Lộ trình đang học Current learning path Current learning path

Cloudflare One Cloudflare One Cloudflare One

Bảo vệ users, access, SaaS và networks — follow-along từ tài khoản đến go-live. Secure users, access, SaaS, and networks — follow along from account to go-live. Secure users, access, SaaS, and networks — follow along from account to go-live.

Về trang lộ trình Track home Track home

Phần 3: Thiết bị — Cloudflare One Client Part 3: Devices — Cloudflare One Client Part 3: Devices — Cloudflare One Client · Bài 1/3 Lesson 1/3 មេរៀន 1/3

Enrollment và cài Cloudflare One Client Enrollment and installing the Cloudflare One Client Enrollment and installing the Cloudflare One Client

Mô-đun 3 — Đăng ký thiết bị (Cloudflare One Client / WARP)

Mục tiêu: Cài Cloudflare One Client (ứng dụng WARP) trên thiết bị để lưu lượng của chúng kết nối an toàn tới Cloudflare, và để Cloudflare kiểm tra mỗi thiết bị khỏe mạnh trước khi cấp quyền truy cập.

👤 Ai làm việc này Đội Endpoint / Desktop
⏱️ Thời gian ~60 phút (pilot); rollout MDM tùy thuộc
🎯 Kết thúc bạn sẽ có Một thiết bị pilot hiện Connected, nằm trong bảng điều khiển, với một posture check đạt
✋ Trước khi bắt đầu Đã xong Mô-đun 2 (IdP đã kết nối + đã test), và một laptop thử nghiệm bạn kiểm soát

📖 Đặt tên: Ứng dụng chính thức là Cloudflare One Client. Bạn vẫn thấy "WARP" trong menu và chính ứng dụng — chúng là cùng một thứ.

Chúng ta sẽ làm theo thứ tự: (A) quyết định ai được đăng ký → (B) đặt cách thiết bị hành xử → (C) cài trên một thiết bị pilot → (D) phân phối chứng chỉ → (E) bật kiểm tra sức khỏe → (F) triển khai quy mô lớn bằng MDM.


Phần A — Quyết định ai được đăng ký (làm bước này trước)

Nếu bỏ qua bước này, ứng dụng sẽ từ chối kết nối với "you are not allowed to enroll."

  1. 👉 Zero Trust → Settings → WARP Client.
  2. 👉 Tìm Device enrollment permissions → nhấp Manage.
  3. 👉 Nhấp Add a rule.
  4. ⌨️ Điền:
    Trường Giá trị
    Rule name Company employees
    Rule action Allow
    Selector Emails ending in
    Value @yourcompany.com
  5. 👉 Dưới login methods / identity providers, chọn IdP bạn đã kết nối ở Mô-đun 2.
  6. 👉 Nhấp Save.

✅ Điểm kiểm tra: Một rule xuất hiện cho phép tên miền email công ty của bạn đăng ký, dùng IdP của bạn.

💡 Mẹo: Với máy chủ hoặc đội thiết bị tự động lớn, sau này bạn có thể tạo rule Service Auth + service token để thiết bị đăng ký im lặng, không cần đăng nhập. Với pilot, rule Allow ở trên là đủ.


Phần B — Đặt cách thiết bị hành xử (device profile)

  1. 👉 Trong Settings → WARP Client, cuộn tới Device settings (hoặc Profile settings).

  2. 👉 Nhấp hồ sơ Default → Configure.

  3. 👉 Đặt các mục sau cho laptop công ty được quản lý:

    Thiết lập Đặt thành Vì sao
    Service mode Gateway with WARP Bảo vệ đầy đủ (lọc web + DNS + truy cập nội bộ)
    Switch Locked On Ngăn người dùng tắt ứng dụng
    Auto connect 1 phút Tự kết nối lại sau khi mất kết nối ngắn
    Captive portal detection On Cho phép người dùng đăng nhập Wi-Fi khách sạn/sân bay
  4. 👉 Nhấp Save profile.

Split Tunnel (lưu lượng nào đi qua Cloudflare)

  1. 👉 Vẫn trong hồ sơ, tìm Split Tunnels → nhấp Manage.
  2. Chọn chế độ:
    • Laptop thuộc công ty → để ở chế độ Exclude (mặc định). Mọi thứ đi qua Cloudflare trừ một danh sách loại trừ có sẵn nhỏ.
    • Thiết bị cá nhân / BYOD → chuyển sang chế độ Include và chỉ liệt kê ứng dụng/mạng công ty, để lưu lượng cá nhân của nhân viên vẫn riêng tư.

