---
title: "What’s new in Calico Enterprise 3.14: WAF, Calico CNI on AKS, and support for RKE2"
source: "https://www.tigera.io/blog/whats-new-in-calico-enterprise-3-14-waf-calico-cni-on-aks-and-support-for-rke2/"
---

[Technical Blog](https://www.tigera.io/category/technical-blog/)

# What’s new in Calico Enterprise 3.14: WAF, Calico CNI on AKS, and support for RKE2

By [Joseph Yostos](https://www.tigera.io/blog/author/joseph-yostos/) on Jun 07, 2022 • 4 min read

At Tigera, we strive to innovate at every opportunity thrown at us and deliver what you need! We have listened to what users ask and today we are excited to announce the early preview of Calico Enterprise 3.14. From new capabilities to product supportability and extending partnerships with our trusted partners, let’s take a look at some of the new features in this release.

## Web application firewall (WAF)

Web applications are a critical aspect of any business, whether they are public facing or internal. There has been a fundamental shift in the way these applications are developed—as they have become more container-based and API-based, we refer to these as cloud-native applications.

To keep these modern web applications secure, we need to analyze all HTTP communication and block any malicious traffic traversing the web application. However, in a cloud-native environment, we can’t achieve this using simple network policies or by using perimeter network firewalls. Instead, a cloud-native web application firewall (WAF) would be necessary.

![Terminal output showing a 'curl' command with a potentially malicious HTTP request to a WordPress site](https://www.tigera.io/app/uploads/2022/06/image1.png)

*Fig. 1: Service annotation for workload-based WAF using Calico*

This is why we have introduced a cloud-native WAF into Calico Enterprise that’s different from the traditional WAFs you may know. While most traditional WAFs are deployed to protect web applications against external attacks on the perimeter level, Calico provides an in-depth WAF that protects web applications from internal and external attacks as it filters traffic between different workloads. This helps you monitor and verify access to web applications and collect access logs for compliance/auditing and analytics.

![Calico Enterprise 'Alert List' showing WAF alerts, demonstrating in-depth web application protection](https://www.tigera.io/app/uploads/2022/06/image3.png)

*Fig. 2: Alert based on a suspicious SQL injection*

Calico Enterprise enables WAF as an add-on to its deployment of Envoy as a DaemonSet. This integration leverages ModSecurity, a popular open-source WAF that provides a core rule set for the most common security risks identified by OWASP, and also enables operators to BYO rule sets or leverage subscription-based rules. (Note: The WAF functionality is also available in the 3.13 release.)

## Support for Calico CNI with AKS

Microsoft recently introduced a bring-your-own CNI (BYOCNI) program to help AKS users address more advanced networking requirements. Calico is the most widely adopted container networking and security solution for Kubernetes, and now it’s available as a CNI on AKS clusters under the BYOCNI program.

Under BYOCNI, AKS users can leverage Calico’s advanced [IPAM](https://www.tigera.io/blog/calico-ipam-explained-and-enhanced/) capabilities the same way in self-managed Azure clusters as they would in managed Azure AKS clusters. This provides a seamless and uniform CNI operation in a single or hybrid cluster environment. Calico CNI users can also integrate with legacy firewalls and address multiple IPAM issues with the previously available Azure or Kubernetes CNIs.

## Support for RKE2

Calico Enterprise is now officially supported on SUSE Rancher Kubernetes Engine2 (RKE2). RKE2 is the next generation of SUSE Rancher’s RKE platform. It is a fully conformant Kubernetes distribution that focuses on security and compliance within the U.S. Federal Government sector and other regulated agencies.

New users on RKE2 can install Calico Enterprise with all its existing features. Installation or deployment is similar to how Calico was installed on RKE. With this support, Calico Enterprise will be able to boost your security infrastructure with its [zero-trust workload controls](https://www.tigera.io/features/access-controls/) for building and running applications on RKE2.

![Screenshot of 'Connect Cluster' dialog in RKE2, showing Rancher RKE as a connection option. Calico Enterprise can be](https://www.tigera.io/app/uploads/2022/06/image2.png)

*Fig. 3: Connecting Calico to SUSE Rancher RKE2*

We’re excited to bring these new features and capabilities to you in our latest release of Calico Enterprise, and continue to work hard toward adding even more updates for future releases.

Watch this space for more early previews, product releases, and Calico updates! Or [talk](https://www.tigera.io/contact/) to our experts to learn more.

***Want to try Calico for free? Sign up for a [free trial](https://www.calicocloud.io/home).***

 

[Products](https://www.tigera.io/tags/products/)[Release](https://www.tigera.io/tags/release/)

## Related posts

[![Meet Mylo: An AI-native way to work with Calico](https://www.tigera.io/app/uploads/2026/09/Meet-Mylo-An-AI-native-way-to-work-with-Calico.png)](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

#### [Meet Mylo: An AI-native way to work with Calico](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

By [Phil DiCorpo](https://www.tigera.io/blog/author/phil-dicorpo/)
on Sep 3, 2026

A library of Calico tools and skills — delivered through the Calico MCP Server What if your hardest network question took ten minutes instead of ten days? Anyone who has operated Kubernetes networking at scale...

[Read more](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

[![The Safest Place to Run an AI Agent Is On a Cluster That Doesn’t Trust It](https://www.tigera.io/app/uploads/2026/08/The-Safest-Place-to-Run-an-AI-Agent-Is-On-a-Cluster-That-Doesnt-Trust-It.png)](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

#### [The Safest Place to Run an AI Agent Is On a Cluster That Doesn’t Trust It](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

By [Alister Baroi](https://www.tigera.io/blog/author/alister-baroi/)
on Aug 27, 2026

Every organization running AI agents has already made a hosting decision. Most made it by accident. The sales team switched on the agent built into their CRM. Engineering is piloting a coding agent in a...

[Read more](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

[![AI Red Team Agents Automate Attacks on your AI Agents. Runtime Policies Automate their Defense.](https://www.tigera.io/app/uploads/2026/08/AI-Red-Team-Agents-Automate-Attacks-on-your-AI-Agents.-Runtime-Policies-Automate-their-Defense.png)](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

#### [AI Red Team Agents Automate Attacks on your AI Agents. Runtime Policies Automate their Defense.](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

By [Alister Baroi](https://www.tigera.io/blog/author/alister-baroi/)
on Aug 24, 2026

The AI red teaming market grew up fast this year. OpenAI bought Promptfoo, Cisco and Microsoft shipped automated attack suites, and a seed-stage startup publicly compromised 50 of 55 live customer service bots. These platforms...

[Read more](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

<!-- plugin=object-cache-pro client=phpredis metric#hits=3201 metric#misses=33 metric#hit-ratio=99.0 metric#bytes=1521327 metric#prefetches=0 metric#store-reads=167 metric#store-writes=16 metric#store-hits=164 metric#store-misses=22 metric#sql-queries=33 metric#ms-total=550.92 metric#ms-cache=34.75 metric#ms-cache-avg=0.1910 metric#ms-cache-ratio=6.3 sample#redis-hits=8246470 sample#redis-misses=3225149 sample#redis-hit-ratio=71.9 sample#redis-ops-per-sec=159 sample#redis-evicted-keys=0 sample#redis-used-memory=123062736 sample#redis-used-memory-rss=105164800 sample#redis-memory-fragmentation-ratio=0.8 sample#redis-connected-clients=1 sample#redis-tracking-clients=0 sample#redis-rejected-connections=0 sample#redis-keys=100135 -->
