Cloudflare One: A Single Fabric for the Post-Castle Network

Cloudflare today announced Cloudflare One, a cloud-based network-as-a-service platform that folds secure connectivity, access control, and performance optimization into a single offering. The product is the result of roughly two years of work on the components that now make it up, informed by conversations with thousands of customers about where corporate networking is headed.

The announcement spans several pieces of technology rolling out this week: WARP Gateway clients for desktop and mobile, Access for SaaS, browser isolation, and a next-generation network firewall with intrusion detection. Together, they form what Cloudflare positions as a SASE-style replacement for the legacy patchwork of appliances and WAN links.

The core premise is that the old corporate network model—private circuits, centralized data centers, and hardware security stacks—no longer matches how work actually happens. Mobile devices, SaaS applications, and public cloud hosting have scattered users and workloads across the Internet. The events of 2020 accelerated that shift dramatically, pushing remote work from an edge case to the default for many organizations.

Cloudflare One is designed around that reality. It unifies user connections, branch office on-ramps, secure application connectivity, and controlled access to SaaS into one platform with a single interface. Traffic is routed over Cloudflare's global backbone, which applies real-time Internet intelligence to avoid outages and filter threats. The network layer handles the security functions that used to require physical boxes—firewalling, DDoS protection, content filtering—at the edge rather than at a central choke point.

The zero trust principle is central to the architecture: no user or device is trusted based on network location. Instead, every connection is authenticated and authorized continuously, whether the user is in an office, at home, or on a mobile device. That model also solves a practical problem that emerged during the pandemic: MPLS and SD-WAN links to idle offices are expensive and pointless when employees are working from kitchen tables.

Cloudflare acknowledges that exposing internal applications to the Internet—a necessary step for zero trust—brings new exposure. DDoS attackers have already shifted focus from public websites to internal apps and networks, a trend Cloudflare observed beginning in late 2019 and continuing through the pandemic. Customers moving to zero trust have therefore paired Access and Gateway with Cloudflare's DDoS mitigation and web application firewall (WAF) products. The lesson, Cloudflare says, is that a SASE or zero trust network must include those protections by default.

Identity and Device Partners: The Border Agent Model

Cloudflare One does not try to replace the identity and endpoint security tools organizations already run. Instead, it integrates with them, acting as a consistent policy enforcement layer across whatever providers a company has deployed.

On the identity side, Cloudflare is announcing partnerships this week with Okta, Ping Identity, and OneLogin. Existing integrations cover Microsoft Active Directory, Google Workspace, and widely used consumer and developer platforms including GitHub, LinkedIn, and Facebook. Importantly, Cloudflare One does not force standardization on a single provider. A company can use one identity provider for full-time employees and another for contractors, for example, or inherit a mix through acquisitions. Cloudflare One can integrate with multiple providers simultaneously and apply consistent access policies across all applications.

Cloudflare frames the relationship with a border control metaphor: the identity provider issues passports, and Cloudflare One acts as the border agent that validates them. Policies can be updated centrally to allow or deny entry from different providers at any time.

Device integrity plays an equally important role. This week Cloudflare is announcing partnerships with CrowdStrike, VMware Carbon Black, SentinelOne, and Tanium for endpoint security. These vendors run on devices to confirm they have not been compromised. Extending the metaphor, this is the equivalent of a health screening at the border: a valid passport is not enough if the traveler is not healthy. Organizations can centralize on a single endpoint vendor or mix providers, with Cloudflare One providing the unified control plane.

Why the Castle and Moat Broke

The Internet was designed for resilience, not security. Early on, that meant enterprises did not trust it as a platform for business. So they built private shadows of it: dedicated MPLS links between offices and data centers, complex routing managed by IT teams, physical firewall and DDoS appliances, and centralized outbound Internet gateways that backhauled all traffic for filtering.

This castle and moat approach required employees to come to the office, kept applications and data in a controlled data center, and built a defensive perimeter around both. The perimeter was made of an unwieldy collection of devices and vendors, but it worked—until it didn't. The failure was not primarily driven by attackers breaching the moat. It was driven by technical transformation: smartphones let employees work outside the perimeter, and SaaS plus public cloud moved corporate applications beyond the castle walls.

2020 finished the job. When the workforce went remote, the paradigm collapsed rather abruptly. The only workable model going forward is to accept that employees, servers, and applications now live on the Internet and design security accordingly.

