> For the complete documentation index, see [llms.txt](https://docs.link11.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.link11.com/welcome/release-notes.md).

# Release Notes

## June 2026 <a href="#june-2026" id="june-2026"></a>

### Fixes

* **Web DDoS configuration**: Resolved two issues where instances could not be re-configured due to certificate-related issues. (2 June, 3 June)&#x20;
* **False positives from TikTok**: Resolved an issue in Zero Touch WAF where requests with TikTok cookies were incorrectly being blocked. (1 June)&#x20;

## May 2026 <a href="#may-2026" id="may-2026"></a>

### What's New

* **WAAP/Secure CDN Certificate Mapping**: For customers using both Link11 WAAP and Secure CDN, an existing WAAP certificate — whether from Let's Encrypt or a customer-uploaded custom certificate — can now be used directly by a Secure CDN instance instead of generating and renewing a separate certificate for it. (11 May)&#x20;

### Fixes

* **CDN-origin error reporting**: Resolved an issue that could arise when Secure CDN was unable to communicate with the customer origin. Although the error would be logged, it was not appearing in the Dashboard. (27 May)&#x20;
* **Intermediate certificate uploads**: Resolved an issue where uploading an intermediate certificate would appear to succeed, but internally would fail. (26 May)&#x20;

## April 2026 <a href="#april-2026" id="april-2026"></a>

### What's New

* **CDN cache key customization**: Secure CDN customers can now [specify the structures of cache keys](/product-guides/secure-cdn/interface/instances/cdn-location-cache-key.md) on a per-location basis. The keys map cached content to client requests; custom structures are useful for optimizing cache hit rates. (29 April)
* **CDN caching control**: In Secure CDN, a [new set of configuration options](/product-guides/secure-cdn/interface/instances/cdn-location-caching-settings.md) now provides granular control over caching behavior, including accepting or overriding origin caching instructions. (20 April)
* **Rerouting notifications**: Previously in Netflow DDoS Detector, notifications were sent when a Reroute Reason was triggered, even if a traffic limit had not been violated. Now, for a notification to be sent, at least one Reason must be triggered and at least one limit must be exceeded. (20 April)
* **DNS Dashboard**: Secure DNS now includes a [Dashboard](/product-guides/secure-dns/interface/dashboard.md), displaying DNS requests in the specified time period. For this release, two metrics are shown: the total requests across all zones and the ten "top talker" zones. For each metric, more granular values are available as well: the total requests and requests per second, for individual time segments or zones. (14 April)

### Fixes

* **False Positive alarm reduction**: Resolved an issue in Zero Touch WAF where encoded authentication-related cookie data was being inspected for threat signatures, and could trigger an alarm. (24 April)
* **Rerouted prefix display**: Resolved an issue in Netflow DDoS Detector where a rerouted prefix might not be available for manual rerouting in the *Rerouted* section of the *Config* page. (15 April)

## March 2026 <a href="#march-2026" id="march-2026"></a>

### What's New

* **Reroute Limits display**: Within Netflow DDoS Detector's Config Reroute Limits page, the prefix list is now sorted: first by subnet size, then in IP order. (24 March)
* **Certificate Generation/Renewal using DNS**: In Secure CDN, DNS challenges are now supported for certificate generation. (23 March)

### Fixes

* **BGP Session Settings**: Resolved an issue in Netflow DDoS Detector where enabling the optional session settings would require all settings to be defined. (2 March)

## February 2026 <a href="#february-2026" id="february-2026"></a>

### What's New

* **Additional flexibility for dynamic traffic routing**: In Netflow DDoS Detector, customers can now announce prefixes on behalf of entities with origin ASNs that are different than the customer's configured ASN. (23 February)
* **Server Name Indication support**: In Secure CDN, customers can now enable SNI, ensuring correct certificate usage for multi-tenant backends. (17 February)

### Fixes

* **Rerouting visibility**: Resolved an issue in Netflow DDoS Detector where a rerouting advertisement was performed, but it did not appear in the *Rerouted* section of the WebGUI interface. (23 February)
* **URL Whitelisting**: Resolved an issue in Web DDoS where certain clients were being blocked as bots, even though their destination URL paths had been whitelisted. (19 February)
* **Response times**: Resolved an issue in Web DDoS where an HTTP 100 response could result in large response times. (17 February)
* **Unblocking IPs**: Resolved an issue in Web DDoS where it was not possible to unblock false-positive IPs that were in peacetime mode. (9 February)
* **Netflow DDoS Detector history**: Resolved an issue where the rerouting history would not be shown for customers which have a different BGP remote IP than a Netflow receiver IP. (9 February)

