Why WARP is moving to MASQUE
Cloudflare has announced that its Zero Trust WARP client will add support for MASQUE, the IETF-standardized protocol for proxying IP and UDP traffic over HTTP/3 and QUIC. The move addresses connectivity, compliance, and extensibility limitations in the current WireGuard-based implementation.
WireGuard has served Cloudflare well since WARP's consumer launch in 2019. It is fast, simple, and secure. But that simplicity carries trade-offs: WireGuard is not easily extended, does not support FIPS-compliant cipher suites, and depends on non-standard ports that some networks block.
Beyond WireGuard's constraints
WireGuard's default port is 51820. Zero Trust WARP currently uses port 2408 for its WireGuard tunnel, but both are non-standard. Enterprises that control their own firewalls can allow these ports, but public Wi-Fi networks, hotels, captive portals, and many of the roughly 7,000 ISPs worldwide often block unknown ports — sometimes unintentionally, sometimes intentionally. Roaming users then lose access to Cloudflare's network entirely.
WireGuard is also a fixed protocol. Cloudflare wants to add capabilities like advanced session management and congestion control, but those would require proprietary extensions on top of WireGuard. MASQUE, by contrast, is designed for precisely this kind of tunneling work and is built on open standards.
The protocol stack underneath
MASQUE extends HTTP/3, which runs on QUIC. Both protocols were developed in the IETF with significant contributions from Cloudflare — QUIC is specified in RFC 9000 and HTTP/3 in RFC 9114. QUIC offers multiplexing and packet coalescing, reducing system interrupts and improving performance on lossy or high-latency networks. It also embeds TLS 1.3, giving connections strong privacy protections by default.
MASQUE adds the application-layer framing that turns QUIC into a general-purpose proxy transport. In Zero Trust WARP, MASQUE will establish a tunnel over HTTP/3 with the same functionality that WireGuard provides today, but with important operational advantages.
- Standard ports: QUIC rides on UDP (protocol number 17) and HTTP/3 uses port 443, both of which are universally allowed on firewalls and networks.
- FIPS-compliant encryption: The initial MASQUE implementation in Zero Trust WARP uses TLS 1.3 with FIPS-approved cipher suites.
- Future extensibility: Cloudflare continues to participate in the IETF MASQUE Working Group and can build on HTTP/3 capabilities over time.
Deployment history and scale
This is not a greenfield protocol for Cloudflare. HTTP/3 was introduced on Cloudflare's network in 2019 and its standard was finalized in 2022. In 2023, HTTP/3 accounted for roughly 30% of all HTTP traffic traversing Cloudflare's global network, which spans more than 310 cities and interconnects with over 13,000 networks.
MASQUE itself is already in production at Cloudflare, powering iCloud Private Relay and other Privacy Proxy partnerships. The underlying infrastructure — including Cloudflare's Rust-based proxy framework and its open-source QUIC implementation, quiche — has been running globally and proven out under real traffic loads.
Availablity for Cloudflare One customers
Cloudflare is implementing MASQUE support across its mobile apps, desktop clients, and network infrastructure. Beta testing for Cloudflare One customers is scheduled to begin early in the second quarter of 2024, with account teams reaching out to coordinate participation.
The switch to MASQUE brings Zero Trust WARP in line with modern web standards and removes the port-based obstruction that has dogged WireGuard tunnels in restrictive network environments. It also positions Cloudflare to layer additional QUIC and HTTP/3 capabilities onto the WARP tunnel as the protocol ecosystem evolves.



