← Back to demo hub
Cloudflare One — SASE & Workspace Security

One platform to connect, protect, and govern your workforce.

Identity, device posture, network access, web filtering, data protection, AI controls — delivered from every Cloudflare PoP, programmable from end to end.

Open the dashboard →
Why SASE, why now

The castle-and-moat model broke.

Work moved out of the walled castle: users, data, apps, and clouds are everywhere — and every point solution added to chase them made operations slower.

ACT 1

Castle-and-moat centralization

Employees, apps, and data lived inside a walled castle. Dedicated private connectivity led back to the data center, and security enforced at the perimeter.

DC perimeter security branch stores remote VPN MPLS VPN
ACT 2

Everything distributed anywhere

Storage and compute migrated to cloud, SaaS became core business infrastructure, and remote/hybrid work became normal — while network and security lagged behind.

legacy DC remote users SaaS apps branch offices cloud data security afterthought
ACT 3

Point solutions exploded

Teams added SD-WAN, VPN, SWG, CASB, DLP, RBI, WAF, and ZTNA one by one. Risk escalated, agility dropped, and costs rose across old and new stacks.

network VPN SD-WAN SWG CASB DLP ZTNA too many consoles
Cloudflare One platform

One global network. One unified control plane.

Cloudflare One consolidates security and networking on programmable cloud-native services that connect users, devices, networks, applications, and data.

Programmable cloud-native services Build connectivity and security capabilities on Cloudflare’s global network and manage them from a unified control plane.
Plan-specific SLA Availability commitments depend on the purchased plan and contract. Enterprise customers should refer to their subscription agreement.
Services designed for every location Cloudflare One services are designed to run across all network locations so traffic can be inspected close to its source.
Consistent speed and scale Anycast routes traffic toward a nearby Cloudflare location, keeping authentication, inspection, and policy enforcement close to users.
Sources
Users
Devices
Networks
Apps
Data
☁ Cloudflare One
Zero Trust Security
AI Security
AI-powered Platform
Network-as-a-Service
Manage & Compose
Integrate & Program
Destinations
SaaS
Internet
AI / MCP / AI Gateway
Private apps
What it actually is

Many sources. Many destinations. One control plane.

Connecting any source to any destination from anywhere, with commodity Internet as the underlay.

Office 1IPSec / GRE Tunnel Private appcloudflared Tunnel DC / colo edgeCloudflare WAN · CNI Agentless usersDNS location · PAC Users with WARPMASQUE · HTTP/3 InternetDNS · HTTP policies SaaS appsSAML/OIDC · IdPGateway · CASB API On-prem / DCcloudflaredCloudflare MeshCloudflare WAN Public cloudcloudflaredIPsec/GRE ☁ Cloudflare One single policy engine single-pass inspection every PoP IPsec / GRE cloudflared · outbound HTTPS/2 CNI private on-ramp WARP · MASQUE / HTTP/3
IPsec / GRE
  • What: router/appliance L3 tunnel into Cloudflare
  • Where: sites, branches, WAN edges
  • Why: well-known network on-ramp, no agent
Cloudflare Tunnel / cloudflared
  • Outbound-only daemon — no public IPs, no inbound firewall holes
  • Exposes inbound to a private app or network behind it
  • Not an egress gateway — host's own outbound still uses its default route
  • Server-initiated egress? use Cloudflare Mesh or Cloudflare WAN
  • Non-standard ports? add private CIDR + Gateway network policy
WARP / Mesh family
  • WARP Client on user devices — MASQUE over HTTP/3
  • Full Zero Trust posture (identity + device + context)
  • Cloudflare Mesh = headless Linux for subnets/servers/IoT
  • Bidirectional, server-initiated paths supported
  • At scale: deploy via MDM — Intune supported
Cloudflare WAN / Network Interconnect
  • Cloudflare WAN: connects branches, headquarters, data centers, and cloud networks
  • Internet on-ramp: IPsec or GRE from existing routers and firewalls
  • CNI private on-ramp: direct or partner interconnect from an existing network location to Cloudflare
  • Typical physical handoff: carrier, colo, or data-center edge
Agentless: DNS location vs PAC
  • DNS location — plain DNS: identified by source IP
  • DNS location — DoH: unique endpoint URL, works on roaming devices
  • DNS location — DoT: source IP or DoT hostname
  • No HTTP inspection on any DNS mode
  • Per-user context: only via DoH user tokens
  • PAC / proxy endpoint: browser HTTP/HTTPS to Gateway, identity-aware
  • Browser only — no UDP, no HTTP/3, no non-browser apps
Pick the right on-ramp

Which on-ramp do I actually deploy?

