Express CNI: Cutting the Complexity Out of Direct Cloudflare Connections
Cloudflare has rolled out its largest update yet to Cloudflare Network Interconnect (CNI), branding the overhauled service Express CNI. At its core, CNI remains a physical cable linking a customer's router to Cloudflare for direct network-to-network traffic exchange, bypassing the public Internet. The legacy service has provided secure, reliable, and fast connectivity for years; the new Express CNI streamlines the ordering and deployment process and removes the requirement for GRE tunnels when connecting with Magic Transit and Magic WAN.
The Real Cost of Interconnection
Private interconnection services trade the variable performance and inherent security risks of the Internet for a dedicated, protected path to a provider’s network. When evaluating vendors in this space, the financial math is often front and center. Port fees, typically based on bandwidth capacity, and data transfer volumes are common cost drivers, with some providers tacking on complex charges for data traversing inter-region networks.
Capturing the value of an interconnection goes beyond the sticker price. Technical and operational factors to weigh include:
- Required capacity, both now and for future scaling
- The vendor’s presence in your colocation facility
- Predictability of fixed versus variable costs
- The broader portfolio of network products available alongside the connection
Cloudflare differentiates itself by charging neither port fees nor inter-region bandwidth costs for CNI. This can yield substantial savings beyond the connection itself. For instance, relaying Magic Transit-cleaned traffic to a data center via CNI instead of a standard Internet link lets enterprises reduce the bandwidth they pay their Internet service provider for. To size up the impact, a single 10 Gigabit per second (Gbps) direct connect port from one major competing vendor carries a nearly $20,000 annual price tag; the equivalent 10 Gbps CNI from Cloudflare costs $0 per year.
Provisioning in Three Minutes
The most significant shift with Express CNI is the provisioning workflow. Previously a manual, vendor-coordinated tasks, ordering a CNI now happens entirely within the Cloudflare dashboard for all Magic Transit and Magic WAN customers. The process takes roughly three clicks and less than three minutes.
Setting up a Direct CNI starts in the new “Interconnects” section of the dashboard. The first step is a quick search to mask sure Cloudflare’s infrastructure is present in the same data center or colocation facility as the customer’s own routers and network hardware. After selecting the specific location within a facility, the user picks the interface port speed. Options generally include 1 Gbps and 10 Gbps links, selected based on current traffic volumes at a single site. While 100 Gbps links are supported, customers at that level are advised to coordinate with their account team for a smoother rollout.
Following speed selection, the interconnection can be named for future reference when directing Magic Transit or Magic WAN traffic. Final confirmation leads to rapid automation on Cloudflare’s side: an interface is provisioned on Cloudflare’s router, point-to-point IP addresses are assigned for the customer's router configuration, and a Letter of Authorization (LOA) is issued so the customer can order a physical cross connect from the colocation facility. The port on Cloudflare's router is live within three minutes of ordering. The LOA can be redownloaded at any time from the dashboard, and as soon as the interface line status is raised, traffic can traverse the CNI.
Magic Transit and Magic WAN Without the GRE Headache
The second major improvement addresses long-standing pain for Magic Transit and Magic WAN clients who rely on CNI for network-layer security and routing. In the past, getting packet delivery right for these products mandated intricate configuration of GRE (Generic Routing Encapsulation) tunnels on the customer's router. That prerequisite was a significant technical hurdle, as GRE setups aren't universally supported on all router and switch hardware and introduce complexities with packet fragmentation and MSS settings.
With Express CNI, GRE tunnels are entirely eliminated. Cloudflare now supports standard 1500-byte packets over the CNI, doing away with complex GRE tunnels and MSS adjustments needed to route traffic into Magic Transit or Magic WAN. For customers aiming to use Cloudflare for protection and optimized routing, this slashes the required router configuration dramatically—a key simplification for network teams reviewing deployment hurdles.
Expanding Capacity and What Comes Next
Express CNI capabilities are currently available in a subset of Cloudflare’s global data centers. The company actively upgrades its network hardware, planning to extend Express CNI compatibility to many more locations over the coming months. Customers looking for Express CNI support at a specific data center who don't see it listed in their dashboard are encouraged to reach out to their account team for assistance.
Soon, Express CNI features will extend out to Cloudflare's Interconnection Platform Partners, including providers like Equinix and Megaport. Enterprises on legacy CNI deployments have no obligation to migrate if they don't need the new capabilities. However, for those that do, attention will turn to BGP routing support, which is expected to roll out for Express CNI connections first. BGP support will offer customers far greater control over how Cloudflare returns traffic to their networks—a capability long sought after by Magic Transit and Magic WAN customers.



