Changelog

Release notes for every vConfig version delivered over OTA.

v26.09.158 2026-09-23

  • Fix: after a device rename, a backbone link silently disappeared because the new record had no room - sync results now name devices without a room
  • Auto-discovery gets an auto-link-room switch (on by default): devices whose hostname carries a room code are linked to that room, creating it if needed

v26.09.156 2026-09-22

  • Price calculator is now available to read-only and ops roles - discount factors are view-only for them
  • Calculation history gets a discount column and one-click row copy - the estimate card shows the route and can be copied
  • Fix: search boxes accepted only one character at a time because re-rendering replaced the input - focus and caret are now restored site-wide and IME composition is no longer interrupted

v26.09.154 2026-09-21

  • Custom dashboards get a board-wide time range that switches every chart at once - each chart can still be adjusted on its own
  • Dashboard time ranges now match the traffic graph page exactly - from last 5 minutes to last year plus today, yesterday, this or last week, this or last month and this year
  • Fix: read-only users saw no data in custom dashboard widgets
  • Fix: the realtime traffic endpoint did not check read permission

v26.09.152 2026-09-21

  • Fix: roles with dashboard edit permission could not create dashboards - write checks in 20 modules now use each module's own permission
  • Fix: links between two newly added devices were missing from the topology map
  • Removed the standalone Reports center, now merged into Dashboards (Asset overview stays)
  • Fix: a spurious 403 on every page load for read-only roles

v26.09.151 2026-09-20

  • Topology: a link between two newly added devices is now drawn automatically instead of being silently skipped

v26.09.150 2026-09-17

  • New certificate expiry monitoring finds HTTPS names in your cloud DNS records and checks the certificate each one serves every day
  • Certificate expiry and broken certificates raise separate alerts
  • The certificate page groups names by main domain and status, with drill-down, bulk delete, and your page kept on refresh and back
  • AAA network devices can be restricted to one authentication protocol
  • The AAA device list shows whether each device actually uses TACACS+ or RADIUS, and Vendor dialect is renamed Authorization attribute format
  • Fixed BGP-LS neighbours being overwritten by config parsing during a link outage, which hid the outage
  • Fixed backbone topology links being deleted in bulk when config parsing returned no neighbours
  • Opening a traffic chart from a topology link is much faster, and live sampling works from that chart
  • Traffic charts only mark outages after a link had carried traffic, drawn as a thin dashed band
  • Fixed the initial admin password possibly being logged in plain text when it could not be saved to a file
  • Bastion names the missing credential for out-of-band devices
  • Switching pages on a slow network no longer stops the rest of the page from loading

v26.09.120 2026-09-16

  • Ship a ready-made 443 reverse-proxy setup so login logs record the visitor real IP instead of the proxy address
  • Fix a config incompatibility that made the service restart repeatedly on some hosts

v26.09.117 2026-09-16

  • Login records, lockout counting and the login captcha no longer trust a forwarded-for header sent by the visitor itself
  • Declare a reverse proxy on another host with VCONFIG_TRUSTED_PROXIES if its forwarded-for header should be believed
  • The bundled SNI router can announce the real client over the PROXY protocol, off by default as it needs a backend that does not terminate TLS

v26.09.115 2026-09-15

  • The stored device login secret now expires after 30 days by default, so a password changed or an account disabled in the directory can no longer keep working on devices indefinitely
  • Authentication and command audit logs now name the actual device and its address instead of the network segment entry, which used to show every device in a segment under one name
  • The overview ranking of most-visited devices follows the same change

v26.09.111 2026-09-15

  • Directory accounts can now authenticate with MS-CHAPv2 once a stored copy exists, instead of being refused merely for not being local accounts
  • When no stored copy exists the reason now says what to do about it, rather than reporting an incorrect password
  • The user list no longer fails to load, and a load failure now writes the underlying error to the browser console instead of hiding it

v26.09.108 2026-09-15

  • MS-CHAPv2 is now supported, so MikroTik RouterOS devices can authenticate through the built-in RADIUS server at last
  • The device login secret is the same as the platform password and is kept as an encrypted copy, because challenge-response authentication cannot work from a one-way hash
  • Whether external directory accounts also get a stored copy is a switch of its own, off by default, with the trade-off spelled out where you turn it on

v26.09.105 2026-09-15

  • RADIUS Access-Accept now carries the authorisation attributes the device needs instead of being an empty packet, so the privilege level a policy grants actually reaches the device
  • MikroTik RouterOS is a selectable vendor dialect and receives its own group name, since RouterOS has no concept of privilege levels
  • A request that uses MS-CHAP or MS-CHAPv2 is now refused by name with the reason, instead of reporting that the packet carried no password at all

v26.09.103 2026-09-15

  • The 3A overview now shows which address each service is bound to, not just the port, so a wrong bind address is visible instead of silently unreachable
  • A Service IP card sits beside the two service cards listing every address on this host that devices can point at, with double-click to copy
  • Copying now falls back to the legacy path when the browser clipboard API refuses the write, instead of reporting a failure that did not have to happen

v26.09.98 2026-09-14

  • Config parsing no longer invents a neighbour between two interfaces that carry the same address, which mis-attributed a real SIN2-SIN3 circuit to SIN1 and left it off the map
  • Existing same-address rows are removed during the neighbour rebuild instead of being greyed out as failed links
  • Backups that only return a device refusal such as authorization failed or login incorrect are now recorded as failed on every capture path instead of being stored as a configuration

v26.09.96 2026-09-14

  • Topology no longer draws one link as several parallel lines when the same /30 appears in two devices' configs after a device swap
  • BGP-LS now disambiguates by node name, so stale config leftovers are marked superseded instead of being shown as active or as a phantom failed link
  • IPAM delete endpoints return a clear message instead of a 500 when a row is still referenced
  • IPAM folder tree keeps full names with actions moved to a right-click menu, and a new Circuits page splits line records from the supplier list

v26.09.87 2026-09-10

  • Clicking Log centre in the AIOps sidebar now opens device logs instead of dropping you on the audit log
  • The new-version banner is now clickable and takes you straight to the upgrade page

