Release Notes
2.12.1.0 Maintenance Release (July 21, 2026 - EOL: July 21, 2028)
What's New in this Release
NFO Security Update
This security update includes the following:
- JRE 17.0.19
- Tomcat 9.0.120
- Apache CXF 4.1.7
- Netty 4.1.133.Final
- Log4j 2.26.0
- Kafka client 4.3.0
- HSQLDB 2.7.4
Customer Request/Ticket numbers: NFC-12439
Improved NFO Central Rebalancing
- Distribution Margin control: A new Distribution Margin (%) parameter in the NFO Central Load Balancer tab sets the maximum percentage points a peer can exceed its weighted share before rebalancing is triggered. Defaults to 5%.
Customer Request/Ticket numbers: NFC-12315
NFO Central: Configuration Management
- Configuration Management: A new Configuration Management tab in NFO Central allows importing configurations from peer nodes, managing saved configuration snapshots, and distributing them to peers within a load balancer pool.
- Configuration Preview: Saved configurations can be previewed before being assigned or pushed to peers.
Customer Request/Ticket numbers: NFC-12325, NFC-12350
NFO Central: Export Current Configuration
When converting a Standalone instance to NFO Central, the current configuration can now be exported directly from the Connection Manager tab. The exported snapshot can then be imported and pushed to peer nodes, avoiding manual reconfiguration of each peer.
Customer Request/Ticket numbers: NFC-12454
NFO Central: Peer Error Log Reporting
NFO Peers now report their error logs to NFO Central, making peer-side issues visible from the central instance without accessing each peer directly.
Customer Request/Ticket numbers: NFC-12293
Network Conversations: Redesigned Enrichment Watch Lists
Enrichment watch lists are now organized into logical groups, improving navigation and configuration clarity for large deployments.
Customer Request/Ticket numbers: NFC-12346
Network Conversations: Application Collector Visible in GUI
The Application Collector is now accessible directly in the NFO interface, allowing administrators to view and inspect collected application data without accessing the underlying files. A configurable TTL was added to the collector, and unused configuration parameters were removed.
Customer Request/Ticket numbers: NFC-12342, NFC-12394
Improved Network Conversations Data Quality
Added two new parameters:
- Data quality filter: Drops malformed records, including invalid IP ranges, bad byte/packet counts, and out-of-range flow timestamps (default: disabled).
- Flow start/end time substitution: Backfills missing
flow_start_timeandflow_end_timefields using the record's internal timestamp, useful for protocols like sFlow that do not provide these values natively (default: disabled).
Customer Request/Ticket numbers: NFC-12298, NFC-12302
Added User Identity Fields Support for Cisco ASA/AVC
NFO now extracts user identity fields (username, idp) from Cisco ASA and AVC flow records and enriches Network Conversations output, enabling user-based visibility without requiring a separate identity integration.
Customer Request/Ticket numbers: NFC-12367
Improved Application Enrichment Configuration
Clarified application name resolution priority and updated GUI labels and tooltips for the Application Enrichment lists. The processing order is now: Custom applications list, then app_name in flow, then Applications override list, then App ID catalog (auto-built from NetFlow Options), with Application names to be ignored suppressing junk values at any stage except custom matches.
No configuration migration is required; existing lists are preserved.
Customer Request/Ticket numbers: NFC-12368
Added IPv6 Support in Applications Collector
The Applications Collector now supports IPv6 addresses, enabling application enrichment for IPv6 flow records.
Customer Request/Ticket numbers: NFC-12377
Added Cloud Provider Field
The Network Conversations Monitor now reports a cloud provider field, identifying the public cloud (AWS, Azure, GCP, OCI) associated with cloud-bound traffic.
Customer Request/Ticket numbers: NFC-12501
User Identity: WinRM Kerberos Authentication
The User Identity agent now supports Kerberos authentication for WinRM connections, in addition to NTLM. Kerberos can authenticate with a username and password or with a pre-populated Kerberos ticket cache for unattended, password-less operation.
