Gateway HTTP Rules Get Application-Level Controls
Cloudflare for Teams combines two products: Cloudflare Access and Cloudflare Gateway. Gateway is the security filtering side, routing user traffic through Cloudflare's network in 200 cities so that consistent policies can be applied to Internet traffic without backhauling it to centralized firewalls.
Gateway first launched with DNS filtering, which gives administrators a single button to block known malware or phishing sources and policies for risky categories. A later addition was the cloud L7 firewall, which applies security and content policies to HTTP traffic—for instance, preventing uploads to particular applications or building rules by URL.
Those URL-based policies work fine for individual hostnames, but problems arise when teams need to manage rules for entire applications. Popular products like Microsoft Office 365 rely on hundreds of hostnames and IP addresses, and those lists change. Salesforce alone uses 11 distinct apex domains such as forceusercontent.com and sfdcstatic.com, a set that continues to expand.
Manually maintaining allow lists for one application is a chore; doing it for hundreds of cloud apps means tracking thousands of hostnames and constant review to keep up with endpoint changes. The burden grows when compliance requirements demand blocking entire categories, like unapproved file-sharing services, where every service and all of its hostnames must be identified.
Applications and App Types in the Rule Builder
Cloudflare now groups these destinations so administrators can build single HTTP rules by application (for example, Salesforce or Microsoft Office 365) or by app type (for example, File Sharing or Social Media). An Application is a collection of hostnames belonging to one cloud service; an App Type is a collection of Applications. Cloudflare manages the underlying lists and updates them as services add new network endpoints.

To create a rule that blocks all Collaboration & Online Meeting tools except Slack, pick Application in the Selector drop-down, choose in in the Operator drop-down, and type Collaboration & Online Meetings into the Value field. The app type auto-completes, and the full set of applications populates in the value list; clicking the x next to Slack removes it.

Select Block in the Action drop-down at the bottom of the rule builder and save the rule. This single rule replaces what would otherwise be a bulk upload of several hundred hostnames, and administrators no longer need to track network endpoint updates for the more than 20 apps in that category.
Availability and Coverage
The rule builder currently supports 223 applications across 17 app types, with the full list documented in Gateway's documentation. Cloudflare intends to add more applications and app types, along with additional controls and visibility into Shadow IT.
Applications and app types are available today to all L7 firewall customers. The L7 firewall is included in Gateway standalone, Teams Standard, and Teams Enterprise plans. New users can sign up for a Gateway account and follow the onboarding directions to get started.