⚠️ Lưu ý: Đừng chạy thiết bị cá nhân ở chế độ Exclude đầy đủ — nó đưa duyệt web cá nhân của người dùng qua công ty, gây lo ngại về quyền riêng tư. Dùng chế độ Include cho BYOD.

✅ Điểm kiểm tra: Hồ sơ Default của bạn hiện Gateway with WARP và chế độ split-tunnel phù hợp với loại thiết bị.

💡 Cần thiết lập khác nhau cho các loại thiết bị khác nhau (BYOD vs. được quản lý vs. máy chủ vs. nhà thầu)? Đó là việc của device profiles. Hướng dẫn đầy đủ — chế độ client, match rules/selectors, thứ tự ưu tiên, split tunnel theo hồ sơ, và local domain fallback — nằm ở trang đi kèm: Mô-đun 3b — Cấu hình Device Profiles.


Phần C — Cài trên thiết bị pilot (thủ công)

Chúng ta sẽ cài trên một laptop trước và xác nhận hoạt động trước mọi triển khai hàng loạt.

Bước C1 — Tải client

  1. 👉 Trên laptop thử nghiệm, mở https://one.one.one.one/ và chọn nền tảng của bạn, hoặc tải trực tiếp:
    • Windows: tải trình cài Cloudflare WARP (.msi / .exe)
    • macOS: tải trình cài Cloudflare WARP (.pkg)
    • Linux / iOS / Android: làm theo hướng dẫn nền tảng trên trang tải

Bước C2 — Cài đặt

  1. 👉 Chạy trình cài và chấp nhận các lời nhắc (trên macOS bạn sẽ Allow system extension và cấu hình VPN; trên Windows, chấp nhận lời nhắc UAC).
  2. 📺 Bạn sẽ thấy: Một logo Cloudflare nhỏ xuất hiện trên thanh menu (macOS) hoặc khay hệ thống (Windows).

Bước C3 — Kết nối với tổ chức của bạn (không phải chế độ consumer)

Đây là bước gắn ứng dụng với tổ chức Zero Trust của bạn.

  1. 👉 Nhấp biểu tượng Cloudflare WARP → biểu tượng bánh răng/cog ⚙️ → Preferences → Account.
  2. 👉 Nhấp Login with Cloudflare Zero Trust.
  3. ⌨️ Khi được hỏi team name, chỉ nhập phần tên (ví dụ acme, không phải URL đầy đủ).
  4. 👉 Nhấp Continue.
  5. 📺 Trình duyệt mở đăng nhập công ty (IdP từ Mô-đun 2). Đăng nhập.
  6. ✅ Bạn sẽ thấy trang "You have successfully authenticated". Quay lại ứng dụng.
  7. 👉 Đảm bảo công tắc chính của ứng dụng đang On / Connected.

✅ Điểm kiểm tra — xác nhận thực sự được bảo vệ:

  1. 👉 Nhấp biểu tượng WARP — nó phải ghi Connected.
  2. 👉 Trong trình duyệt trên laptop đó, truy cập https://www.cloudflare.com/cdn-cgi/trace/
  3. 📺 Trong văn bản hiện ra, tìm:
    • warp=on
    • gateway=on
  4. 👉 Bây giờ kiểm tra bảng điều khiển: Zero Trust → My Team → Devices. Thiết bị thử nghiệm xuất hiện trong danh sách. 🎉

⚠️ Nếu hiện "not allowed to enroll": quay lại Phần A — tên miền email chưa được rule đăng ký bao phủ, hoặc chọn sai IdP.


Phần D — Phân phối chứng chỉ Cloudflare

Bước này bắt buộc trước khi bạn bật HTTPS inspection, DLP, hoặc quét prompt AI ở các mô-đun sau. Nếu thiếu, website bảo mật sẽ báo lỗi chứng chỉ.

  1. 👉 Zero Trust → Settings → Resources (menu cũ: Settings → Devices → Certificate).
  2. 👉 Tìm Cloudflare certificate và Download nó.
  3. Cài vào kho chứng chỉ tin cậy của thiết bị:
    • Pilot (thủ công): nhấp đúp chứng chỉ và thêm vào kho hệ thống/keychain "Trusted Root".
    • Quy mô lớn: đẩy qua MDM (nêu ở Phần F).