v26.09.86 2026-09-09

  • BGP-LS collection now parses the real NLRI format: a link-state feed that returned zero links while quietly writing a 200 KB capture file is now read correctly
  • Port descriptions no longer go blank when a site switches its neighbour source to BGP-LS
  • A long interface description no longer aborts the whole neighbour table rebuild

v26.09.84 2026-09-09

  • Palo Alto PA-series, FortiGate and Centec devices are now fully supported: inventory, transceivers, interface status, backup and software version
  • Firewall CPU and memory graphs now have a data source, and each metric is scoped to its own device
  • Interface filter notices name the exact rule that hid an interface, so you can go change it
  • Cloud billing collection no longer polls paid APIs on the free-API cadence, cutting AWS Cost Explorer cost per account from about 490 US dollars a month to under 1
  • Topology maps no longer drift into dense link clutter or lose every link over time
  • ISIS neighbours on IOS-XR routers are now parsed from the router isis block
  • Upgrading a long-lived database no longer stops halfway on a missing column or an over-long port description

v26.09.68 2026-09-07

  • Alert and report emails now share one professional HTML template that reads correctly in both light and dark mode
  • Traffic chart stats collapsed from six rows to a single line, showing only the latest value and the 95th percentile
  • Chart legends renamed to In, Out and 95th so the whole row fits beside the time range
  • IPAM lists now carry their own VRF, site and device names, so the page renders without waiting for a full reference download
  • Dashboard and IPAM summaries refresh in the background, so nobody waits for a cold recalculation
  • Database passwords no longer live in systemd unit files, and upgrades migrate machines that were already installed
  • DCIM refusal messages are translated into all eight interface languages
  • Subnet detail shows the same VRF name as the list, and a deleted reference shows its id instead of a blank cell

v26.09.53 2026-09-04

  • Patch panel cores are now colour-coded by state: green in use, amber reserved, red faulty, with a legend and per-state counts above the grid
  • A patch panel that still has core records cannot be unmounted or deleted, and the message names the exact pairs
  • In a bulk unmount, a blocked device is skipped with its own explanation while the rest proceed
  • A rack whose store notes are not empty cannot be deleted, and the message quotes what is recorded
  • Fixed warning toasts site-wide having no colour accent
  • Toasts now stay on screen longer for longer messages

v26.09.51 2026-09-04

  • Patch panel cores now keep a change log of who changed which fields and when
  • Clearing and re-registering a pair no longer breaks its history
  • Core dialog buttons are right-aligned with the primary action last
  • The model text on the rack base plate is dimmed so it no longer competes with device names
  • Fixed Edit showing as English in all seven dictionaries and filled in missing English strings for patch panels
  • Write buttons on patch panels are no longer shown to read-only accounts

v26.09.49 2026-09-04

  • DCIM list search boxes now match the whole row: words that appear on screen but are not stored fields, such as unracked or router, are searchable, and so are asset tags and serial numbers
  • This is the site-wide default and applies to search boxes added later as well
  • Rack management gained an in-rack store: a plain text box for what is kept in the rack and at which U, with the last-updated time recorded automatically and a warning when edits are unsaved
  • A patch panel can be renamed after it is mounted, and the rack diagram follows
  • The fibre pair form is now one field per row with the label on the left, and every control shares the same width
  • Pair fields are now near-end info, far-end info, circuit ID, circuit type, customer, patch date defaulting to today, status and notes
  • Both ends are plain text boxes again, since what people type on site is usually a sentence that no dropdown can offer

v26.09.46 2026-09-04

  • Interface names were only resolved once, when an exporter first appeared, and that attempt often lands while the device SNMP is still unreachable, leaving the list showing raw ifIndex numbers forever
  • Discovery now retries every thirty minutes while any interface is still unnamed and leaves named ones alone

v26.09.45 2026-09-04

  • Fixed an error when pressing Re-identify: the device id was read after the application context had gone, which hit every device whose hostname matches one in the inventory
  • Interface names were written correctly and only the final response failed, which made the symptom misleading

v26.09.44 2026-09-04

  • NetFlow interface names gained a credential-free source: the ifIndex-to-name table devices publish in NetFlow option data, which Cisco, Huawei, H3C and Juniper all send
  • SNMP discovery now prefers the device own community string and also tries its management address, since the flow source is usually an egress interface while SNMP only answers on the management address
  • When a name cannot be resolved the page explains why instead of showing a bare ifIndex number
  • Chart height is now configurable under monitoring settings, from 160 to 900 pixels, and applies to every chart in the product
  • Charts now use the site-wide font scale and align grid lines to device pixels, which makes text and lines visibly sharper on non-retina screens
  • Charts redraw at the new size when their card is resized instead of stretching the old bitmap
  • Time axes are horizontal and pick their density from the measured label width
  • DCIM common components no longer include ODF, blank panels or console servers
  • A patch panel binds to its rack on mount, defaults to 48 fibres, and every two fibres form a pair you can document with far-end device, port, customer and patch date
  • The home dashboard gained log-table indexes and computes its seven-day trend in one query, taking the endpoint from 750 ms down to 200 ms
  • The system overview now serves a stale cache and refreshes in the background, and is warmed at startup
  • The cloud sidebar gained its collapse button and no longer leaves truncated labels when collapsed

v26.09.28 2026-09-03

  • Dashboard rebuilt with a left rail and multiple boards, plus custom boards whose widgets can be dragged into place
  • Reports and system status merged into the dashboard, and the asset overview is now a statistics page
  • Interconnect table now carries Equinix Fabric and Megaport access point name, provider status, circuit type and IBX
  • Fixed empty far-end VLAN on QINQ circuits, where only the outer tag was read and the inner tag was dropped
  • Fixed inverted status colours on interconnects, where healthy circuits showed as orange warnings
  • Side navigation width now adapts to the interface language and can be collapsed to icons
  • Update page gained an auto-upgrade switch and a configurable check frequency
  • Dropdown menus unified site-wide, fixing candidate lists clipped inside modals
  • Log centre now loads on demand, bringing the first-load bundle back to 801KB