The Zero Trust Lineage

Cloudflare traces the intellectual foundation of this approach to Google's 2014 paper, "BeyondCorp: A New Approach to Enterprise Security," which brought zero trust into the mainstream. Google's insight was that every application should inherently distrust every connection, regardless of network origin. Users would be continuously authenticated, which simultaneously strengthened security and made it easier to support cloud applications, mobile work, and remote employees.

That framing, Cloudflare notes, did not fully anticipate the challenges that came with zero trust in practice. One is well understood: exposing more internal applications to the Internet requires strong access control. But it also invites attacks that were previously only a concern for public-facing workloads, including DDoS and application-layer attacks. Cloudflare's observation from customer deployments is that a complete zero trust architecture needs to bundle the protections historically reserved for the public Internet—DDoS mitigation and WAF—alongside the access and connectivity layers.

The broader shift is one of mindset: rather than trying to build ever more private networks, the future corporate network runs on the Internet itself, with security, performance, and reliability layered on top. That is the bet Cloudflare One represents.

Why Cloudflare Is Building a Service Provider Network

For years, the gap between the public Internet and private corporate networks has forced enterprises to depend on clunky VPNs, dedicated MPLS links, and appliance-based security. Cloudflare argues the Internet is almost good enough to replace all that—if you have the right infrastructure behind it. Rather than stitching together virtual appliances in regional public clouds, the company is positioning its own global network as the foundation for enterprise connectivity.

Introducing Cloudflare One Embedded Image - THDRMP

That network already handles a significant share of web traffic—W3Techs data shows more than 14% of the web relies on Cloudflare. The same infrastructure that accelerates websites and absorbs attacks, the company says, can route employee traffic, secure connections to SaaS apps, and filter traffic between offices, all while measuring the Internet at scale to find better routes.

From Consumer WARP to Enterprise On-Ramp

Cloudflare’s approach to enterprise networking grew out of consumer products. Last year the company launched Cloudflare WARP, a VPN-like client that routes device traffic through Cloudflare’s network. The mobile-first strategy was deliberate: mobile is the hardest environment for VPNs, which traditionally drain batteries and slow connections. By solving that problem for consumers, Cloudflare built a client that could later be adapted for enterprise endpoints.

Introducing Cloudflare One Embedded Image - TAuhXQ

Consumer WARP also doubled as quality assurance. More than 10 million users have tested it over the past year, surfacing edge cases from across the Internet that helped iron out bugs. The same client is now being positioned as one of the on-ramps to Cloudflare One.

For offices and data centers, Cloudflare has been assembling the network-side pieces. Magic Transit, announced last year, provides secure IP connectivity to the Internet, while Cloudflare Network Interconnect (CNI) ties branch offices and data centers directly into Cloudflare’s backbone.

The filtering side of the stack builds on existing products. Cloudflare Access introduces identity into the network, applying context-aware filters to inbound and outbound traffic. Cloudflare Gateway routes traffic through Cloudflare’s network to protect connections to the Internet, letting customers drop on-premise firewalls and eliminate the Internet backhaul that slows remote users.

Introducing Cloudflare One Embedded Image - 2g3kPZ

Two Sides of One Platform

Cloudflare One products fall into two categories:

  • On-ramps: connections from endpoints, offices, or data centers to Cloudflare’s edge. WARP covers devices; Magic Transit and CNI cover networks; Argo Smart Routing accelerates traffic on Cloudflare’s backbone.
  • Filters: protection and policy enforcement, including Access for Zero Trust rules, Gateway for traffic filtering, and Magic Firewall for network-layer filtering.

The argument for combining these is efficiency. Point solutions that address either connectivity or security separately force organizations to manage multiple vendors and stitch policies across products. By integrating both on-ramps and filters into a single network, Cloudflare One offers administrators one place to manage security for their whole network.

Introducing Cloudflare One Embedded Image - KO3Y6r

What Sets Cloudflare One Apart

Deployment Without a Crisis

Cloudflare built its products to be self-service from the start, with free and pay-as-you-go tiers that don’t require a systems integrator. That shaped the control plane and dashboard to be approachable enough for small teams while remaining comprehensive for enterprises. The endpoint client follows the same path, reusing what worked in the consumer WARP app.

A Single Pane for Mixed Environments

Real companies rarely have uniform infrastructure—legacy apps coexist with cloud services, and acquisitions bring in multiple identity providers. Cloudflare One plugs those different providers into one network control plane, letting IT enforce consistent policy across applications whether they are old or new, on-premise or in a multi-tenant SaaS platform. Because the network touches every application, building policy control into the network is the common denominator.

