Why connect directly to Cloudflare?
Cloudflare Network Interconnect (CNI) gives customers a dedicated path from their physical network edge into Cloudflare's global network, bypassing the public Internet. Instead of routing traffic through whatever transit providers and intermediate networks happen to carry it, CNI traffic crosses a direct link — either a private network interconnect (PNI), which is a physical cable or virtual "pseudo-wire," or a connection over an Internet Exchange (IX) switch fabric. The result is lower latency, less jitter, reduced exposure to Internet-based threats, and more predictable throughput for any Cloudflare product that touches customer-originated traffic.
The benefits apply across the product suite. With Cloudflare Access, teams can replace corporate VPNs while keeping internal tools in hybrid or multi-cloud environments, and CNI lets their existing MPLS network meet Cloudflare's directly. CDN customers see faster cache fills and lower origin load. Magic Transit traffic gets to their datacenters with less jitter, and Cloudflare Workers customers gain a secure, low-latency path to serverless compute that never traverses the public Internet.
Performance: cutting time off origin pulls
When content misses cache, the edge must reach back to the origin — and that round trip is where interconnection pays off. Instead of letting origin pulls cross the public Internet, CNI moves them over a dedicated link with predictable latency. Using Argo Tiered Cache, customers can align upstream cache tiers with their interconnect locations, which raises cache hit rates and further reduces origin load.
Real customer data illustrates the magnitude of the improvement. One CDN-heavy customer provisioned PNIs in multiple locations and saw their 90th percentile origin round trip time in Warsaw, Poland drop from 7.5ms to 1ms — an 87% reduction. Jitter on that link fell from 82.9 to 0.3, reflecting the dedicated, stable nature of the connection.

Security: taking the public Internet out of the path
Enterprises moving on-premises infrastructure to the cloud typically preserve their existing security model: they buy transit from ISPs, then bolt on hardware firewalls, load balancers, DDoS mitigation appliances, and WAN optimizers. CNI offers an alternative: provision security services on Cloudflare's network, connect your existing network to it privately, and apply consistent policy across both on-prem and cloud environments. Because the link is reserved exclusively for the customer, traffic stays isolated and private end to end.
Magic Transit without Internet exposure
Magic Transit's job is to attract customer IP traffic to Cloudflare's edge via BGP, filter it, and forward only clean traffic to the customer's network. Before CNI, that forwarding happened over GRE tunnels on the public Internet — and because GRE endpoints are publicly routable, they could in principle be discovered and attacked, giving attackers a way around Cloudflare's DDoS protection.
CNI removes that exposure entirely. The advantages are threefold:
- Reduced threat exposure — risk-sensitive organizations never expose endpoints to the public Internet; Cloudflare absorbs that risk and forwards only clean traffic over a private interface.
- Increased reliability — traffic avoids intermediate networks with their unpredictable latency and packet loss; after Magic Transit processes traffic, it goes directly to the customer network.
- Simplified configuration — Magic Transit + CNI customers will soon have the option to skip MSS (maximum segment size) changes during onboarding, a required step for GRE-over-Internet that complicates life for service providers managing downstream customers' MSS as well.
Example: a branch-and-core deployment with Cloudflare for Teams
Consider a hypothetical enterprise — call it Penguin Corp — with a fully connected private MPLS network, a dedicated team of network engineers, and just two worldwide egress points to keep costs down. That architecture forces users' traffic to travel long distances for basic tasks, all while crossing the corporate network boundary.

SASE (Secure Access Service Edge) models promise to fix this by moving firewall, DDoS mitigation, and encryption to the network edge as a service. CNI lets Penguin adopt a SASE-like architecture while keeping public Internet exposure at zero. The company establishes a PNI from its San Jose branch to Cloudflare's San Jose location for Cloudflare for Teams, and a second PNI from its Austin colocation facility to Cloudflare's Dallas location for Magic Transit to protect core networks.
Cloudflare for Teams replaces VPN appliances with Cloudflare Access for internal applications and physical web gateway boxes with Cloudflare Gateway for filtering and logging. These services run in every Cloudflare datacenter, and CNI makes them faster still: a simple configuration change sends all branch traffic to Cloudflare's edge, where policies apply — eliminating the need to backhaul traffic to centralized filtering appliances.
Once Penguin is interconnected, two things happen. The company uses Cloudflare's full set of security services without provisioning expensive physical or virtualized appliances, and those services run in Cloudflare's network across more than 200 cities, putting security functionality physically closer to users and employees.

Built for global topologies
CNI's value scales with Cloudflare's footprint because customers can interconnect locally wherever their branches and core infrastructure sit — and their employees too. A globally distributed network makes local interconnection easy regardless of where a customer operates, which matters for companies that need many interconnection points spread across continents.
That scale consideration shaped the pricing model: Cloudflare does not charge enterprise customers anything to provision CNI. Customers may still pay third parties for access to an interconnection platform or a datacenter cross-connect, but the CNI product itself is free — positioned to accommodate both complex enterprise network topologies and modern IT budgets.
Choosing a connection method
Cloudflare Network Interconnect offers three ways to reach Cloudflare's network: a private network interconnect (PNI), an Internet Exchange (IX), or through an interconnection platform partner. The BGP session establishment and IP routing are identical regardless of the method chosen; only the physical medium differs.
Private Network Interconnects
PNIs are available at any of Cloudflare's listed private peering facilities. To set one up, specify the location, port speed, and target VLANs. Cloudflare authorizes the request, the customer places the order, and Cloudflare handles the rest. A PNI is the right choice when you need higher throughput than a virtual connection can provide, or when you want to minimize the number of intermediaries between your network and Cloudflare's.
Internet Exchanges
For organizations already present at an exchange, Cloudflare participates in over 235 Internet Exchanges. Customers simply follow the IX's connection instructions, and Cloudflare brings up its side of the session. IX connectivity is a good fit when you already peer at an exchange or when you need to interconnect in a location without an interconnection platform.
Interconnection platform partners
Through partnerships with Equinix, Megaport, PCCW ConsoleConnect, PacketFabric, and Zayo, customers can establish a virtual connection with Cloudflare in any partner-supported location. This option suits organizations that already use these providers, or those wanting a streamlined onboarding path to a secure cloud environment.

Finding the optimal interconnect points
The Cloudflare Network Interconnect product page includes tools to help determine the best locations for interconnecting. These resources let customers evaluate where to connect to maximize reach to other cloud providers and ISPs generally.
CNI versus traditional peering
While CNI and traditional peering share the same technical mechanisms under the hood, the intent differs. Cloudflare's open peering policy applies to any network and remains unchanged; it exists to build a more reliable Internet by connecting networks together. Conventional networks use peering to improve performance for their own customers while reducing costs. CNI extends the same benefits directly to Cloudflare's enterprise customers as a paid offering.
Next steps
Compared to routing over the public Internet, CNI provides customers with dedicated links that deliver more consistent latency, jitter, and available bandwidth, along with Cloudflare's security features at each interconnection point. Physical interconnects can be established at any of Cloudflare's locations today. Enterprise sales can assist with adding Cloudflare Network Interconnect to existing service agreements.