v26.09.20 2026-09-02

  • The dashboard is now a left-right layout: every board sits in one flat left-hand menu — system overview, your own boards, the asset report and system status
  • Custom dashboards with 14 widget types including interface traffic charts and NetFlow Top-N, each configured on its own, resized and reordered by dragging
  • A whole board loads in a single request, and a widget that fails to load only breaks its own tile and says why
  • Check for updates gained a check-frequency setting alongside the automatic-upgrade switch
  • Reports were trimmed to the asset overview, reachable from the dashboard menu

v26.09.16 2026-09-02

  • Customers can change their own portal password from the account menu, with the current password required and other devices signed out
  • Administrators can open the customer portal as a given account to see exactly what the customer sees — one-time link, a banner that stays on screen, and both issuing and entering are audited
  • The portal theme switch is now an icon that flips between light and dark
  • Check for updates gains an Automatic upgrades switch, off by default: when on, a new version found by the daily check is installed and the service restarts
  • Fixed the self-service portal page failing to load and Customer view landing on the sign-in page after upgrading, caused by a missing database column migration

v26.09.14 2026-09-02

  • Customer portal reordered to Users, Traffic analysis, Interface charts, with a drill-down sidebar that expands one section at a time
  • Sub-accounts are now created in a single dialog (username, name, password, email) and edited in place instead of reset-password only
  • Customer administrators can grant each sub-account access to specific circuits — leaving it unrestricted keeps today's behaviour
  • A sidebar search box filters lines, collectors, interfaces and accounts, and no longer scrambles text typed with a Chinese IME
  • Theme and language moved out of the account menu and sit next to it in the top bar
  • Traffic analysis in the portal now shows only the collector-level detail, with the per-circuit usage profile kept where a circuit is actually selected

v26.09.12 2026-09-02

  • Search boxes no longer scramble text typed with a Chinese IME, and no longer re-filter thousands of rows on every keystroke
  • Domain management gains a Registration info panel with the registrar's real fields, exportable as CSV, plus a direct link to the registrar console for the official certificate
  • Volcengine Cloud DNS is now managed alongside the other clouds — zones, records, add/edit/delete and pause/resume
  • Enabling the customer portal is now blocked up front when it would collide with the admin port, and the accounts page says plainly when the portal is not actually running

v26.09.10 2026-09-01

  • Customer portal gains sections for interface charts, traffic analysis and self-service sub-account management
  • Portal traffic analysis now includes NetFlow Top-N detail, and it is withheld with an explanation when the collecting device also terminates another tenant's circuits
  • Fixed a sign-in defect where duplicate usernames across customers locked both sides out while showing only Wrong account or password
  • Sign-in failures now record the real reason on the server and are listed under the portal accounts table
  • Every topology now has a list view with inline circuit editing and per-interface traffic charts
  • Alerting no longer reports everything as resolved when Prometheus is unreachable, and raises a monitoring-source-unreachable alert instead

v26.08.103 2026-08-31

  • Alert rules written with vendor mnemonics such as %IOSXE_PEM-FANFAIL now match. The mnemonic is stored apart from the message body, and only the body was searched
  • Alert rule lookback windows are no longer silently truncated. On busy networks a rule set to four hours only ever saw the most recent stretch
  • Clicking a rule hit count now lands on the matching logs, centred on the last hit. When there is still nothing, the page explains why
  • Log Centre now warns when the Syslog match switch in the alert engine is off. Rules kept showing as enabled while nothing reached the Alert Centre
  • Fan, power supply and temperature alarms no longer flap every few minutes. The query window was as short as the five minute polling interval
  • Topology lines edited on the map are no longer duplicated by the next neighbour sync
  • Bandwidth and carrier edited on a topology line are now written back to the matching neighbour record, so both pages agree
  • A service code shown on a line now opens that line in Neighbour relations
  • NetFlow no longer counts a per device counter write as a lost bucket. Aggregate traffic and top talkers were always saved
  • Update checks no longer offer a downgrade when the installed version is newer than the published one

v26.08.94 2026-08-31

  • Volcengine edge cloud hosts (VEEN) are now synced together with central ECS instances, they were previously missing entirely because edge hosts belong to a separate product with its own API
  • Edge host location now shows the cluster alias, such as a city and carrier name, instead of the raw administrative area code the API returns
  • A failure fetching edge hosts no longer drops the central cloud instances of that region, and it is reported as a warning instead of being skipped silently

v26.08.92 2026-08-28

  • New AAA module: TACACS+ and RADIUS for device login authentication, command authorization and accounting, with AD-first identity and local fallback
  • Authorization combines user group, device group and command set, and a policy simulator tells you which rule made the decision
  • Factory templates for shell profiles and command sets, plus a read-only catch-all policy, so a fresh install is usable straight away
  • Network devices can be synced from the device inventory in one click, imported and exported as CSV, and edited in bulk
  • Lists across the product now sort IP addresses by value, so .10 no longer comes before .2
  • Fixed sessions being dropped on every refresh when the site is reached over plain HTTP
  • Fixed request-path log entries never reaching the log in production
  • Fixed bastion command rules being left behind in the old table during upgrade

v26.08.80 2026-08-27

  • API keys never worked: every call returned 401 because the Bearer scheme name was compared case-sensitively
  • Key roles are now enforced. A read-only key really is read-only, so a script using a non-admin key to write will now get 403
  • Key authentication is stateless again. It no longer hands out a session cookie, so deleting a key takes effect immediately
  • The API keys page now shows the endpoint URL and a ready-to-run command, and new keys can be copied together with the address

v26.08.78 2026-08-27

  • Syslog now starts, stops and rebinds the moment you save the setting
  • If the port cannot be bound the exact reason is shown instead of a silent success
  • Device renames now reach the inventory, golden-config, compliance and process-memory pages, while audit records keep the name they had at the time
  • The inventory page shows how many devices have never been inventoried, and can run just those

v26.08.77 2026-08-27

  • Fixed the whole site slowing down: the flow-analysis top-N aggregator scanned every slot for each new conversation, so the collector thread saturated a core and every page queued behind it
  • The aggregator now uses a lazy min-heap with identical eviction rules, raising throughput from 5 thousand to 115 thousand flows per second
  • Interface-description collection built a new SNMP engine for every OID tree at 78 ms each, burning 117 seconds of CPU across 749 devices
  • It now builds one engine per device with concurrency lowered from 16 to 6, so collection no longer slows the pages down
  • Two performance floor tests were added so this class of regression is caught immediately