Cost Architecture

Serving the whole Internet forces an obsession with cost efficiency, and Cloudflare passes that efficiency along as fixed-rate pricing. The company argues this makes Cloudflare One cheaper than combining point products, particularly compared to competitors built on public cloud infrastructure with its inherited costs and variable performance. The platform runs on every server in Cloudflare’s network spanning more than 200 cities—an architecture decision that keeps any branch office or remote worker within a few milliseconds of the service.

Visibility at Scale

Because Cloudflare already fronts a large slice of the Internet, its security services constantly observe new threats. That vantage point also improves routing: an employee hitting a shopping site from a branch office can travel from Magic Transit, across Cloudflare’s global backbone, over CNI, and to the destination—encrypted and optimized end to end. As more of the Internet joins Cloudflare’s network, the routing advantage compounds.

What Cloudflare One Replaces

The pitch is to retire the stack of gear that traditional enterprise networks require. Instead of MPLS links or complex SD-WAN deployments, Cloudflare One offers two on-ramps: WARP for individual devices and users from any location, and Magic Transit for whole offices or data centers.

For security, Cloudflare Access replaces the private-network-as-security model with Zero Trust controls. Cloudflare Gateway removes the need for traditional web gateways by inspecting traffic from any device to block threats and prevent data exfiltration. Magic Firewall does the same at the transport layer, replacing the firewall appliances often used to stop attacks from unsecured network protocols.

Introducing Cloudflare One Embedded Image - TWJv7b

The Roadmap Beyond Launch

Cloudflare One is available now in pieces: Access for Zero Trust application controls, Gateway for secure DNS, Magic Transit for DDoS protection, and Argo Tunnel for connecting applications through Cloudflare. But the announcements aren’t done. Later this week Cloudflare is rolling out:

  • Zero Trust security for all applications, including SaaS (Tuesday)
  • WARP as a full proxy for employee traffic, extending Gateway beyond DNS-only security (Wednesday)
  • Browser isolation beta sign-ups (Thursday)
  • New APIs for controlling Magic Transit network security (Friday)

Beyond the launch week, Cloudflare plans to fill more gaps. Magic WAN is aimed at replacing complex SD-WAN deployments, with Magic Firewall as an alternative to clunky next-generation firewall appliances for outbound traffic. Data loss prevention and new intrusion detection tools are also on the roadmap, intended to cover unauthorized access to SaaS applications and attack detection anywhere on the network.

What is Cloudflare One? Embedded Image - 2dc5eA

The first step, though, is getting enterprises onto the platform—and then proving that the Internet really can be secure and reliable enough to replace a corporate network.

Cloudflare One in Practice

Cloudflare built its network over the past decade with a focus on speed, reliability, and security. That same infrastructure now underpins Cloudflare One, giving organizations a way to apply Zero Trust principles without rebuilding their entire connectivity stack. The shift away from传统 VPNs and perimeter-based security has been in motion for years; the practical results from early adopters show what that looks like across different industries and use cases.

From Remote Access to Context-Aware Policies

For companies that need to get employees into internal tools quickly, Cloudflare One has replaced legacy VPN setups with identity-based checks. JetBlue Travel Products uses it to give crew members simple, secure access to internally managed benefit applications. OneTrust has taken a similar path, building context-aware Zero Trust policies for developer tools — with the added benefit that employees connect so easily they don't notice the security layer behind the scenes.

Discord applies the same model to its engineering team. Every request to critical applications is evaluated for both identity and context, reflecting a full Zero Trust approach rather than a simple network-level check.

Speed of Deployment for New Organizations

Cloudflare One has also proven useful for organizations that needed to stand up access quickly. Oak National Academy launched in April 2020 to deliver remote learning to children in the UK during the pandemic. The team used Cloudflare Access to authenticate a large network of teachers and developers into production sites, with setup completed in under an hour. Cloudflare's WAF protected the public-facing website from the start, providing security and resilience without extra engineering effort.

Area 1 Security, a fast-growing security company, points to the simplicity and speed of connecting employees to necessary tools — a critical factor when any delay affects development velocity.

Reducing IT Overhead

INSEAD has reduced its reliance on VPNs and IP allow-listing for development environments. Developers and testers no longer need to log in from specific locations, and an SSO solution has simplified the login process overall. Managing remote access through Cloudflare has been less burdensome than maintaining traditional VPN infrastructure, freeing IT teams to work on internal projects instead of access-related maintenance.

The early experiences of these organizations show a consistent pattern: Cloudflare One shifts the perimeter from the network to the user request, allowing for more flexible policies, faster deployment, and less operational overhead.