Customer Request/Ticket numbers: NFC-12496
SNMP Pro Licensing
SNMP Pro is now a separately licensed component as of version 2.12.1. The license format has been updated to measure NetFlow and SNMP Pro usage independently:
- New license format:
netflow_blocks=n;snmp_pro_blocks=m. The priorblocks=nformat remains supported. - SNMP Pro block calculation: SNMP Pro blocks are calculated every 5 minutes and apply only when SNMP Pro features are in use: SNMPv3 credentials are configured, or module 10103 (SNMP Polling Rules) or 10701 is enabled. Deployments using only SNMPv2c without these modules are not counted against SNMP Pro blocks.
- Detection alert: NFO logs an alert when SNMP Pro feature usage is detected on a license that does not include SNMP Pro. Existing functionality continues to operate while licensing is arranged.
Customer Request/Ticket numbers: NFC-12337
SNMP Auto-Discovery: Additional Connection Discovery Sources
Auto-discovery topology detection was expanded with additional connection sources:
- Layer 2 connections: Detected using Bridge/STP and MAC forwarding tables, complementing existing LLDP/CDP neighbor discovery.
- BGP and OSPF connections: When a device's routing table is too large to process efficiently, Layer 3 connections are derived from BGP peer and OSPFv3 neighbor adjacencies instead. Both are polled on Layer 3 devices only and are disabled by default.
- Additional connection fields: Connection output now includes management IP, device name, destination management IP, and interface index.
Customer Request/Ticket numbers: NFC-12414, NFC-12457, NFC-12409, NFC-12514
Module 10067: Interface Name Enrichment
The Top Traffic Monitor (Module 10067) now enriches output with interface names.
Customer Request/Ticket numbers: NFC-12228
Aligned Fields Across Network Conversations and Top Traffic
The Network Conversations Monitor (Module 10062) and Top Traffic Monitor (Module 10067) are the two primary NetFlow/IPFIX processing modules. Their common fields are now aligned so both expose an identical base set, with Module 10062 additionally carrying its extra enrichment fields. Previously some fields were present in one module but not the other (for example, exp_name was in 10062 but not 10067).
device_typeadded to both modules: At flow processing time, each module looks up the SNMP device record matching the flow's Exporter IP (the same lookup used forsysName,ifName, and other SNMP-enriched fields) and adds the device type (for examplerouter,switch,firewall,wireless) to the output. If no SNMP record exists for the Exporter IP, the field is omitted, consistent with other SNMP-enriched fields. For cloud flow logs,device_typeis set tocloud.exp_namealigned so it is present in both modules, along with other common fields.
Customer Request/Ticket numbers: NFC-12398
Graceful Degradation When SNMP Service Is Off
Previously, when the SNMP service was disabled or not configured, several kron policies that use SNMP only for optional enrichment would fail their iteration and report a kron policy failure. These policies now degrade gracefully, continuing to process flows without the optional SNMP-derived fields instead of reporting a failure.
Customer Request/Ticket numbers: NFC-12424
Improved OpenTelemetry Output
Revised the OpenTelemetry metrics model for consistency across all system components. SNMP module (10103) and MDT Service field mappings have been updated to correctly classify output fields as metrics (gauge, counter) or attributes, resulting in cleaner and more consistent OTEL data in downstream observability platforms.
Customer Request/Ticket numbers: NFC-12316
Improved MDT Field Normalization
MDT field names are now aligned with SNMP polling field naming conventions. For example, memory utilization elements are now reported as mem_used, mem_free, and mem_total across both MDT and SNMP data sources, enabling consistent dashboards and queries regardless of the telemetry source.
Customer Request/Ticket numbers: NFC-12211
Restart EDFN from the NFO Interface
Administrators can now restart the External Data Feeder (EDFN) directly from the NFO web interface, eliminating the need for SSH access to the EDFN host.
Customer Request/Ticket numbers: NFC-12074
NFO Status Page: Expanded Device List
The Status page device list was expanded to show more devices, improving visibility in larger deployments.
Customer Request/Ticket numbers: NFC-12285
Improved NFO GUI Usability
General usability improvements across the NFO web interface.
Customer Request/Ticket numbers: NFC-12282
Improved Splunk App Navigation Support
The Splunk App NetFlow dashboard navigation hierarchy changed from nfo_hostname, then device group and device, to a new Site, then Device Type, then Device hierarchy. Two fields support this:
sitefield: A new optional server-level field identifying the deployment location of the NFO instance. Used as the top-level navigation dimension in the Splunk App.device_typefield: Used as the second navigation level. This field is added to the Network Conversations Monitor (Module 10062) and Top Traffic Monitor (Module 10067) output as part of the module field alignment described above.
