Skip to main content

What's New and Release Notes for 26.x

What's New in Release 26.2.20-VEN

This release provides support for the following:

Enhanced firewall tampering detection and reporting

Firewall tampering detection now reports potential tampering events to the PCE immediately upon initial detection, allowing administrators to investigate suspected tampering sooner. Event reporting now includes richer metadata, distinguish between possible and confirmed tampering, track repeated detections, and use aggregation logic to reduce noise from recurring events.

For more information, see VEN Firewall Tampering Detection.

PCE NLA for Domain-Joined Windows Endpoints

Note

This functionality is applicable only to Endpoint VENs. It doesn't apply to Server VENs or C-VENs.

Illumio now supports PCE-based Network Location Awareness (PCE NLA) for domain-joined Windows endpoints, helping secure hybrid and remote workforces regardless of where they work.

This supports a combined scenario when:

  • Domain-joined Windows endpoints move from on-campus to remote

  • Distinct on-campus versus off-campus policy enforcement is needed

  • Netskope Private Access clients are in-place for egress enforcement

PCE NLA for domain-joined Windows Endpoints requires organization-wide configuration and applies to all VENs paired for that organization. On-Prem customers enable this feature with a north-bound API call. SaaS customers must contact Illumio to create an OPS ticket. For details, see Network Location Awareness (NLA) Support for Endpoints.

Adaptive User Segmentation: Continued Enforcement if PCE is Unreachable

Note

This functionality is supported with the following PCE and VEN combinations: PCE 26.2.10 and later & VEN 26.2.12 and later.

The Adaptive User Segmentation (AUS) now maintains policy enforcement even when the PCE is temporarily unreachable.

Previously, the VEN required a live PCE connection to report user status and fetch the needed AUS policy. With this release, the enforcement layer proactively fetches and caches AUS policy for all configured user groups, so rules are available locally and enforced even if the PCE is unreachable.

This applies to both supported integration types:

  • Microsoft Entra ID environments, where group and user data is automatically synced to the PCE via the UGM service.

  • Microsoft Active Directory environments, where groups are manually configured in the PCE.

When the PCE comes back online, AUS policy is refreshed automatically and normal enforcement resumes without dropping existing sessions.

AUS policy resilience applies at the PCE cluster level and defaults to off. To enable this feature, add the following to the PCE runtime_env.yml, then restart the PCE.

agent_service:
aus_resiliency_enabled: true

For more about AUS generally, see Adaptive User Segmentation in the Security Policy Guide.

Linux Outbound Process-Based Traffic Enforcement

Linux Outbound Process-based traffic enforcement now recovers automatically across VEN restarts, binary updates, symlink changes, and container contexts. Policy changes are logged with source attribution, tamper detection, optional auto-remediation, and JSON audit output for SIEM ingestion.

See Linux Process-Based Flow Visibility and Outbound Policy Enforcement.

Support for Ubuntu 26.04

Beginning with this release, VENs are now supported for use on workloads running Ubuntu, version 26.04.

Support for Endpoint VENs on macOS Golden Gate, v27

Beginning with this release, Endpoint VENs are now supported for use on workloads running macOS Golden gate, version 27.

VEN RHEL 9+ FIPS 140-3 Readiness

The VEN for RHEL 9 and later is FIPS 140-3-ready.