Compare Products
Hide
VS
|
Version Number |
NGFW_NTOS1.0R14 |
|
Version Type |
Official version |
|
Applicable Product |
RG-CF10S RG-CF10S-LTE RG-CF30XS RG-CF50XS |
|
Applicable Customer |
General |
|
Release Type |
Official release |
|
Release Date |
July 24, 2026 |
|
Baseline Version Number |
NGFW_NTOS1.0R13 |
|
Description |
Official release |
|
Feature |
Description |
|
New hardware support |
This version supports the RG-CF50XS. |
|
NAT64/NAT66 |
NAT64 and NAT66 support active-standby synchronization in high availability (HA) scenarios. |
|
Application identification |
The maximum number of custom application groups has been expanded to 150. |
|
DDoS |
DDoS protection is supported for SYN packets of the SSL VPN service. |
|
SSL proxy |
The maximum number of concurrent SSL proxy sessions for the RG-CF50XS has been increased. |
|
DHCP service |
The DHCP service supports Options 66 and 67. |
|
GRE |
The IP address of the local loopback interface can be configured as the source address of a GRE tunnel. |
|
PPPoE client |
The PPPoE dial-up status and logs can be queried. Service Name can be configured. |
|
User authentication |
l The authentication feature on Cybrey Cloud supports account-based rate limiting. l Ruijie Cloud and Cybrey Cloud support local voucher authentication. l Supports integration with the property management system (PMS). |
|
Dynamic routing |
Supports basic BGP capabilities. |
|
Web-based authentication |
l Web-based authentication logs are supported, including connection and disconnection reason fields. l Logs can be viewed on the web interface. |
|
Web usability |
Device names can be configured on the web interface. Device names can be displayed on the home page. Device names can be displayed on the browser tabs. |
|
Syslog |
The Syslog functionality is improved and the types of logs that can be forwarded are expanded. l The source IP address or source interface can be selected for forwarding logs via Syslog. l The types of logs that can be forwarded via Syslog are expanded, including operation logs, SSL VPN logs, and IPsec VPN logs. |
|
AI-based threat detection |
AI-based threat detection capabilities are enhanced to detect abnormal heartbeat callback behaviors in outbound TCP-encrypted protocol traffic. |
|
Traffic control policy |
Policies based on source MAC addresses are supported. |
|
PBR |
Policies based on source MAC addresses are supported. |
|
Patch upgrade |
Forced patch upgrades are not supported; automatic and manual patch upgrades are supported. |
|
URL library |
Local URL libraries are supported. |
|
Web |
The web interface supports Indonesian and Turkish. |
|
SSL VPN |
The configuration page for SSL VPN tunnel resources has been optimized to improve usability. |
|
Security policy |
All regions can be selected on the configuration page for security policies. |
|
Alarm |
When multiple WAN ports belong to the same subnet, alarms are no longer displayed on the web home page. |
|
Defaults restoration |
A prompt is added to the Defaults Restoration page, reminding users that personal information can be deleted after the operation. |
|
User authentication |
Passwords containing ruijie (case-insensitive) are not supported. |
|
Operation logs |
After the IP allowlist/blocklist or custom threat intelligence configuration is modified, the operation log description includes detailed modification information, making it easier to compare the configuration before and after the modification. |
|
VPN |
l A mechanism for detecting idle tunnels is supported for IPsec VPN. l Response speed for SSL VPN access to management devices has been improved. |
|
Compliance |
Individual Internet access information can be queried and downloaded based on IPv4 or IPv6 addresses. |
|
Behavior analysis |
Some features (including IM, search engines, microblogs, forums, and web email) are removed from behavior analysis, and their corresponding web pages are removed as well. |
|
Threat intelligence |
Logs can be aggregated based on intelligence categories. |
|
Security policy |
The policy list supports viewing address, address groups, services, service groups, users, user groups, and user tags, and allows quick editing. |
|
WAF |
Supports URL and Base64 decoding as well as gzip decompression, improving the rule-based detection capabilities. |
|
Interface |
A mechanism is added to handle IPv4 subnet conflicts between LAN and WAN ports. |
|
Security dashboard |
IPS, AV, and WAF cards are added to the security dashboard. |
|
Bug ID |
Description |
|
After the DHCP address assignment is configured, the copy running startup command must be executed to save the configuration. Otherwise, the configuration is lost when the device is powered off or restarted. |
|
|
The session statistics of ICMP Echo Request packets are abnormal. |
|
|
The idle-time logout function for authenticated users needs optimization when the device has been running for a long period. |
|
|