The diagram shows what connects. This table answers what to pick.

On-ramp Routes what Identity-aware Install Best for Main limits
WARP client Device DNS, HTTP/HTTPS, optionally broader L4 Yes (per user/device) Per device (MDM/Intune at scale) Managed laptops/desktops, full Zero Trust posture Needs client; HTTPS inspection requires root cert + TLS decrypt
DNS location DNS only Network/source-IP based None Offices, branches, simple DNS filtering No HTTP inspection; no per-user context by default
Proxy endpoint (PAC) Browser HTTP/HTTPS via PAC Yes (auth endpoints) Browser/PAC config, no agent VDI, locked-down endpoints, legacy proxy migration Browser only; no UDP, no HTTP/3, no non-browser apps
Cloudflare Mesh Subnet/network traffic, server-initiated Network-level One Linux gateway per subnet Servers, IoT, routers, whole subnets — no per-device install Not per-device endpoint visibility
Cloudflare WAN Whole-branch / whole-DC L3 Network-level Router/appliance via IPsec, GRE, or CNI Branch offices, data centers, site-to-site Network-level context; CNI requires a provisioned interconnect
Rule of thumb
  • Employees / end-user devices → WARP client
  • Office DNS-only filtering → DNS location
  • No agent possible → Proxy endpoint / PAC
  • Subnets, servers, IoT → Cloudflare Mesh
  • Whole branch or DC → Cloudflare WAN (GRE / IPsec)
  • Private app behind firewall, no inbound holes → cloudflared Tunnel
Choose the capability depth

With people connected to resources, it’s time to build the policies that protect every interaction.

Each deep page separates configured account evidence from documented capability and planned proof paths, so the demo never overstates what is live.

ZTNA

Zero Trust Network Access

Verify identity + device + context. Grant access to one app, not the network. Augments or replaces VPN.

Cloudflare Access WARP Device posture
$ EXPLORE ZTNA →
SWG

Secure Web Gateway

Cyber threat defense at DNS, network, HTTP, and egress layers. Block phishing, ransomware, and shadow IT.

Cloudflare Gateway DNS policies HTTP policies
$ EXPLORE SWG →
RBI

Remote Browser Isolation

Risky web content executes in Cloudflare — never in the user's browser. Protect data-in-use without sacrificing UX.

NVR rendering Zero-day defense Data-in-use
$ EXPLORE RBI →
CASB

Cloud Access Security Broker

Multimode CASB — inline + API + SaaS posture in one engine. Surface shadow IT and prevent exfiltration.

SaaS posture API integration Shadow IT
$ EXPLORE CASB →
DLP

Data Loss Prevention

Predefined + custom profiles, Exact Data Match, and Microsoft Information Protection labels — inline and at rest.

EDM MIP labels Inline + at rest
$ EXPLORE DLP →
AI SEC

AI Security

Discover workforce AI, protect application-to-model traffic, and govern the tools agents can reach.

Gateway + DLP AI Gateway MCP portals
$ EXPLORE AI SECURITY →
EMAIL

Email Security

Add phishing, BEC, malicious-link, and campaign-response controls around Microsoft 365 or Google Workspace.

MX / Inline API / BCC Campaign response
$ EXPLORE EMAIL →
DEX

Digital Experience Monitoring

End-to-end visibility into how users actually experience your apps — endpoint, network, and app-layer telemetry in one view.

Endpoint health Network paths App-layer signals
$ EXPLORE DEX →
Proof and adoption path

Cloudflare uses Cloudflare One — then helps customers adopt it in phases.

Start with one high-value path, prove policy and visibility, then expand across users, apps, data, branches, and clouds.

Cloudflare uses Cloudflare One
"Securing Cloudflare with our own services is the most effective way not only to protect our business, but also to innovate for our customers."
Cloudflare dogfoods Cloudflare One for workforce access, web security, data protection, and email defense.

A practical adoption path, not a rip-and-replace.

Phase 1 · See traffic DNS filtering, app inventory, SaaS posture, and initial DLP/log visibility.
Phase 2 · Control identity Corporate IdP, MFA, Access policies, HTTPS inspection, and basic Gateway rules.
Phase 3 · Reduce risk ZTNA for private apps, device posture, DLP profiles, CASB findings, and isolation.
Phase 4 · Operate as code Logs, review loops, hardware-backed MFA, network segmentation, and auto-scaling on-ramps.
Built by Rodrigo Nobre with Cloudflare Workers