## January 2026 <a href="#january-2026" id="january-2026"></a>

### What's New

* **CAA record support**: Secure DNS now supports Certification Authority Authorization `issue`, `issuewild`, and `iodef` records. (20 January)
* **AS-path override**: In Network DDoS Detector's BGP route customization, specifying the `34309:2920` community will override all other settings and set the AS-path to Link11's ASN. (7 January)

### Fixes

* **Attack reports**: Resolved an issue where attacks were blocked and alarm notifications were sent, but attack reports were not being delivered. (15 January)
* **Alarming tests**: Resolved an issue where contacts within an Alarming rule would not receive test notification messages. (13 January)
* **False Positives**: Resolved two issues where specific cookie values could trigger blocking by Zero Touch WAF. (6 January)
* **SSL certificate uploads**: Resolved an issue in Secure CDN where an uploaded certificate was not being delivered. (2 January)

## December 2025 <a href="#december-2025" id="december-2025"></a>

### What's New

* **Enhanced traffic engineering**: Network DDoS Detector now offers [BGP route customization](/product-guides/netflow-ddos-detector/interface/config.md). Customers can configure AS Path Prepend, Next Hop, and BGP Communities for route injection (both automated and manual), with per-router granularity. (4 December)

### Fixes

* **Wildcard certificate auto-renewal**: Resolved an issue where wildcard certificates would not be auto-renewed from DNS challenges. (16 December)
* **Domain validation**: Resolved an issue that could potentially cause timeouts for HTTP-01 challenges for multiple domains using Secure CDN. (16 December)
* **Manual rerouting**: Resolved an issue in Netflow DDoS Detector that prevented immediate execution of manual route withdrawals if a previous automatic route removal had been scheduled. (3 December)
* **Rerouting history**: Resolved an issue in Netflow DDoS Detector where incorrect times were shown in the netflow rerouting history. (3 December)
* **Rerouting status**: Resolved an issue in Netflow DDoS Detector where prefixes that had been rerouted were still displayed as "Not Rerouted". (3 December)

## November 2025 <a href="#november-2025" id="november-2025"></a>

### What's New

* **DNSSEC support**: Secure DNS now supports Domain Name System Security Extensions, which uses cryptographic signatures to secure the transmission of DNS information and prevent attacks such as cache poisoning and spoofing. (25 November)
* **Inactive BGP sessions**: Netflow DDoS Detector now ignores BGP sessions without a status of `active` during automatic rerouting, manual rerouting, and startup reannouncements. (25 November)
* **AXFR Hidden Masters**: Secure DNS now includes a whitelist for IPs that can send NOTIFY messages for AXFR zone transfers. Currently, the Hidden Master list is offered for configuration only; starting in January, whitelisting will be enforced, and messages from non-listed IPs will be rejected. (11 November)

### Fixes

* **Hidden master whitelists**: Resolved an issue in Secure DNS that prevented the addition of IP whitelists. (27 November)
* **Secure CDN domain settings**: Improved the error-handling when customers enter incorrect domain information. (19 November)
* **BGP session info**: Resolved an issue in Network DDoS where sessions could be shown with incorrect ASNs. (15 November)
* **Rerouting History**: Resolved an issue in Netflow DDoS Detector where duplicate entries could appear in the rerouting history. (3 November)

## October 2025

### What's New

* **DNS server hardening**: Enabled Response Rate Limiting on secondary DNS servers to prevent reflection amplification attacks. (29 October)

### Fixes

* **Certificate renewal**: Resolved an issue in Secure CDN where auto-renewal was not occurring for all domains/hosts for a given instance. (28 October)
* **Secure CDN monitoring**: Improved the robustness of internal CDN node monitoring across IPv6. (24 October)
* **DNSSEC in Secure DNS**: Resolved an issue where DNSKEY records across authoritative nameservers could become inconsistent. (9 October)
* **Secure CDN configuration**: Resolved an issue where node configurations could differ when geoblocking was enabled. (2 October)
* **DNS configuration**: In Secure DNS, improved the validation of user inputs when configuring domains. (1 October)

## September 2025

### What's New

* **Client IP retention**: Client requests arriving via Secure CDN now have the original IPs preserved in XFF headers, enabling Link11 WAAP to include this information in logs, analytics, etc. (22 September)

### Fixes

* **Subdomain definition**: Resolved an issue in Secure CDN preventing the creation of subdomains in certain circumstances. (23 September)
* **Web DDoS analytics**: Resolved an issue where the Dashboard was providing attack details in requests per minute instead of requests per second. (13 September)
* **Active CDN nodes**: Resolved an issue where Link11 WAAP could retain IPs of CDN nodes that no longer exist. (5 September)
* **False Positive alarms**: Resolved an issue where WAF was incorrectly blocking requests containing Tik Tok session cookies. (2 September)

