The network perimeter is gone — what replaces it?
Enterprise networking used to follow a castle-and-moat model. Users and applications lived inside a protected perimeter, and anyone inside was implicitly trusted. That model worked when employees sat in offices and workloads ran in nearby data centers. It no longer matches reality: users work from anywhere, applications run across multiple clouds, and critical services are delivered directly over the Internet. Yet many organizations still spend heavily on more complex versions of the same defensive walls.
Cloudflare One is Cloudflare's answer to that mismatch — a unified approach to corporate networking and security that combines connectivity for remote users with globally distributed security controls. Instead of layering more appliances onto an outdated architecture, it treats the Internet itself as the new corporate network.
Routing that follows users, not offices
When employees were inside an office, they reached datacenter applications over a private network. Remote workers used VPNs to tunnel back inside, and branch offices connected over MPLS. When applications moved to the cloud and users scattered, organizations responded by buying more VPN licenses and replacing MPLS with complex SD-WAN deployments. The result was networks that grew more complicated trying to mimic an obsolete model, with traffic taking indirect "hairpin" paths through security checkpoints.
Cloudflare One flips that approach. Cloudflare WARP and Gateway filter outbound Internet traffic from any location, eliminating the need to backhaul traffic to central security appliances. For office networks, Magic Firewall brings next-generation firewall capabilities to Magic Transit, targeting the top-of-shelf firewall appliances. Magic WAN provides a control plane for routing traffic through Cloudflare's network, offering a simpler and more cost-effective alternative to MPLS and SD-WAN models.
Replacing VPNs with Zero Trust access
VPNs served a second function beyond connectivity: placing users on a private network so access controls could apply. Cloudflare Access replaces that function with Zero Trust controls that work without a private network model. Later this week, Cloudflare plans to extend Access to any application, including SaaS offerings, and preview browser isolation technology to protect the endpoints that connect to those applications from malware.
Filling the visibility gap
A patchwork of point solutions did more than fragment defense-in-depth — it destroyed visibility. Security teams lost sight of what was happening across their networks and applications. Customers consistently report that capturing and standardizing logs is one of their largest hurdles, made worse by regulatory pressure on data retention and analysis. The Gateway filtering launch includes logs that provide visibility into traffic leaving the organization, with plans for an Intrusion Detection System that detects and stops intrusion attempts.
Without that visibility, security teams were forced to guess at what could go wrong. Organizations wanting to adopt an "assume breach" model couldn't determine what kind of breach to prepare for, so they deployed every possible solution. Many enterprises purchase new scanning and filtering services, often as virtual appliances, for problems they aren't sure they have — then attempt to remediate every possible event manually rather than targeting specific threats and adapting accordingly.
From the moat to the internet
Cloudflare One is built around a simple observation: the controls that once protected a physical perimeter need to follow users and workloads wherever they go. The product family spans connectivity, security filtering, access control, and logging — with several components available today, more arriving this week, and others in development. It represents a shift away from trying to force distributed work back inside castle walls and toward treating the Internet as the network that enterprises actually run on.
One network, many on-ramps
Cloudflare One is the result of assembling products that originally targeted individual security problems into a single, cohesive platform. The core idea is that Cloudflare’s network—already used as a reverse proxy for Internet-facing properties—can also process forward traffic from employees, branch offices, and data centers. That means the same edge that protects and accelerates inbound web traffic can apply identical controls to outbound connections.
The on-ramps to this model are varied. Cloudflare WARP, launched in 2019 as a mobile app for private, encrypted Internet connections, is now packaged in an enterprise version to connect roaming employees to Cloudflare Gateway. Magic Transit, launched last year, secures on-premises networks from IP-layer attacks with best-in-class DDoS mitigation. This year, Cloudflare Network Interconnect (CNI) extended that model by letting customers connect branch offices and data centers directly to Cloudflare; outbound filtering is now applied to those same connections.
Each on-ramp is enhanced with Argo Smart Routing, which has been shown to reduce latency by 30% or more in real-world deployments. The point is not just to move corporate networking to the Internet, but to make it faster than a typical Internet connection by leveraging a carrier-agnostic, globally peered network that delivers the same services from every data center.
Policy from identity to packet
When traffic no longer flows through a headquarters firewall appliance, security controls have to move to the edge. Cloudflare One applies standard controls to all traffic, regardless of where a connection originates or what layer of the network stack it touches.
Identity is introduced through Cloudflare Access, which lets teams filter inbound and outbound connections based on identity and context. Every login, request, and response proxies through Cloudflare’s network, and the scale of that network allows for filtering and logging without performance trade-offs.
For application-layer threats leaving devices and networks, Cloudflare Gateway inspects traffic for malware and data loss. A transport-layer version is planned. On the network side, Magic Firewall is a next-generation firewall for traffic leaving offices and data centers. Rules can be written once and applied everywhere, or tailored to specific use cases, all from a single control plane.
For threats that evade known filters, Cloudflare Browser provides an isolated browsing environment, preventing malicious code from jumping from the browser to an endpoint. A beta is opening for customers later this week.
Certificate management is also part of the platform, addressing a common pain point for teams modernizing their security model. Cloudflare already supports modern standards like TLS 1.3 and offers one-click encryption for websites; the same ease of management is being applied to network functions.
Centralized visibility and logging
Cloudflare’s network handles an average of 18 million HTTP requests per second, and the logging pipelines built for that scale are reused for Cloudflare One. Cloudflare Access and Gateway capture every request—inbound or outbound—without server-side code changes or elaborate client configuration. Logs can be exported to any SIEM via Cloudflare Logpush, the same pipeline used for public site HTTP events. Magic Transit extends logging to entire networks and offices.
Beyond raw logs, Cloudflare Web Analytics converts log data into insights today, and the company plans to expand that analytics capability to network operations. The goal is to replace the fragmented, expensive security analytics ecosystem with the same unified edge model used for other network functions.
Toward automatic response
Log systems that surface events are useful; ones that remediate them are better. Launching into a closed preview this week, Cloudflare Intrusion Detection System (IDS) proactively scans network traffic for anomalies and either recommends actions or takes them automatically. The same proactive scanning and remediation approach is planned for Cloudflare Access and Cloudflare Gateway.
Same edge, same performance
More than 25 million Internet properties rely on Cloudflare’s network, including 16% of the Fortune 1000. Cloudflare One runs from the same data centers, with every one delivering the full set of services—Access, WARP, Magic Transit, or the WAF. When an employee connects via WARP to a nearby data center, they may never leave that facility to reach the sites or data they need; the entire Internet experience becomes faster regardless of location.
That advantage grows as browsing moves to the edge with Cloudflare Browser, where isolated browsers can request content stored in the same data center. As more properties adopt Cloudflare Workers, entire application workflows can remain within a data center, keeping latency under 100 ms.