✅ Điểm kiểm tra: Chứng chỉ Cloudflare đã được cài và tin cậy trên thiết bị pilot.

⚠️ Lưu ý: Đừng bật giải mã TLS/HTTPS (Mô-đun 5) cho đến khi chứng chỉ này có trên thiết bị, nếu không website HTTPS sẽ hỏng.


Phần E — Bật kiểm tra sức khỏe thiết bị (posture)

Hãy thêm một kiểm tra đơn giản để bạn có thể yêu cầu thiết bị khỏe mạnh ở các mô-đun sau.

  1. 👉 Zero Trust → Settings → WARP Client → Device posture (hoặc Reusable components → Posture checks).
  2. 👉 Nhấp Add → chọn một kiểm tra client đơn giản, ví dụ Disk encryption.
  3. ⌨️ Đặt tên Disk encrypted, chọn (các) nền tảng, và lưu.

📺 Bạn sẽ thấy: Posture check mới được liệt kê, đang đánh giá các thiết bị đã đăng ký.

✅ Điểm kiểm tra: Thiết bị pilot báo compliant cho kiểm tra mã hóa đĩa (giả sử đĩa đã được mã hóa).

💡 Mẹo: Với kiểm tra phiên bản OS, yêu cầu phiên bản mới nhất bạn đã kiểm tra, không phải bản mới nhất tuyệt đối — nếu không một bản OS vừa ra có thể khóa mọi người ngay ngày phát hành. Nếu bạn dùng CrowdStrike, SentinelOne, hoặc Intune, bạn cũng có thể thêm chúng làm nguồn posture tại đây (Enterprise). Lưu ý: posture Tanium hoạt động với Access nhưng không với Gateway.

🛡️ Posture là một chủ đề lớn. Bộ công cụ đầy đủ — mọi kiểm tra có sẵn, tích hợp EDR/MDM bên thứ ba, dùng posture trong chính sách Access & Gateway, và đánh giá lại liên tục — xem Mô-đun 3c — Device Posture Checks.


Phần F — Triển khai cho mọi người (MDM)

Khi thiết bị pilot hoạt động, triển khai cho đội thiết bị im lặng bằng MDM (Intune, Jamf, Kandji, Workspace ONE, SCCM…). Bạn đẩy cùng ứng dụng cộng một cấu hình nhỏ để nó tự đăng ký, không cần bước người dùng.

Các thiết lập chính cần đẩy

Thiết lập Giá trị Mục đích
organization team name của bạn Gắn ứng dụng với tổ chức (bắt buộc)
service_mode warp Gateway with WARP
onboarding false Ẩn màn hình chào (im lặng)
auto_connect 1 Kết nối ngay
switch_locked true Người dùng không tắt được
support_url liên kết hỗ trợ IT của bạn Hiện trong ứng dụng

Để đăng ký hoàn toàn im lặng (không hỏi đăng nhập), cũng đẩy một service token:

  1. 👉 Tạo rule đăng ký Service Auth (Phần A → action Service Auth).
  2. 👉 Zero Trust → Access → Service Auth → Service Tokens → Create → sao chép Client ID và Client Secret.
  3. Đẩy chúng thành auth_client_id và auth_client_secret trong cấu hình MDM.

⚠️ Lưu ý: Thiết lập MDM cục bộ ghi đè thiết lập bảng điều khiển. Và service token cần rule đăng ký Service Auth — rule Allow thường không dùng được cho đăng ký bằng token.

Ví dụ hồ sơ cấu hình macOS (com.cloudflare.warp):

<dict>
  <key>organization</key>       <string>acme</string>
  <key>service_mode</key>       <string>warp</string>
  <key>onboarding</key>         <false/>
  <key>auto_connect</key>       <integer>1</integer>
  <key>switch_locked</key>      <true/>
  <key>support_url</key>        <string>https://help.acme.com</string>
</dict>

Đẩy Cloudflare certificate (Phần D) qua cùng hồ sơ MDM.

✅ Điểm kiểm tra: Một thiết bị thứ hai, đăng ký qua MDM, xuất hiện dưới My Team → Devices là Connected mà không cần đăng nhập thủ công.


✅ Hoàn thành Mô-đun 3!

