Netforge.ai Docs
Open the app →
Docs/Reference/What's New

What's New

Feature history and release notes.

Major capabilities in the order they shipped (newest first).

August 2026#

  • Drawings that read like an engineer drew them — the members of a port-channel now draw as one stroke with a Po1 · 4×100G pill (right-click to see every member; path trace and failure simulation still light the stroke when any member is on the path), links leave from the facing edge of a device and the connection points move onto that face — a spine finally presents its downlinks along its underside instead of stacking them down one side — and links route around unrelated devices through the aisles between rows, with runs that share an aisle fanned apart into parallel tracks like a wiring harness. A full leaf–spine mesh deliberately keeps its straight diagonal fan (bent through one aisle it would draw as a barcode). Rows now wrap evenly (8 + 8, never 11 + 5), tier bands take their name from your devices when names disagree with roles, and a new Key pill above the minimap explains every colour and dash the drawing uses. Across the shipped reference designs, strokes crossing an unrelated device went from hundreds to zero on every canvas where routing is the right answer.
  • A console layer you can switch off— console runs fan across every tier and can be half the lines on a small site's drawing. Canvases with console runs gain an amber Console pill next to Site area that hides and shows the whole out-of-band layer while you read the data topology. View setting only — the runs stay in the design, validation, the BOM, and every export.
  • The drawing you share is the drawing you see — tier bands now appear in every PNG and PDF export (they were previously missing from all of them), and a share link renders the same drawing the author sees: bands, routed links, bundled port-channels and the Key included, instead of a rougher copy.
  • If it didn't save, it says so— a failed history restore can no longer blank a design: the canvas stays untouched and the message says what happened. A project that can't load says so instead of opening an empty canvas that could save over the real one. Renames, notes, comments and collaborator removals report failure honestly — removing a collaborator that doesn't go through now tells you they still have access. A config template that fails to load stops generation and deploy instead of quietly producing a config with the template missing. And the Retry save chip explains why saving is failing instead of just glowing red.
  • Rack layouts you can hand to an installer — panels included, and saved — the rack elevation now draws the passive hardware a real rack needs: every switch with RJ45 access ports gets a matching Cat6A patch panel seated directly above it (48 ports → 48-port panel, 24 → 24-port, one more per additional 48 — a fully loaded modular campus chassis gets its whole stack), and any rack whose device runs fiberto an ISP gets one 24-port LC fiber panel where the carrier's strands terminate. Inter-switch links stay cabled direct. Panels are derived from the design — drag a switch and its panel follows — and appear in the drawer, the PNG/PDF elevation (dashed, so passive reads at a glance) and a new PANELS section in the BOM and its CSV, so the parts list finally prices the hardware nobody remembers until install day. A copper broadband handoff correctly gets no LIU, and DC leaves with fiber faceplates get no desk panel. And the layout now saves: Apply keeps every device's rack and U position, reopening the drawer shows exactly what you saved instead of recomputing (or re-rolling the AI), hand-typed rack names like RACK-A01 become durable identities instead of being renamed, devices added later are placed into free space and noted, and Apply is undoable as one step. See the new Rack Layout & Panels guide page.
  • Looking Glass — a real looking glass — the outside-in view rebuilt end to end (Tools → Looking Glass). One input — hostname, IP, prefix or ASN — returns a graded verdict scorecard (Healthy / Needs attention / Problem) a non-BGP-specialist can act on: announced (with a “barely visible” warning below ten peer sessions — normal for a lab, also what a quiet hijack looks like), single-vs-multi origin with same-organization multi-origin recognized as legitimate, RPKI ROA validity per origin, IRR route objects, the registry address block, and well-known communities including blackhole and suppression detection. Context signals (route age, visibility, deaggregation) can raise “needs attention” but never “problem”. A per-collector view places every RIPE route collector on a world map with what it sees; the AS-path summary shows top paths, adjacent ASNs and prepending. ASN mode scores an AS number's identity, announcements, visibility, neighbours and age. When an upstream lookup fails, checks report N/A with reduced confidence instead of guessing — a timeout is never presented as a red verdict.
  • Watchtower BGP monitors — a new monitor type that tells you when the internet's view of your prefix changes: origin set, RPKI validity, IRR sources, carried prefixes and well-known communities are fingerprinted, and each alert names what moved — origin change, ROA gone invalid, blackhole community appearing, IRR change. A withdrawn prefix (no collector carries it) is the one down condition. Optional expected origins alert on first observation, closing the gap where a hijack already underway silently becomes the baseline. Peer counts and visibility percentages are deliberately not fingerprinted — they move hourly and would alert forever.
  • Signing out now means it — signing out ends the session on the server, for every device the account is signed in on, not just the browser that clicked it. Changing or resetting a password signs out every other session — resetting a password because it was stolen now actually evicts whoever stole it (the session making the change continues without interruption). A deliberate sign-out also clears everything the session stored in the browser: saved deploy credential profiles, Azure service-principal secrets, local design copies and dismissed findings. A session that merely expires clears the credentials but never touches locally saved work.
  • One account menu everywhere — the avatar menu is now a single control across the whole app: the floating badge, the landing-page nav pill, and the canvas top bar all offer the same items, role-gated once. Admins keep Admin Portal while working on the canvas (it used to disappear there), Dashboard and User Guide are available from everywhere, and the row for the page you're already on drops out. The menu is fully keyboard-operable — arrows, Home/End, type-ahead, Esc returns focus to the avatar — and no longer clips inside the landing nav or covers page controls (the admin analytics and speed-test headers now clear it). On phones, the landing menu gains the Start Designing action that was previously unreachable below 600px, and the avatar menu is the compact route to your projects.
  • My IP: dual-stack detection repaired — the browser-side IPv4/IPv6 probes had been blocked by the platform's own security policy since they shipped, so the tool only ever showed the server-observed address (behind a proxy, sometimes not even your public one). Both families now resolve, the public address correctly replaces a proxy-observed one, and when the probes are blocked in your browser — an extension, a content blocker, a filtering network — the tool says it couldn't check instead of asserting you have no IPv6.