v26.08.76 2026-08-27

  • Fixed the whole site slowing down: the flow-analysis top-N aggregator scanned every slot for each new conversation, so the collector thread saturated a core and every page had to queue behind it
  • The aggregator now uses a lazy min-heap with identical eviction and error accounting, raising throughput from 5 thousand to 115 thousand flows per second
  • A throughput floor test was added so this class of regression is caught immediately

v26.08.73 2026-08-27

  • Fixed the Syslog server switch falling back to off after saving: the settings request left out the switch and the listening port, so the server kept the old values
  • Every control on the settings page was checked for the same problem and only these two were affected, with a test now pinning that each control is really submitted
  • Web terminal wording is now loaded with the terminal page, so the first load of every other page is smaller

v26.08.72 2026-08-26

  • Fixed the web terminal never connecting: the real cause was the browser not trusting the self-signed certificate on the gateway port, while the message pointed at the firewall
  • The terminal now checks the gateway from the server first and then shows what to do next, with one click to trust the certificate and reconnect
  • Self-signed certificates now carry subject alternative names, which Chrome requires before it will accept a certificate at all
  • Regenerating the certificate in Settings now includes the address you are actually browsing with
  • Opening the gateway port in a browser now shows a short bilingual page instead of a bare 426 Upgrade Required

v26.08.71 2026-08-26

  • Fixed the web terminal never connecting: the real cause was the browser not trusting the self-signed certificate on the gateway port, while the message pointed at the firewall
  • The terminal now checks the gateway from the server first and then shows what to do next, with one click to trust the certificate and reconnect
  • Self-signed certificates now carry subject alternative names, which Chrome requires before it will accept a certificate at all
  • Regenerating the certificate in Settings now includes the address you are actually browsing with
  • Opening the gateway port in a browser now shows a short bilingual page instead of a bare 426 Upgrade Required

v26.08.70 2026-08-26

  • New login CAPTCHA (slider puzzle), off by default, required either after N failed attempts or on every sign-in, and always checked before the password
  • Flow analysis names the customer behind an IP on every sub-page, from exporter details to attack detection and packet capture, falling back to device and interface, then to the ISP
  • Owners are re-resolved when a list is read, so filling in the IPAM ledger or renaming a customer also fixes historical rows without re-collecting
  • The exporter detail page opens instantly now, with the whole page aggregation cached while the per-interface managed switch still takes effect immediately
  • Fixed around a hundred translations per language that never took effect and made those strings fall back to Chinese

v26.08.66 2026-08-26

  • Fixed: internal IPs in the flow analysis top lists showed the name of the ISP that owns the address block instead of the customer using it
  • The IPAM lookup had never worked, it read a column name that does not exist and the error was swallowed, so the list always fell back to the public registry
  • The customer name now comes from the IPAM tenant, a single-address assignment beats the prefix it sits in, and a prefix with no owner is not treated as an answer
  • The list re-resolves the owner when it is read, so filling in the ledger later fixes history too
  • When no customer is recorded the list shows the device and interface instead of an ISP name, and a device name never poses as a customer name

v26.08.63 2026-08-26

  • Traffic graphs now include RouterOS rate-limit queues, both simple queues and queue trees
  • The metrics were already being collected, but only the device page showed a current-rate table, so there was no history curve to look at
  • A queue graph carries the same shape as an interface graph, in and out in bps with drops on a second axis, and shares the same list, paging and column controls
  • A queue tree is one-directional, so only one curve is drawn instead of inventing a second one

v26.08.62 2026-08-26

  • Fixed: the Linked neighbor picker on a manual link was always empty
  • It only ever listed ISIS neighbors between two sites in an active state, so networks running OSPF or LLDP, neighbors parsed from configs, and external exits over BGP or default routes never showed up
  • External exits now appear when either end matches, so a link can be drawn to an upstream by hand
  • Each option now carries its protocol and state, and an empty list explains why and points at the show-all switch

v26.08.61 2026-08-26

  • Neighbor relations can now read RouterOS (MikroTik) exports: default routes, interface addresses and BGP peers
  • A RouterOS route without dst-address is a default route, which is how most of them are written, and those were all missed before
  • Long RouterOS lines wrapped with a trailing backslash are joined before parsing, otherwise the second half was read as another record
  • Disabled routes and interfaces are skipped, and a gateway may be an IP, an outgoing interface, an IP with an interface, or a comma separated list

v26.08.60 2026-08-26

  • Fixed: clicking Sync neighbors built the links and then deleted them in the same request
  • The cleanup step that removes tunnel links dated from when tunnels were never drawn and ran unconditionally, so a map whose sites are connected only by tunnels ended up empty again
  • It now runs only when the rule says to exclude tunnels

v26.08.59 2026-08-26

  • Fixed: a network whose sites are connected only by tunnels synced an empty site-to-site topology, because the factory rule excludes tunnel interfaces
  • Tunnels are now excluded only when excluding them still leaves something to draw
  • A sync that dropped every neighbor on the tunnel rule now says how many, instead of just showing zero links

v26.08.58 2026-08-26

  • Fixed: the neighbor-state fallback looked at the whole table instead of the protocols the rule selected
  • LLDP neighbors being up hid the fact that the selected OSPF neighbors were all inferred, so the site-to-site map stayed empty
  • The factory default and the no-match message now compute states within the selected protocols

v26.08.57 2026-08-26

  • Fixed: a site-to-site topology could still sync empty because the default rule only accepted neighbors in state active or up, while neighbors parsed from backup configs are all marked inferred
  • When no neighbor is in an active state the factory default now follows the states that exist, still excluding down, because drawing a link that is known to be down misleads more than drawing nothing
  • A sync that matched nothing now says whether it was the protocol or the state that did not match

v26.08.56 2026-08-26

  • Fixed: a newly created site-to-site topology always synced empty because the factory rule only accepted ISIS neighbors
  • The factory default now follows the neighbors this system actually has, preferring ISIS then OSPF then LLDP, and picks only the top one
  • When no neighbor matches the rule, the map now names the protocols it wants and the ones that exist instead of just showing zero links
  • Maps that already have a saved automation rule are untouched