Bây giờ bạn có:

  • ✅ Một rule đăng ký kiểm soát ai được tham gia
  • ✅ Một device profile (Gateway with WARP + split tunnel)
  • ✅ Một thiết bị pilot Connected và nằm trong bảng điều khiển
  • ✅ Chứng chỉ Cloudflare đã được phân phối
  • ✅ Một device posture check hoạt động
  • ✅ Một kế hoạch rollout MDM cho phần còn lại của đội thiết bị

Khắc phục nhanh

Vấn đề Cách khắc phục
"You are not allowed to enroll" Thêm/sửa rule đăng ký (Phần A); xác nhận tên miền email + IdP
Ứng dụng kẹt "Connecting" Kiểm tra thiết bị ra được internet; thử tắt/bật; kiểm tra tường lửa không chặn WARP
gateway=on không hiện trong trace Service mode không phải Gateway with WARP, hoặc đang ở chế độ chỉ DNS — sửa hồ sơ (Phần B)
Website HTTPS hiện cảnh báo chứng chỉ Chứng chỉ Cloudflare chưa được tin cậy — cài nó (Phần D) trước mọi HTTPS inspection
Thiết bị cá nhân đưa lưu lượng cá nhân đi qua Chuyển hồ sơ đó sang chế độ split-tunnel Include (Phần B)

👉 Tiếp theo: Mô-đun 4 — ZTNA / Access

Bạn sẽ xuất bản ứng dụng nội bộ đầu tiên và thay thế truy cập VPN tới nó.

Module 3 — Device Enrollment (Cloudflare One Client / WARP)

Goal: Install the Cloudflare One Client (the WARP app) on your devices so their traffic can be securely connected to Cloudflare, and so Cloudflare can check each device is healthy before granting access.

👤 Who does this Endpoint / Desktop team
⏱️ Time ~60 minutes (pilot); MDM rollout varies
🎯 You'll finish with A pilot device showing Connected, listed in your dashboard, with a posture check passing
✋ Before you begin Module 2 done (IdP connected + tested), and one test laptop you control

📖 Naming: The app is officially the Cloudflare One Client. You'll still see "WARP" in menus and the app itself — they're the same thing.

We'll go in this order: (A) decide who can enroll → (B) set how devices behave → (C) install on a pilot device → (D) distribute the certificate → (E) turn on health checks → (F) roll out at scale with MDM.


Part A — Decide who's allowed to enroll (do this first)

If you skip this, the app will refuse to connect with "you are not allowed to enroll."

  1. 👉 Zero Trust → Settings → WARP Client.
  2. 👉 Find Device enrollment permissions → click Manage.
  3. 👉 Click Add a rule.
  4. ⌨️ Fill in:
    Field Value
    Rule name Company employees
    Rule action Allow
    Selector Emails ending in
    Value @yourcompany.com
  5. 👉 Under login methods / identity providers, select the IdP you connected in Module 2.
  6. 👉 Click Save.

✅ Checkpoint: A rule appears that allows your company's email domain to enroll, using your IdP.

💡 Tip: For servers or large automated fleets, you can later create a Service Auth rule + service token so devices enroll silently with no login. For your pilot, the Allow rule above is all you need.


Part B — Set how devices behave (device profile)

  1. 👉 In Settings → WARP Client, scroll to Device settings (or Profile settings).

  2. 👉 Click the Default profile → Configure.

  3. 👉 Set these for managed company laptops:

    Setting Set to Why
    Service mode Gateway with WARP Full protection (web + DNS filtering + private access)
    Switch Locked On Stops users turning the app off
    Auto connect 1 minute Reconnects automatically after brief drops
    Captive portal detection On Lets users sign in to hotel/airport Wi-Fi
  4. 👉 Click Save profile.

Split Tunnel (what traffic goes through Cloudflare)

  1. 👉 Still in the profile, find Split Tunnels → click Manage.
  2. Choose your mode:
    • Company-owned laptops → leave it on Exclude mode (the default). Everything goes through Cloudflare except a small built-in exclusion list.
    • Personal / BYOD devices → switch to Include mode and list only your company apps/networks, so employees' personal traffic stays private.

⚠️ Watch out: Don't run personal devices in full Exclude mode — it routes the user's personal browsing through your company, which raises privacy concerns. Use Include mode for BYOD.

