What's New in Release 26.2.20-VEN
This release provides support for the following:
Enhanced firewall tampering detection and reporting
Firewall tampering detection now reports potential tampering events to the PCE immediately upon initial detection, allowing administrators to investigate suspected tampering sooner. Event reporting now includes richer metadata, distinguish between possible and confirmed tampering, track repeated detections, and use aggregation logic to reduce noise from recurring events.
For more information, see VEN Firewall Tampering Detection.
PCE NLA for Domain-Joined Windows Endpoints
Note
This functionality is applicable only to Endpoint VENs. It doesn't apply to Server VENs or C-VENs.
Illumio now supports PCE-based Network Location Awareness (PCE NLA) for domain-joined Windows endpoints, helping secure hybrid and remote workforces regardless of where they work.
This supports a combined scenario when:
Domain-joined Windows endpoints move from on-campus to remote
Distinct on-campus versus off-campus policy enforcement is needed
Netskope Private Access clients are in-place for egress enforcement
PCE NLA for domain-joined Windows Endpoints requires organization-wide configuration and applies to all VENs paired for that organization. On-Prem customers enable this feature with a north-bound API call. SaaS customers must contact Illumio to create an OPS ticket. For details, see Network Location Awareness (NLA) Support for Endpoints.
Adaptive User Segmentation: Continued Enforcement if PCE is Unreachable
Note
This functionality is supported with the following PCE and VEN combinations: PCE 26.2.10 and later & VEN 26.2.12 and later.
The Adaptive User Segmentation (AUS) now maintains policy enforcement even when the PCE is temporarily unreachable.
Previously, the VEN required a live PCE connection to report user status and fetch the needed AUS policy. With this release, the enforcement layer proactively fetches and caches AUS policy for all configured user groups, so rules are available locally and enforced even if the PCE is unreachable.
This applies to both supported integration types:
Microsoft Entra ID environments, where group and user data is automatically synced to the PCE via the UGM service.
Microsoft Active Directory environments, where groups are manually configured in the PCE.
When the PCE comes back online, AUS policy is refreshed automatically and normal enforcement resumes without dropping existing sessions.
AUS policy resilience applies at the PCE cluster level and defaults to off. To enable this feature, add the following to the PCE runtime_env.yml, then restart the PCE.
agent_service: aus_resiliency_enabled: true
For more about AUS generally, see Adaptive User Segmentation in the Security Policy Guide.
Linux Outbound Process-Based Traffic Enforcement
Linux Outbound Process-based traffic enforcement now recovers automatically across VEN restarts, binary updates, symlink changes, and container contexts. Policy changes are logged with source attribution, tamper detection, optional auto-remediation, and JSON audit output for SIEM ingestion.
See Linux Process-Based Flow Visibility and Outbound Policy Enforcement.
Support for Ubuntu 26.04
Beginning with this release, VENs are now supported for use on workloads running Ubuntu, version 26.04.
Support for Endpoint VENs on macOS Golden Gate, v27
Beginning with this release, Endpoint VENs are now supported for use on workloads running macOS Golden gate, version 27.
VEN RHEL 9+ FIPS 140-3 Readiness
The VEN for RHEL 9 and later is FIPS 140-3-ready.