BlogsCloudflareConnectivity Cloud Platform

Connectivity Cloud Platform

Connectivity Cloud Platform

34
posts
2012–2026

Cloudflare is evolving its platform to offer a unified 'connectivity cloud' that integrates security, performance, and developer services. This approach aims to simplify complex IT environments by providing deep integration with the internet and enterprise networks, programmability for customization, platform intelligence through traffic analysis, and a simplified user experience with a single pane of glass. This vision is realized through the consolidation of various services to address customer needs, including advanced AI agent security, post-quantum cryptography integration across all major on- and off-ramps, and a composable, programmable SASE platform that leverages Cloudflare Workers for custom logic. The platform aims to provide a unified codebase with truly unified control, data, and infrastructure planes, enabling rapid deployment of new use cases and secure adoption of AI technologies.

2026

Cloudflare is the only vendor named a Visionary in 2026 SASE and SSE reports

8/6/2026

This post highlights Cloudflare's recognition as a Visionary in Gartner's SASE and SSE reports, attributing this to its unified 'connectivity cloud' architecture. It details how this architecture addresses market gaps by offering a single global network for security and connectivity, natively governing AI agents alongside human users, and deploying post-quantum encryption. The post emphasizes the platform's composability, ease of use, and programmability through Cloudflare Workers, enabling customers to secure AI adoption, manage AI agents, and achieve deeper architectural consolidation.

2024

Simplify cloud routing and object storage configurations with Cloud Connector

8/16/2024

Introduced Cloud Connector, a new feature that simplifies routing traffic to multiple public cloud object storage services (AWS S3, Google Cloud Storage, Azure Blob Storage, R2) from a single hostname. This is achieved by extending the Ruleset Engine's 'route' action and using a thin API translator layer on Workers. A new `http_request_cloud_connector` phase was added to ensure Cloud Connector rules have the highest priority in traffic routing decisions. The implementation decomposes a single Cloud Connector rule into multiple underlying Ruleset Engine actions, including host header adjustments and origin settings, with a 'skip' action to prevent conflicts.

Magic Cloud Networking simplifies security, connectivity, and management of public clouds

3/6/2024

Introduces Magic Cloud Networking, a new capability built on acquired Nefeli Networks technology, to simplify, unify, and automate the management and operations of public cloud networks. It provides end-to-end visibility and control across multiple cloud providers by leveraging native cloud data plane constructs and integrating with Cloudflare One. The post details the challenges of cloud networking, such as poor visibility, rapid pace of change, different technologies, new cost models, security risks, and multi-vendor environments, and positions Magic Cloud Networking as a solution that addresses these issues by focusing on the management plane.

Simplifying how enterprises connect to Cloudflare with Express Cloudflare Network Interconnect

3/6/2024

Introduced 'Express Cloudflare Network Interconnect' (Express CNI) to simplify and accelerate the deployment of physical network connections (CNIs) between enterprise networks and Cloudflare. This includes a 3-minute provisioning process directly from the Cloudflare dashboard, eliminating the need for GRE tunnels for Magic Transit and Magic WAN, and supporting standard 1500-byte packets. This reduces configuration complexity and improves the efficiency of connecting to Cloudflare's network services.

2023

Announcing General Availability for the Magic WAN Connector: the easiest way to jumpstart SASE transformation for your network

10/3/2023

This post announces the general availability of the Magic WAN Connector, a key component of Cloudflare One's SASE platform. It details how the connector simplifies the integration of existing network hardware with Cloudflare's network, enabling zero-touch connectivity and Zero Trust security for enterprise branches. The contribution highlights the shift from manual configuration of Anycast GRE or IPsec tunnels to a pre-installed software solution on certified hardware, managed via the Cloudflare One dashboard. It emphasizes the automation of tunnel configuration, routing policies, traffic steering, shaping, and failover, as well as the integration of Secure Web Gateway policies and private traffic filtering. The post also positions this as an evolution beyond SD-WAN, advocating for a 'light branch, heavy cloud' architecture.