v26.08.55 2026-08-26

  • Fixed: nodes placed automatically on a global map lost their site prefix in the label
  • SZX1.ROS1-PROD and SHA1.ROS1-Aliyun both showed as ROS1-something and could not be told apart
  • Labels are now shortened only when the rule targets one specific site

v26.08.54 2026-08-26

  • Fixed: syncing a topology map created no links and said nothing about why. Nodes named with a short name now match the full hostname in the neighbor table, for example HKG1.ROS1 matches HKG1.ROS1-PROD
  • A short name that matches two devices is never guessed, it is reported so you can bind the node yourself
  • When a sync produces no links, the map now names the nodes that match no device instead of just showing zero
  • A custom map whose automation rule names specific devices now places those nodes on an empty map

v26.08.53 2026-08-26

  • Customer portal (formerly Customer ledger) is now a single circuit list with create, edit, delete, bulk import and export, and terminations you can attach by hand
  • Auto-linking circuits to customers asks whether to match on customer code or customer name and only takes unique matches
  • The customer portal entry moved to Visualization and old bookmarks still work
  • Fixed: the customer portal flashed its login screen on every refresh
  • The login page subtitle is now editable under System settings, General
  • Flow analysis lets you type interface descriptions by hand and delete unused interfaces in bulk
  • Every interface name now opens its traffic chart and every device name opens the device page
  • Fixed: the hover card on the topology map was clipped by the canvas and its buttons could not be clicked
  • Tables no longer break short values such as a bandwidth of 200 Mbps across two lines
  • Roles and user groups: the module tree matches the current product and granting a parent module also grants its children
  • 36 sub-modules that used to have no effect are now enforced, and audit and login logs can be granted to any role instead of administrators only

v26.08.35 2026-08-22

  • Customer self-service portal (optional, off by default). Customers sign in and see only their own sites, circuits and bandwidth charts, served by a separate process that never touches the database
  • One-click portal deployment from the admin UI, to this machine or another one, with certificate upload or reuse of the system certificate
  • Admin UI and customer portal both answer on port 443 on a single-IP machine, routed by domain name
  • Portal bandwidth charts add 6-month and 1-year ranges plus drag-to-zoom on any period, in 8 languages the customer can switch
  • Customer ledger records which circuit lands on which device port, so the portal shows the right chart to the right customer
  • Prometheus retention raised from 90 days to 1 year, configurable at install time
  • Alert notifications are now rich cards that state the criteria that fired them and link straight to the device, and identical alerts in one round are merged into one message
  • Device import and export share one CSV format, so an exported file can be imported back
  • Fix: device reboot false alarms caused by the 32-bit sysUpTime counter wrapping every 497 days
  • Fix: config insight silently stopped for 7 days when its worker was killed

v26.08.13 2026-08-21

  • User groups with per-menu permissions, plus LDAP group mapping so directory users get the right access on their first login
  • Sign in with Google or GitHub, with provider logos on the login page
  • Alert messages are now rich cards with structured fields and deep links, rendered natively for WeCom, DingTalk, Feishu, Slack, Discord and Teams
  • Every alert now states the criteria it fired on, including the known blind spots of that particular check
  • Alerts of the same type raised in one evaluation cycle are merged into a single notification, so one switch reboot no longer floods the chat
  • Webhook tests now read the provider response instead of trusting HTTP 200, and report the provider error verbatim when delivery fails
  • Email test failures now name the step that failed instead of returning a bare timeout
  • Device import switched to CSV and matches export field for field, so an exported file can be edited and imported straight back
  • Import and export now cover every field including SNMP, credentials and serial number, with only hostname and management IP required
  • Device groups are shown as a collapsible tree instead of a flat list of full path names
  • Authentication and alert settings are now one row per method with a drill-in dialog, and the service status page shows each listening port
  • The upgrade log stays open while you read it and can be copied with one click
  • Version numbers switched to year.month.sequence, for example 26.08.13

v26.08.03 2026-08-20

  • Version numbers now read year.month.sequence, so 26.08.03 is the third release of August 2026 — the jump from 2.519.0 is the new scheme, not a downgrade, and update checks still work as before
  • Authentication and alert settings are now a list of methods with the current state on each row, and clicking one opens just that method's parameters
  • System service status now shows the listening port of each service, and says plainly when a service has no port at all rather than leaving it blank
  • Fixed the SLA matrix returning no data from RouterOS probe nodes, and latency parsing now copes with vendors whose ping output differs from the expected format
  • Fixed settings dialogs being squeezed so narrow that field values were cut off, the two-factor panel opening empty, and missing spacing between cards on several settings pages

v2.519.0 2026-08-20

  • Fixed SLA matrix probes from RouterOS nodes returning no data, and latency parsing now tolerates vendors whose ping output format differs from the one expected for their family
  • Rack 3D view: the base plate moved to the cabinet floor and is twice as large, and a failed mount no longer leaves an orphaned component behind
  • Refreshing the 2D or 3D rack view no longer jumps back to the parent page, and a rack detail view can now be shared by URL
  • The Edit rules link in the interface traffic notice now opens the correct monitoring settings page, and the neighbor description regex now ships matching everything with an example

v2.515.0 2026-08-20

  • Dragging a shared component onto a rack works in Chrome and Firefox again. The palette declared a copy drag while the drop zone answered move, a combination browsers reject outright
  • Opening a rack now shows in the address bar, so refreshing or sharing the link brings you back to the same rack instead of the rack list
  • The rack elevation follows the design tokens. It was hardcoded in an older palette and turned into a white cabinet in light mode, with dark equipment panels stranded on a white background

v2.513.0 2026-08-20

  • Drag-and-drop rack mounting works in Chrome and Firefox again. The drop targets sit inside a 3D transform, which only Safari routed drag events through
  • The pending-device list is one row per device showing name and height only, and its search box now fills the column and says what it searches
  • Collector wiring (Prometheus and SNMP exporter addresses, module and auth names) is folded away and read-only on container installs, where changing it only stops collection
  • Interface graph filtering is off by default. The default was declared in three places, so saving the settings page once silently switched filtering on
  • Toolbars no longer sit flush against the table below them, and every module now uses the same spacing
  • The multi-cloud account table uses the same action column as every other table
  • Settings sections show the Save button only when it actually saves something
  • The top navigation now reads AIOps

