Bringing Application Services to Private Networks
Cloudflare’s Application Services have long protected and accelerated public-facing websites and APIs. With Cloudflare One, the same underlying network is extended to corporate networks. Now, new integrations between these two product families aim to close the gap, letting security and IT teams apply the same WAF, API security, load balancing, and performance tools to traffic that never touches the public Internet.
The goal is operational simplicity: fewer point products and a single control plane for both public and private traffic. But these integrations also unlock use cases that rely on Cloudflare’s network architecture, where every server runs the same software stack and a packet can pass through a complete set of filters in one pass without hair-pinning to multiple locations.
WAF Policies for Fully Private Traffic
Cloudflare’s WAF is trusted by millions of customers to protect Internet-exposed applications, including those fronted by Cloudflare Tunnel with a public hostname. The new integration extends the same WAF controls to applications that are reachable only through a private network. This is designed for customers who want to filter all traffic, including requests that originate from inside a “trusted” network, as though it came from the open Internet—a stricter Zero Trust posture.
It also addresses customers connecting entire data centers or cloud properties via GRE, IPsec, or CNI, and those who want Cloudflare WAF for private apps without having to assign public hostnames. By integrating the WAF directly with the Cloudflare One dataplane, policies can be enforced in-path on fully private traffic flows.
API Security Beyond the Perimeter
After web applications, public-facing APIs are the next attack surface many teams lock down. Cloudflare offers DDoS protection, abuse prevention, and data-loss controls for those APIs. But distributed architectures and microsegmentation push internal APIs out of the safety of a single perimeter, making them an equally important target.
With Cloudflare One, entire private networks can be routed through the same security stack that protects public APIs. Networking and security teams can apply Zero Trust principles to private API flows, improving overall security posture without deploying separate tooling for internal traffic.
Load Balancing and Local Traffic Steering
Security is half the story. Cloudflare’s load balancing suite includes application-layer controls for origins behind the reverse proxy and network-layer controls for IP traffic. Customers have asked for the ability to define application-layer load balancing policies regardless of the off-ramp used to connect traffic—whether that is Cloudflare Tunnel for apps or GRE, IPsec, or CNI for IP networks.
There is also interest in extending these policies into local networks, steering traffic across servers within a single data center or cloud property rather than only across multiple global locations. These capabilities are planned to improve resiliency by giving teams more granular control over private apps and local traffic.
Performance Optimizations at Every Layer
Argo Smart Routing already accelerates reverse-proxied traffic with application-layer optimizations and IP packets via network-layer decisions over Cloudflare’s global private backbone. As the integration between Application Services and the private networking dataplane deepens, customers should automatically gain similar speed and efficiency benefits for all traffic connected to Cloudflare, at every layer of networking.
Private DNS for Internal Resources
Cloudflare’s authoritative DNS protects millions of public domains, but not every organization wants those queries visible to anyone. Private DNS lets customers resolve queries to private domains only when the user is connected to the Zero Trust private network they define within Cloudflare. Built on the same authoritative DNS and Gateway filtering services, it supports common DNS record types, resolves overlapping IPs across virtual networks, and applies the same DNS filtering controls already available for Zero Trust traffic.
Combining external and internal DNS in a single pane of glass simplifies infrastructure and reduces operational overhead while inheriting Cloudflare’s response time, redundancy, and security.
Beta access for the new integrations is available through the sign-up list.



