One platform, every on-ramp: Cloudflare One completes its connection matrix
Cloudflare is expanding the flexibility of its Cloudflare One platform, aiming to smooth the transition from legacy network architecture to a Zero Trust model. The company has announced that all of its network on-ramps and off-ramps are now fully composable and interoperable, along with new management features for IPsec tunnels and additional SD-WAN integration guides.
The core promise is straightforward: organizations should be able to connect to Cloudflare's network using the hardware, carriers, and protocols they already have deployed. That means supporting traditional standards like GRE and IPsec tunnels alongside modern, lighter-weight approaches like the Cloudflare Tunnel application connector. With the latest update, routing is now seamless between any mix of these connection types. For instance, traffic from a site connected via a GRE tunnel, an IPsec tunnel, or Cloudflare Network Interconnect (CNI) can now reach applications protected by a Cloudflare Tunnel. This completes the interoperability matrix for all on- and off-ramp combinations.
This granular flexibility is intended to let IT teams improve performance and security with technologies that resemble their current setup, then incrementally shift components to Zero Trust without a disruptive "big bang" migration. The platform acts as a global router with a single control plane, allowing traffic to flow between devices, offices, data centers, cloud properties, and SaaS applications regardless of the connection type used at each endpoint.
IPsec gets a management overhaul
Since launching Anycast IPsec as an on-ramp in December, Cloudflare has seen strong demand. Given the near-thirty-year history of IPsec, the protocol has a vast number of implementations and parameter variations. To simplify the setup and lifecycle management of these tunnels from diverse network devices, Cloudflare has added several capabilities on top of its initial release.
- Broader parameter support: Cloudflare wrote its own IPsec implementation from scratch, which allows it to add new configuration parameters in a single development cycle. The current, up-to-date list is maintained in the developer documentation.
- Dashboard configuration: GRE and Anycast IPsec tunnels can now be provisioned with a few clicks in the Cloudflare dashboard. Once created, administrators can view tunnel connectivity from every Cloudflare location worldwide and run on-demand traceroutes or packet captures for deeper troubleshooting.
- Infrastructure as code: The Terraform provider now supports managing IPsec tunnels, enabling teams to treat network configuration like any other codebase.
- Vendor guides: Step-by-step tutorials are available to walk through establishing tunnels from a variety of existing hardware devices, and the library is slated to grow over time.
SD-WAN integrations expand
Many organizations, particularly those with multiple locations, prefer to use their installed SD-WAN appliances as the on-ramp to Cloudflare. After previously announcing partnerships with leading SD-WAN providers, Cloudflare is now introducing integration guides for additional devices and tunnel mechanisms, including Cisco Viptela. These verified, step-by-step instructions are designed to let IT teams configure connectivity to Cloudflare's network quickly and without guesswork.
The combination of composable connections, expanded tunnel management, and new hardware guides is aimed squarely at enterprises that are stuck with legacy, hardware-centric networks. The message is that they can start modernizing security and performance today using the gear they already own, and evolve toward a Zero Trust architecture at their own speed. Details on all the new features are available in the Cloudflare developer documentation and on the Cloudflare One product page.



