Cloudflare One reaches mainland China through partner networks

Cross-border connectivity between mainland China and the rest of the world has long been a sore spot for IT teams at multinational organizations. Packet loss, latency, and route instability on paths across the border complicate what should be routine access to global resources. Cloudflare is now extending its Cloudflare One SASE platform into China through strategic partnerships, aiming to give organizations a unified way to apply security policies and improve performance for China-bound traffic.

The company already operates application services from 45 data centers across 38 Chinese cities through a partnership with JD Cloud, but the new Cloudflare One integrations tackle network-layer and user-level connectivity. All policy enforcement and traffic management remains under a single Cloudflare control plane, regardless of where users or resources sit.

Optimized routing for China office networks

The first use case addresses traffic from corporate offices in China reaching private or public resources hosted outside the country. A typical deployment sees last-mile connectivity at Chinese office locations provided by Cloudflare's regional partners. Those partners route domestic traffic locally and forward cross-border traffic over a secure link to the nearest Cloudflare data center outside mainland China.

Once at that Cloudflare edge location, traffic passes through the full security stack: network firewall-as-a-service and Secure Web Gateway policies are applied before traffic continues toward its destination, whether that's a private network endpoint connected through an Anycast GRE or IPsec tunnel, a direct connection, or a public internet resource. For internet-bound traffic, egress can use either a shared or dedicated Cloudflare-owned IP pool. Return traffic follows the reverse path, with security policies applied again at the Cloudflare edge before handing off to the partner network.

This network-level solution is generally available now.

Remote user access via WARP and partner acceleration

The second scenario covers employees working in China who need access to corporate resources outside the country, regardless of whether they're at an office or on the road. Cloudflare is adapting its device client, WARP, for this environment through private beta testing with partners.

When the WARP client is installed on a company-managed device enrolled in a Cloudflare Zero Trust organization, it establishes a Wireguard tunnel to the nearest Cloudflare point of presence outside mainland China. In China, that traffic is carried by Cloudflare's partner acceleration networks; the traffic itself stays encapsulated in WARP, so content remains secure while in transit through partner infrastructure.

Once the tunnel reaches Cloudflare's edge, administrators apply the same Gateway and Access policies used elsewhere in the world — or choose to enforce different rules for Chinese vs. global traffic. Since this relies on WARP, IT teams manage a single device client for all users regardless of geography, avoiding parallel security stacks.

This capability is in private beta, with broader availability planned through partner collaborations.

Plans for full SASE within China

Cloudflare acknowledges that local traffic within China also stands to benefit from SASE functionality. The company stated it is working toward offering the full Cloudflare One suite from its China-based data centers, a step that would put SASE enforcement milliseconds from users and applications inside the country. This effort will expand on the existing application services footprint in China and is currently being developed with partners. Interested customers can join a waitlist for beta access.