July 2026#

  • One layout engine for every generator — blueprint wizard output, templates and the AVD fabric all place devices through the same engine, which now knows real node heights: overlapping devices on generated canvases went from hundreds to zero, and new devices placed onto an existing canvas land around what is already there instead of on top of it.
  • Publish without an account — everything that is a stateless render of the design in the browser now works signed out: validation, config generation, ZIP and Ansible bundles, firewall handover, cabling and BOM CSVs, and the design document. An account is required only for what an account holds — saving, sharing, the org gallery, labs, deploy and Azure.
  • Review gate for publishing — sharing to the organization gallery or as a public template is now draft → pending → published. Owners and admins publish directly; everyone else submits for review and can withdraw while pending. Drafts stay private to their authors and collaborators — they never appear in the gallery or search until someone accountable approves them.
  • Config Compare — a change-review diff in the network toolbox (Tools → Diagnostics). Paste, upload or drop two configs, route tables or any text dumps and the panes themselves become a live side-by-side comparison — no Compare button, and nothing leaves the browser. Green is identical, yellow is a pair of lines that open with the same command word and differ only in their detail (the changed words are highlighted inside the row), red is a pair whose command words differ, or a line with no counterpart at all. Counterparts are always shown opposite each other — a cell stays blank only when one side runs out of lines. Block-aware sorting cancels out reordering while keeping interface, router bgp, ip sla and policy-map groups intact; every change is classified major or minor (fail-closed — only known-cosmetic lines are minor) with a filter and change-to-change navigation. Ignore rules cover whitespace, case, blank lines, comments and volatile lines, plus your own regex; replacement rules let a renamed hostname or renumbered prefix compare as equal. Exports as a unified .diff or a standalone HTML report.
  • Two-factor authentication required for privileged rolesowner, admin and lab_editor accounts must enrol TOTP. Signing in without it goes straight to enrolment in the profile, the rest of the app stays locked until a six-digit code is verified, and 2FA cannot be switched off while the account holds a privileged role. The requirement is checked on every request, so a promotion into a privileged role applies immediately rather than at the next sign-in. Editors, viewers and observers are unaffected.
  • Blueprint wizard v2 — flexible addressing, subnet profiles, routing designs, OOB — supernets now run /8–/16 with right-sized per-site blocks (DC/campus ~/20, branch /21) packed automatically and overridable per site; generated blocks pin so additive re-runs never renumber existing sites. An editable subnet profile per site kind (Data, Voice, Servers, Guest, Mgmt, Transit, Loopbacks) drives VLANs, HSRP gateway SVIs, DHCP relay, voice VLANs on access ports, trunk lists and IPAM pools. A new Routing step picks the LAN IGP (OSPF/EIGRP/static) and WAN advertisement (eBGP/static) — edges join the site IGP and originate the default, BGP advertises the site block over BFD-protected PE sessions, and EIGRP (new across model, panels and IOS-XE/NX-OS rendering) requires the Cisco kits. An optional out-of-band layer (default on) adds a right-sized Lantronix SLC per site with console runs to every device. Firewalls, SD-WAN edges and every switch ship coherent reachability config — plus template-level fixes: Aruba OSPF interface enrollment, PAN-OS real interface IPs + zone bindings, Firepower static routing, NX-OS DHCP relay features.
  • Multi-canvas Blueprints — site tabs, the Overview, whole-network tooling — projects span multiple canvases as Chrome-style tabs: one per site plus a pinned WAN Overview whose site blocks jump to their tabs. Inter-site connectivity is declared on the Overview and mirrored by WAN id stub clouds on site tabs; Validate/Looking Glass/simulation run over the joined graph with new findings (island sites, unmatched WAN ids, Overview↔config mismatches, per-site pool overlaps), and finding clicks switch tabs. BOM/cable/rack/firewall-handover exports gain site filters and per-site sections; comments scope to their tab. The classic single-canvas blueprint gallery is retired — the wizard is the one Blueprint entry (old deep links redirect), with the three frozen Enterprise WAN designs remaining as static Featured templates.
