The Hardware Firewall Tax

Network firewalls are a perennial pain point for enterprises. They are expensive, capacity-constrained appliances that force teams to over-provision just to handle peak loads. When CPU or memory runs short, the answer is usually more boxes, more vendors to manage, and more policies to keep in sync across a patchwork of devices.

"We're constantly running out of memory and running into connection limits on our firewalls. It's a huge problem."

These are band-aid solutions. They do not address the core question: how do you get a unified view of your entire network, understand what is traversing it, and apply policy globally and instantly?

Moving Filtering to the Cloudflare Network

Magic Firewall is Cloudflare's answer: a network-level firewall delivered as-a-service from the Cloudflare global network. It is designed to replace on-premises firewall appliances for remote users, branch offices, data centers, and cloud infrastructure.

By running in Cloudflare's network, the firewall scales dynamically with demand. This also eliminates the need to backhaul traffic to a single chokepoint for inspection. Cloudflare's network spans data centers in 200 cities, each capable of enforcing policies. This means regional offices and data centers can rely on a firewall engine that is often within 100 milliseconds of their operations.

One Policy for the Whole Network

Magic Firewall is intended to be a core component of Cloudflare One, applying a consistent filtering engine across the entire enterprise. The same rules that govern traffic leaving your data centers can also apply to traffic leaving employee devices.

This is achieved through integration with existing Cloudflare services. Traffic from endpoints outside the corporate network can reach Cloudflare via the WARP client, where Gateway applies the same rules used for network-level filtering. Branch offices and data centers connect through Magic Transit and receive the exact same policy set. The result is a single dashboard for your entire network, rather than a hunt across multiple devices and vendor consoles.

Self-Service Rules at the Edge

Magic Firewall pushes your network perimeter out to the edge. While Cloudflare has long applied firewall rules for Magic Transit customers, the process for changing rules previously involved contacting an account team or support. The first generally available version will change that, allowing all Magic Transit customers to apply static OSI Layer 3 and 4 mitigations fully self-service.

Initial support will focus on static rules that apply to the whole network, covering devices and applications in the cloud, on employee laptops, or in branch offices. You will be able to allow or block traffic based on:

  • Protocol
  • Source or destination IP and port
  • Packet length
  • Bit field match

Rules are expressed using Wireshark filter syntax, a domain-specific language common in networking and the same syntax used across other Cloudflare products. This allows for precise, powerful rulesets. If a bad actor is suspected inside or outside your perimeter, you can log into the dashboard and block that traffic, with the rule pushing out globally in seconds.

Configuration is designed to be flexible. A UI supports complex logic, but you can also type filter rules manually using Wireshark syntax, or add rules programmatically through the API.

Beyond the Packet Header

Static packet filtering is only the first step. Cloudflare's position as a middleman between any two actors interacting with your assets—employee devices or internet-facing services—allows it to inspect not just where traffic is coming from, but what is inside the traffic. Cloudflare has announced plans to add capabilities for automatically detecting intrusion events based on datastream contents in the near future.

Magic Firewall will enter a limited beta, starting with existing Magic Transit customers.