&quot;anchor-link&quot; href=&quot;#主要功能&quot;&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;anchor-icon&quot;&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 24 24&quot;&gt;&lt;path fill=&quot;currentcolor&quot; d=&quot;m12.11 15.39-3.88 3.88a2.52 2.52 0 0 1-3.5 0 2.47 2.47 0 0 1 0-3.5l3.88-3.88a1 1 0 0 0-1.42-1.42l-3.88 3.89a4.48 4.48 0 0 0 6.33 6.33l3.89-3.88a1 1 0 1 0-1.42-1.42Zm8.58-12.08a4.49 4.49 0 0 0-6.33 0l-3.89 3.88a1 1 0 0 0 1.42 1.42l3.88-3.88a2.52 2.52 0 0 1 3.5 0 2.47 2.47 0 0 1 0 3.5l-3.88 3.88a1 1 0 1 0 1.42 1.42l3.88-3.89a4.49 4.49 0 0 0 0-6.33ZM8.83 15.17a1 1 0 0 0 1.1.22 1 1 0 0 0 .32-.22l4.92-4.92a1 1 0 0 0-1.42-1.42l-4.92 4.92a1 1 0 0 0 0 1.42Z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;p&gt;从今日起，安全团队可以扫描以下资产的安全发现结果：&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;公开项目&lt;/strong&gt; — 设置为公开可见性的项目&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;项目附件&lt;/strong&gt; — 添加到项目中违反 DLP 策略的文件和文档&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;聊天文件&lt;/strong&gt; — 违反 DLP 策略的用户上传和提供商生成的文件&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;聊天消息&lt;/strong&gt; — 违反 DLP 策略的用户提示和提供商响应&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Artifacts&lt;/strong&gt; — 违反 DLP 策略的提供商生成的文档和文件&lt;/li&gt;
&lt;/ul&gt;
&lt;div tabindex=&quot;-1&quot; class=&quot;heading-wrapper level-h4&quot;&gt;&lt;h4 id=&quot;了解更多&quot;&gt;了解更多&lt;/h4&gt;&lt;a class=&quot;anchor-link&quot; href=&quot;#了解更多&quot;&gt;&lt;span aria-hidden=&quot;true&quot; class=&quot;anchor-icon&quot;&gt;&lt;svg width=&quot;16&quot; height=&quot;16&quot; viewBox=&quot;0 0 24 24&quot;&gt;&lt;path fill=&quot;currentcolor&quot; d=&quot;m12.11 15.39-3.88 3.88a2.52 2.52 0 0 1-3.5 0 2.47 2.47 0 0 1 0-3.5l3.88-3.88a1 1 0 0 0-1.42-1.42l-3.88 3.89a4.48 4.48 0 0 0 6.33 6.33l3.89-3.88a1 1 0 1 0-1.42-1.42Zm8.58-12.08a4.49 4.49 0 0 0-6.33 0l-3.89 3.88a1 1 0 0 0 1.42 1.42l3.88-3.88a2.52 2.52 0 0 1 3.5 0 2.47 2.47 0 0 1 0 3.5l-3.88 3.88a1 1 0 1 0 1.42 1.42l3.88-3.89a4.49 4.49 0 0 0 0-6.33ZM8.83 15.17a1 1 0 0 0 1.1.22 1 1 0 0 0 .32-.22l4.92-4.92a1 1 0 0 0-1.42-1.42l-4.92 4.92a1 1 0 0 0 0 1.42Z&quot;&gt;&lt;/path&gt;&lt;/svg&gt;&lt;/span&gt;&lt;/a&gt;&lt;/div&gt;
&lt;p&gt;此&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/integrations/cloud-and-saas/anthropic/&quot;&gt;集成&lt;/a&gt;向所有 Cloudflare One 客户开放。新 Cloudflare 客户可以注册并免费开始使用前两个集成。现有客户可直接在仪表板中启用集成。集成在启用后立即开始扫描，并在几分钟内在仪表板中呈现发现结果。&lt;/p&gt;</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><product>CASB</product><category>CASB</category></item><item><title>Cloudflare WAN, Magic Transit - Unified Routing 支持 Network Analytics</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-05-18-unified-routing-network-analytics/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-05-18-unified-routing-network-analytics/</guid><description>&lt;p&gt;使用 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-wan/reference/traffic-steering/#unified-routing-mode-beta&quot;&gt;Unified Routing&lt;/a&gt; 模式的账户现在已完全支持 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/analytics/network-analytics/&quot;&gt;Network Analytics&lt;/a&gt;。通过 Unified Routing onramp 和 offramp 的流量现在可以在 Network Analytics 中可见，其维度和过滤器与标准数据平面上的流量相同。&lt;/p&gt;
&lt;p&gt;这弥补了已将隧道迁移到 Unified Routing 但在 Network Analytics 仪表板中失去对其数据平面流量可视性的客户的功能差距。无需更改配置——所有启用了 Unified Routing 的账户都会自动收集分析数据。&lt;/p&gt;
