From Existing Networks to Zero Trust: Cloudflare Bridges the Gap
Cloudflare One, the company's Zero Trust network-as-a-service platform, now supports steering traffic from devices running the WARP client into any network connected via Magic IP-layer tunnels, including Anycast GRE, IPsec, or Cloudflare Network Interconnect (CNI). The move is designed to give organizations a practical migration path from traditional, perimeter-based network architectures toward a Zero Trust model without requiring a complete, disruptive overhaul.
The Three Generations of Corporate Networking
Most enterprises can be placed in one of three architectural phases. The first generation kept applications on company-owned servers inside a datacenter, with access controlled by perimeter security appliances over private LAN or WAN links. As applications moved to the cloud and users became increasingly distributed, organizations adopted second-generation approaches such as SD-WAN and virtualized appliances to cope with fragmented, internet-dependent traffic. The result, for many, has been a patchwork of legacy and modern systems with visibility gaps and added management burden.
Cloudflare positions its vision as the third generation, aligned with the SASE model Gartner describes: security and network functions delivered as cloud-native services that operate in close proximity to users and applications worldwide. The promised benefits include stronger security, lower total cost of ownership, and a shift in IT's role from cost center to enabler of business change.

However, wholesale architectural transformation takes time. Cloudflare intends to serve as the transitional layer, allowing organizations to adopt Zero Trust incrementally regardless of their starting point.
Multiple On-Ramps for Traffic
Cloudflare One already supported several ways to bring traffic onto its network. The WARP client, installed on user devices, functions as a forward proxy that tunnels traffic to the nearest Cloudflare point of presence. Cloudflare Tunnel creates outbound-only connections from origin servers to Cloudflare via a lightweight daemon. Last year, Cloudflare announced the ability to route private TCP and UDP traffic from WARP-enrolled devices to applications connected via Cloudflare Tunnel—the recommended architecture for Zero Trust network access.
For Layer 3 connectivity, Cloudflare offers standards-based GRE and IPsec tunnels with an Anycast twist: a single tunnel from a customer network connects automatically across Cloudflare's footprint of 250+ cities, which improves redundancy and reduces configuration overhead. Alternatively, Cloudflare Network Interconnect provides direct physical or virtual connections in more than 1,600 locations. These on-ramps let organizations connect existing public and private networks to Cloudflare using familiar technologies while gaining performance and resilience benefits across all IP traffic.
With this announcement, traffic flowing from WARP-enrolled devices can automatically route over those IP-layer connections, extending the range of connectivity options available inside Cloudflare One and paving a gradual path away from conventional VPN-centric architectures.

How WARP-to-Network Routing Works
When a device with the WARP client is enrolled in a Cloudflare account with Zero Trust and private routing enabled, its traffic arrives at the nearest Cloudflare location and enters that account's dedicated network namespace—an isolated, logical copy of the Linux networking stack that exists on every server in every Cloudflare data center. That namespace holds all routing and tunnel configuration for the customer's connected networks.
From there, traffic is forwarded over the configured GRE, IPsec, or CNI tunnels to the destination network. Customers can set route priorities to balance load across multiple tunnels and to fail over automatically to the healthiest path from each Cloudflare location.
Return traffic takes a more involved path. Since a customer's network tunnels terminate at the closest Cloudflare location—which may differ from the one handling the WARP session—the return packets need to be forwarded to the server hosting that session. This is handled by an internal service called Hermes. Similar to how Quicksilver propagates key-value data across Cloudflare's network, Hermes enables servers to write data that other servers can read. When a WARP session establishes, its location is recorded in Hermes; when return traffic arrives, the system reads the session's location from Hermes and routes the packets appropriately.
Availability and Roadmap
The new IP-layer on-ramp capability is live today for all Cloudflare One customers; account teams are handling setup. Cloudflare says future work will layer additional security policies onto connected network traffic and introduce service discovery features, both intended to help organizations identify and prioritize which applications to move to Zero Trust connectivity first.