  • Cloud-shaped connectivity nodesInternet Cloud, MPLS Cloud and VPN Cloud (Generic catalog) now draw as actual cloud outlines instead of device cards. They are pure connection points for terminating WAN links: no port inventory, no properties panel, and they are excluded from config generation and deploy. Existing designs upgrade automatically on load. Validation still recognizes them as WAN endpoints (edge/core/spine links to a cloud remain valid).
  • Enterprise WAN template family — three reference designs on the Templates page (violet Enterprise WAN cards: a 30-office overview with 70 devices, a data center, and a branch office) plus three parameterized canvas blueprints (company code, office count, access switches). Every office runs two Silver Peak EdgeConnect spokes on dual transports — wan0 on the MPLS underlay (172.31.0.0/16), wan1 on the Internet underlay (100.64.0.0/16) — while both DCs pair EC-XL hubs (static + BGP redistribution into the overlay under AS 65020) with a Cisco C9500 core (HSRP VIPs aligned to the STP root, OSPF area 0, default at the firewall) and a Palo Alto pair that centralizes Internet breakout: PAN-form static routes plus zones, outbound PAT and the security rulebase as raw-config on the PA-3260s. Branch designs seed uncabled user ports, and the engine now renders configured-but-uncabled switchports so those ports generate config without endpoint nodes on the canvas.
  • Closed-loop drift & as-built — a new Drift toolbar action compares each device's live running-config against the config NetForge last deployed for it (the intended baseline), reporting in sync / drifted (line + structural diff) / unreachable / no baseline and badging affected nodes. Running-configs are secret-scrubbed before any diff is stored. Admins can schedule recurring checks with owner-contact alerts (reusing the Watchtower channels). The Import wizard gains an as-built mode that pulls a live device + LLDP neighbors via the credential vault and reconciles matched / new / missing against the current design before an additive, undoable apply.
  • SPAN / port mirroring — monitor sessions on every standalone switch and router (Monitoring tab): session id, source interface with direction, destination, enable toggle — rendered per dialect (IOS-XE/EOS monitor session, NX-OS session block with switchport monitor, ArubaOS-CX mirror session) with duplicate/ceiling/destination-reuse validation and an uncabled-source nudge.
  • Console cables drop anywhere — dragging from a Lantronix console port (or a device's console port) and releasing anywhere on the far node now lands on its console port automatically; the SLC's eth uplinks still cable as LAN links when dragged explicitly.
  • SSH admin settings — session time-out, authentication retries and a version pin (site-inheritable), rendered on IOS-XE with NX-OS ssh login-attempts and capability warnings elsewhere; ip ssh version 2 stays the default emission, with compat as an explicit, validation-flagged opt-out.
  • Roles: editor by default, owner-only assignment, Lab Editor — new sign-ups (email and SSO) now start as editor instead of read-only viewer, so teammates can build immediately. Changing anyone's role is now reserved for the owner (admins still create accounts — as editors — and reset passwords). A new lab_editor role carries everything an editor has plus permission to create live labs on the lab host; the grant travels in the session token so lab.netforge.ai can authorize it directly.
  • A warmer interface — modals and drawers now animate in and out, canvas feedback arrives as calm color-coded toasts instead of a red banner, destructive actions confirm in-app (naming what's deleted and what it takes with it), OS-native dropdowns/checkboxes/tooltips are replaced app-wide with NetForge's own controls, and error messages say what happened and what to do next.
  • Console & OOB management — every network device gains a console port (cables only to Lantronix terminal-server ports, rendered as named deviceport entries with baud) and its real dedicated mgmt interface (mgmt0/Management1/GigabitEthernet0/…) with cabling, a configurable management VRF (per-NOS defaults preserved), IPAM auto-assign with manual-override protection, and full validation (console-invalid-target, mgmt-ip-duplicate, …). Console cables no longer emit a bogus data-interface stanza on the switch side. Dragging a device onto a Lantronix now auto-cables the console run (sequential ports, overridable; occupied picks silently bump to the next free port; the SLC's eth ports remain its LAN-mgmt uplinks), and console-port-conflict flags two runs on one SLC port.
