| [ Web Proxy ] |
| Viewing: https://developers.cloudflare.com/cloudflare-one/changelog/cloudflare-network-firewall/ | [Back] [Original] |
Cloudflare Advanced Network Firewall IP lists, IDS, and SIP rules are now supported for accounts using Unified Routing mode. These features require a Cloudflare Advanced Network Firewall subscription.
Support for additional features - Threat Intel Lists, Rate Limiting, and Managed Rulesets - is planned.
For the full list of current beta limitations, refer to Traffic steering beta limitations.
Cloudflare Advanced Network Firewall Country rules are now supported for accounts using Unified Routing mode. This feature requires a Cloudflare Advanced Network Firewall subscription.
You can create firewall rules that match traffic based on source or destination country to enforce geographic access policies across your network.
This is the first of the Cloudflare Advanced Network Firewall features to become available in Unified Routing. Support for additional features - IP Lists, ASN Lists, Threat Intel Lists, IDS, Rate Limiting, SIP, and Managed Rulesets - is planned.
For the full list of current beta limitations, refer to Traffic steering beta limitations.
We are updating naming related to some of our Networking products to better clarify their place in the Zero Trust and Secure Access Service Edge (SASE) journey.
We are retiring some older brand names in favor of names that describe exactly what the products do within your network. We are doing this to help customers build better, clearer mental models for comprehensive SASE architecture delivered on Cloudflare.
No action is required by you all functionality, existing configurations, and billing will remain exactly the same.
For more information, visit the Cloudflare One documentation.
The Network Services menu structure in Cloudflare's dashboard has been updated to reflect solutions and capabilities instead of product names. This will make it easier for you to find what you need and better reflects how our services work together.
Your existing configurations will remain the same, and you will have access to all of the same features and functionality.
The changes visible in your dashboard may vary based on the products you use. Overall, changes relate to Magic Transit , Magic WAN , and Magic Firewall .
Summary of changes:
If you would like to provide feedback, complete this form . You can also find these details in the January 7, 2026 email titled [FYI] Upcoming Network Services Dashboard Navigation Update.
Preview:
[Networking Navigation]
Magic Firewall now supports a new managed list of Cloudflare IP ranges. This list is available as an option when creating a Magic Firewall policy based on IP source/destination addresses. When selecting "is in list" or "is not in list", the option "Cloudflare IP Ranges" will appear in the dropdown menu.
This list is based on the IPs listed in the Cloudflare IP ranges . Updates to this managed list are applied automatically.
[Cloudflare IPs Managed List]
Note: IP Lists require a Cloudflare Advanced Network Firewall subscription. For more details about Cloudflare Network Firewall plans, refer to Plans.
The Magic Firewall dashboard now allows you to search custom rules using the rule name and/or ID.
[Search for firewall rules with rule IDs]
Additionally, the rule ID URL link has been added to Network Analytics.
New UI improvements
The dashboard now displays the order number of custom rules, and improved drag and drop functionality. You can also preview rules on a side panel without leaving the current page.
Cloudflare Network Firewall Analytics Rule Log Enhancement
Customers who create a rule in a disabled mode will see the rule as Log (rule disabled).
| Web Proxy Viewer | New URL | Original Page |