Customer Request/Ticket numbers: NFC-12389
What's Been Fixed in this Release
User Identity: WinRM invalid checksum error when multiple Domain Controllers are polled
Customer Request/Ticket numbers: NFC-12288
NFO peers do not attempt to reconnect after a lost connection
Customer Request/Ticket numbers: NFC-12294
HSQLDB .lobs file grows uncontrollably
Customer Request/Ticket numbers: NFC-12360
SNMP service permanently fails with "error 37 / snmp service error: 2" due to a data race
Customer Request/Ticket numbers: NFC-12428
NFO server fails to start when the NFO site name is empty
Customer Request/Ticket numbers: NFC-12443
2.12.0.3 Security Update (June 18, 2026 - EOL: June 18, 2028)
What's New in this Release
NFO Security Update
This security update includes the following:
- JRE 17.0.19
- Tomcat 9.0.118
- [CVE-2026-22732] Spring Security: Enable eager HTTP header writing
- Netty 4.1.133.Final
- Log4j 2.26.0
- Kafka client 4.3.0
- HSQLDB 2.7.4
2.12.0.0.61 Major Release (March 9, 2026 - EOL: March 9, 2028)
What's New in this Release
NFO Security Update
This security update includes the following:
- JRE 17.0.18
- Tomcat 9.0.115
Feature Highlight: Zero-Touch SNMP Automation
Ditch the manual configuration. Get instant visibility.
This release introduces the Zero-Touch Discovery Engine, turning hours of setup into seconds of automated discovery. Simply define your network ranges; NFO does the rest.
The Power of Automation:
- Instant Inventory: Watch your device list populate in real-time as NFO probes your subnets.
- Smart Classification: NFO automatically recognizes the difference between a core switch, a firewall, and a wireless controller, applying surgical-grade polling the moment they're found.
- Self-Healing Dashboards: If your hardware changes, NFO auto-updates your metrics and groups. Your visibility stays current, even when your network doesn't.
This release includes:
- Improved Device Classification: Automated device classification via a new Device Type field to accurately categorize hardware like routers, firewalls, and switches across major vendors. You can now customize this identification logic through enhanced GUI mapping tabs or YAML-based rule sets for granular infrastructure visibility.
Additionally, assign a device to multiple Device Groups (Vendor, Role, Feature).
Customer Request/Ticket numbers: NFC-12181, NFC-12236, NFC-12265
- SNMP Polling Rules: We've added a powerful new feature that allows you to create custom rules for filtering SNMP polling data. You can now define conditions using logical and comparison operators to report on only the most critical interfaces or devices, significantly reducing the load in large-scale environments.
Customer Request/Ticket numbers: NFC-11995
- Improved Auto-discovery: When credentials are not specified for a subnet, devices will be polled using all configured credentials.
Customer Request/Ticket numbers: NFC-12079
- Added SNMP sysObjectID to Default OIDs: The default SNMP polling OIDs now include sysObjectID, providing enhanced device identification and compatibility.
Customer Request/Ticket numbers: NFC-11996
- Load all default MIBs: All MIBs packaged with NFO are now loaded to improve OID sets creation.
Customer Request/Ticket numbers: NFC-12214
- Improve SNMP polling device availability: Change SNMP "unresponsive device" logic from device level to OID set level.
Customer Request/Ticket numbers: NFC-12225
- Added SNMP Connectivity Tester: Now you can test SNMP connection to check if device is reachable. Optionally, you can test SNMP polling for specific OIDs or tables.
Customer Request/Ticket numbers: NFC-12073
- Improved Custom OID Set Monitor Module:
Customer Request/Ticket numbers: NFC-12093, NFC-12227
Implement NFO Central feature (Preview)
NFO Central utilizes a custom, dynamic load balancing algorithm to distribute incoming traffic. The system continuously monitors real-time data, such as flow rate by exporter, to determine the least loaded NFO peer and automatically rebalance traffic distribution. This rebalancing is also triggered instantly when nodes join or leave the cluster.