Cloudflare is now powering Microsoft Edge Secure Network

9/28/2023

This post details the technical implementation of Cloudflare's Privacy Proxy Platform, which powers the Microsoft Edge Secure Network VPN. It explains the use of HTTP CONNECT for proxying traffic, the integration with 1.1.1.1 for DNS resolution, and the application of the Privacy Pass protocol for token-based client authentication without collecting personal information. It also describes the role of the Token Proxy, Privacy API, and Privacy Proxy services, and how Geo-egress is used to provide location-relevant egress IP addresses. The post highlights the benefits of Cloudflare's global network for low last-mile latency and geolocation parity, and mentions the use of Oxy, Cloudflare's proxying framework, for operational aspects.

Cloudflare’s 2023 Annual Founders’ Letter

9/27/2023

This post announces the expansion of Cloudflare's connectivity cloud to include GPU resources for AI inference across its global network. It details the strategy of deploying these resources in over 100 cities by the end of the year and nearly every city by the end of 2024, aiming to provide a 'third place' for AI inference between on-device and centralized public clouds. The post highlights the benefits of this approach for AI customers, including reduced latency, improved data locality, and cost-effectiveness, and mentions the development of Cloudflare Workers AI as a platform for this capability.

Welcome to connectivity cloud: the modern way to connect and protect your clouds, networks, applications and users

9/26/2023

This post introduces the concept of a 'connectivity cloud' as a new approach to IT and security challenges. It outlines four fundamental principles: deep integration, programmability, platform intelligence, and simplicity. The post argues that Cloudflare is the world's first connectivity cloud, citing customer examples like Conrad Electronic, Carrefour, and Canva to illustrate how this platform addresses issues of control loss, complexity, and the need for unified security and networking solutions.

Donning a MASQUE: building a new protocol into Cloudflare WARP

6/22/2023

Introduced MASQUE, a new protocol for WARP that extends HTTP/3 and leverages QUIC for efficient IP and UDP traffic proxying, aiming to improve Internet browsing speed and stability. This represents a shift from WireGuard to a standards-based protocol for enhanced flexibility and future cryptographic advancements. The implementation utilizes Cloudflare's global network and existing proxy framework, with plans to integrate into the Zero Trust suite.

From IP packets to HTTP: the many faces of our Oxy framework

3/30/2023

This post introduces Oxy, a Rust-based framework for proxies that spans multiple OSI layers. It details how Oxy handles raw IP packets for Cloudflare One and WARP via IP tunneling (connected and unconnected), tracks IP flows for policy enforcement and logging, and upgrades IP flows to TCP streams using Linux TUN interfaces and network namespaces for stateful NAT. It also discusses the use of the etherparse crate for parsing IP and transport headers.

Cloud CNI privately connects your clouds to Cloudflare

1/13/2023

This post announces and details the integration of Cloudflare Network Interconnect (CNI) with major public cloud providers (IBM Cloud, Google Cloud, Azure, OCI, AWS). It explains the importance of direct cloud interconnection for enterprises needing private access to cloud resources, contrasting it with the public internet. The post outlines how CNI simplifies connectivity by allowing direct connections from cloud VPCs into Cloudflare, eliminating the need for customers to maintain direct connections to their data centers. It details the provisioning process, using Google Cloud's Private Service Connect as an example, highlighting its speed and automation. The integration with Cloudflare One products like Magic WAN and Access is also discussed, enabling private routing and unified security policies.

China Express: Cloudflare partners to boost performance in China for corporate networks

1/13/2023

Introduces China Express, a suite of capabilities designed to address connectivity and performance challenges in mainland China. This includes Premium DIA for optimized cross-border public internet connectivity with partners CMI and CBC Tech, Private Link for secure private network connections, and Travel SIM in partnership with CMI for integrated mobile connectivity and Zero Trust security enforcement via the WARP client. Extends Cloudflare One and Magic WAN to China.

