DNS filtering
Block or resolve domains before a browser or app opens a connection. Current demo: DNS Test for *.noble.lab through a Gateway location.
Cyber threat defense at DNS, network, HTTP, and egress layers.
Use this page to explain Cloudflare Gateway as the Secure Web Gateway in Cloudflare One: DNS, HTTP, and network policy enforced at the edge for traffic arriving through the right on-ramp. Keep it precise: Gateway is policy-based SWG enforcement, not a traditional Snort/Firepower-style IDS replacement.
SWG is the decision layer: traffic enters Cloudflare, Gateway evaluates policy, then the action is allow, block, isolate, inspect, resolve, or log.
Your account already has DNS and HTTP examples. Network policy is the main missing surface to add for a complete SWG walkthrough.
Block or resolve domains before a browser or app opens a connection. Current demo: DNS Test for *.noble.lab through a Gateway location.
Layer 3/4 policy for non-HTTP apps and traffic proxied through Gateway. Good next demo: block a TCP destination or allow a private subnet path.
Application, hostname, upload/download, isolation, and DLP controls. Current demos include ChatGPT, cloud storage, fast.com isolation, and card-upload DLP.
Use the action model as the customer-facing frame, then show which actions are configured today and which ones are candidate demos.
Let known-good traffic pass and log it.
Stop destinations, categories, apps, or risky uploads.
Open risky sites in Cloudflare Browser Isolation.
Send users to a safer URL or controlled destination.
Bypass TLS inspection for sensitive or incompatible traffic.
Prevent matching traffic from being browser-isolated.
Bypass AV/DLP scanning for trusted flows.
Use these as the policy menu for the live walkthrough: simple web controls first, then deeper exceptions and handoffs when the customer asks.
chat.openai.com / ChatGPT traffic
Dropbox, personal storage, consumer sync paths
Risky browsing opens in Cloudflare Browser Isolation
*.noble.lab resolves through Gateway
POST uploads carrying payment data
Secrets in MCP tool response traffic
Redirect risky or training domains to a safe landing page
Bypass inspection for finance / healthcare / pinned-cert apps
Control TCP/UDP traffic after HTTP policies are evaluated
Use these shortcuts to move from the visual story into real policy, location, DLP profile, and log views.