Customer Request/Ticket numbers: NFC-12131, NFC-12155, NFC-12160, NFC-12161, NFC-12193, NFC-12224
Improved Device NetFlow Statistics
The system now collects and displays Input Packets (Total and Rate) per device under the Status -> Statistics -> Devices screen. This new, granular metric provides deeper visibility into network flow activity and is a foundational step for implementing rate-based load balancing
Customer Request/Ticket numbers: NFC-12122
Added support for AES-256C in SNMPv3
This release introduces support for AES-256C encryption, providing "military-grade" security for sensitive telemetry. This specific symmetric cipher implementation leverages 256-bit keys with Cipher Feedback (CFB) mode to deliver enhanced privacy and data protection for SNMPv3 communication. It is specifically designed for compatibility with high-security Cisco and OpenSSL-based systems.
Customer Request/Ticket numbers: NFC-12174
Implement Microsoft AD Integration on Linux
Implement integration with Microsoft AD (enriching flow data with username) on Linux deployments using WinRM. This eliminates the need to have a Windows-based EDFN for AD integration.
Customer Request/Ticket numbers: NFC-12101
Improved MDT Input Configuration
Enhanced validation for MDT input settings and watch lists, including checks for MDT TLS configuration ID uniqueness, valid certificate/key file access, and correct network interface address/port settings.
Customer Request/Ticket numbers: NFC-12134
Splunk HEC output: added channel identifier
Added a channel identifier for Splunk HEC outputs, now with support for indexer acknowledgment.
Customer Request/Ticket numbers: NFC-11915
Unified HEC Output for Splunk and CrowdStrike Falcon LogScale
NFO has expanded its HTTP Event Collector (HEC) output capabilities to provide seamless, native support for both Splunk and CrowdStrike Falcon LogScale. This update allows organizations to utilize a single, high-performance ingestion protocol for their preferred analytics and SIEM platforms.
Customer Request/Ticket numbers: NFC-12198, NFC-12208
Added ability to ignore client port in Top Traffic Module
Now there is an option to ignore client port when aggregating flows. This greatly improves volume reduction without loosing any valuable information.
Customer Request/Ticket numbers: NFC-12115
Deprecation Notice
Added Deprecation Notice to Modules which are going to be deprecated in upcoming rleases.
Customer Request/Ticket numbers: NFC-12180
Enhanced NFO stability
Improved Quality of Service (QoS) mechanisms to prevent out-of-memory (OOM) situations and ensure more stable performance under heavy load.
Customer Request/Ticket numbers: NFC-12105
Improved NFO GUI usability
Customer Request/Ticket numbers: NFC-12142
2.11.3.0.49 Maintenance Release (July 31, 2025 - EOL: July 31, 2027)
What's New in this Release
NFO Security Update
This security update includes the following:
- Upgrade OpenSSL and crypto libraries to version 3.x
Customer Request/Ticket numbers: NFC-11919
Added support for Model Driven Telemetry (MDT) input (Preview)
Introduced support for Model Driven Telemetry (MDT) input, enabling more granular and real-time network visibility.
Customer Request/Ticket numbers: NFC-11922, NFC-12008, NFC-12145
Improved Auto-discovery feature
We have significantly enhanced our Auto-discovery feature to include an automatic and rule-based device classification system. Previously, the feature could discover devices and their basic properties. Now, it can also automatically classify them, allowing you to create and manage device groups more efficiently. This new functionality streamlines the onboarding of new devices and ensures consistent policy application across your network.
Key Features:
- Automatic Device Classification: Auto-discovery now automatically assigns devices to a default group based on SNMP SysObjectID and other identifying attributes.
- Rule-Based Device Grouping: Create your own custom rules to automatically classify and assign discovered devices to specific groups based on criteria you define. This allows for tailored configurations and reporting for different segments of your network.
- Enhanced Usability: This improvement reduces manual effort and simplifies the management of large-scale network environments.
Customer Request/Ticket numbers: NFC-11979, NFC-12012, NFC-12050
Splunk HEC output: add channel identifier
Customer Request/Ticket numbers: NFC-11915
Added support for Cisco SD-WAN IPFIX fields (including options)
Added support for Cisco SD-WAN IPFIX fields (including options), providing deeper visibility into SD-WAN traffic.