When DDoS SYN flood protection is triggered, certain non-standard IPv6 packets may cause the DDoS function to operate abnormally. |
|
|
In a routing loop scenario, endpoints can access and manage the local device through the address configured on an interface in Down state. |
|
|
The data displayed for the same day in the attack trend card on the home page is inconsistent between the Recent 7 Days and Recent 24 Hours views. |
|
|
When a port mapping rule is configured, the automatically generated security policy uses any as both the source address object and destination address object. |
|
|
The IP address conflict check is not performed on the destination IP address of a GRE tunnel. When the destination IP address of a tunnel is consistent with the IP address configured on the SSL VPN gateway, no IP address conflict prompt is displayed, resulting in the failure of the GRE over IPsec service. |
|
|
After an interface is added to a security zone, it cannot be added as a member of an aggregate interface. The web interface prompts that the interface must be removed from the security zone before it can be added to the aggregate interface. |
|
|
When the exported log content contains invalid characters, the export fails. |
|
|
Under high database load, some traffic report content is missing. |
|
|
When the variable-bindings field in an SNMP request packet is empty, the device cannot receive the corresponding response packet. |
|
|
Users must read and accept the user privacy policy before they can log in. |
|
|
In the WiFiDog V1 authentication scenario, non-UTF8 characters in the account name cause abnormal log display. |
|
|
When all features in Content Security are disabled, HTTP requests with excessively long headers may cause high CPU usage. |
|
|
Cloud-based analysis is unstable, and its timeouts may cause a memory leak. |
|
|
Hardware encryption/decryption fails for the SSL proxy. |
|
|
After flow control is enabled, traffic may fail to match the corresponding flow control policy due to incorrect URL identification. |
|
|
In the security policy simulation space, clicking Apply to Real Network twice consecutively causes the real policies to be cleared. |
|
|
SA creation fails due to device capacity limitations, resulting in service interruption. |
|
|
In an IPsec VPN active/standby tunnel scenario with multiple peers, stale states during peer switching cause abnormal tunnel status. |
|
|
SSL VPN tunnels cannot forward oversized single packets (greater than or equal to 28,000 bytes). |
|
|
Entries with empty hardware signatures cannot be deleted on the Hardware Signature management page. |
|
|
The promiscuous mode is enabled on the MGMT port by default, which may cause it to receive a large number of junk frames from connected devices. This leads to frequent system interruptions and high CPU utilization. |
This version is for customers only.
If you are not using this software in , to avoid being unable to use it after upgrading, we recommend that you select another version.
Ruijie Networks websites use cookies to deliver and improve the website experience.
See our cookie policy for further details on how we use cookies and how to change your cookie settings.
Cookie Manager
When you visit any website, the website will store or retrieve the information on your browser. This process is mostly in the form of cookies. Such information may involve your personal information, preferences or equipment, and is mainly used to enable the website to provide services in accordance with your expectations. Such information usually does not directly identify your personal information, but it can provide you with a more personalized network experience. We fully respect your privacy, so you can choose not to allow certain types of cookies. You only need to click on the names of different cookie categories to learn more and change the default settings. However, blocking certain types of cookies may affect your website experience and the services we can provide you.
Through this type of cookie, we can count website visits and traffic sources in order to evaluate and improve the performance of our website. This type of cookie can also help us understand the popularity of the page and the activity of visitors on the site. All information collected by such cookies will be aggregated to ensure the anonymity of the information. If you do not allow such cookies, we will have no way of knowing when you visited our website, and we will not be able to monitor website performance.
This type of cookie is necessary for the normal operation of the website and cannot be turned off in our system. Usually, they are only set for the actions you do, which are equivalent to service requests, such as setting your privacy preferences, logging in, or filling out forms. You can set your browser to block or remind you of such cookies, but certain functions of the website will not be available. Such cookies do not store any personally identifiable information.
Contact Us
How can we help you?