Cloudflare Application Services for private networks: do more with the tools you already love

1/13/2023

This post announces new integrations that extend Cloudflare's Application Services and Cloudflare One to private networks. Key technical contributions include enabling WAF policies for fully private traffic flows by building private networks on Cloudflare, applying public API security controls to private APIs by routing private API traffic through the Cloudflare One dataplane, and extending application-layer load balancing policies to traffic connected via various off-ramps (Cloudflare Tunnel, GRE, IPsec, CNI). It also highlights the automatic application of Argo Smart Routing to private app traffic and the introduction of private DNS for managing internal network resources within the Zero Trust private network.

Announcing the Magic WAN Connector: the easiest on-ramp to your next generation network

1/10/2023

Introduced the Magic WAN Connector, a lightweight software package that can be installed on physical or virtual hardware to automatically connect, steer, and shape IP traffic to the closest Cloudflare network location. This simplifies the on-ramp to Cloudflare One and SASE by automating configuration and orchestration, providing end-to-end traffic management features like routing, load balancing, failover, and application-aware steering, and integrating security from day one. The software is also being open-sourced.

Cloudflare protection for all your cardinal directions

1/10/2023

This post recaps the evolution of corporate network traffic definitions (north/south, east/west) and explains how Cloudflare One provides protection for all traffic flows. It details how Cloudflare's application security and network services protect public-facing applications, and how Zero Trust Network Access and Secure Web Gateway secure internal user traffic. It also explains how Cloudflare One can be used for east/west traffic between locations and for filtering local traffic by routing it to the nearest Cloudflare location. The post highlights that new capabilities will apply across all traffic flows due to the unified delivery model.

2022

Cloudflare expands Project Pangea to connect and protect (even) more community networks

12/13/2022

Project Pangea has been expanded to support community networks by relaxing the technical requirement of bringing their own /24 IP space. This allows eligible networks to access Cloudflare's services, including Internet connectivity, DDoS protection, network firewalling, and traffic acceleration, for free. This change leverages existing services like Magic Transit and Magic Firewall, and extends the functionality of Magic Transit to support customers without their own IP address space, now made available to community networks.

Cloudflare partners to simplify China connectivity for corporate networks

11/29/2022

This post details the expansion of Cloudflare One's SASE capabilities into mainland China through strategic partnerships. It describes two primary use cases: accelerating traffic from China networks to resources outside China via partner networks and enforcing uniform security policy across remote China user traffic using the WARP client. It also outlines future plans to extend SASE filtering to local China data centers. The architecture involves Cloudflare partners routing local traffic and global traffic to Cloudflare's network outside China for security policy enforcement, and then to its destination. For remote users, the WARP client tunnels traffic through partner networks to Cloudflare's PoPs outside China for policy application.

MPLS to Zero Trust in 30 days

6/23/2022

This post details the transition from legacy MPLS-based WAN architectures to a Zero Trust model using Cloudflare Magic WAN. It outlines the challenges of outdated MPLS networks in supporting distributed SaaS and hybrid multi-cloud environments, the limitations of SD-WAN, and the advantages of Magic WAN. The post provides a comprehensive guide for planning and executing this transformation, including preparing documentation, conducting workshops, developing a transition plan with bridging points and UAT, and migrating branches to the Cloudflare network.

Magic NAT: everywhere, unbounded, and lower cost

5/12/2022

Introduces Magic NAT, a new network function built on Cloudflare One. Magic NAT provides a globally distributed, unbounded, and cross-platform NAT solution. It addresses the limitations of traditional NAT by leveraging Cloudflare's Anycast architecture, offering dedicated egress IPs, and integrating with security policies. It supports both public and private NAT use cases, including IP address conservation and communication between overlapping IP spaces. The service also includes 4to6 and 6to4 NAT capabilities.

Cloudflare and Aruba partner to deliver a seamless global secure network from the branch to the cloud

3/17/2022

This post details the integration of Aruba EdgeConnect SD-WAN appliances with Cloudflare One, enabling customers to secure corporate traffic from branch offices using Cloudflare's Secure Web Gateway and Magic Firewall. It describes the establishment of Anycast GRE or IPSec tunnels between EdgeConnect appliances and Cloudflare's edge, and the use of Aruba Orchestrator's Business Intent Overlays to steer application traffic to Cloudflare for enhanced security and control. The integration aims to simplify network transformation by leveraging existing SD-WAN investments without requiring a rip-and-replace solution.