✅ Checkpoint: Your Default profile shows Gateway with WARP and a split-tunnel mode appropriate for your device type.

💡 Need different settings for different devices (BYOD vs. managed vs. servers vs. contractors)? That's what device profiles are for. The full walkthrough — client modes, match rules/selectors, order of precedence, per-profile split tunnels, and local domain fallback — is in the companion page: Module 3b — Device Profiles Configuration.


Part C — Install on your pilot device (manual)

We'll install on one laptop first and confirm it works before any mass deployment.

Step C1 — Download the client

  1. 👉 On the test laptop, open https://one.one.one.one/ and choose your platform, or download directly:
    • Windows: download the Cloudflare WARP installer (.msi / .exe)
    • macOS: download the Cloudflare WARP installer (.pkg)
    • Linux / iOS / Android: follow the platform instructions on the download page

Step C2 — Install it

  1. 👉 Run the installer and accept the prompts (on macOS you'll Allow a system extension and VPN configuration; on Windows, accept the UAC prompt).
  2. 📺 What you'll see: A small Cloudflare logo appears in your menu bar (macOS) or system tray (Windows).

Step C3 — Connect it to your organization (not consumer mode)

This is the step that links the app to your Zero Trust org.

  1. 👉 Click the Cloudflare WARP icon → the gear/cog ⚙️ icon → Preferences → Account.
  2. 👉 Click Login with Cloudflare Zero Trust.
  3. ⌨️ When prompted for your team name, enter just the name part (e.g. acme, not the full URL).
  4. 👉 Click Continue.
  5. 📺 Your browser opens your company login (the IdP from Module 2). Sign in.
  6. ✅ You'll see a "You have successfully authenticated" page. Return to the app.
  7. 👉 Make sure the app's main toggle is switched On / Connected.

✅ Checkpoint — confirm it's really protected:

  1. 👉 Click the WARP icon — it should say Connected.
  2. 👉 In a browser on that laptop, visit https://www.cloudflare.com/cdn-cgi/trace/
  3. 📺 In the text shown, look for:
    • warp=on
    • gateway=on
  4. 👉 Now check the dashboard: Zero Trust → My Team → Devices. Your test device appears in the list. 🎉

⚠️ If it says "not allowed to enroll": revisit Part A — your email domain isn't covered by an enrollment rule, or the wrong IdP is selected.


Part D — Distribute the Cloudflare certificate

This is required before you turn on HTTPS inspection, DLP, or AI prompt scanning in later modules. Without it, secure websites will show certificate errors.

  1. 👉 Zero Trust → Settings → Resources (older menus: Settings → Devices → Certificate).
  2. 👉 Find the Cloudflare certificate and Download it.
  3. Install it into the device's trusted certificate store:
    • Pilot (manual): double-click the certificate and add it to the system/keychain "Trusted Root" store.
    • At scale: push it through your MDM (covered in Part F).

✅ Checkpoint: The Cloudflare certificate is installed and trusted on your pilot device.

⚠️ Watch out: Do not enable TLS/HTTPS decryption (Module 5) until this certificate is on the device, or HTTPS websites will break.


Part E — Turn on a device health check (posture)

Let's add one simple check so you can require healthy devices in later modules.

  1. 👉 Zero Trust → Settings → WARP Client → Device posture (or Reusable components → Posture checks).
  2. 👉 Click Add → choose a simple client check, e.g. Disk encryption.
  3. ⌨️ Name it Disk encrypted, choose the platform(s), and save.

📺 What you'll see: The new posture check listed, evaluating your enrolled devices.

✅ Checkpoint: Your pilot device reports compliant for the disk-encryption check (assuming its disk is encrypted).

💡 Tip: For OS-version checks, require the latest version you've already tested, not the absolute newest — otherwise a brand-new OS release could lock everyone out the day it ships. If you use CrowdStrike, SentinelOne, or Intune, you can add those as posture sources here too (Enterprise). Note: Tanium posture works for Access but not Gateway.

🛡️ Posture is a big topic. For the full toolkit — every built-in check, third-party EDR/MDM integrations, using posture in Access & Gateway policies, and continuous re-evaluation — see Module 3c — Device Posture Checks.


Part F — Roll out to everyone (MDM)

Once your pilot device works, deploy to the fleet silently using your MDM (Intune, Jamf, Kandji, Workspace ONE, SCCM…). You push the same app plus a small config so it self-enrolls with no user steps.