v2.510.0 2026-08-20

  • Interface graphs now say when interfaces are hidden by the regular-interface filter, with one click to show them all. A stale filter could hide every interface, looking just like SNMP not collecting
  • Config insight now ships with no extraction rules at all: every interface is kept, and a copy-ready example profile is shown in the UI
  • H3C (Comware 5) LLDP neighbours are collected again. The old command list only worked on Comware 7, so switches connected fine and returned nothing
  • H3C configurations are no longer detected as Cisco. Comware indents its sysname line, which sent every H3C device to the Cisco fallback
  • Upgrades now show download progress: how much has arrived, how fast, and the estimated time remaining
  • Fixed a drag highlight left behind in the rack elevation after dragging a shared component without dropping it

v2.507.1 2026-08-20

  • Traffic analysis sub-pages now open instantly. A corrected database index took the slowest query from 11.9 s to under 0.1 s
  • Fixed the attacked-IP history chart, which rendered blurred and reported a peak that disagreed with the one on the alert card
  • Ranking boards let you choose Top 10 / 20 / 50 / 100 and export the data as CSV
  • The exporter count on the status bar is now a link into the exporter list
  • Rack elevations record half-U occupancy per slot, and rear-face drag placement is fixed
  • Search boxes across the product now carry a magnifier icon

v2.504.0 2026-08-19

  • Tighter page layout: the gap between the left navigation and the content, and the space to the right window edge, are both 16px and no longer grow with window width. The top bar and the page content now share the same left and right margins.

v2.503.0 2026-08-19

  • Auto-discovery and vendor settings now use the same card style as every other settings page. The device management sidebar entry is renamed to Inventory settings.

v2.502.0 2026-08-19

  • Bastion settings now live under the Bastion page and inventory settings under Device management, next to the work they belong to. Report pages adopt the current colour scheme instead of the retired blue one. Checkboxes have a clearly visible border in dark mode, the auto-discovery page no longer looks lighter than the rest, and the divider above each Manage group is now the same on every page.

v2.501.0 2026-08-19

  • Rack view: the common-components tray is visible again and the rear face accepts drag-and-drop mounting. Devices and device groups can now have SNMP disabled (ICMP liveness only) and are then left out of collection targets and probes. DCIM device list gains batch edit for type, status, vendor, model, room, height and more. New rooms get their code filled from the name automatically.

v2.500.0 2026-08-19

  • Rack view gains a common-components tray (PDU, patch panel, cable manager, shelf, media converter, blank panel and more) that can be dragged straight onto a U slot. Devices can now be mounted at half-U positions such as 1.5U, with 0.5U heights supported. Device type list grows from 4 to 15 built-in types and users can add their own from the type dropdown.

v2.499.0 2026-08-19

  • Fixes flow collection on container installs upgraded from older versions: the host did not publish the collector UDP port, so the collector ran but never received a flow. vconfigctl update now adds the missing port mapping. The in-container port is fixed at udp/2055 - to move the host-facing port, change NETFLOW_PORT in .env.

v2.498.0 2026-08-19

  • Flow exporters are now listed one per device with a detail page showing interfaces, per-interface traffic curves and per-device Top 10 rankings. The traffic overview can be filtered to a single device. Exporters are identified over SNMP so devices exporting from a non-management address get their hostname and interface names. Help icons now show on hover. All three flow protocols use one collector port. Fixed the flow-analysis translations, which had failed to load in every non-Chinese language since 08-14.

v2.497.0 2026-08-19

  • Attack detection now only judges IP addresses you have declared as internal assets, so outbound peers are never reported as victims. Detection thresholds were reset to carrier-grade values and an attack must persist across consecutive intervals before it is reported. NetFlow, IPFIX and sFlow can now share one UDP port. Flow exporters and individual interfaces can be unmanaged so their traffic is dropped on arrival. Collector port changes take effect on save without restarting the service.

v2.496.0 2026-08-19

  • The update page now always states whether you are on the latest version, and no longer shows an old upgrade record that contradicts the running version. On container installs the upgrade command appears only when there is something to upgrade. API responses are no longer cacheable, so the numbers on screen are always freshly fetched.

v2.494.0 2026-08-18

  • Traffic charts now open instantly from topology links: expired caches serve last known data while refreshing in the background. NetFlow bucket writes retry on database deadlock instead of losing that minute of traffic. Link traffic API now reports how stale its data is.

v2.492.0 2026-08-18

  • Settings sidebar flattened, reset-defaults and restart buttons removed, service status subtitles inline

v2.491.3 2026-08-18

  • Inventory: CHR reports system-id rather than software-id, both accepted

v2.491.2 2026-08-18

  • Inventory: chassis supplement runs even when the main command parses nothing, so CHR gets its software-id serial

v2.491.1 2026-08-18

  • RouterOS 7 CHR model normalised to CHR

v2.491.0 2026-08-18

  • Sidebar split into regular and Manage sections across all modules, settings moved next to the modules they belong to
  • RouterOS model, version and serial number now collected correctly (CHR uses its software-id)
  • Topology capacity hint can be dismissed

v2.490.0 2026-08-18

  • Link capacity falls back to 1G when the interface reports no speed and no manual bandwidth is set, with the source shown in the popup

v2.489.0 2026-08-18

  • Topology links can now be coloured by absolute traffic (Mbps) for tunnel-only networks whose interfaces report no capacity, with an on-map hint and one-click switch
  • Neighbour SNMP fallback targets are only generated when the device table is empty
  • Inter font bundled and full vAIOS design language

v2.487.1 2026-08-18

  • Slimmer image: only the Volcengine SDK modules actually used are kept, cutting 471MB of unpacked size
  • Release images are now built on the developer machine, so the production host is no longer starved during a release

v2.482.0 2026-08-16

  • SNMP graphs were empty on every Docker install because nothing generated the device target list. Fixed.
  • Monitoring configuration is now refreshed on every upgrade, so changing the SNMP community no longer silently breaks collection.
  • Devices with their own SNMP community now report CPU, memory, BGP and environment data, not just interface traffic.
  • RouterOS queue monitoring now actually ships. Its collector definition had never reached any install.

