Magic Transit now protects smaller networks and cloud-hosted IPs
Cloudflare has expanded Magic Transit so that it no longer requires customers to bring their own IP address space. The service, previously limited to networks with at least a /24 prefix, can now be applied to Cloudflare-managed static IPs, opening up DDoS protection and traffic acceleration to branch offices, remote sites, event venues, and even home networks.
Magic Transit works by advertising customer IP prefixes over BGP, attracting all inbound traffic to the closest Cloudflare data center. There, traffic passes through a security stack including DDoS mitigation and a cloud firewall. Clean traffic is then forwarded to the customer network via Anycast GRE or IPsec tunnels, or through Cloudflare Network Interconnect. The system includes load balancing and automatic failover across tunnels to route traffic over the healthiest path from any location worldwide.
A key advantage is Cloudflare's Anycast architecture: every server in its network runs every service, so traffic is processed wherever it lands. This gives customers access to the full capacity of Cloudflare's network—121+ Tbps at the time of the announcement—to absorb large-scale attacks. It also avoids the performance penalty of traditional "scrubbing center" models that route traffic to specialized processing locations.
IP address requirement removed
Historically, Magic Transit required customers to use their own IP prefixes of at least a /24, since that is the minimum prefix length that can be advertised via BGP on the public Internet. Smaller networks were left without a way to get IP-layer protection through the service.
With this change, customers can direct traffic to dedicated, Cloudflare-managed IPs and receive the same protections: DDoS mitigation, network analytics and alerts, performance benefits, and resiliency. This extends Magic Transit to any network size without requiring the customer to own any IP space.
Scenarios: hybrid cloud, branch networks, streaming
Hybrid and multi-cloud security. Organizations managing workloads across multiple cloud providers often struggle to keep security policies consistent. In a hybrid cloud deployment, Cloudflare can act as a single control plane for security policy management, providing uniform protection and visibility across an entire environment—regardless of the underlying provider or whether resources are physical, virtual, or cloud-based.
Branch office coverage. DDoS attacks increasingly target corporate infrastructure, including internal applications. With Cloudflare-managed IP space, organizations can now cover every network location—branch offices, stores, remote sites, and event venues—under the same protection umbrella. The built-in cloud firewall filters bidirectional traffic and propagates policy changes globally within seconds, which can also allow organizations to replace legacy hardware firewalls at these sites.
Streamer IP protection. Attackers don't need to target a hosted service; the public IP of a home network can be leaked and used to knock a live stream offline. By routing traffic through a Magic Transit-protected IP, streamers can shield their home network. Attack traffic is blocked at the Cloudflare location nearest the attacker, far from the streamer's network, while the global network's interconnectivity is designed to avoid adding noticeable latency to gaming traffic.
The service is available now, and existing customers can contact their account team to get started.



