← Back to Cloudflare One
SWG

Secure Web Gateway

Cyber threat defense at DNS, network, HTTP, and egress layers.

✓ Guided dashboard demo
Mental model

Control Internet and SaaS traffic before threats, shadow IT, or sensitive data reach the endpoint.

Use this page to explain Cloudflare Gateway as the Secure Web Gateway in Cloudflare One: DNS, HTTP, and network policy enforced at the edge for traffic arriving through the right on-ramp. Keep it precise: Gateway is policy-based SWG enforcement, not a traditional Snort/Firepower-style IDS replacement.

Traffic enters GatewayUsers reach Cloudflare through WARP, Gateway location DNS, PAC/DoH, or browser traffic paths.
Policy is evaluated onceGateway rules decide whether to allow, block, isolate, resolve, or apply data controls.
Threats and shadow IT are reducedThe same dashboard can show DNS control, app control, browser isolation, and DLP enforcement.
Traffic control layer

Gateway decides what happens to Internet and SaaS traffic.

SWG is the decision layer: traffic enters Cloudflare, Gateway evaluates policy, then the action is allow, block, isolate, inspect, resolve, or log.

💻WARPmanaged endpoint
🏢DNS locationoffice / branch
🌐PAC / proxybrowser traffic
DNS · HTTP · network
☁ Cloudflare Gateway
identitydevicedestinationdata
policy action
allow block isolate inspect resolve log
Policy surfaces

Gateway policy is not just HTTP — it spans DNS, Network, and HTTP controls.

Your account already has DNS and HTTP examples. Network policy is the main missing surface to add for a complete SWG walkthrough.

DNSconfigured

DNS filtering

Block or resolve domains before a browser or app opens a connection. Current demo: DNS Test for *.noble.lab through a Gateway location.

Networkmissing

Network filtering

Layer 3/4 policy for non-HTTP apps and traffic proxied through Gateway. Good next demo: block a TCP destination or allow a private subnet path.

HTTPconfigured

HTTP inspection

Application, hostname, upload/download, isolation, and DLP controls. Current demos include ChatGPT, cloud storage, fast.com isolation, and card-upload DLP.

Action model

Gateway can do more than allow or block.

Use the action model as the customer-facing frame, then show which actions are configured today and which ones are candidate demos.

☁Gateway decisionmatch traffic → choose action
Allow

Let known-good traffic pass and log it.

Block

Stop destinations, categories, apps, or risky uploads.

Isolate

Open risky sites in Cloudflare Browser Isolation.

Redirect

Send users to a safer URL or controlled destination.

Do Not Inspect

Bypass TLS inspection for sensitive or incompatible traffic.

Do Not Isolate

Prevent matching traffic from being browser-isolated.

Do Not Scan

Bypass AV/DLP scanning for trusted flows.

Configured examples

Gateway examples for block, isolate, resolve, inspect, redirect, and bypass decisions.

Use these as the policy menu for the live walkthrough: simple web controls first, then deeper exceptions and handoffs when the customer asks.

block

Block ChatGPT

HTTP · HTTP app rule · App ID 1199

chat.openai.com / ChatGPT traffic

block

Block Personal Cloud Storage

HTTP · HTTP app rule · App IDs 538, 554, 2216, 637

Dropbox, personal storage, consumer sync paths

isolate

Isolate fast.com

HTTP · HTTP hostname rule

Risky browsing opens in Cloudflare Browser Isolation

resolve

DNS Test

DNS · DNS resolver rule

*.noble.lab resolves through Gateway

inspect

Block Credit Card Uploads

HTTP · HTTP + Financial Information DLP

POST uploads carrying payment data

inspect

Block MCP Portal DLP traffic

HTTP · HTTP + Credentials and Secrets DLP

Secrets in MCP tool response traffic

redirect

Redirect risky category

DNS/HTTP · Candidate policy

Redirect risky or training domains to a safe landing page

do-not-inspect

Do Not Inspect banking

HTTP · Candidate TLS bypass

Bypass inspection for finance / healthcare / pinned-cert apps

block

Block non-HTTP destination

Network · Candidate Network rule

Control TCP/UDP traffic after HTTP policies are evaluated

Open in dashboard

The Gateway views behind the SWG demo.

Use these shortcuts to move from the visual story into real policy, location, DLP profile, and log views.

Gateway HTTP policies ↗Block, isolate, and inspect browser/SaaS trafficTraffic policies · DNS ↗DNS policy examples for block, override, SafeSearch, and YouTube RestrictedGateway DNS policies ↗DNS filtering and resolver policyGateway locations ↗Agentless DNS location: Test LocationDLP profiles ↗Financial Information and Credentials and Secrets profilesGateway logs ↗Verify matched rule, identity, destination, and action
Built by Rodrigo Nobre with Cloudflare Workers