v2.481.0 2026-08-16

  • MikroTik RouterOS: interface traffic graphs are built again, previously every interface was filtered out and the page showed 0 interfaces
  • MikroTik RouterOS: neighbor discovery is supported, now read from /ip neighbor which merges LLDP, CDP and MNDP into a single table
  • MikroTik RouterOS: config insight now parses RouterOS configurations, covering interfaces, addresses, routing, BGP/OSPF, VLAN and bridge
  • Container deployments: System service status no longer shows unknown for every item
  • New factory defaults: interface graph filtering is off, neighbor data source is config file parsing, and neighbor collection runs daily
  • Neighbor collection frequency is now one shared setting for ISIS, OSPF, CDP/LLDP and external neighbors, existing installations keep their current behaviour
  • Scheduled external neighbor collection and neighbor table rebuild now actually run, both previously required a manual click

v2.462.1 2026-08-13

  • New Traffic analysis (NetFlow / IPFIX / sFlow): who is using the bandwidth, by 5-tuple — ten rankings covering source/destination IP, conversation, ports, protocol, source/destination AS, country and province, with time range and search
  • Flow attribution: internal addresses resolve against your IPAM records (which yields customer and service — no public database has that layer), public addresses against a built-in prefix database for AS and country, with optional GeoLite2 you supply. Entirely offline, nothing leaves the box
  • Targeted capture: the rankings cannot say who an off-the-charts IP talked to yesterday, so open a full recording on one IP or small prefix — it stops on its own
  • Two flow alert rules (off by default): New talker — a source absent from 24h of rankings that suddenly ranks high; and traffic on suspicious ports such as Telnet, SMB, RDP or Redis over a wide-area link
  • Collector ports UDP 2055/4739/6343 are published by the installer with conflict detection. Collection itself stays off until you enable it under Visualization / Traffic analysis
  • Neighbour latency monitoring now logs in once per device per cycle instead of once per neighbour — a backbone router with several neighbours was being logged into 2000 times a day, filling its syslog with login/logout pairs
  • The device detail page can now edit the SNMP read-only community — it existed only in the add-device dialog, and editing an existing device goes through the detail page
  • Form layout: one input width per form (a field with help text no longer stretches to double width), and editable dropdowns now use our own styled list instead of the unstyleable OS one
  • Fixed: the new-version banner pointed at a menu that does not exist (upgrades live under Settings / Updates) and no longer promises container installs a button they do not have

v2.458.1 2026-08-13

  • Push tickets can now be stopped: while executing or rolling back, hit Stop to abort — it stops between commands, and no further device is touched (devices already pushed are not rolled back automatically — use Rollback for that)
  • RADIUS login: sign in to the platform with your Cisco ISE (or any RADIUS) account
  • Bastion adds a third credential mode — each person's own AAA credentials, shared with the config-push credential store so you only enter them once
  • A device can carry its own SNMP community, falling back to the global setting when left empty
  • Three new vendors: FortiGate, Hillstone and Palo Alto, with device-type keywords filled in for every vendor
  • Huawei/H3C transceiver inventory now runs several commands and merges the results by port — models differ in which command they accept, so nothing is missing from the list any more
  • Fixed Mikrotik (RouterOS) backups storing terminal echo instead of the configuration — it now logs in with a dumb terminal, and Telnet reads until the device stops sending
  • Backups no longer end with the shell prompt line, so renaming a device stops showing up as a configuration change
  • Image transfer: the target filesystem is now probed on the device instead of guessed from the model, an empty model falls back to the image name, and the built-in FTP port plus the device call-back address work end to end
  • The transfer progress banner can be dragged and collapsed, so it never covers the command line
  • Web terminal: mouse selection no longer lands one character off, each split pane has a close button, and refreshing the page keeps your sessions open
  • Command history keeps real commands only and redacts secrets before storing them
  • IPAM subnets can be split partially, leaving the rest for a different mask later, and prefixes on the overview link straight to their subnet
  • A half-filled dialog survives being closed or the page being refreshed
  • Instances deployed as containers can now be upgraded from the web UI
  • Fixed: a fresh install seeded no built-in vendors at all (three firewall vendors were missing a sort field and broke the whole batch), which showed up as vendors failing to save
  • Fixed: the search box on the device list returned an error
  • Fixed: Add row and Quick scan did nothing on the discovery page
  • Rack management now loads on demand, bringing the first-load size back down

v2.442.0 2026-08-11

  • Device groups can now be nested — name them like East/Shanghai/DC-A and manage them as a tree
  • granting a parent group automatically covers every group beneath it
  • Push credentials are now visible only to whoever created them, and a ticket can take a username and password typed in on the spot — used once, wiped as soon as it runs, never stored
  • Cisco image transfers now use the right filesystem per platform: bootflash on NX-OS, flash on IOS and IOS-XE, harddisk on IOS-XR, with the matching checksum command
  • The built-in FTP source now takes the standard port 21 where it can — many network devices silently ignore a custom port in the URL and the copy would fail with connection refused
  • Telnet sessions now tell the device the real window width, so long commands no longer wrap in the wrong place and the cursor lands where you expect

v2.438.0 2026-08-11

  • First-run setup: a fresh install now asks for language, time zone and system name before you sign in — getting the time zone right up front keeps every backup, alert and audit timestamp correct
  • Quick start wizard: four guided steps that take you from a fresh install to a device you have actually connected to and backed up, with plain-language errors when credentials, protocol or port are wrong
  • Evaluation notice is now a softer highlight and can be dismissed; compliance notices (device overage, expiry) stay put
  • Settings pages reclaim a row of vertical space — Save, Restore defaults and Restart now sit on the section title line
  • Fixed a class of hidden elements that stayed visible, most visibly a stray Back button in the setup wizard

