Enhanced View

Cloudflare One Connectivity Matrix

Comprehensive guide to connecting locations, users, and applications

← Back to Diagram
17
Total Options
17
Showing
3
Connection Types
4
Use Cases
Connectivity Option Locations
(Networks)
Users
(End Users)
Applications
(Resources)
Use Cases Key Features & Protocols
WARP Client
Requires client installation (Default mode)
Full identity-based policies
Remote Work
WireGuard MASQUE DNS Filtering Network Filtering HTTP Inspection Data Loss Prevention (DLP) Device Posture Checks AV Scanning Remote Browser Isolation (RBI)
WARP Client (Gateway with DoH)
DNS-only filtering mode
🟡DNS filtering only
Remote Work
DNS over HTTPS (DoH) DNS Filtering
WARP Client (Gateway without DNS)
HTTP inspection without DNS
No DNS filtering
Remote Work
WireGuard MASQUE Network Filtering HTTP Inspection Data Loss Prevention (DLP) Device Posture Checks AV Scanning Remote Browser Isolation (RBI)
WARP Client (Proxy Mode)
HTTP proxy configuration
Proxy-based filtering
Remote Work
Localhost Proxy WireGuard MASQUE HTTP Inspection Data Loss Prevention (DLP) AV Scanning Remote Browser Isolation (RBI)
DNS Resolver IPs
Office Router DNS configuration
Location-based DNS 🟡Limited identity context
Office Networks
DNS Filtering
DNS over HTTPS (DoH)
DoH token configuration
Location-specific endpoints User-specific tokens
Office Networks Remote Work
DNS over HTTPS (DoH) DNS Filtering DoH Identity Tokens
DNS over TLS (DoT)
TLS DNS configuration
Location-specific endpoints 🟡Limited identity
Office Networks
DNS over TLS (DoT) DNS Filtering Port 853
Proxy Endpoint (PAC)
PAC file with authorization endpoint
Authorization endpoint
Office Networks Remote Work
Authorization Endpoint HTTP Inspection Identity-Based Policies PAC file
Clientless RBI
Browser isolation deployment
On-ramp via GRE or IPSec Tunnel 🟡Non-identity via PAC, GRE or IPSec Tunnel
Office Networks Remote Work
Remote Browser Isolation (RBI) Web Isolation (Isolated) HTTP Inspection (Isolated) Network Filtering (Isolated) DNS Filtering
Cloudflare Tunnel
Outbound-only connections
Private Networks Private Networks and Public Hostnames
Data Centers Cloud Resources Office Networks
HTTP/HTTPS SSH RDP SMB gRPC TCP Kubernetes Layer 4
WARP Connector
Site-to-site, bidirectional, and mesh networking connectivity
Data Centers Cloud Resources Office Networks
WireGuard IP Routing Private Networks Layer 3
Magic WAN
Enterprise network infrastructure
Connection via GRE or IPSec Tunnel
Data Centers Office Networks
IPSec GRE SD-WAN (NGFW) Network Filtering Traffic Steering IP Routing
Network Interconnect (CNI)
Physical network connections
Direct peering IP Routing
Data Centers
Direct Connect / Peering BGP High Bandwidth
Identity Provider (SAML/OIDC)
IdP integration required
SSO integration SaaS Applications
Remote Work Office Networks SaaS Applications
SAML OIDC OAuth SSO
Mutual TLS (mTLS)
Certificate management
Network authentication 🟡Service accounts API endpoints
Data Centers Cloud Resources
mTLS Client Certificates API Authentication
Service Tokens
Token-based authentication
🟡Service accounts API endpoints
Data Centers Cloud Resources
Bearer Tokens API Authentication
CASB (API Integration)
SaaS API integration
SaaS applications
Remote Work Office Networks SaaS Applications
API Integration SaaS Security Data Protection
WARP Client (Device Info Only)
Device posture only
🟡Device posture only
Remote Work
Device Posture Checks No Traffic Routing
✅ Full Support
🟡 Caveats Apply
— Not Applicable

Implementation Notes

🔐 Identity-Based Policies

Options marked with 🟡 have limited or no support for identity-based policies. Full identity support requires user authentication through IdP or WARP client.

🌐 Protocol Support

Modern protocols like Post-Quantum Cryptography, WireGuard, and MASQUE are supported across applicable connection types.

🔗 Additional Resources

For detailed implementation guides, visit the Cloudflare One Documentation and explore specific configuration examples.