2021

Cloudflare One helps optimize user connectivity to Microsoft 365

12/10/2021

This post details Cloudflare One's qualification for the Microsoft 365 Networking Partner Program (NPP). It explains how Cloudflare One optimizes user connectivity to Microsoft 365 by providing direct, local breakouts to Microsoft's network, reducing latency and improving performance. It also highlights the security aspects of Cloudflare One, including its Zero Trust capabilities, network firewall, DNS filtering, and Secure Web Gateway, which protect users from threats on the rest of the internet while ensuring unfettered access to Microsoft 365. The post also outlines the simple, one-click enablement process for optimizing Microsoft 365 traffic within the Cloudflare for Teams dashboard.

Announcing Anycast IPsec: a new on-ramp to Cloudflare One

12/6/2021

Introduced Anycast IPsec as a new on-ramp to Cloudflare One. This implementation leverages Cloudflare's global Anycast network to provide a single IPsec tunnel that connects to over 250 locations, eliminating traditional hub-and-spoke performance penalties. The system uses a custom IKE daemon and an upgraded Cloudflare Tunnel technology for SA distribution to all edge servers, enabling rapid deployment and broad vendor support. This integrates with existing Cloudflare One services like Magic Transit, Magic Firewall, and Zero Trust.

Welcome to CIO Week and the future of corporate networks

12/5/2021

This post introduces the concept of next-generation corporate networks, contrasting traditional 'castle and moat' architectures with the challenges and opportunities presented by cloud adoption and remote work. It critiques the limitations of 'smörgåsbord of point solutions' and positions Cloudflare One as a comprehensive Network-as-a-Service (NaaS) solution to address gaps in visibility, security, user experience, cost, and network fragility. The post details the evolution of network architecture through three generations, highlighting the shift towards a more integrated and programmable approach.

Cloudflare for Offices

9/29/2021

Introduced 'Cloudflare for Offices,' a new initiative to extend Cloudflare's network directly into enterprise office buildings and multi-dwelling units through strategic partnerships and custom hardware. This aims to provide on-premises traffic with microsecond latency to Cloudflare's network, simplifying branch office connectivity by replacing traditional hardware solutions (MPLS, WANs, hardware firewalls, VPNs) with a direct connection to Cloudflare's services. This acts as an onramp to Cloudflare One, enabling Zero Trust security and performance benefits for office environments, and also enhances the performance of Cloudflare Workers by bringing the edge closer to users within these locations.

Announcing WARP for Linux and Proxy Mode

6/17/2021

This post announces the release of Cloudflare WARP for Linux and introduces a new 'proxy mode' for WARP across all desktop platforms. WARP for Linux is built using a shared Rust codebase (BoringTun) for cross-platform compatibility and is controlled via a command-line interface (`warp-cli`). Proxy mode allows users to configure specific applications to route their traffic through WARP, rather than encrypting all device traffic. This provides more granular control over which applications benefit from WARP's security and performance enhancements.

Announcing Network On-ramp Partners for Cloudflare One

3/22/2021

This post announces new Network On-ramp Partnerships for Cloudflare One, specifically for Magic WAN. It details the integration with VMware, Aruba, and Infovista for WAN/SD-WAN connectivity, and adds Digital Realty, CoreSite, EdgeConneX, 365 Data Centers, BBIX, Teraco, and Netrality Data Centers as Network Interconnect partners. The post outlines how these partnerships enable customers to connect their existing infrastructure (physical or virtual appliances) to Magic WAN using GRE tunnels, with IPSec support coming soon. It also highlights the benefits of private interconnection via Network Interconnect Partners for enhanced security and performance, and mentions future self-configuration capabilities for on-ramp partner devices.

