{
  "summary": "Added SourceIP as a new scope condition on firewall and DLP rules - restrict any rule (domain, category, IP, region, ZTNA access, or content-inspection rule) to traffic from a specific source IP or CIDR range, alongside the existing device, user, and group scoping. Also improved ZTNA device-to-device access: a single-node deployment can now route directly to another enrolled device's exposed local port via its virtual IP, without requiring a separate connector daemon."
}
