Update | Description | Release Date | Documentation |
Internet Firewall optimization | This bandwidth is automatically assumed by north-south bandwidth without separate allocation, elastic protection configurations are automatically merged, serial firewalls no longer consume general instance quotas (occupied quotas are automatically returned), bandwidth management is simplified, and bandwidth usage flexibility is improved. | 2026-07-08 | |
Traffic Log Optimization | CFW flow logs add two new columns: "Final Action" and "Access Control rule". They mark the actual allow/block result of each session after multi-module flow control (supporting differentiation between Access Control blocks and Intrusion Defense blocks) and directly display the details of the matched Access Control rule. It also supports filtering and exporting based on final action and Access Control rule ID/rule description, allows restoring the actual session results in a single view, and reduces manual cross-log comparison. | 2026-07-08 | |
Log Storage Optimization | CFW log storage settings are optimized, removing the limit on the number of modifications to retention period and storage type (only the edition restriction is retained), and adding longer retention period options of 365 days and 730 days. | 2026-07-08 | |
Enterprise Security Group Optimization | CFW Enterprise Security Group supports managing more asset instance types, improves policy delivery speed, further expands the coverage of private network micro-segmentation control, and enhances configuration efficiency. | 2026-07-08 | |
NDR AI Security Exposure Surface | NDR adds AI exposure surface and exposure surface risk detection capabilities, addressing the core operational demands of "which AI assets are exposed, on which ports they are exposed, and whether there is high-risk access". Through deep full-traffic analysis and passive identification, it identifies the port exposure paths of AI services such as large model APIs, Agents, and MCP Servers, and identifies real risks such as unauthenticated public network exposure, plaintext HTTP transmission, and overseas access. It provides a dual view of "exposure surface mapping + risk monitoring", helps enterprises transition from AI asset discovery to risk governance, and assists in the convergence of AI exposure surfaces. | 2026-07-08 | |
NDR AI Vulnerability Attack | The NDR alarm chain introduces security large model capabilities, performs intelligent secondary analysis on original alarms, improves alarm accuracy and credibility, helps security teams focus on real threats, and enhances overall security operation response capabilities. | 2026-07-08 | |
NDR Traffic Risk Analysis | NDR sensitive information detection capability is upgraded, adding 17 sensitive information detection rules such as for keys and credentials, further enriching the dimensions of sensitive information identification, improving the detection capability for data leakage risks, and helping enterprises discover and prevent sensitive data exfiltration risks in multiple aspects. | 2026-07-08 |
Update | Description | Release Date | Documentation |
Intelligent Query Writing for Log Analysis | Log Analysis introduces intelligent query writing, which supports automatically generating log query statements based on natural language descriptions. It can also explain the meaning of query statements, recommend more log analysis perspectives, intelligently diagnose and correct syntax errors, and lower the barrier to writing query statements. | 2026-06-10 | |
Optimizing Domain Name Matching for Access Control | Access Control domain name matching (FQDN match) extends the supported format for wildcard domains. In addition to the original support for wildcard domains in the format of .xxx.com, it now also supports domain name matching in the format of xx.com, covering more domain name matching scenarios. | 2026-06-10 | |
Elastic Protection for NAT/VPC Firewall | NAT/VPC Firewall (Cluster Mode) introduces elastic protection. When traffic exceeds the instance bandwidth specification, it continues to provide protection and charges based on the exceeded amount, preventing out-of-spec traffic from losing protection. | 2026-06-10 |
Update | Description | Release Date | Documentation |
NDR Traffic Collection Scope Configuration Upgrade | NDR traffic collection scope configuration is upgraded, adding an "Exclude" policy type to support precise exclusion of specific subnets from the collection CIDR blocks. The maximum number of rules is increased from 2 to 5. Priority is automatically assigned based on the policy type. | 2026-05-28 | |
NDR XFF Custom Configuration | NDR adds XFF custom configuration capability, supporting the complete display mode and precise extraction mode. It allows flexible configuration of the XFF field and IP address extraction sequence based on domain name rules, enabling accurate identification of the real client IP address behind a proxy. | 2026-05-28 | |
NDR AI Security Scenario Protection | NDR adds AI security scenario protection, covering five major scenarios: AI asset inventory, AI data leakage, malicious Skill poisoning, AI vulnerability attacks, and AI traffic auditing, helping enterprises build an AI business security system. | 2026-05-07 | |
NDR AI Traffic Audit | NDR adds AI traffic auditing capability. Through deep analysis and passive identification of AI traffic, it completely retains full traffic logs, achieving full traceability and auditing of AI business traffic. | 2026-05-07 | |
NDR Core Module Upgrade | NDR completes the upgrade of core modules including traffic access, threat detection, file sandbox detection, traffic risk analysis, asset fingerprinting, and protocol parsing and storage. It optimizes the page layout and underlying logic, comprehensively improving product usability and operational efficiency. | 2026-05-07 | |
NAT Firewall supports cluster mode. | NAT Firewall supports cluster mode and natively protects cross-VPC north-south public network traffic that is forwarded to the NAT Gateway via CCN under the "centralized egress" network architecture. | 2026-05-07 |
Update | Description | Release Date | Documentation |
Access Control rule supports domain name templates. | Access Control rule supports domain name templates. It supports directly referencing domain name templates in FQDN match, loose match, and strict match modes, improving batch configuration and management efficiency in scenarios with a large number of domain names. | 2026-04-01 | |
Log Analysis adds the alarm policy feature. | Log Analysis adds the alarm policy feature. It supports configuring custom SQL alarm policies based on various traffic and security logs from CFW, allows setting flexible trigger conditions and execution cycles, and enables receiving alarm notifications in real time through the observability platform. | 2026-04-01 | |
NAT/VPC boundary rate limiting rule supports rate limiting mode. | NAT/VPC boundary (primary/secondary) rate limiting rule supports rate limiting mode. Users can flexibly choose whether all IP addresses in the CIDR blocks share the same rate limit or each IP address has its own dedicated rate limit. | 2026-04-01 | |
NDR outbound traffic sensitive data detection | NDR adds outbound traffic sensitive data detection capability, which now covers bidirectional traffic, can comprehensively monitor sensitive data transmission, quickly discover data leakage risks, and improve data security protection levels. | 2026-04-01 | |
NDR encrypted traffic detection pre-check | NDR adds the pre-check feature before encrypted traffic detection is enabled. It can comprehensively evaluate asset bandwidth performance and Agent running status, providing a decision-making basis for enabling encrypted traffic detection. | 2026-04-01 |
Update | Description | Release Date | Documentation |
AI Agent | A new conversational security operations assistant. It supports in-depth intelligent analysis of network attacks, massive alarms, and full-network traffic, and can generate structured professional analysis reports with one click using natural language. | 2026-03-25 | |
Network Detection and Response (NDR) Capability Upgrade | AI Application Asset Auto-Identification: Automatically identifies AI applications through deep traffic analysis and monitors enterprise AI application deployment in real time. | 2026-03-25 | |
Network Detection and Response (NDR) Capability Upgrade | Malicious Skill File Detection: Uses cloud sandbox to detect Skill file behavior, automatically identifies and marks malicious threats, supports one-click blocking and isolation, and achieves risk closure. | 2026-03-25 | |
NDR Billing Model Update | The billing model for NDR has been upgraded and adjusted, adopting a new tiered pricing model where the greater the usage, the lower the unit price. | 2026-03-01 |
Update | Description | Release Date | Documentation |
Network Detection and Response (NDR) Capability Upgrade | Added file security scanning capability, which performs real-time analysis of files transmitted in traffic through Intelligence Cloud Check and cloud sandbox to accurately identify malicious files. Added AI application data leakage detection capability, which identifies the behavior of uploading sensitive information to AI applications such as ChatGPT, helping enterprises discover and prevent new types of data leakage risks. | 2026-01-15 | |
Network Detection and Response (NDR) Capability Upgrade | Added detection capability for encrypted traffic of container assets, improving security visibility in cloud-native environments. | 2026-01-15 | |
Network Detection and Response (NDR) Engine Upgrade | The detection engine has been fully upgraded with added support for RDP, QUIC, and HTTP/2 protocol parsing. A deep vulnerability scanning engine has been introduced, enhancing detection capabilities for application-layer attacks such as XSS, SQL injection, sensitive file probing, and CSRF. | 2026-01-15 | - |
Alarm Center Capability Upgrade | The alarm details page now displays a proxy IP field (including IP addresses such as X-Forwarded-For), supporting the viewing of real client IP address or proxy IP addresses, thereby improving the efficiency of security event tracing and investigation. | 2026-01-15 |
Was this page helpful?
You can also Contact sales or Submit a Ticket for help.
Help us improve! Rate your documentation experience in 5 mins.
Feedback