Customer Request/Ticket numbers: NFC-11169
Add Archive and Restore Configuration
Introduced Archive and Restore Configuration, allowing you to easily back up and restore your NFO settings.
Customer Request/Ticket numbers: NFC-11997
Improved Splunk HEC output
- Introduced support for multiple Splunk HEC outputs to a single IP/port, facilitating the routing of various NFO data types to distinct Splunk indexes.
- NFO now supports Splunk HEC output in JSON format, for improved data ingestion.
Customer Request/Ticket numbers: NFC-11933, NFC-11978
Improved SNMP v3 Trap Handling
We've made SNMP v3 trap handling much simpler. Now, NFO automatically handles device EngineIDs when encrypted SNMP v3 traps are received. This means you no longer need to create separate credentials for each device, significantly streamlining your setup.
Customer Request/Ticket numbers: NFC-12011
NFO License Manager to report SNMP polling blocks
The NFO License Manager now includes reporting on SNMP polling blocks, helping you manage your licensed capacity more effectively.
Customer Request/Ticket numbers: NFC-12000
Usability improvments
- Explanations for Auto-discovery steps
- External Data Feeder for NFO page - EDFN selection in case of multiple EDFNs are configured
- Added upload button to EDFN Agent configuration lists
- Added Clear and reset buttons to EDFN agent settings
Customer Request/Ticket numbers: NFC-12050, NFC-11989, NFC-12013, NFC-12042
What's Been Fixed in this Release
Auto-discovery: SNMP v3 is Not Processed Correctly (Intermittent)
Customer Request/Ticket numbers: NFC-12076
Upload yaml OID Set with New Device Group Name is not Allowed
Now when yaml OID set is uploaded with a new Device Group name, this Group is automatically added.
Customer Request/Ticket numbers: NFC-11992
2.11.2.0.32 Maintenance Release (April 30, 2025 - EOL: April 30, 2027)
What's New in this Release
NFO Security Update
This security update includes the following:
- JRE 11.0.27 (CVE-2025-21587)
- Json-smart 2.5.2 (CVE-2024-57699)
Customer Request/Ticket numbers: NFC-11919
Added support for Open Telemetry (OTel) output
Customer Request/Ticket numbers: NFC-11811
Redesigned SNMP device group assigments
Customer Request/Ticket numbers: NFC-11941
Sending NFO/EDFN internal logs to syslog server or Splunk HEC
Customer Request/Ticket numbers: NFC-11926
Improved NFO Output Preview
Customer Request/Ticket numbers: NFC-11929
Option to fix out of sequence timestamps in NFv5 and IPFIX
Customer Request/Ticket numbers: NFC-11948
Usability improvments
- GUI for installations with multiple EDFNs
Customer Request/Ticket numbers: NFC-11972
2.11.1.1.1 Hotfix Release (March 9, 2025)
What's New in this Release
SNMP Custom OID Sets Monitor bug fix
Download the Module set:
Instructions how yo apply the fix
2.11.1.0.70 Maintenence Release (February 10, 2025 - EOL: February 10, 2027)
What's New in this Release
NFO Security Update
This security update includes the following:
- Apache Tomcat 9.0.98
- JRE 11.0.25
- Implemented Cross-Site Request Forgery (CSRF) protection
Customer Request/Ticket numbers: NFC-10410
Improved performance for Linux 9
Customer Request/Ticket numbers: NFC-11837
Added support of IPv6 exp_ip sampling
Customer Request/Ticket numbers: NFC-11264
Improved performance for AWS S3 output
Customer Request/Ticket numbers: NFC-11337
Implement Preview output feature
Customer Request/Ticket numbers: NFC-11840, NFC-11805
Added support for post-NAT IP addresses in Network Conversations Module
Customer Request/Ticket numbers: NFC-11863
Changed default in Network Conversations Module
Changed default to report bi-directional conversations
Customer Request/Ticket numbers: NFC-11830
Improved Auto-discovery feature
- Added connections based on next_hop
- Added connections IEEE 802.1D devices
- Allow to enable/disable auto-discovery
Customer Request/Ticket numbers: NFC-11871, NFC-11838, NFC-11855
Implement exclusion list for port consolidation
In the list of known server destination port numbers, allow marking which server application ports should be processed with client ports reported.
