IP Fabric v7.11
Upgrade Version Policy
We support the following upgrade paths:
- The latest version in the previous major line → any version in the
current major line (for example:
7.12.4→8.0.1). - Any version in the current major line → any newer version in the current
major line (for example:
8.0→8.1). - An upgrade to
8.0can be only performed from version7.12.4or newer.
Clearing Browser Cache
After upgrading IP Fabric to a newer version, you should see the Your
application has been updated and must be refreshed dialog in the main GUI.
It is usually sufficient to just click the Refresh button.
However, in case of issues with the main GUI or if you did not see the mentioned dialog, please force refresh your browser cache.
The key combination for doing this depends on your operating system. In your browser window with your IP Fabric appliance’s URL open, use one of the following key combinations:
- Windows:
Ctrl+F5 - macOS:
Command+Shift+R - Linux:
Ctrl+F5
This will only affect the browser cache for the IP Fabric appliance.
Known Issues
Support Status Page Endpoint Error
When a policy excludes the GET /support/status endpoint in API scope, the Support Status page may intermittently switch between loading correctly and showing a 403 Failed to load data error.
Workaround: Include GET /support/status in the policy. This allows access to hardware information while still restricting actions such as service restarts.
Wrong Elapsed Time When Loading a Snapshot
When loading a before unloaded snapshot, the displayed elapsed time may appear unexpectedly high. This is a display issue only and does not affect data integrity.
Discovery Stuck Due to Scanner Processing Excluded IPs
Discovery may get stuck when scanner jobs receive IPs that are later removed by the exclude list during the discovery process.
After the exclude list is applied, a scanworker can end up with no IPs left to scan. The job may not finish correctly, blocking discovery progress.
We track this issue internally under reference NIM-23846.
Symptoms: Scanner process is enabled, discovery is stuck or not progressing, scanner appears to process IPs from the exclude list, scanworker jobs remain active even though there are no valid IPs left to scan.
Workaround: Review the discovery scope and exclude list. If there are IPs for a scanworker which are part of exclude list, adjust the discovery scope or exclude list.
Fix delivered in version 7.11.10.
VRF Routes Not Collected on Cisco NX-OS
VRF routes are not collected on Cisco NX-OS devices when the BGP route download limit is disabled.
Workaround
Enable the Limit download BGP routes setting and set a sufficiently high threshold (for example, 100000 or higher) to allow full route collection.
Fix delivered in version 7.11.8.
Maximum Number of Parallel Sessions Setting in GUI Is Not Enforced
The Maximum number of parallel sessions value configured in the GUI is not propagated to discovery workers, so discovery runs in unlimited mode regardless of the configured value.
A workaround is available through worker settings, but it requires manual changes to service files with Support assistance. Customers who need this limit enforced should contact Support.
Fix delivered in version 7.11.5.
v7.11.11 (June 4th, 2026; GA)
SHA256 (ipfabric-update-7-11-11+0.tar.zst.sig) = c2c1f3072f957b7cd94b6c64c9158cc00bc06b66e149a92168039622ef611c99
MD5 (ipfabric-update-7-11-11+0.tar.zst.sig) = 856774ff9feac9674268fd7d0bc77981
SHA256 (ipfabric-7-11-11+0.qcow2) = a26c465d084ce39d5d2300dffa7e9c6afde141574125545deda0216515dc556d
MD5 (ipfabric-7-11-11+0.qcow2) = 8a5da4d7d8eb4a3d8842d46b4064b80e
SHA256 (ipfabric-7-11-11+0.vmdk) = bf770b11250babeb6e3681d00d8eb052e1d35258a79315ed69cc0f1061d85e27
MD5 (ipfabric-7-11-11+0.vmdk) = fef16ab2236857837ffc4b164e1928e6
SHA256 (ipfabric-7-11-11+0.vhdx.zst) = bb68a63ca0995392b754763f307a081daf9eae573644faf714939c8b982a2272
MD5 (ipfabric-7-11-11+0.vhdx.zst) = ff488ee9cb45d67012dacd10e40d00d1
SHA256 (unsupported-ESXi6.7U2-ipfabric-7-11-11+0.ova) = dc4fcc3628a2d436ef18a569e4cb345d4875ec39705427b8d0e8c339ebb31609
MD5 (unsupported-ESXi6.7U2-ipfabric-7-11-11+0.ova) = 627c2292e9ce3937f5d25e861407a659
SHA256 (unsupported-ESXi7.0-ipfabric-7-11-11+0.ova) = 51257cf11a2e328d5784639957419fddaae34409d89384c81b4d85e0abb05b3c
MD5 (unsupported-ESXi7.0-ipfabric-7-11-11+0.ova) = 9ba87402172a619bb2782d39a44cbec0
SHA256 (ESXi8.0-ipfabric-7-11-11+0.ova) = ed55673bf0da4f6b06dbea824e3d04d6136234a1c28021abeff387cb748bc93f
MD5 (ESXi8.0-ipfabric-7-11-11+0.ova) = 58c2fabb6a4cd58e49ee0181f290b78b
Improvements
- Improved database query performance, reducing topology calculation time.
