Why CIOs Are Replacing Hardware With Cloudflare One

Cloudflare One is now over a year old, and the way enterprises are using it has evolved well beyond what Cloudflare anticipated at launch. The suite is designed to let companies handle connectivity, security, and analytics for their corporate network through a single vendor and a single control plane, rather than the traditional patchwork of on-premise appliances.

That older model—buying point solutions from dozens of hardware vendors—was already straining under the weight of distributed offices, remote work, and apps moving to SaaS and public cloud. The attacks targeting those networks got more sophisticated at the same time. Customers told Cloudflare the resulting problems formed a clear hierarchy: first, users, offices, data centers, and clouds all need to reach each other and the Internet; second, traffic between those entities needs filtering; third, that traffic needs to be logged, diagnosed, and analyzed—and the whole solution has to be fast, reliable, and compliant with local regulations.

Cloudflare One answers that hierarchy by putting Cloudflare's global, programmable edge network to work for corporate customers, not just the websites and services it already accelerates and protects. Cloudflare One: One Year Later

One Network, Many On-Ramps

Cloudflare One's architecture is built around a simple premise: get traffic onto Cloudflare's network as early as possible, then apply security and performance policies from that centralized point. The on-ramps are deliberately varied. Offices and data centers can connect via SD-WAN partnerships or the upcoming Cloudflare for Offices infrastructure, with IPsec Tunnels now supported alongside the existing GRE Tunnels. Remote workers on managed devices install a lightweight agent, while contractors and unmanaged devices can reach internal tools in a fully agentless mode. Improvements to Cloudflare Tunnel and network interfacing provisioning are also in the pipeline to ease the connection process.

BLOG-834 Embedded Image - RmqYgd

Once traffic lands on the network, a composable security stack takes over. Customers can apply controls ranging from IP-layer DDoS mitigation to remote browser isolation, and new network firewall features are being introduced this week to further displace physical appliances. Zero Trust access policies govern who can reach internal resources and SaaS applications.

BLOG-834 Embedded Image - h8LMcL
BLOG-834 Embedded Image - R8xQsM

Beyond security, the network is engineered for speed. Cloudflare's infrastructure is peered with over 10,000 networks, providing redundant paths that route around Internet disruptions. This week brings updates on network performance and new features for intelligently accelerating packets in transit.

Local compliance requirements are also addressed. Customers can choose where security functions are applied and how logs are stored and exported, with new features forthcoming that create metadata boundaries within the network.

Traffic Defended: A 400% Surge

Traffic flowing through Cloudflare One has grown by nearly 400% over the past year, with filtering applied at wire-speed to every bit. The composable filtering stack lets customers mix and match controls by traffic type: some use simple four-tuple rules based on IP addresses and ports, others write custom eBPF filters to process hundreds of gigabits per second, and still others deploy pure Zero Trust architectures with identity-based policies and endpoint protection.

In a typical 24-hour stretch, customers blocked over 9.3 trillion packets, requests, and other network "nouns" from reaching their networks. These custom rules are managed centrally, impose no performance penalty, and are enforced uniformly regardless of whether traffic originates from an office, data center, or cloud provider. Because the entire edge acts as a single firewall, there is no backhauling to a central device for policy enforcement.

192,000 Applications Under Zero Trust

Cloudflare Access replaces private network security with a Zero Trust model that treats internal applications like the fastest SaaS offerings. Resources are connected to Cloudflare's network without exposing firewall ports, and administrators create global or per-resource rules governing who can log in and how. Users launch applications with a single click while the network enforces policy and accelerates traffic.

Over 192,000 applications are now protected by Zero Trust rules, from mission-critical systems to marketing websites. Non-HTTP use cases have also moved into the browser, with SSH and VNC clients that require no additional software. Policy granularity can be stacked from "only my team can log in" to "only this group, from a corporate device, with a physical hardkey, from these countries." Additional features introduced this year prompt users to justify their access and require a second admin to approve sensitive requests in real time.

Performance is not sacrificed for security. Zero Trust rules are enforced in every one of Cloudflare's 250 data centers, with policy decisions running on serverless compute to keep latency low. Secured applications also benefit from the same routing acceleration used by the Internet's largest websites.

Small Teams Get Enterprise Security

When Cloudflare Access launched over three years ago, smaller organizations were often shut out of Zero Trust products. That has changed: more than 10,000 organizations now use Cloudflare One without a contract, and the free tier was raised to 50 seats last year.

