Cloudflare Expands On-Ramp Options for Cloudflare One
Cloudflare has announced a new set of Network On-ramp Partners for Cloudflare One, its secure access service edge (SASE) platform. The program is designed to make it easier for enterprises to replace MPLS links with Cloudflare's global network, using equipment and connectivity they may already have in place.
The new partnerships fall into two categories: WAN and SD-WAN integrations, and private network interconnect (PNI) providers. Together, they give organizations more ways to get traffic onto Cloudflare's network—either by tunneling from existing appliances or by establishing private, physical connections in colocation facilities.
Extending Magic WAN to Existing SD-WAN Deployments
Cloudflare's Magic WAN service lets customers route traffic between offices, data centers, and cloud properties over Cloudflare's network, with policy configuration managed through a single SaaS control plane. The goal is to eliminate the cost and lead time of MPLS circuits, as well as the latency penalties that come from hairpinning traffic through distant hubs.
Previously, getting that traffic onto Cloudflare required either direct connections or manual tunnel setup. The new WAN and SD-WAN partnerships with VMware, Aruba, and Infovista change that. Customers using those vendors' physical or virtual appliances can now point them at Cloudflare's network with a few simple commands, without replacing their existing hardware or software investments.
A typical deployment might combine a physical appliance at one site, a virtual appliance in a public cloud VPC, and a standard Linux-based router elsewhere, all connected to the nearest Cloudflare data center via Anycast GRE tunnels. Because Cloudflare operates in more than 200 cities, that nearest point of presence is rarely far away. Once traffic enters the Cloudflare network, routing policies are applied centrally, and Magic Firewall can enforce consistent security rules across all traffic, regardless of where it originated.
Today's integrations use Anycast GRE, but IPSec support is on the roadmap, which will add another connectivity option. Looking further ahead, Cloudflare and its partners intend to make the setup process more automated. Future versions of partner device software would be able to use a set of authorization credentials to call the Magic WAN management API and configure themselves, moving closer to a plug-and-play model for cloud networking.
"VMware SD-WAN virtualizes the WAN to decouple network software services from the underlying hardware—providing agility and performance for all enterprises and is a foundational component of the VMware Secure Access Service Edge (SASE) platform. VMware and Cloudflare share a vision to provide customers a cost-effective, turnkey and more secure Global WAN." — Mark Vondemkamp, vice president products, SD-WAN and SASE business, VMware
Private Interconnect Options Grow
For organizations that want to avoid exposing traffic to the public internet entirely, Cloudflare also offers private interconnect options. Tunneling over GRE or IPSec relies on internet-facing endpoints, which inherently creates some attack surface. A private layer 2 connection between a customer's network and Cloudflare's edge removes that exposure and provides a more predictable, higher-performance path.
The existing Network Interconnect partner list—Equinix ECX, Megaport, PacketFabric, PCCW ConsoleConnect, and Zayo—is now joined by Digital Realty, CoreSite, EdgeConneX, 365 Data Centers, BBIX, Teraco, and Netrality Data Centers. These providers add colocation presence in more locations, offering reduced cross-connect lead times and reference architectures for connecting to Cloudflare.
With these additions, the combined Network On-ramp program spans 15 connectivity providers in 70 unique locations. Customers can choose between cloud exchange-based connections—provisioned as a software-defined VLAN through the Cloudflare dashboard—or direct physical interconnect, depending on their security and performance requirements.
"CoreSite's collaboration with Cloudflare provides customers with the high-speed direct fiber interconnection and enhanced security they need to meet the strictest performance and compliance requirements supporting modern hybrid applications. We are excited to enable Cloudflare Network Interconnect services within our network-dense, cloud-enabled Los Angeles and Denver data center campuses." — Maile Kaiser, SVP — Sales, CoreSite
Broadening the Path to Cloudflare One
The Network On-ramp program is part of a larger push to make Cloudflare One a viable alternative to traditional WAN infrastructure. Magic WAN handles the connectivity and routing layer, while Cloudflare's Zero Trust tools—which span ZTNA, Secure Web Gateway, Remote Browser Isolation, DNS security, and L4 firewall—can be layered on the same platform. Rather than stitching together separate point products, enterprises can use a single tier for both network transport and security enforcement.
For existing Cloudflare customers, the practical effect is more choice in how traffic reaches the network. Those with VMware, Aruba, or Infovista SD-WAN gear can start tunneling immediately. Those with presence in any of the newly added colocation providers' facilities can request a private cross-connect. Both routes lead to the same Cloudflare One service, with the same management interface and policy controls.



