Keeping Source IP Allowlists While Moving Off Legacy Gateways
Source IP allowlisting has long been a convenient way for organizations to control access to their applications and third-party services. Legacy on-premise security tools like VPNs, firewalls, and secure web gateways (SWGs) make this simple by tying traffic to static IP addresses. But these hardware appliances come with scalability headaches, security risks, and poor support for globally distributed or remote workforces.
Cloudflare Gateway, our SWG, is designed to replace those legacy tools as part of a broader Zero Trust platform. It handles traffic filtering and routing for recursive DNS, Zero Trust network access, remote browser isolation, and inline CASB, among other functions. As organizations make the transition, however, we recognize that many administrators still want the familiarity of source IPs. That is why we offer dedicated egress IPs and are building more granular egress policies on top of them.
How Dedicated Egress IPs Work
Source IPs remain a common way to verify that traffic originates from a known organization or user when accessing applications and external destinations. When users proxy their traffic through Cloudflare's global network, we apply filtering and routing at the data center closest to them. This approach works well for roaming employees and distributed teams — there are no static IP lists to update as users move, and no single location can become a traffic bottleneck.
Today, proxied traffic egresses in one of two ways:
- Device client (WARP) Proxy IP – Cloudflare forwards user traffic using an IP from the default range shared across all Zero Trust accounts.
- Dedicated egress IP – Customers receive a dedicated IP (IPv4 and IPv6) or range geolocated to one or more Cloudflare network locations.
The WARP Proxy IP range is the default egress for all Cloudflare Zero Trust customers. It preserves user privacy and routes traffic through the nearest network location for the best performance. However, it does not offer the granularity needed for source IP-based allowlists tied to a specific organization.
Dedicated egress IPs are exclusive to the assigned customer — no other tenant shares them. Leasing these IPs from Cloudflare avoids the privacy concerns of carving them out of an organization's own address space, and it removes the need to defend on-premise VPN IP ranges from DDoS attacks.
Dedicated egress IPs are available as an add-on to any Cloudflare Zero Trust enterprise contract. Customers can select which Cloudflare data centers their egress traffic uses, and every subscriber gets at least two IPs so traffic is always routed to the closest dedicated egress location for performance and resilience. These IPs work across all of Cloudflare's on-ramps: the WARP device client, proxy endpoints, GRE and IPsec tunnels, and any of the 1,600+ peering locations with ISPs, cloud providers, and enterprises.
Common Customer Use Cases
Organizations across industries are already using Gateway dedicated egress IPs to simplify application access. Three patterns are most common:
- Allowlisting third-party application access: Suppliers, partners, and other external organizations often still authenticate traffic by source IP. Dedicated egress IPs let users reach those tools without forcing the third party to change its security model.
- Allowlisting SaaS app access: Source IPs remain a useful defense-in-depth layer for SaaS access, alongside stronger controls like multi-factor authentication and identity provider checks.
- Deprecating VPN usage: Hosted VPNs typically draw from a customer's advertised IP range, and many organizations want to keep existing IP allowlist processes when they migrate. Dedicated egress IPs ease that transition while routing traffic over Cloudflare's global network instead of a centralized VPN concentrator.
More Granular Control With Egress Policies
We are also introducing a forthcoming egress policy builder in the Cloudflare Zero Trust dashboard. Administrators will be able to specify which dedicated egress IP is used for traffic based on attributes like identity, application, network, and geolocation.
This allows fine-grained routing decisions — for example, sending only certain applications, Internet destinations, or user groups through dedicated egress IPs while everything else uses the default WARP Proxy IP range. Selectors will include application, content category, domain, user group, destination IP, and more. That flexibility supports a layered security approach while keeping the most critical destinations on dedicated IPs for performance.
The policy builder will also let administrators direct traffic through any country or region where Cloudflare has a presence. This is valuable for globally distributed teams that need geo-specific experiences. Consider a media conglomerate with marketing teams verifying digital ad layouts across multiple regions. Instead of relying on colleagues in each market or spinning up regional VPNs, they could match a custom test domain per region and egress through their dedicated IP deployed there.
Availability
Dedicated egress IPs are available as an add-on to a Cloudflare Zero Trust Enterprise plan. Interested customers can contact their account team. Those who want early access to the Gateway egress policy builder can join the waitlist.



