26.9.0 Release Notes

Subject to change until official general availability announcement. Linked documentation may be incomplete or missing until the GA milestone is announced.

This release introduces enhancements across Cloud Control Center, IdentityGraph, Policy, Data Plane, UX / UI, and Data Visibility—along with API changes and configuration command updates.

Release 26.9.0

IdentityGraph

Tanium IdentityGraph Connector
Elisity now supports Tanium as an IdentityGraph connector, enriching devices matched by MAC and/or IP address with endpoint attributes collected by Tanium. Administrators can also bring in up to 20 text and 10 numeric attributes from their Tanium sensor catalog as custom attributes.

Rapid7 InsightVM IdentityGraph Connector
Elisity now supports Rapid7 InsightVM as an IdentityGraph connector, enriching devices with vulnerability context including risk score, vulnerability counts by severity, and exploit and malware-kit exposure. Multiple InsightVM instances can be connected to a single tenant.

Microsoft Defender for IoT Multi-Site Label Support
A Microsoft Defender for IoT sensor can now be assigned to multiple Site Labels, and multiple sensors can be assigned to the same Site Label. Each sensor also appears with its own status under the Defender for IoT connector on the Connector List.

Microsoft Intune Hostname Matching
The Microsoft Intune connector can now match devices by hostname when MAC and IP address matching finds no Intune record, enriching devices with multiple network adapters. Hostname matching is optional and enabled in the connector settings.

Microsoft Azure Connector Subscription and Region Scoping
The Microsoft Azure connector setup now lets administrators choose which subscriptions and regions to discover workloads from, and the scope can be changed after the connector is created.

Cloud Workload Detail Columns in IdentityGraph
The IdentityGraph Workload table now includes AWS Account ID, AWS Account Name, Subnet Name, and VPC Name columns for AWS workloads, and Subscription ID, Subscription Name, Subnet Name, and VNet Name columns for Azure workloads. All of these can be filtered and sorted.

Generic HEC Log Connector Export Format Selection
The Generic HEC log connector now supports an Export Format setting with options for Raw, JSON, CEF, and LEEF, with JSON as the default.

Device Category Icon on Device Details
The Device Details page now shows an icon for the device's Elisity Category next to the device name.

Device List Source Group Headers
On the Device List, the header for each source's column group stays visible while scrolling horizontally, and adjacent source groups are shown in distinct colors.

Policy

Security Profile Filtering and Export
The Security Profiles and Access Security Profiles pages now offer Protocol and Port filters — including Side A and Side B selectors — with global search that matches ports defined individually or within a range (for example, searching 8081 matches a rule defined as 8080–8090), so administrators can locate profiles by the specific port they need. Profile and rule export offers Export All Data and Export Filtered Data options.

Custom Security Profile Drawer and Defaults
The custom security profile drawer uses a redesigned layout, and new custom Access Security Profiles include a default DHCP/DNS rule for ports 53, 67, and 68.

Policy Group Enhancements
The Policy Groups page introduces a unified layout, numeric naming, and coverage visibility:

  • Unified Page Layout — The Policy Groups page uses a single layout on both the Device Policy Groups and Workload Policy Groups tabs whether or not nested policy groups are enabled. When nested policy groups are enabled, the Create Nested Policy Group action is available from the quick action and the left pane.
  • Numeric Policy Group Names — Policy Group names can start with a number, for both device and workload Policy Groups.
  • Device Coverage and ZTP Visibility — The Policy Group page for Device Policy Groups displays device and policy coverage scores, calculated as an average across Policy Sets. Selecting a coverage score opens a ZTP tab with the ZTP policy details.

Policy Matrix CSV Export
Policy details can be exported to CSV directly from the Policy Matrix view, with the same Export All Data and Export Filtered Data options and shared filter state as the Table view — so operators working in the Matrix can export without switching views. Export All Data includes every policy across all pages with all available fields, while Export Filtered Data covers policies matching the applied filters, limited to the displayed fields.

Policy Set Details Page
Policy Sets now have a dedicated details page, accessible by selecting the Policy Set name, with the same layout and information blocks used on other policy pages.

Access Policy Name on Device Details
Devices in IdentityGraph that are associated with an Access Policy display the Access Policy name, and clicking it opens the Access Policy's details page for rule review.

Traffic Direction Indicator on Policy Details
The Traffic Analytics tab on the policy details page displays which traffic direction is being viewed via a Return Path Policy toggle, keeping the active direction clear when switching between forward and return paths.

Refreshed Filled Cell Mode Design
Filled cells in the Policy Matrix's Filled Cell Mode feature a refreshed visual design that makes each policy state clearer and easier to scan.