Outbound Internet traffic is also filtered with the same rigor. Over 5,500 organizations secure traffic leaving their devices and offices. The security stack includes the world's fastest DNS resolver for threat and content filtering, identity-based network policies, file transfer blocking, and HTTP virus inspection. Customers can control which tenants of SaaS applications are accessible and receive a Shadow IT report generated from network visibility. For organizations that trust nothing, the isolated browser can be applied to all destinations or specific ones, with data controls that block copy-paste, printing, or text input by user and destination. This browser isolation avoids legacy techniques like pixel pushing and DOM manipulation.

Scale Delivered on Owned Hardware

Every service runs on bare metal hardware that Cloudflare owns and operates in over 250 cities. There are no public clouds in the path — each server in each location is capable of processing every customer's packet, eliminating the need for hardware sizing or location selection.

That architecture is handling more than 1.69Tbps of peak forward proxy traffic per day, with the largest customers pushing hundreds of gigabits per second over a single virtual interface. Customer networks also interlink directly: most Cloudflare One customers have significant traffic exchanges with other customers' networks, many via physical connections in 158 peering facilities worldwide.

Real-world deployments

Tens of thousands of customers have adopted Cloudflare One over the past year. Several organizations stand out for how they applied the platform to specific security and networking problems.

Serving as the federal government's protective DNS

BLOG-834 Embedded Image - fz6pxb

The Cybersecurity and Infrastructure Security Agency (CISA), part of the U.S. Department of Homeland Security, repeatedly flagged malicious hostnames, phishing links, and untrustworthy upstream DNS resolvers as a major risk. Attackers can compromise devices by tricking endpoints into querying a malicious hostname, then steal credentials or install malware once the user connects to the resolved destination.

Earlier this year, CISA and the National Security Agency (NSA) recommended protective DNS resolvers, which check the queried hostname against threat intelligence and block the connection if the destination is dangerous. CISA did not stop at a recommendation: it selected Cloudflare and Accenture Federal Services to deliver a protective DNS solution to its partner agencies across the federal, state, local, tribal, and territorial governments.

Replacing VPNs at a hardware manufacturer

BLOG-834 Embedded Image - 83znaF

In 2018, the developer operations team at a major telecom and network equipment company grew frustrated with its legacy VPN. Developers depended on the VPN to reach internal tools, but the friction generated constant help desk tickets. The team decided to eliminate the VPN and signed up for Cloudflare Access, initially using an administrator's personal credit card, to make internal applications feel as seamless as SaaS tools.

Over the next three years, other departments requested the same setup. As thousands of users migrated to a Zero Trust model, the security team began building rules and using logs without touching server-side code. Last month, that team extended the model to the rest of the internet, deploying Cloudflare Gateway to replace its legacy DNS filtering with a faster platform that protects the company's 100,000+ employees from phishing, malware, and ransomware regardless of location.

Scaling security at BlockFi

BLOG-834 Embedded Image - TwUimW

BlockFi, which provides interest accounts, cryptocurrency-backed loans, rewards cards, and crypto trading to over 450,000 funded clients with more than $10 billion in assets, turned to Cloudflare One after a major DDoS attack on its sign-up API. Cloudflare mitigated the attack and got systems running within hours. With Bot Management added the first day, BlockFi blocked roughly 10 million malicious bots.

BlockFi then shifted focus to internal security. Its legacy private network relied on IP-based allow/deny lists that consumed engineering time and broke down when users left the office. BlockFi replaced that model with Cloudflare One, bringing identity-driven Zero Trust control to internal resources: team members now authenticate via single sign-on from any location. The security team also deployed Cloudflare One's DNS filtering and Secure Web Gateway to protect employees from targeted phishing and malware.

Preserving call quality under ransom attack

BLOG-834 Embedded Image - dD7REM

A large VoIP and unified communications provider came under ransom attack and deployed Cloudflare Magic Transit in front of its entire internet presence—corporate and production networks—in under 24 hours. Given the sensitivity of internet telephony, the company worried about performance regressions affecting call quality. Instead, key metrics like latency and jitter improved, surprising its network administrators and underscoring Cloudflare's ability to handle performance-critical workloads where milliseconds and reliability matter.

The road ahead

This week brings dozens of new Cloudflare One announcements addressing new problems. The platform continues to evolve as the next-generation corporate network, and organizations can get started via the Cloudflare One sign-up page.