Key settings to push

Setting Value Purpose
organization your team name Links the app to your org (required)
service_mode warp Gateway with WARP
onboarding false Hides the welcome screens (silent)
auto_connect 1 Connects immediately
switch_locked true Users can't disable it
support_url your IT help link Shown in the app

For fully silent enrollment (no login prompt), also push a service token:

  1. 👉 Create a Service Auth enrollment rule (Part A → action Service Auth).
  2. 👉 Zero Trust → Access → Service Auth → Service Tokens → Create → copy the Client ID and Client Secret.
  3. Push them as auth_client_id and auth_client_secret in your MDM config.

⚠️ Watch out: Local MDM settings override dashboard settings. And service tokens require a Service Auth enrollment rule — a plain Allow rule won't work for token enrollment.

Example macOS configuration profile (com.cloudflare.warp):

<dict>
  <key>organization</key>       <string>acme</string>
  <key>service_mode</key>       <string>warp</string>
  <key>onboarding</key>         <false/>
  <key>auto_connect</key>       <integer>1</integer>
  <key>switch_locked</key>      <true/>
  <key>support_url</key>        <string>https://help.acme.com</string>
</dict>

Push the Cloudflare certificate (Part D) through the same MDM profile.

✅ Checkpoint: A second device, enrolled via MDM, appears under My Team → Devices as Connected with no manual login.


✅ Module 3 complete!

You now have:

  • ✅ An enrollment rule controlling who can join
  • ✅ A device profile (Gateway with WARP + split tunnel)
  • ✅ A pilot device Connected and listed in the dashboard
  • ✅ The Cloudflare certificate distributed
  • ✅ A working device posture check
  • ✅ An MDM rollout plan for the rest of the fleet

Quick troubleshooting

Problem Fix
"You are not allowed to enroll" Add/repair the enrollment rule (Part A); confirm the email domain + IdP
App stuck "Connecting" Check the device can reach the internet; try toggling off/on; check a firewall isn't blocking WARP
gateway=on not showing in the trace Service mode isn't Gateway with WARP, or a DNS-only mode is set — fix the profile (Part B)
HTTPS sites show certificate warnings The Cloudflare certificate isn't trusted yet — install it (Part D) before any HTTPS inspection
Personal device routes personal traffic Switch that profile to Include split-tunnel mode (Part B)

👉 Next: Module 4 — ZTNA / Access

You'll publish your first private application and replace VPN access to it.

Nguồn cộng đồng — không phải tài liệu chính thức của Cloudflare: https://zerotrust.cfsase.workers.dev Community source — not an official Cloudflare publication: https://zerotrust.cfsase.workers.dev

Ví dụ triển khai (Cloudflare Resources) Deployment examples (Cloudflare Resources) Deployment examples (Cloudflare Resources)

Ví dụ chính thức từ Cloudflare Resources — gợi ý theo chủ đề bài học trong lộ trình này. Official examples from Cloudflare Resources — matched to this lesson within this path. Official examples from Cloudflare Resources — matched to this lesson within this path.

Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Access một ứng dụng web thông qua tên máy chủ riêng của nó mà không có Cloudflare One Client Access a web application via its private hostname without the Cloudflare One Client Access កម្មវិធីបណ្តាញតាមរយៈឈ្មោះម៉ាស៊ីនឯកជនរបស់វាដោយគ្មាន Cloudflare One Client

Với Cloudflare cách ly trình duyệt và các chính sách giải quyết, người dùng có thể kết nối với các ứng dụng dựa trên web riêng tư thông qua tên máy chủ riêng của họ.

With Cloudflare Browser Isolation and resolver policies, users can connect to private web-based applications via their private hostnames.

ជាមួយនឹង Cloudflare គោលការណ៍ញែកកម្មវិធីរុករក និងដំណោះស្រាយ អ្នកប្រើប្រាស់អាចភ្ជាប់ទៅកម្មវិធីដែលមានមូលដ្ឋានលើបណ្តាញឯកជនតាមរយៈឈ្មោះម៉ាស៊ីនឯកជនរបស់ពួកគេ។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Phát triển Cloudflare One Client trên máy Linux không đầu Deploy the Cloudflare One Client on headless Linux machines ការផ្លាស់ប្តូរអតិថិជន Cloudflare One នៅលើម៉ាស៊ីន Linux មិនមែនជា headless

Hướng dẫn này giải thích cách triển khai Cloudflare One Client trên các thiết bị Linux không có đầu bằng cách sử dụng token dịch vụ và kịch bản cài đặt.