## August 2025

### What's New

* **Reverse zone updates**: In Secure DNS, reverse zone SOA records are now updated only as needed, rather than periodically. (21 August)
* **IPv6 reverse zones**: Secure DNS fully supports reverse zones for IPv6, including in WebGUI. (20 August)
* **AXFR security**: In Secure DNS, AXFR NOTIFY messages must pass internal ACL verification before being accepted. (19 August)&#x20;
* **Zone replication**: Secure DNS now monitors SOA records across primary and secondary servers, ensuring that any replication issues can be addressed immediately. (18 August)

### Fixes

* **SOA records**: Resolved an issue in Secure DNS where timezone issues could cause problems generating SOA serials. (29 August)

## July 2025 <a href="#july-2025" id="july-2025"></a>

### What's New

* **More granular configuration for CDN:** Cache strategies can now be tailored more precisely to your architecture. Cache and other settings can now be applied to locations/paths according to exact match, regex patterns, recursively, or in any combination of these. **Note**: as part of this release, we are discontinuing support for the file extension location type, which was previously used to apply cache settings to specific file types (e.g., .js, .png). File extension settings are now specified using [regex locations](/product-guides/secure-cdn/interface/instances.md#using-regex-to-match-file-types). (29 July)
* **NSEC3 support**: Secure DNS now supports NSEC3, making brute-force enumeration computationally expensive. (29 July)
* **Customer escalation roles**: Contacts within Link11 now have an escalation level. Escalations will follow a defined call chain starting at Level 1 and progressing upward only if necessary. (16 July)
* **New names for two Link11 solutions**: The Infrastructure DDoS and Cloud Insights solutions have been renamed to Network DDoS and Netflow DDoS Detector, respectively. (8 July)
* **Additional MIME types for CDN compression**: In Secure CDN, admins can now specify custom file types for compression, and the list of default types has been expanded. (7 July)

### Fixes

* **Client IP visibility**: Resolved an issue in Web DDoS where CDN node IPs were being saved in access logs instead of client IPs. (27 July)
* **Prefix rerouting**: In Netflow DDoS Detector, resolved an issue that could occur when rerouting a prefix that was still included in an associated BGP session. (21 July)
* **Traffic visibility**: Resolved an issue where traffic data was not shown correctly in Netflow DDoS Detector's Dashboard. (21 July)
* **Events from IPv6 addresses**: Resolved an issue where IPv6 addresses were not being shown correctly in WebGUI. (1 July)

## June 2025

### What's New:

* **ANAME support**: Secure DNS now supports ANAME records, which are useful for apex (root) domains and CNAME flattening. (3 June)

## May 2025

### What's New:

* **Geographic enabling/disabling of CDN nodes:** Admins can now prevent Secure CDN from storing/caching content in servers within designated countries, nor will end users be able to connect to those nodes. (5 May)

### Fixes

* **TLS certificates**: Resolved an issue where auto-renewal of TLS certificates could fail. (12 May)

## April 2025

### What's New:

* **Netflow Traffic Anomalies**: The interface has been clarified to reduce potential uncertainty about traffic rerouting. (15 April)

### Fixes:

* **Date/time ranges for data display**: Resolved an issue where WebGUI's date/time selector was not correctly handling changes in time zones. (30 April)

## March 2025

### What's New:

* **Reduced database workloads**: PDF reports are now generated with a limit of up to three simultaneous connections, and there is a new one-hour buffer between cron jobs for daily and weekly reports. These changes will reduce the load on the database. (25 March)

### Fixes:

* **Web DDoS:** Resolved an issue where client uploads were failing due to size, despite the data being within the *Max POST Size* limit. (2 April)
* **Dashboards**: Resolved an issue where timeframe selection menus were not working correctly. (10 March)
* **Secure DNS**: Resolved an edge case that could prevent a name server from finding a domain. (4 March)

## February 2025

### What's New:

* **Improved bandwidth reporting**: In WebGUI, bandwidth reporting now precisely reflects internal calculations. Previously, general labels (GB, MB, KB) had been used in the interface; now, more precise labels (GiB, MiB, KiB) are shown. (27 February)

### Fixes:

* **Netflow Analytics**: Resolved an issue where the Netflow DDoS Detector Dashboard was reporting incorrect packet metrics. (12 February)
* **Blocklist display**: Resolved an issue in Network DDoS where the blocklist was showing the same entries on all pages. (10 February)
* **Editing DNS records**: Resolved an issue in Secure DNS where once a subdomain record was created, its record type could not be changed. (6 February)