&lt;p&gt;有关其余的 Beta 限制，请参阅&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-wan/reference/traffic-steering/#beta-limitations&quot;&gt;流量引导 Beta 限制&lt;/a&gt;。&lt;/p&gt;</description><pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate><product>Cloudflare WAN</product><category>Cloudflare WAN</category><category>Magic Transit</category></item><item><title>Cloudflare One, Access - Access 登录页面更新</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-05-12-access-login-page-refresh/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-05-12-access-login-page-refresh/</guid><description>&lt;p&gt;&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/reusable-components/custom-pages/access-login-page/&quot;&gt;Access 登录页面&lt;/a&gt;和&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/integrations/identity-providers/one-time-pin/&quot;&gt;一次性密码 (OTP)&lt;/a&gt; 页面现在采用全新设计，提高了视觉一致性、用户信任度和移动端自适应性。&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;更新前：&lt;/strong&gt;&lt;/p&gt;
&lt;img src=&quot;https://cloudflaredoc.ubitools.com/_astro/access-login-old.CwNVkCQH_Z187ARH.webp&quot; alt=&quot;先前 Access 登录页面的屏幕截图&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;532&quot; height=&quot;906&quot;&gt;
&lt;p&gt;&lt;strong&gt;更新后：&lt;/strong&gt;&lt;/p&gt;
&lt;img src=&quot;https://cloudflaredoc.ubitools.com/_astro/access-login-new.Y7WUfg9G_1QeY33.webp&quot; alt=&quot;更新后的 Access 登录页面的屏幕截图&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;541&quot; height=&quot;722&quot;&gt;
&lt;p&gt;更新后的登录体验包括：&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;统一的身份验证卡&lt;/strong&gt; - 所有登录选项（身份提供商按钮、电子邮件输入、OTP）现在都显示在具有一致样式的单个卡片中，取代了先前的多部分布局。&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;一致的按钮样式&lt;/strong&gt; - 身份提供商按钮使用统一的大小和布局，以便于快速浏览和选择。&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;更好的移动端体验&lt;/strong&gt; - 自适应布局的改进确保登录页面在手机和平板电脑上正确渲染。&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;支持深色模式&lt;/strong&gt; - 登录页面现在支持深色模式。&lt;/li&gt;
&lt;/ul&gt;</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate><product>Cloudflare One</product><category>Cloudflare One</category><category>Access</category></item><item><title>Cloudflare WAN, Magic Transit, Cloudflare One - 新账户分配单个 IPv4 Anycast 地址</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-05-12-single-anycast-ip-default/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-05-12-single-anycast-ip-default/</guid><description>&lt;p&gt;默认情况下，现在为新的 Magic Transit 和 Cloudflare WAN 账户分配单个 IPv4 Anycast 地址。&lt;/p&gt;
&lt;p&gt;Cloudflare 会通过从全球许多分布式数据中心内的多个节点广播您的端点 IP，从而自动处理其网络上的故障。要处理您网络上的故障，请从不同的路由器配置两个隧道。&lt;/p&gt;
&lt;p&gt;如需为您的账户申请额外的 Anycast IP 地址，请联系您的账户团队。&lt;/p&gt;
&lt;p&gt;有关隧道配置指南，请参阅 Cloudflare WAN 的&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-wan/configuration/how-to/configure-tunnel-endpoints/&quot;&gt;配置隧道端点&lt;/a&gt;或 Magic Transit 的&lt;a href=&quot;https://cloudflaredoc.ubitools.com/magic-transit/how-to/configure-tunnel-endpoints/&quot;&gt;配置隧道端点&lt;/a&gt;。&lt;/p&gt;</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate><product>Cloudflare WAN</product><category>Cloudflare WAN</category><category>Magic Transit</category><category>Cloudflare One</category></item><item><title>Gateway - 使用自然语言创建 Gateway 防火墙策略</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-05-12-natural-language-policy-creation/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-05-12-natural-language-policy-creation/</guid><description>&lt;p&gt;Cloudflare Gateway 现在支持针对 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/dns-policies/&quot;&gt;DNS&lt;/a&gt;、&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/http-policies/&quot;&gt;HTTP&lt;/a&gt; 和 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/network-policies/&quot;&gt;网络&lt;/a&gt;防火墙策略使用自然语言创建策略。管理员可以用纯文本描述他们想要的结果，Cloudflare 将生成一个完整的策略规则来填充策略生成器表单。&lt;/p&gt;