Data Plane

Aruba AOS-S Access Policy Support
Elisity now supports Access Policy on Aruba AOS-S 2530, 2920, 2930, and 3810 switches, with automated onboarding, endpoint discovery, policy enforcement, and flow telemetry.

Access Port Discovery Protection
A new Access Port Discovery Protection setting keeps endpoint discovery and policy enforcement active on Cisco, Aruba CX, and Arista access ports when a downstream switch is detected, so the devices behind it stay visible. The setting is off by default and can be enabled in Edge Settings or per Virtual Edge Node.

Visibility Virtual Edge Node Platform Expansion
Rockwell Automation Stratix and Cisco Nexus switches can now be onboarded as Visibility Virtual Edge Nodes through the standard onboarding wizard.

Automatic Backoff for Rejected Policy Updates
When a Cisco switch rejects policy updates because of stuck TrustSec entries, the Virtual Edge now backs off and retries at increasing intervals, and the switch recovers on its own once rebooted.

Virtual Edge and Virtual Edge Node Summary Charts
The Virtual Edges and Virtual Edge Nodes pages now include Summary charts for status, vendor and model, software version, and CPU and memory usage. Clicking a chart on the Virtual Edge Nodes page filters the table.

Observability

Received Traffic in the Policy Matrix Traffic View
Policy Matrix traffic view cells that carry only received traffic are now marked, and the cell tooltip shows bytes and packets both sent and received.

Expanded Traffic Analytics Time Ranges and Filters
Traffic Records now offers Weekly and Monthly time ranges on Device and Distribution Zone views and an Hourly range on Distribution Zone views. Monthly views also support IP, subnet, and Distribution Zone filters.

Zero Trust Posture Scores for Offline Devices
Zero Trust Posture scores now include offline devices that belong to a Policy Group, so scores stay consistent from day to day.

Device-to-Workload Zero Trust Posture Scores
Zero Trust Posture deployment scores now cover policies between device and workload Policy Groups.

General UX/UI

Expanded Table Page Sizes
Tables across Cloud Control Center now show more rows per page, with most list views defaulting to 250 rows and the Device List to 500.

API Updates

API endpoints may be added or updated to accommodate new functionality. Track updates to the API schema in the API Schema Updates Per Release article.

 

New/Updated Commands (Config Command Authorization)

New/Updated Global Config Commands:

## Cisco Nexus (NX-OS) Visibility Virtual Edge Nodes
terminal length 0
terminal width 0
terminal width 511
show version
show interface
show ip interface brief
show running-config | section interface
show vlan
show vrf
show ip route
show ip route vrf <vrf-name>
show cdp neighbors detail
show cdp neighbor detail
show lldp neighbors detail
show lldp neighbor detail
show mac address-table
show mac address-table | i dynamic

## Aruba AOS-S Virtual Edge Nodes
no page
show system
show system memory
show cpu
show ip
show interfaces brief
show port-access clients
show port-access clients detailed
show lldp info remote-device
show lldp info remote-device <port>
show cdp neighbors
show access-list resources
show running-config
write memory
radius-server host <virtual-edge-ip> key <secret>
radius-server host <virtual-edge-ip> dyn-authorization
aaa accounting network start-stop radius
aaa accounting update periodic 5
aaa authentication mac-based chap-radius
aaa port-access mac-based addr-format multi-colon
aaa authorization user-role enable
aaa authorization user-role initial-role <role-name>
aaa authorization user-role initial-role denyall
aaa authorization user-role name <role-name>
 policy <policy-name>
class ipv4 <class-name>
 <seq> match <protocol> <source> <source-wildcard> <destination> <destination-wildcard> [eq|range <port>]
policy user <policy-name>
 <seq> class ipv4 <class-name> action permit|deny
sflow <instance> destination <virtual-edge-ip> <port>
sflow <instance> sampling <port-list> <rate>
sflow <instance> polling <port-list> <interval>
no sflow <instance> destination <virtual-edge-ip>
no aaa authorization user-role name <role-name>
no policy user <policy-name>
no class ipv4 <class-name>
no aaa authorization user-role enable
no aaa accounting update
no aaa accounting network
aaa port-access mac-based addr-format no-delimiter
no radius-server host <virtual-edge-ip> dyn-authorization
no radius-server host <virtual-edge-ip>

Interface-Level Config Commands:

## Aruba AOS-S Virtual Edge Nodes (applied to a port list)
aaa port-access mac-based <port-list>
aaa port-access mac-based <port-list> addr-limit 256
aaa port-access mac-based <port-list> addr-moves
no aaa port-access mac-based <port-list>
aaa port-access mac-based <port-list> addr-limit 1
no aaa port-access mac-based <port-list> addr-moves
Was this article helpful?
0 out of 0 found this helpful