Cloud networking’s management gap

Public clouds promise on-demand IT infrastructure without the overhead of running a datacenter. But the reality of operating cloud networks at scale—across multiple accounts and providers—has not matched that promise. Today, Cloudflare is announcing Magic Cloud Networking, powered by technology from the recently acquired Nefeli Networks, to address that gap.

Magic Cloud Networking provides a single interface to control and unify the native network capabilities of multiple cloud providers, using familiar concepts to create reliable, cost-effective, and secure cloud networks. The goal is to give customers a clearer way to connect and protect users, private networks, and applications that span any combination of internal and external resources.

Why cloud networking is hard

Cloud networking abstracts away much of the physical complexity of on-premises networks. The ethernet and physical layers are hidden, control plane protocols are replaced by a fully programmable software-defined network (SDN), and capacity is available on-demand, charged only for what is used. Yet enterprises still struggle with several recurring problems:

  • Poor end-to-end visibility: monitoring tools are difficult to use, and silos exist even within a single cloud provider, impeding troubleshooting.
  • Faster pace: ClickOps and CLI-driven procedures cannot keep up with instant, on-demand deployment; automation is required.
  • Different technology: architectures that rely on ethernet and advanced control plane protocols do not transition seamlessly to the cloud.
  • New cost models: pay-as-you-go usage-based pricing clashes with approaches built around fixed-cost circuits and 5-year depreciation, which drives different architectural decisions.
  • New security risks: achieving zero trust and least-privilege in public clouds requires mature operating processes, automation, and familiarity with cloud-specific policies and IAM controls.
  • Multi-vendor operation: extending beyond a single cloud—into other clouds or on-premises environments—creates a multi-vendor scenario that challenges single-vendor sourcing strategies.

These problems point to a core question: where should the solution be implemented? Nefeli’s approach identifies the management plane—not the underlying network fabric—as the right layer to fix.

An analogy from rail transport

Consider a train system, which has three layers: the tracks and trains, the electronic signals, and the company that manages the system and sells tickets. If the tracks, trains, and signals are excellent, but the ticket agents cannot keep up with passenger demand, the system operates below its potential. The fix is not to rebuild the tracks—it is to simplify schedules and pricing, improve booking systems, and automate ticket machines.

Networking has an analogous set of three layers:

  • Data Plane: the paths that transport packets from source to destination.
  • Control Plane: the protocols and logic that steer packets across the data plane.
  • Management Plane: the configuration and monitoring interfaces for the data and control planes.

In public clouds, these map to the Virtual Private Cloud (VPC) or Virtual Network (VNet) service with its subnets, routing tables, security groups, and load-balancers (data plane); a software-defined network that programs static routes (control plane); and an administrative UI/API for configuration and monitoring (management plane). Just as with the train system, the problems our customers face are concentrated in the management plane.

Nefeli’s technology simplifies, unifies, and automates cloud network management and operations at this layer.

Avoiding VNF shortcuts

One common approach to cloud network management problems is to insert Virtual Network Functions (VNFs)—VMs that do packet forwarding—into the data plane. VNFs may be routers, firewalls, or load-balancers ported from physical appliances, or software proxies built on open-source projects like NGINX or Envoy. They let IT teams keep familiar management tooling, but they come with significant downsides:

  • VMs lack custom network silicon, relying instead on raw compute power sized for peak load, driving high costs regardless of actual utilization.
  • High availability depends on fragile, costly, and complex network configuration.
  • Service insertion often forces packet paths that incur additional bandwidth charges.
  • VNFs are typically licensed similarly to their on-premises counterparts, making them expensive.
  • VNFs lock enterprises into a specific implementation, potentially excluding them from improvements in native cloud data plane offerings.

The native network capabilities of public clouds are elastic, performant, robust, usage-priced, and backed by provider SLAs with integrated high-availability options. Rebuilding the data plane to solve management plane problems is the wrong approach. The right solution works with the native capabilities of the cloud service provider rather than replacing them.

Nefeli leverages native cloud data plane constructs instead of third-party VNFs.

One Pane for Public Cloud Networks

Cloudflare has folded the Nefeli team into its Cloudflare One platform to launch Magic Cloud Networking. The new capability lets enterprises discover, visualize, and manage public cloud network resources through the Cloudflare dashboard and API, then connect those networks to Cloudflare One.

Cloud providers, much like train operators, only concern themselves with journeys inside their own network. But enterprises typically run hundreds of cloud accounts spread across multiple providers, creating disconnected silos that add operational overhead and security risk. Magic Cloud Networking acts as the aggregator: it discovers resources across all accounts and providers, shows the full end-to-end topology, and automates the workflow for building a scalable network in one interface.

BLOG-2234 Embedded Image - FoHVy7

The resource inventory renders all configuration in its entirety through a responsive UI, giving a single source of truth for network state.

BLOG-2234 Embedded Image - yJ2bpY

Resource inventory shows all configuration in a single and responsive UI

Handling Per-Cloud Complexity

Public clouds are built from modular building blocks that stack from a billing account up through VPC networking to compute, storage, and network infrastructure. Even a relatively simple architecture can involve hundreds of resources. The abstractions they expose differ from on-premises equivalents and vary between providers, and the web of dependencies between them comes with configuration rules that are inconsistent across resource types and clouds. Whether you can modify an IP network while 100 VMs are attached to it, for example, depends entirely on the provider and the specifics of the resource.

Magic Cloud Networking takes on those differences itself. It configures native cloud constructs—VPN gateways, routes, and security groups—to connect a cloud VPC to Cloudflare One, without requiring operators to learn each provider's particular way of standing up VPN connections and hubs.

Coordinated Automation Prevents Drift

Cloud configuration suffers from the same coordination problem as railway signaling. If maintenance crews manually set a signal to stop traffic and the scheduling office later clears that signal through a remote change, the safety measure is silently lost. In cloud networks, the equivalent happens when different teams—billing, support, security, networking, firewalls, database, application development—make changes through different automation and configuration interfaces without visibility into each other.

BLOG-2234 Embedded Image - 8nR4PN

After a network is deployed, Magic Cloud Networking continuously monitors configuration and health to confirm that the security and connectivity put in place is still in place. It tracks the cloud resources under its management and automatically reverts drift introduced by out-of-band changes, while leaving other resources such as storage buckets and application servers available for separate automation tooling. When the network itself changes, route management is handled centrally, injecting and withdrawing routes across Cloudflare and all connected cloud provider networks. The service is fully programmable via API and slots into existing automation workflows.

BLOG-2234 Embedded Image - Hc5gT3

The interface warns when cloud network infrastructure drifts from intent

Early Access

Magic Cloud Networking is positioned as the latest step toward the Connectivity Cloud vision, enabling customers to get securely connected to public clouds, stay connected, and realize flexibility and cost savings. Early access sign-ups are open at cloudflare.com/lp/cloud-networking.

BLOG-2234 Embedded Image - 1dxJfp