Bug Fixes
- Fixed an issue that could cause worker failures during Vendor API discovery.
v7.11.10 (June 2nd, 2026; GA)
Bug Fixes
- Discovery & snapshot fixes:
- Fixed an issue where discovery could remain stuck in the
Discovery onDone startedstate. This occurred due to CLI log compression running at the end of discovery. CLI logs for successfully discovered devices are now compressed immediately, reducing end-of-discovery processing overhead. - Resolved discovery getting stuck due to
scanworkerjobs remaining active when no IPs were left to scan after applying the exclude list. This also addresses the known issue tracked internally before this release. - Fixed missing multicast snapshots in PostgreSQL causing Path Lookup E2E test failures.
- Fixed an issue where discovery could remain stuck in the
- Palo Alto PAN-OS fixes:
- Fixed missing MAC addresses on subinterfaces that caused wrong Path Lookup results.
- Corrected Advanced routing mode handling on firewalls running in cluster mode.
- Virtual IPs are now displayed in the IPv4 Managed IP Summary table.
- Corrected zone firewall rule duplication during configuration parsing.
- Cisco fixes:
- NX-OS: Fixed issue where VRF routes were not collected when the configuration had no BGP limit.
- IOS-XR: Resolved an issue where the worker kept waiting for command output after the server closed the session.
- ACI: Resolved an exception on leaf devices when a host appeared on many VLANs.
- Path Lookup: Fixed failure with
Invalid packet annotationerror when VRF was missing.
- GCP fixes:
- Resolved duplicate IP issue with
wan-x.x.x.xinterfaces. - Corrected missing pagination when retrieving the GCP projects list.
- Suppressed errors for empty Network Endpoint Groups (
NEGs) and unassigned tags in the ACL task. - Resolved errors for NAT44 tasks for load balancers.
- Corrected Path Lookup ACL evaluation for Echo Request (ICMP).
- Resolved duplicate IP issue with
- Azure fixes:
- IP Fabric now uses the correct subscription when a VNet peers with a gateway in a different subscription.
- AWS fixes:
- Reduced excessive duration of AWS load balancer health check queries to prevent slow discoveries.
v7.11.8 (Withdrawn)
v7.11.7 (May 12th, 2026; GA)
Improvements
- Improved Azure Path Lookup handling.
- Optimized the Connectivity Report query, reducing load time by about 6 seconds.
Bug Fixes
- Resolved AWS Discovery errors:
Cannot read properties of undefined (reading 'send')andABRequestFailed. - Applied critical Azure Discovery fixes:
- Resolved global peering route handling.
- Fixed cross-subscription prefix resolution.
- Resolved validation errors across several Azure services.
v7.11.5 (May 5th, 2026; GA)
Improvements
- Discovery follows the maximum number of parallel SSH sessions set in the settings.
- Optimized the PostgreSQL queries
setCliJobsAsFoundNotInSubnetsandgetSwitchToApwhich prolonged discovery time. - Improved scanner performance by excluding local routes and routes from exclude list during scanning.
- Improved handling for Vendor API discovery when a
connect ETIMEDOUTerror occurs, the system sends the request again. - When rediscovery of device occurs, it respects snapshot settings.
- Improvements of Azure and GCP discovery.
Bug Fixes
- Fixed duplicated Path Inspector path options occurring on port-channels.
- Corrected Palo Alto security policy evaluation where self-originated traffic was incorrectly matched against Security Policy rules.
- Cisco ACI fixes:
- Corrected ACI Security Evaluation to prevent unexpected deny results for allowed traffic in E2E Path Lookup
- Fixed E2E Path Lookup security evaluation to use the correct VNI for Cisco ACI environments
- Updated
MikroTikOSPF parsing to allowrouterIdto be a string instead of strictly validating it as an IP address. - Corrected Fortinet FortiGate NAT44 parsing so rules disabled with “set status disable” are no longer shown as “Active - Yes” in the NAT44 table.