&lt;img src=&quot;https://cloudflaredoc.ubitools.com/_astro/gateway-create-with-ai.BYG07coh_1T38Vz.webp&quot; alt=&quot;Gateway 防火墙策略页面上的“使用 AI 创建”按钮&quot; loading=&quot;lazy&quot; decoding=&quot;async&quot; width=&quot;2360&quot; height=&quot;1088&quot;&gt;
&lt;p&gt;要使用自然语言创建策略，请在任何 Gateway 防火墙策略选项卡上选择 &lt;strong&gt;Create with AI（使用 AI 创建）&lt;/strong&gt;。选择策略类型，描述该策略应执行的操作，随后一个完整配置的规则将显示在策略生成器中以供审查。您可以在保存之前编辑任何字段，或使用不同的提示词重新生成。&lt;/p&gt;
&lt;p&gt;生成的策略结合了您的账户上下文（包括列表、DLP 配置文件、应用和设备状态检查），从而自动解析对现有资源的引用。&lt;/p&gt;
&lt;p&gt;内置的反馈机制允许您对每个生成的策略进行评分并提供可选评论，Cloudflare 会使用这些评论来不断改进输出质量。&lt;/p&gt;
&lt;p&gt;有关更多信息，请参阅 &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/traffic-policies/&quot;&gt;Gateway 防火墙策略&lt;/a&gt;。&lt;/p&gt;</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate><product>Gateway</product><category>Gateway</category></item><item><title>Cloudflare One Client - Cloudflare One Client for Windows (version 2026.4.1350.0)</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-05-11-warp-windows-ga/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-05-11-warp-windows-ga/</guid><description>&lt;p&gt;A new GA release for the Windows Cloudflare One Client is now available on the &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/&quot;&gt;stable releases downloads page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This release introduces the new Cloudflare One Client UI for Windows! You can expect a cleaner and more intuitive design as well as easier access to common actions and information. Here are some of the many things we have found our users appreciate:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Right click context menu to access the most common client actions quickly&lt;/li&gt;
&lt;li&gt;Built-in captive portal login experience&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Additional Changes and improvements&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Added a new CLI command: warp-cli mdm refresh. This command executes an immediate refresh of the Mobile Device Management (MDM) configuration file.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Known issues&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Registration authentication for devices via the integrated WebView2 browser is unavailable in this version as a temporary measure. As a result, the client will utilize the default browser on the device to complete the authentication process.&lt;/li&gt;
&lt;li&gt;An error indicating that Microsoft Edge can&amp;#39;t read and write to its data directory may be displayed during captive portal login; this error is benign and can be dismissed.&lt;/li&gt;
&lt;li&gt;Registration may hang at &amp;quot;Checking your organization configuration&amp;quot; due to IPC errors. A system reboot should resolve the error, allowing registration to proceed.&lt;/li&gt;
&lt;li&gt;Split tunnel list configuration is not available in the new UI. Management of Split Tunnel entries is currently only possible via &lt;code&gt;warp-cli tunnel ip&lt;/code&gt; and &lt;code&gt;warp-cli tunnel host&lt;/code&gt;. UI support will be added in a future release.&lt;/li&gt;
