Magic WAN and Magic Firewall Bring Network Security to the Edge

Cloudflare has expanded its Cloudflare One platform with two new services that aim to simplify enterprise networking and security. Magic WAN delivers secure connectivity and routing for corporate networks as a service, while Magic Firewall enforces network firewall policies at the edge across all traffic from any connected entity. Together, they represent a move away from traditional hardware-centric network architectures toward a software-defined approach built on Cloudflare's global network.

The limits of traditional network designs

Enterprise networks have long relied on a few established architectures, all of which were built around secure information flow between offices and data centers, with internet access controlled at office perimeters. As applications have moved to the cloud and employees have left offices, these designs have become increasingly inadequate. VPN boxes and similar stopgap solutions don't address the underlying problems.

Full mesh MPLS networks are expensive and slow to deploy, hard to maintain, exponentially complex to scale, and often lack visibility. Alternatives that backhaul traffic through central locations impose latency penalties and require costly hub hardware sized for peak capacity rather than actual use. Many organizations end up with a patchwork of architectures stitched together over years. Security teams face the added burden of juggling hardware boxes from multiple vendors, trading off cost, performance, and security as networks grow.

Connectivity and policy as a service

Magic WAN & Magic Firewall: secure network connectivity as a service

Magic WAN connects any traffic source—data centers, offices, devices, cloud properties—to Cloudflare's network, with routing policies managed through a single SaaS solution. On-ramps include Anycast GRE tunnels, Cloudflare Network Interconnect, Argo Tunnel, WARP, and Network On-ramp Partners. This approach eliminates MPLS expense and lead times, avoids the performance penalties of traffic trombones, and replaces a tangle of legacy solutions with Cloudflare's global Anycast network as an extension of the corporate network.

Magic WAN & Magic Firewall: secure network connectivity as a service Embedded Image - kgBJAL

Magic Firewall gives administrators central policy management across the entire network, applied at the edge as a service. It provides fine-grained control over data entering, leaving, or flowing within the network, along with visibility into traffic patterns from a single dashboard. As part of Cloudflare One, it enables customers to activate additional Zero Trust features such as the Secure Web Gateway with remote browser isolation, Intrusion Detection System, and Smart Routing.

"Our network team is excited by Magic WAN. Cloudflare has built a global network-as-a-service platform that will help network teams manage complex edge and multi-cloud environments much more efficiently. Operating a single global WAN with built-in security and fast routing functionality — regardless of the HQ, data center, branch office, or end user location — is a game-changer in WAN technology."— Sander Petersson, Head of Infrastructure, FlightRadar24

Use case: replacing MPLS between offices

Consider Acme Corp, which connects offices worldwide to regional data centers and each other via MPLS. Its data centers host corporate applications behind rack upon rack of security hardware, with leased line connectivity between facilities. Acme is migrating applications to the cloud and planning direct data center connections to cloud providers.

Magic WAN & Magic Firewall: secure network connectivity as a service Embedded Image - QZOvId

Managing MPLS is Acme's most persistent pain point. Deployment lead times are long, costs are high, and expansion—especially international or through acquisitions—is slow. Employees accessing cloud providers and SaaS apps suffer latency because traffic hairpins through data centers for security inspection. Office-to-office traffic such as IP telephony and video conferencing has no security policies applied, leaving gaps in the security posture.

Acme considered fully meshed site-to-site IPSec VPN tunnels over the internet, but the complexity strained its networking team and heterogeneous router deployments. Magic WAN offers a simpler path: each office and VPC connects to Cloudflare with Anycast GRE tunnels. With a single tunnel per site, Acme automatically gets connectivity to Cloudflare's entire global network (200+ cities in 100+ countries). Data centers can use Cloudflare Network Interconnect for dedicated private connectivity.

Once tunnels are established, Acme configures allowed routes for private network traffic (RFC 1918 space), and Cloudflare handles routing, resiliency, and traffic optimization. The setup takes only a few hours, allowing Acme to begin its MPLS migration immediately.

Use case: remote employee access

When Acme's employees shifted to remote work, legacy VPNs didn't hold up under the load. Acme can instead use Cloudflare for Teams and Magic WAN to provide secure access to private network resources. Employees install the WARP client on their devices, sending traffic to Cloudflare's network where it is authenticated and routed to resources in data centers or VPCs connected via GRE tunnel, Argon Tunnel, Cloudflare Network Interconnect, or IPSec (coming soon).

This architecture routes traffic to the closest Cloudflare location, where policy is applied at the edge before sending it along an optimized path—rather than through a single choke point appliance. The same Magic Firewall policies apply to employee devices, offices, and data centers alike, regardless of on-ramp. IT and security teams manage everything from the Cloudflare dashboard, replacing separate VPNs, firewalls, and cloud services.

Magic WAN & Magic Firewall: secure network connectivity as a service Embedded Image - e4ROEK

This approach lets Acme retire its VPN, firewall, and secure web gateway appliances while improving performance and simplifying policy management.

Use case: moving security to the edge

Acme's security team has relied on hardware appliances—specialized firewalls, intrusion detection systems, SIEMs—in physical locations to enforce network security and gain visibility. As the organization moves to the cloud and rethinks remote work, it's looking for sustainable solutions that improve security beyond what was possible in a traditional castle-and-moat architecture.

Once traffic flows through Cloudflare via Magic WAN, access controls and filtering functions can augment or replace on-prem hardware. Magic Firewall provides firewall-as-a-service at the edge, simplifying both configuration and compliance auditing. For example, Acme can allow internet traffic to its web servers on ports 80 and 443 while locking down SSH access to specific private networks in branch offices.

Magic WAN & Magic Firewall: secure network connectivity as a service Embedded Image - LJ3dM9

For deeper lockdown, Acme can adopt a Zero Trust access model with Access and Gateway, controlling who can reach what and how across all traffic. As Cloudflare releases new functions like IDS/IPS and DLP, they can be enabled with a few clicks.

Magic WAN & Magic Firewall: secure network connectivity as a service Embedded Image - gUiM9w

Acme's long-term goal is to migrate all security and performance functions to the cloud, consumed as a service. Magic WAN supports this transition, allowing Acme to deepen security gradually while retiring legacy hardware.

Increased cloud adoption along with the recent pivot to remote workers has increased the volume of Internet, SaaS, and IaaS traffic straining traditional network architectures such as MPLS. WAN architectures that offer a global scale, integrated enterprise network security functions, and direct, secure connectivity to remote users are key to organizations looking to increase their operational agility and lower total costs of ownership.— Ghassan Abdo, IDC Research VP, WW Telecom, Virtualization & CDN

Cloudflare's network as your own

Magic WAN and Magic Firewall grew from problems Cloudflare faced in securing and scaling its own network. The approach offers three structural advantages:

  • Global scale and proximity: Cloudflare's CDN business demanded close connectivity to eyeball networks, which benefits remote workers needing solid connections from home and enables threats to be stopped close to their source.
  • Hardware and carrier-agnostic: Connect with existing hardware and benefit from Cloudflare's diverse carrier connectivity, providing built-in resiliency.
  • Built from scratch to work together: All products are developed in software and designed to integrate seamlessly, each improving the others as they evolve.

Availability

Magic WAN is available in limited beta. Magic Firewall is generally available for all Magic Transit customers and included out of the box with Magic WAN.