## January 2025

### What's New:

* **Smart Routing minimum cooldown periods**: Netflow DDoS Detector's Smart Routing now requires a minimum cooldown period of 15 minutes. This mitigates the risk of multiple cycles of routing and rerouting during repeated attacks. (21 January)
* **Improved AS visibility for BGP Sessions**: In Network DDoS, customers with multiple Autonomous Systems under protection can now easily see the ASN under which each prefix would be announced during an attack. (20 January)
* **Default Smart Routing behavior**: Previously in Netflow DDoS Detector, rerouting behavior had to be specified for each defined prefix range, which could be time-consuming for a large number of ranges. Now, Smart Routing includes default policies for `0.0.0.0/0` and `::/0`. These specify the behavior for all prefixes that are not explicitly defined otherwise. (19 January)

### Fixes:

* **CAPTCHA Template usage**: Resolved an issue in Web DDoS where customized CAPTCHA pages were not being used by the system. (31 January)
* **Restored HTTP/2 support on Secure CDN**: Resolved an issue that was recently introduced by a config update, which was preventing HTTP/2 from working. (21 January)
* **IP blocking**: Resolved an issue where under certain circumstances during an attack, Network DDoS was not blocking IPs that should have been blocked. (17 January)

## December 2024

### What's New:

* **Increased granularity for traffic rerouting**: Netflow DDoS Detector now offers greater control over Smart Routing. Admins can now specify different parameters (such as cooldown times) for subnets or even individual IPs within a subnet. (12 December)

## November 2024

### Fixes:

* **Web DDoS**: Clarified an error message that's displayed when the TLS certificate expires for an instance. Previously, the certificate was only noted as being invalid. (18 November)

## October 2024

### What's New: <a href="#august2024-whatsnew" id="august2024-whatsnew"></a>

* **Netflow DDoS Detector:** Added [Smart Routing](/product-guides/netflow-ddos-detector/interface/smart-routing.md), a feature to make it easier to configure and manage the automated releasing of traffic back to its original routing after an attack. (21 October)
* **Secure CDN**: Added a new Geo Blocking feature. (10 October)

## August 2024

### What's New: <a href="#august2024-whatsnew" id="august2024-whatsnew"></a>

* **Network DDoS:** Admins can now access API keys in the WebGUI and manage the whitelist of allowed source IPs.
* **Secure CDN**: Access Logs are now available for Secure CDN: a display of all requests made per Instance/Domain to the CDN in the specified period. Log entries include details of the requests and their sources, cache statuses for the requested resources, processing results, and more.

## July 2024

### What's New: <a href="#july2024-whatsnew" id="july2024-whatsnew"></a>

* **Web DDoS**: The URL Whitelist feature (which whitelists all traffic to a specific destination) now supports regex. For example, `/op-content/*/public` will whitelist `/wp-content/media/public` but not `/wp-content/media/private`. This is not currently available in the WebGUI; if you wish to use this feature, contact support. (16 July)
* **Netflow DDoS Detector**: The manual routing timeout (enforced between additions/removals and vice versa, to prevent route flapping) was reduced from 60 minutes to 15 minutes. (8 July)
* **WebGUI**: For C5 compliance, when a user password is changed, an email is now sent to that user informing them of this. (8 July)

### Fixes: <a href="#july2024-fixes" id="july2024-fixes"></a>

* **WAF**: Resolved an issue where modsecurity log entries were being truncated when variable values were too long. (16 July)
* **WAF**: Resolved an issue where WebDAV requests were being blocked. (LOCK requests without a "Content Length" parameter were being rejected.) (16 July)

## June 2024

### What's New: <a href="#june2024-whatsnew" id="june2024-whatsnew"></a>

* **Web DDoS**: The `DDoS ASN Blocking` list now supports Autonomous Systems that exclusively contain IPv6 networks. (25 June)
* **Web DDoS**: `Max POST Size` limit has been increased to 3 GB. (19 June)
* **Web DDoS**: Added a new configuration option to disable client renegotiations, thus preventing a potential CVE-2021-3449 vulnerability for the client. (June 18)
* **Network DDoS** / **Netflow DDoS Detector**: Added an API endpoint to manually trigger a reroute. (June 1)

### Fixes: <a href="#june2024-fixes" id="june2024-fixes"></a>

* **Netflow DDoS Detector**: Resolved an issue that prevented the addition of new reroute limits. (25 June)
* **WebGUI**: Resolved a database deadlock that could occur when a user password was reset. (25 June)
