Network traffic directions are melting away
Traditional network diagrams divided traffic into clean categories with different security postures. "North/south" flows crossed the corporate boundary and were filtered hard at a handful of choke points. "East/west" traffic stayed inside trusted LANs and WAN links, carrying less scrutiny under the assumption that anything internal was safe. As applications moved to the cloud and users to the Internet, that tidy split no longer holds. The WAN, the perimeter, and even the notion of private versus public application access are all dissolving.
Cloudflare’s position is that its One platform can secure these flows no matter how blurry the definitions get. Here is how the old model worked and where the protections land now.
What the old labels meant
Back when IT teams ran "trusted" private networks, traffic leaving for another network—whether a partner's private cloud or the public Internet—was drawn upward on diagrams, hence "north/south." Security teams forced every one of those flows through one or a few central inspection points where they could watch for intruders and data exfiltration.

Everything else was "east/west": a desktop hitting an office printer, or later traffic between LANs across a campus or over private MPLS connections between dispersed sites. That traffic largely bypassed the tight controls applied to north/south flows.
Once applications left the data center and users stopped coming into the office, those labels stopped mapping to reality. Traffic once considered "private" routinely crosses the public Internet, pushing organizations toward cloud-first security models like SASE that relocate where policies are enforced.
Applying Cloudflare wherever the flow goes
Cloudflare says its services now cover the full range of flows, whether the architecture is purely cloud-native or still built on physical locations.
For classic north/south traffic into public applications, the application security portfolio layers DDoS protection, the Web Application Firewall, API security, and Bot Management across the OSI stack. Its network services bring similar protections to all IP traffic. For internal users heading out to the Internet, Zero Trust Network Access grants access to corporate resources, while Secure Web Gateway filters outbound requests for malware, ransomware, phishing, and command-and-control traffic.

East/west traffic between sites takes a different path under Cloudflare One. Customers can attach to Cloudflare's network—which sits within 50ms of 95% of the world’s Internet-connected population—via a device client, application/network-layer tunnels, or direct connections, then run Zero Trust policy checks on anything moving between locations. Some also route local LAN traffic out to the nearest Cloudflare location specifically so the IT team can apply one consistent policy set from a single control plane instead of managing per-site rules.
Because every Cloudflare location runs the full set of services, a customer connected once gains a mesh of capabilities usable by any traffic flow. That means newly released features apply everywhere at once, regardless of whether a request is heading north, south, east, or west. Cloudflare hints that additional product integrations along these lines are coming during CIO Week, especially around more flexible application-layer control for private network traffic.