- Fixed Cisco IOS-XE syslog parsing on C9300-48U (cat9300) devices so “logging host FQDN ipv4” entries display the actual FQDN instead of “FQDN” as the host.
v7.11.3 (April 22nd, 2026; GA)
New Features
MCP Server – AI Assistant Integration
The new MCP Server enables seamless integration between IP Fabric and AI assistants (such as GitHub Copilot and Claude Desktop) via the Model Context Protocol (MCP). It allows AI assistants to query network data, analyze paths, and assess network health — see the full documentation to learn about its capabilities. The MCP Server is built into the IP Fabric appliance and can be enabled in Settings → Integration → MCP Server.
Cloud Load Balancers – SSL Certificate Visibility
IP Fabric now provides visibility into managed SSL/TLS certificates associated with supported cloud load balancers. Certificates are collected and displayed in a dedicated table at Technology → Security → SSL Certificates, with direct access from related load-balancing tables.
Supported platforms:
- Azure — Application Gateway (L7 regional load balancer)
- AWS — Application Load Balancer, Network Load Balancer
This helps security and network teams inventory certificates, identify expiring or expired certificates, and improve their overall security posture.
Do Not Forget to Update Cloud IAM Policies
To collect SSL/TLS certificate information for cloud load balancers, the required IAM policies must be updated on both supported platforms.
Azure If Azure Key Vault access is configured with role-based access control, update the Azure IAM policy to grant the permissions required to collect certificate data.
Download the updated policy here.
AWS If you are using AWS API discovery, update your IAM policy to include AWS Certificate Manager (ACM) permissions so IP Fabric can retrieve SSL/TLS certificate details associated with load balancers and other AWS services.
- Users of the Simplified policy must update to: IAM-policy-IPF_simplified_7.11_or_newer.json
- Users of a previous Granular policy version must update to: IAM-policy-IPF_7.11-full.json
For more details, see AWS API Configuration – Required IAM Policy.
Improvements
- Improved the stability and reduced the memory footprint of the
syslogWorker(responsible for ingesting data into Configuration Management) and of all remaining discovery workers. - Improved discovery logging by replacing the logging library for discovery workers. This resolved missing logs and memory leaks due to logging issues.
Path Lookup
- We extended path lookup support to redirect traffic to an Azure VM after transit. The implementation currently supports only a single destination IP address. Support for a destination subnet will be added in the future. For now, traffic to a subnet destination is dropped.
Vendor Support and Improvements
-
GCP
- Added support for classic VPN gateways.
- Added support for dynamic routes exchanged over VPC Peering.
New GCP Permission Required
The
compute.networks.listPeeringRoutespermission must be added to your GCP IAM role to enable this feature.
-
Azure
- Added support for ExpressRoute circuits in Virtual WAN.
- Improved routing for Azure VPN and ExpressRoute gateways (Virtual Hub).
- Added BGP support for Azure VPN Gateway (Virtual Hub).
Do Not Forget to Update Azure IAM Policy
The IAM policy must be updated to grant the necessary permissions for collecting VPN Gateway routes, BGP peer details, and Virtual Hub routing intent information.
You can download the new policy here.
- AWS
- Updated IAM policies to include AWS Certificate Manager (ACM) permissions required for SSL/TLS certificate discovery.
- Meraki
- SD-WAN
- Added support for Meraki SD-WAN (AutoVPN).
- SD-WAN connections are now listed in Technology → SD-WAN → Meraki.
- Meraki SD-WAN links are now shown in both the Network Diagram and Path Lookup.
- This enhancement improves visibility and troubleshooting of Meraki SD-WAN connectivity in IP Fabric.
- IPsec
- Added support for Meraki IPsec tunnels.
- All configured tunnels are listed in Technology → Security → IPsec.
- Path Lookup and routing information currently support only statically configured routes for IPsec; BGP is not yet supported.
- IPsec tunnels are now shown in both the Network Diagram and Path Lookup.
- SD-WAN
- D-Link
- Added support for basic discovery of D-Link DGS-1250 family switches. See Feature Matrix for more details.
- Covered features include:
- Platform & system: init, device information
- Configuration
- Interfaces: Layer 2 interfaces, Layer 3 interfaces, port-channel
- Network data: ARP, MAC table, LLDP
- Routing & switching: routing table, STP, VLAN
- Management: AAA, DNS client, NTP, SNMP, logging
Miscellaneous
- The Feature Flag
ENABLE_ACI_SERVICEGRAPHS_ENDPOINTShas been removed, and endpoints related to service graphs are now always downloaded.
Topology Calculation Technical Changes
- Network topology calculation has been relocated from the tasker process to a dedicated topology calculation job running within the API process. This change was implemented for technical and architectural reasons and lays the foundation for upcoming advanced product features.
- Topology calculation logs are now clearly distinguishable from general tasker process logs through the addition of a dedicated label prefix:
[topology-calculation].