&lt;li&gt;Windows ARM may prompt the user to close running applications while trying to install this version. Simply click “Ok” with the default highlighted option.&lt;/li&gt;
&lt;li&gt;DNS resolution may be broken when the following conditions are all true:&lt;ul&gt;
&lt;li&gt;The client is in Secure Web Gateway without DNS filtering (tunnel-only) mode.&lt;/li&gt;
&lt;li&gt;A custom DNS server address is configured on the primary network adapter.&lt;/li&gt;
&lt;li&gt;The custom DNS server address on the primary network adapter is changed while the client is connected.&lt;br&gt;To work around this issue, please reconnect the client by selecting &amp;quot;disconnect&amp;quot; and then &amp;quot;connect&amp;quot; in the client user interface.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Mon, 11 May 2026 17:35:58 GMT</pubDate><product>Cloudflare One Client</product><category>Cloudflare One Client</category></item><item><title>Cloudflare One Client - Cloudflare One Client for macOS (version 2026.4.1350.0)</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-05-11-warp-macos-ga/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-05-11-warp-macos-ga/</guid><description>&lt;p&gt;A new GA release for the macOS Cloudflare One Client is now available on the &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/&quot;&gt;stable releases downloads page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This release introduces the new Cloudflare One Client UI for macOS! You can expect a cleaner and more intuitive design as well as easier access to common actions and information. Here are some of the many things we have found our users appreciate:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Right click context menu to access the most common client actions quickly&lt;/li&gt;
&lt;li&gt;Built-in captive portal login experience&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Additional Changes and improvements&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Added a new CLI command: warp-cli mdm refresh. This command executes an immediate refresh of the Mobile Device Management (MDM) configuration file.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Known issues&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Registration may hang at &amp;quot;Checking your organization configuration&amp;quot; due to IPC errors. A system reboot should resolve the error, allowing registration to proceed.&lt;/li&gt;
&lt;li&gt;Split tunnel list configuration is not available in the new UI. Management of split tunnel entries is currently only possible via &lt;code&gt;warp-cli tunnel ip&lt;/code&gt; and &lt;code&gt;warp-cli tunnel host&lt;/code&gt;. UI support will be added in a future release.&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Mon, 11 May 2026 17:35:57 GMT</pubDate><product>Cloudflare One Client</product><category>Cloudflare One Client</category></item><item><title>Cloudflare One Client - Cloudflare One Client for Linux (version 2026.4.1350.0)</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-05-11-warp-linux-ga/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-05-11-warp-linux-ga/</guid><description>&lt;p&gt;A new GA release for the Linux Cloudflare One Client is now available on the &lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/&quot;&gt;stable releases downloads page&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This release introduces the new Cloudflare One Client UI for Linux! You can expect a cleaner and more intuitive design as well as easier access to common actions and information. Here are some of the many things we have found our users appreciate:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Right click context menu to access the most common client actions quickly&lt;/li&gt;
