跳转到内容
搜索文档

更新日志

Cloudflare 的最新更新与改进。

Cloudflare One Client for Linux (version 2026.4.1350.0)

A new GA release for the Linux Cloudflare One Client is now available on the stable releases downloads page.

This release introduces the new Cloudflare One Client UI for Linux! You can expect a cleaner and more intuitive design as well as easier access to common actions and information. Here are some of the many things we have found our users appreciate:

  • Right click context menu to access the most common client actions quickly
  • Built-in captive portal login experience

Changes and improvements

  • Added a new CLI command: warp-cli mdm refresh. This command executes an immediate refresh of the Mobile Device Management (MDM) configuration file.
  • Official support for RHEL 9 has been added for Cloudflare Mesh nodes. To install the RHEL 9 package, the Extra Packages for Enterprise Linux (EPEL) repository must be active, as it contains dependencies required for the tray icon and captive portal webview.

Known issues

  • Registration may hang at "Checking your organization configuration" due to IPC errors. A system reboot should resolve the error, allowing registration to proceed.
  • Split tunnel list configuration is not available in the new UI. Management of split tunnel entries is currently only possible via warp-cli tunnel ip and warp-cli tunnel host. UI support will be added in a future release.

UDP 端口 500 上的 IKE 支持 NAT-T

Cloudflare IPsec 现在支持标准 NAT 穿透(NAT-T,NAT traversal)流程,其中 IKE 在 UDP 端口 500 上启动,并在检测到 NAT 后切换到 UDP 端口 4500

以前,必须将 NAT 后面的设备配置为直接在 UDP 端口 4500 上发起 IKE。当路径中存在 NAT 时,在 UDP 端口 500 上启动的设备无法完成 IKE 握手。这需要在 VeloCloud SD-WAN 边缘、Cisco IOS-XE 路由器和 Juniper SRX 防火墙等设备上进行自定义配置,而且并非在所有平台上都可行。

已发生的变化:

  • NAT 后面的设备现在可以在 UDP 端口 500 或 UDP 端口 4500 上发起 IKE。
  • 在 UDP 端口 500 上启动 IKE 并在检测到 NAT 后切换到 UDP 端口 4500 的设备现在可以成功完成握手。
  • Cloudflare 上不需要更改配置。此更改适用于 Cloudflare WAN 和 Magic Transit 上的所有 IPsec 隧道。

此更改不影响现有隧道:

  • 未检测到 NAT 且使用 UDP 端口 500 的隧道继续像以前一样运行。
  • 配置为在 UDP 端口 4500 上启动 IKE 的隧道继续像以前一样运行。
  • NAT 检测逻辑未发生变化。

有关配置详细信息,请参阅GRE 和 IPsec 隧道