  • Credential vault — every device secret (local-user passwords, enable secret, TACACS+/RADIUS keys, SNMP community & v3 keys, NTP key, SD-WAN orchestrator key) now references an encrypted per-org vault; generated configs render the real value with a ! vault: marker, designs and public shares carry only the reference, and deleted references are flagged.
  • Sub-interfaces (dot1q) — routed parents on routers and standalone Nexus/Arista L3 switches take dot1q sub-interfaces (tag, IP/prefix, VRF, description, shutdown) with tag range/uniqueness validation and role-gated UI.
  • HSRP/VRRP depth — SVIs gain preempt with delays, interface/object tracking + decrement, hello/hold timers, version selection, virtual MAC (HSRP), plain-text/MD5 auth (vault-backed), and secondary virtual IPs, rendered per vendor with capability-aware validation.
  • Port-channel depth — bundles take MTU, speed, negotiation, load-interval, bandwidth, admin state, in/out ACLs, and STP edge, plus a device-wide load-balance method mapped per vendor with ACL-reference validation.
  • NTP authentication algorithm — choose MD5 / HMAC-SHA1 / HMAC-SHA2-256 (site-inheritable); NX-OS falls back to MD5 with a note, and the key value is vault-backed.
  • Loopback interfaces — fully configurable on every L3 device (ID, IP/prefix, secondary, VRF, OSPF area, shutdown) with per-vendor rendering, design-wide duplicate-IP checks, and source-interface reference validation.
  • Live role refresh — promotions/demotions now apply automatically on the next page load or tab focus; no re-login needed.
  • SSH host keys & discovery everywhere — configurable RSA key generation (general-keys, label, modulus 2048/3072/4096 with a NIST/CIS 2048-bit floor) on every Cisco template incl. Catalyst switches; global CDP/LLDP extended to Catalyst and Arista (LLDP-only, validated).
  • User guide — this documentation portal: tree navigation, search, role-based tracks, vendor references.
  • Management-plane depth — AAA servers with timeout/retransmit/VRF + source-interface + Test AAA, Common-Criteria password policy, NTP authentication/prefer/source/access-group, console & VTY line hardening, global CDP/LLDP, NetFlow exporter detail, static routes with IP SLA tracking.
  • Site Areas — full shared management plane with inheritance + per-device override; site panel uses the same tabs as devices; local users; per-vendor rendering closed across IOS-XE/NX-OS/EOS/ArubaOS-CX/PAN-OS.
  • Roles & access — owner/admin/editor/viewer/observer enforced end-to-end; admin portal manages accounts and roles; viewers get a read-only canvas.
  • Per-vendor capability validation — interface options and management settings a platform can't render are omitted and flagged, never invented.
  • Named feature objects — ACLs, prefix-lists, route-maps, QoS, flow monitors with reference-integrity validation and BGP policy binding.

Earlier#

  • Azure — resource nodes with synchronized Terraform, subscription import wizard, scheduled drift checks, Ansible device management.
  • AVD fabric wizard — Arista EVPN-VXLAN spine-leaf (Architect·Validate·Deploy) with full validation parity and BOM integration.
  • Publish workflow — unified Publish with Deploy-or-static choice, cabling map, BOM, design document; public/private publishing with scrubbing; shared credential store for deploys.
  • Collaboration — co-edit share links, public design templates, live multi-user editing.
  • Watchtower — uptime monitoring with multi-channel alerting; external uptime watch on the platform itself.
  • Tools — speed test, network tools with admin self-test, Looking Glass, visitor analytics dashboard.
  • Accounts — email-verified registration, password compliance, 2FA, profiles, SSO for on-prem; Cloudflare geo-restriction.
  • Import — Visio topology import with generic-element flagging; config ingestion into the template library.
  • Canvas foundations — vendor catalog, hover-zoom connection points, Link Editor with 1–400G speeds, auto-layout, IPAM with conflict detection, reference-design template gallery.
Tip
Every new feature updates this guide in the same release — if it's in the product, it's documented here.