Magic WAN Connector hits general availability

Cloudflare has announced the general availability of the Magic WAN Connector, the final piece of its Cloudflare One SASE platform. The connector is a pre-installed software component on Cloudflare-certified hardware, managed entirely from the Cloudflare One dashboard, designed to bridge existing network infrastructure with Cloudflare’s network edge.

According to Cloudflare, the deployment process takes only minutes from unboxing to seeing traffic automatically routed to the nearest Cloudflare location. Once there, traffic passes through the full Zero Trust security stack before being sent onward to its destination — whether that is another private network location, a SaaS application, or any public Internet service.

Zero-touch branch connectivity

Traditional on-ramps to Cloudflare’s Magic WAN have required Anycast GRE or IPsec tunnels configured on existing routers or firewalls, or direct connections via Cloudflare Network Interconnect (CNI). Customer feedback pointed to a need for something simpler: plug-in-and-go hardware that handles the rest automatically.

The Magic WAN Connector delivers exactly that. In addition to automatically configuring tunnels and routing policies, it handles traffic steering, shaping, and failover to ensure packets take the best available path to the closest Cloudflare network location. All configuration is controlled via the Cloudflare dashboard, and traffic flows are visible in Cloudflare’s analytics and logs, giving a unified observability view across branches and network traffic.

Security controls built in

With the connector deployed, organizations can enforce Zero Trust policies across both public and private traffic without additional hardware.

For Internet-bound traffic, Secure Web Gateway policies defend against ransomware and phishing. Traffic from connector-enabled locations routes through Cloudflare Gateway by default, meaning physical locations and remote employees are managed from the same policy plane.

For private traffic between network locations, the SASE architecture brings multiple layers of filtering and control that would otherwise require a stack of security hardware and backhauling through a central location. In Cloudflare’s model, those controls are enforced across its distributed network and managed from a single dashboard or API.

The connector also extends seamlessly to hybrid cloud setups. Cloudflare One provides connectivity for physical and cloud networks via different on-ramps — cloud-native constructs such as VPN gateways for VPCs, or Cloud CNI for direct cloud connectivity. A unified control plane across physical and cloud infrastructure helps reduce the overhead of managing multi-cloud networks.

Beyond SD-WAN

Cloudflare positions the connector as an evolution beyond SD-WAN. While SD-WAN offers orchestration and last-mile traffic management, its devices generally lack embedded security controls, leaving teams to assemble their own patchwork of hardware and virtualized tools. SD-WAN appliances also have no influence over traffic between the last mile and its destination, and virtualized versions deployed in cloud environments don’t support native cloud connectivity.

Cloudflare One’s architecture follows a “light branch, heavy cloud” principle: minimal hardware at physical locations, low-cost Internet connectivity to reach the nearest service edge, and security filtering and traffic optimization at that edge before forwarding. Notably, organizations that want to keep their existing SD-WAN vendor can still use any appliance supporting IPsec or GRE as an on-ramp to Cloudflare One.

More details on device specifications, feature information, and onboarding can be found in the developer documentation for the Magic WAN Connector.