Customer Request/Ticket numbers: NFC-11285
Added Azure VNet flow logs support
Customer Request/Ticket numbers: NFC-11648
Improved NFO license manager
Allow to exclude peer nodes from production usage count
Customer Request/Ticket numbers: NFC-11696
Improved SNMP service and Auto-discovery
Customer Request/Ticket numbers: NFC-11786
Improved NFO Status page and troubleshooting
Customer Request/Ticket numbers: NFC-11809, NFC-11810, NFC-11828, NFC-11833, NFC-11882,
Improved NFO upgrade procedure
Restore server.cfg file after upgrade
Customer Request/Ticket numbers: NFC-11786
What's Been Fixed in this Release
TFS registration error occurs intermittently in NFO server for sFlow data
Customer Request/Ticket numbers: NFC-11308
The server drops TFS due to duplicate template registration within 10-second interval
Customer Request/Ticket numbers: NFC-11820
Modified NFO server.cfg file incorrectly synchronized with config DB
Customer Request/Ticket numbers: NFC-11850
Missing VNet exporter names for Microsoft Azure Flow Logs input
Customer Request/Ticket numbers: NFC-11867
2.11.0.0.95 Major Release (September 30, 2024 - EOL: September 30, 2026)
What's New in this Release
Implemented automatic device discovery using SNMP polling, streamlining network monitoring setup
Customer Request/Ticket numbers: NFC-11588
Implemented NFO output filtering based on Module id (nfc_id)
Customer Request/Ticket numbers: NFC-11703
Okta SSO
Customer Request/Ticket numbers: NFC-11700
Implement EDFN agent for OpenCTI
Customer Request/Ticket numbers: NFC-10641
Implement EDFN agent for Cisco ACI Bridge Domain enrichment
Customer Request/Ticket numbers: NFC-10434
Added support for username reported by Palo Alto Networks, Cisco AVC, and IPFIX element 371
Customer Request/Ticket numbers: NFC-11707
Added Support for nexthop, allowing for detailed visualization of network traffic routing paths
Customer Request/Ticket numbers: NFC-11630
Added Support for NetScaler IPFIX elements: AppName, RTT, and TCP retransmits
Customer Request/Ticket numbers: NFC-11167
Implemented "Catch all" in Repeater filters
Customer Request/Ticket numbers: NFC-11391
Performance improvement
Customer Request/Ticket numbers: NFC-11668
What's Been Fixed in this Release
vCenter agent generates records with duplicate MAC addresses and zero IP addresses
Customer Request/Ticket numbers: NFC-11780
AWS S3 output: Some Syslog generated files missing the header row
Customer Request/Ticket numbers: NFC-11725
2.10.2.0.88 Maintenance Release (April 24, 2024 - EOL: April 24, 2026)
What's New in this Release
NFO Security Update
This security update includes the following:
- Apache Tomcat 9.0.88
- JRE 11.0.23
Added Support for Oracle Cloud Infrastructure (OCI)
Customer Request/Ticket numbers: NFC-11422, NFC-11449
Added support for IPv6 in Security Threat Lists in Network Conversations Module
Customer Request/Ticket numbers: NFC-11296
Implemented Azure Logs Ingestion API (as Data Collector API will be deprecated)
Customer Request/Ticket numbers: NFC-11448
Added support for Original Flow Data and NetFlow Recorder to AWS S3 output
Customer Request/Ticket numbers: NFC-11197
Improved EDFN Agent to support AWS/Azure/GCP/OCI public IP ranges
Customer Request/Ticket numbers: NFC-11461
Added support for IPv6 in SNMP Polling and Traps
Customer Request/Ticket numbers: NFC-11481
Added support of SNMP Polling Configuration via YAML Packages
Customer Request/Ticket numbers: NFC-11554
Added ifHighSpeed OID to SNMP Polling
Customer Request/Ticket numbers: NFC-11486
Added new SNMP OIDs to interface_mon Set
Customer Request/Ticket numbers: NFC-11491
Performance Improvements
Customer Request/Ticket numbers: NFC-11318, NFC-11543
Various Usability Improvements
Customer Request/Ticket numbers: NFC-11469, NFC-11478, NFC-11480, NFC-11544, NFC-11575, NFC-11611