Magic WAN & Magic Firewall: secure network connectivity as a service

3/22/2021

This post introduces Magic WAN and Magic Firewall as foundational components of Cloudflare One. Magic WAN provides secure, performant connectivity and routing for corporate networks using Anycast GRE tunnels, Cloudflare Network Interconnect, Argo Tunnel, WARP, and Network On-ramp Partners, aiming to replace expensive and complex MPLS networks. Magic Firewall integrates with Magic WAN to enforce network firewall policies at the edge across all traffic sources, offering centralized policy management and visibility.

2020

How our network powers Cloudflare One

10/16/2020

This post details how Cloudflare's global network, with its extensive distribution (200+ cities, 100+ countries, 42 Tbps capacity), scalability (commodity hardware, software-based functions), connectivity (8,800+ interconnections), and insight (attack intelligence, smart routing), powers Cloudflare One. It emphasizes how these network advantages translate into benefits for enterprise networking and security, enabling unified control, consistent performance, and enhanced visibility across distributed organizations.

What is Cloudflare One?

10/12/2020

This post introduces Cloudflare One, a unified vision for corporate security and networking. It combines existing and new products like WARP, Gateway, Magic Transit, and Access to address the challenges of modern enterprise networks. Key technical contributions include the packaging of WARP technology for enterprise use with Cloudflare Gateway for outbound traffic filtering, the planned integration of next-generation firewall capabilities into Magic Transit (Magic Firewall) for office networks, and the use of Cloudflare Access for Zero Trust controls to replace private network security models. The post also highlights the integration of logging for visibility into outbound traffic and the upcoming Intrusion Detection System.

Introducing Cloudflare Network Interconnect

8/4/2020

Introduced Cloudflare Network Interconnect (CNI) to allow customers to directly interconnect their branch and HQ locations with Cloudflare's network. CNI offers private network interconnects (PNI) and connections over Internet Exchange (IX) points. It enhances security, reliability, and performance for products like Cloudflare Access, CDN, Magic Transit, and Cloudflare Workers by bypassing the public internet for traffic between customer infrastructure and Cloudflare's edge. Performance improvements are demonstrated with reduced RTT and jitter for origin pulls, and enhanced security by removing public internet exposure for Magic Transit traffic.

Bringing Your Own IPs to Cloudflare (BYOIP)

7/30/2020

This post announces the general availability of Bring Your Own IP (BYOIP) across Cloudflare's Layer 7 products, Spectrum, and Magic Transit. It details the technical requirements for BYOIP, including Letters of Authorization (LOA) and updated Internet Routing Registry (IRR) records, and mentions support for RPKI. The post also describes configuration options like dynamic advertisement toggles and delegations for managing prefix usage across accounts, with specific implications for Layer 7 (SSL for SaaS) and Spectrum services.

2019

Extending Cloudflare to On-Prem Networks

8/13/2019

Introduced Magic Transit, a service that extends Cloudflare's global edge network to on-premise networks for secure, performant, and reliable IP connectivity. Magic Transit leverages BGP and anycast for global IP address space announcement and traffic ingestion, applies DDoS mitigation and advanced packet filtering, and connects back to origin infrastructure via GRE tunnels. It aims to provide a unified solution for IP security and network function virtualization, reducing the cost and complexity of managing traditional on-premise network hardware.

Magic Transit: Network functions at Cloudflare scale

8/13/2019

This post introduces Magic Transit, a new capability that extends Cloudflare's network functions to operate at the IP layer for any IP traffic. It details how Magic Transit leverages Cloudflare's existing global network, anycast, and homogeneous server architecture to provide DoS mitigation, firewalling, and routing for customer IP prefixes. The post explains the use of network namespaces for isolation and control, and GRE tunneling with anycast IP addresses for delivering traffic back to customer networks. It highlights the technical implementation details of packet flow, routing, and tunneling.

2012

CloudFlare Now Supporting More Ports

3/1/2012

This post details the expansion of Cloudflare's proxied ports to include common web control panel ports (2052, 2053, 2082, 2083, 2086, 2087, 2095, 2096, 8080, 8443, 8880) beyond the initial 80 and 443. It also explains the technical limitations preventing the proxying of non-web protocols like FTP and SSH due to the lack of a HOST header, and how this blocking adds a layer of security and contributes to Cloudflare's threat intelligence.