v2.435.0 2026-08-10

  • Fresh installs: fixed the web service failing to start (TLS cert was never generated on the gunicorn path) and the installer reporting success while the service was down
  • Monitoring on a clean machine now actually takes over the Prometheus scrape config instead of silently skipping it
  • Directory admins are no longer half read-only — permissions come from the role, not from how you logged in
  • Image repository with drag-and-drop transfer to devices: built-in HTTP/FTP/SCP sources with one-time credentials, external sources, directory browsing, space precheck and MD5 verification
  • API keys: dedicated management page, source-IP allowlist, hashed at rest, rotatable
  • LLM providers: multiple channels with failover, add/edit/enable per channel
  • Much faster page loads — first-paint bundle cut by roughly two thirds, refresh now serves from cache

v2.294.3 2026-07-31

  • Demo data realism: device CPU and memory curves now behave like real hardware instead of random noise
  • Demo topologies: regional backbones and a metro ring, laid out from real coordinates

v2.294.2 2026-07-30

  • Admin console: source IP with country, plan display names, tighter tables
  • Demo tooling: the simulated devices now answer ping in each vendor's real format with distance-based latency

v2.294.0 2026-07-30

  • System version is reported as the distribution alone — the kernel string no longer crowds out what you actually read

v2.293.1 2026-07-30

  • Install registration now counts one machine as one — the install ID was being regenerated on every upgrade
  • Config Insight: service codes, VRFs and customer names now resolve from real configs
  • JunOS: interface description is inherited by its units — one service is one row, not two half-rows
  • Huawei VRP: short-form vpn-target route-targets are no longer silently dropped
  • Reconcile: IPAM aggregate blocks are classified separately instead of flooding the report

v2.291.0 2026-07-30

  • Install registration: every copy reports once on first start (random ID, version, OS, device count only — VCONFIG_NO_TELEMETRY=1 disables)
  • Rack view: one free U between devices, blinking status LEDs
  • Fixed container healthcheck ignoring FLASK_PORT

v2.289.3 2026-07-30

  • Heartbeat now reports the host OS instead of the container image distro — an Ubuntu host no longer shows up as Debian
  • Container healthcheck follows FLASK_PORT

v2.289.2 2026-07-30

  • Container healthcheck now follows FLASK_PORT — the app no longer reports a false unhealthy on the default 443 layout
  • Admin console links customers, orders, licenses and tickets together
  • One-click copy for license keys, order and subscription ids

v2.289.1 2026-07-30

  • Cloud region, zone and access-point names now render in English outside Chinese UI
  • Fixed Tencent access points never resolving to a region name

v2.288.2 2026-07-30

  • Demo instances: site-wide delete disabled, everything else editable
  • login page pre-fills the demo account
  • AI root causes, incident titles and 11 status labels now translated instead of falling back to Chinese

v2.282.1 2026-07-28

  • Activation heartbeats now report the operating system version and the server's own IP address, so support can see what an instance is running without asking

v2.280.1 2026-07-27

  • The date calendar no longer gets clipped by panels and dialogs, and is more compact

v2.280.0 2026-07-27

  • Date fields now open vConfig's own calendar instead of the browser's system popup — same look in light and dark, in every place a date or schedule is picked

v2.279.2 2026-07-26

  • Licence activation and update checks now identify themselves with a proper User-Agent, so a tightened WAF rule at vconfig.ai can never silently block them

v2.279.1 2026-07-26

  • Removed a Prometheus scrape target that could never come up (no node_exporter is shipped and no part of the product reads its metrics)

v2.279.0 2026-07-26

  • Fixed SNMP collection failing to start on snmp_exporter 0.23 and newer (including Ubuntu 24.04's packaged 0.25): the collector config now uses the auths/modules format

v2.278.0 2026-07-26

  • One-command install now brings up the whole platform: bastion gateway, AIOps worker, Prometheus and SNMP exporter are installed and wired automatically, and the device syslog port is published
  • Server Shell works in container deployments — the diagnostic user and its tools (ping, mtr, dig, nslookup) ship in the image
  • vconfigctl gained 'health' and per-service logs/restart

v2.276.1 2026-07-26

  • Device limits are now enforced on network auto-discovery and CLI import, closing a path that bypassed them
  • Expired licences freeze new devices instead of dropping you to the Community limit — every device you already manage keeps working

v2.267.0 2026-07-26

  • Live demo environment at demo.vconfig.ai
  • Reverse-proxy backend deployment mode
  • Unattended install mode for deploy tooling
  • Fresh-install self-test fixtures

v2.266.1 2026-07-25

  • Fix: container first boot now auto-generates the self-signed TLS certificate

v2.266.0 2026-07-25

  • Commercial launch: online license activation with daily silent renewal
  • OTA update channel with signed images and one-command upgrade
  • In-app update notifications

v2.262.0 2026-07-25

  • Compliance baseline center: scan results, rule templates, live-network baselines and variable profiles
  • 52 built-in rules with per-vendor rule models
  • One-click remediation tickets riding the change-approval pipeline

v2.242.0 2026-07-25

  • Interface density overhaul: full typography token system across the UI
  • Consistent table sorting and action-button styling platform-wide

v2.230.0 2026-07-25

  • Config Insight: business ledger reverse-engineered from configurations
  • Cross-batch enrichment cache for external system lookups

v2.200.0 2026-07-24

  • Log insight: per-device Top-10 filters and one-click drill-down

v2.170.0 2026-07-23

  • Alert enrichment: interface descriptions and real VRF names in alerts
  • Sustained-condition criteria for loss/error alerts (less flapping)
  • Clickable alert titles linking straight to the evidence

v2.140.0 2026-07-21

  • Permission-aware UI: write actions hidden for read-only roles across every page

v2.116.0 2026-07-18

  • Multi-cloud onboarding: cloud accounts with encrypted credentials
  • Read-only compute collection (Alibaba Cloud ECS first), more providers via connector SPI

v2.60.0 2026-07-15

  • IPAM: subnet split/planning, utilization columns and directory memory
  • Per-subnet utilization computed via address-bin indexes

v2.16.0 2026-07-13

  • Git-backed config versioning: every backup batch becomes a commit
  • Config drift detection against golden baselines
  • BGP session-flap and traffic-surge (DDoS) alerting
  • SNMPv3 discovery support
  • Sandboxed Jinja2 config templating