This tutorial explains how to deploy the Cloudflare One Client on headless Linux devices using a service token and an installation script.

វគ្គបណ្តុះបណ្តាលនេះបង្ហាញពីរបៀបដំឡើងអតិថិជន Cloudflare One នៅលើឧបករណ៍ Linux ដែលមិនមានក្បាលដោយប្រើគណនីសេវាកម្មនិងគណនីដំឡើង។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Access và bảo mật cơ sở dữ liệu MySQL bằng cách sử dụng Cloudflare Tunnel và chính sách mạng Access and secure a MySQL database using Cloudflare Tunnel and network policies Access និងធានានូវមូលដ្ឋានទិន្នន័យ MySQL ដោយប្រើ Cloudflare Tunnel និងគោលការណ៍បណ្តាញ

Sử dụng mạng riêng của Cloudflare Tunnel, người dùng có thể kết nối với các ứng dụng dựa trên TCP/UDP, chẳng hạn như cơ sở dữ liệu. Bạn có thể thiết lập chính sách mạng thực hiện các điều khiển zero trust để xác định ai và những gì access có thể sử dụng các ứng dụng đó bằng cách sử dụng Cloudflare One Client.

Using Cloudflare Tunnel's private networks, users can connect to arbitrary non-browser based TCP/UDP applications, like databases. You can set up network policies that implement zero trust controls to define who and what can access those applications using the Cloudflare One Client.

ដោយប្រើបណ្តាញឯកជនរបស់ Cloudflare Tunnel អ្នកប្រើប្រាស់អាចភ្ជាប់ទៅកម្មវិធី TCP/UDP ដែលមានមូលដ្ឋានលើកម្មវិធីរុករកតាមអំពើចិត្ត ដូចជាមូលដ្ឋានទិន្នន័យជាដើម។ អ្នកអាចរៀបចំគោលការណ៍បណ្តាញដែលអនុវត្តការគ្រប់គ្រង zero trust ដើម្បីកំណត់ថាតើនរណា និងអ្វីដែលអាច access កម្មវិធីទាំងនោះដោយប្រើ Cloudflare One Client ។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម

Xem thêm ví dụ trong lộ trình → More examples in this path → More examples in this path →

Tài liệu Cloudflare Developers Cloudflare Developer docs Cloudflare Developer docs

Sơ đồ kiến trúc tham chiếu (Cloudflare Docs) Architecture diagrams (Cloudflare Docs) Architecture diagrams (Cloudflare Docs)

Hình 1: Bảo vệ dữ liệu từ thiết bị user đến website/API

Bảo vệ dữ liệu đang truyền (data in transit) Securing data in transit Securing data in transit

Bảo vệ data in transit với Gateway/DLP — inspect TLS traffic trước khi tới SaaS hoặc Internet. Data in transit is often considered vulnerable to interception or tampering during transmission. Data Loss Prevention (DLP) technologies can be used to inspect the contents of network traffic and block sensitive data from going to a risky destination. Data in transit is often considered vulnerable to interception or tampering during transmission. Data Loss Prevention (DLP) technologies can be used to inspect the contents of network traffic and block sensitive data from going to a risky destination.

Thuật ngữ: Concepts: Concepts: Gateway · DLP · TLS · CASB · Inline inspection

Sơ đồ chính thức ↗ Official diagram ↗ Official diagram ↗ · Bảo mật Security Security

Sản phẩm liên quan Related products Related products

Học xong hoặc muốn đổi hướng? Finished or want a different path? Finished or want a different path?

Ba lộ trình độc lập — mỗi lộ trình chỉ gồm bài học và tài liệu trong phạm vi đó. Chọn lộ trình khác khi sẵn sàng, không cần học song song. Three independent paths — each includes only lessons and materials for that scope. Switch when you are ready; no need to study paths in parallel. Three independent paths — each includes only lessons and materials for that scope. Switch when you are ready; no need to study paths in parallel.

Chưa chắc — làm bài chọn lộ trình Not sure — use the path selector Not sure — use the path selector · So sánh cả ba lộ trình Compare all three paths Compare all three paths