&lt;li&gt;Built-in captive portal login experience&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Changes and improvements&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Added a new CLI command: warp-cli mdm refresh. This command executes an immediate refresh of the Mobile Device Management (MDM) configuration file.&lt;/li&gt;
&lt;li&gt;Official support for RHEL 9 has been added for Cloudflare Mesh nodes. To install the RHEL 9 package, the Extra Packages for Enterprise Linux (EPEL) repository must be active, as it contains dependencies required for the tray icon and captive portal webview.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Known issues&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Registration may hang at &amp;quot;Checking your organization configuration&amp;quot; due to IPC errors. A system reboot should resolve the error, allowing registration to proceed.&lt;/li&gt;
&lt;li&gt;Split tunnel list configuration is not available in the new UI. Management of split tunnel entries is currently only possible via &lt;code&gt;warp-cli tunnel ip&lt;/code&gt; and &lt;code&gt;warp-cli tunnel host&lt;/code&gt;. UI support will be added in a future release.&lt;/li&gt;
&lt;/ul&gt;
</description><pubDate>Mon, 11 May 2026 15:17:54 GMT</pubDate><product>Cloudflare One Client</product><category>Cloudflare One Client</category></item><item><title>Cloudflare WAN, Magic Transit - UDP 端口 500 上的 IKE 支持 NAT-T</title><link>https://cloudflaredoc.ubitools.com/changelog/post/2026-05-11-nat-t-port-500/</link><guid isPermaLink="true">https://cloudflaredoc.ubitools.com/changelog/post/2026-05-11-nat-t-port-500/</guid><description>&lt;p&gt;Cloudflare IPsec 现在支持标准 NAT 穿透（NAT-T，NAT traversal）流程，其中 IKE 在 UDP 端口 &lt;code&gt;500&lt;/code&gt; 上启动，并在检测到 NAT 后切换到 UDP 端口 &lt;code&gt;4500&lt;/code&gt;。&lt;/p&gt;
&lt;p&gt;以前，必须将 NAT 后面的设备配置为直接在 UDP 端口 &lt;code&gt;4500&lt;/code&gt; 上发起 IKE。当路径中存在 NAT 时，在 UDP 端口 &lt;code&gt;500&lt;/code&gt; 上启动的设备无法完成 IKE 握手。这需要在 VeloCloud SD-WAN 边缘、Cisco IOS-XE 路由器和 Juniper SRX 防火墙等设备上进行自定义配置，而且并非在所有平台上都可行。&lt;/p&gt;
&lt;p&gt;已发生的变化：&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;NAT 后面的设备现在可以在 UDP 端口 &lt;code&gt;500&lt;/code&gt; 或 UDP 端口 &lt;code&gt;4500&lt;/code&gt; 上发起 IKE。&lt;/li&gt;
&lt;li&gt;在 UDP 端口 &lt;code&gt;500&lt;/code&gt; 上启动 IKE 并在检测到 NAT 后切换到 UDP 端口 &lt;code&gt;4500&lt;/code&gt; 的设备现在可以成功完成握手。&lt;/li&gt;
&lt;li&gt;Cloudflare 上不需要更改配置。此更改适用于 Cloudflare WAN 和 Magic Transit 上的所有 IPsec 隧道。&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;此更改不影响现有隧道：&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;未检测到 NAT 且使用 UDP 端口 &lt;code&gt;500&lt;/code&gt; 的隧道继续像以前一样运行。&lt;/li&gt;
&lt;li&gt;配置为在 UDP 端口 &lt;code&gt;4500&lt;/code&gt; 上启动 IKE 的隧道继续像以前一样运行。&lt;/li&gt;
&lt;li&gt;NAT 检测逻辑未发生变化。&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;有关配置详细信息，请参阅&lt;a href=&quot;https://cloudflaredoc.ubitools.com/cloudflare-wan/reference/gre-ipsec-tunnels/&quot;&gt;GRE 和 IPsec 隧道&lt;/a&gt;。&lt;/p&gt;</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate><product>Cloudflare WAN</product><category>Cloudflare WAN</category><category>Magic Transit</category></item></channel></rss>