06-23-2026 12:58 AM
This is the first beta release for MX 26.2.
This release further expands security capabilities to provide deeper inspection and control than ever before with new Adaptive Policy enforcement support, TLS inspection, and greatly expanded organization-wide group policy functionality.
Additionally, MX 26.2 brings exiting new BGP and VRF configuration options, alongside IP-in-IP and DS-Lite support. and improved support for IPv6-only connectivity. Together, this provides many new ways to configure and deploy MX appliances.
Please see the full details below.
Adaptive Policy & Security: New capabilities include IP-to-SGT mapping, SGACL support, and TLS and HTTPS inspection with IPS support.
Expanded Firewall Capabilities: Comprehensive Organization-wide Group Policy support, including mixed L3/L7 rule criteria, IPv4/IPv6 matching, reusable rulesets, and VLAN-based policy rules with per-rule logging.
Advanced Routing & BGP: Expanded IPv6-only networking support, enhanced VRF support for eBGP and AutoVPN, and new controls for BGP outbound filtering, and route preference.
Enhanced WAN & Connectivity: Added support for IP-in-IP and DS-Lite support for service-provider use cases.
When configured for this version, Z3(C) devices will run MX 19.2.7.
When configured for this version, MX64(W), MX65(W), MX84, MX100, and vMX100 devices will run MX 18.107.13.
The product complies with EN 18031-1:2024 and EN 18031-2: 2024
06-23-2026 01:05 AM
06-23-2026 02:42 AM
That's the proof that reincarnation is possible ... 😉
06-23-2026 06:11 AM
I wonder how much the performance hit is on classic MX vs Secure Routers
06-24-2026 06:39 AM
And I wonder if they are only going to support it outbound or in the future they will also allow the inbound port forward based decrypt - known key method.
Secondly I'm also curious if they are going to implement it in combination with org-wide group policies.
If you use org-wide on a VLAN you can't use network wide. When you want to limit the which local VLANs will be decrypted-outbound you will need the controls to do that.
06-24-2026 12:13 PM
Inbound support is a future consideration but not in the plans yet as primary demand has been on the outbound side
Regarding org-wide group policies, yes decrypt support is being added in the 27 release
06-25-2026 12:53 AM
Nice to know thanks!
Btw while I have you here.. regarding org-wide policies. Is the content filtering feature also something that will be added to it so we can fully move towards org-wide policies instead of VLAN based network-wide group-policies?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide