Lộ trình đang học Current learning path Current learning path

Cloudflare One Cloudflare One Cloudflare One

Bảo vệ users, access, SaaS và networks — follow-along từ tài khoản đến go-live. Secure users, access, SaaS, and networks — follow along from account to go-live. Secure users, access, SaaS, and networks — follow along from account to go-live.

Về trang lộ trình Track home Track home

Phần 4: ZTNA — Access và connectors Part 4: ZTNA — Access and connectors Part 4: ZTNA — Access and connectors · Bài 3/3 Lesson 3/3 មេរៀន 3/3

Chọn connector: Tunnel, Mesh hay Appliance Pick a connector: Tunnel, Mesh, or Appliance Pick a connector: Tunnel, Mesh, or Appliance

Mô-đun 4b — Kết nối mạng của bạn: Tunnel, Mesh & Appliance

Mục tiêu: Hiểu và thiết lập ba cách kết nối tài nguyên nội bộ tới Cloudflare — Cloudflare Tunnel (ứng dụng & máy chủ), Cloudflare Mesh (site-to-site và device mesh), và Cloudflare One Appliance (cả chi nhánh) — và biết khi nào dùng cái nào.

👤 Ai làm việc này Đội Network / infrastructure
⏱️ Thời gian ~45 phút
🎯 Kết thúc bạn sẽ có Một mạng riêng hoặc site được kết nối tới Cloudflare với đúng connector
✋ Trước khi bắt đầu Mô-đun 3 xong (thiết bị đã đăng ký). Với Tunnel: một máy chủ/VM tới được mạng riêng của bạn.

🧭 Ý tưởng lớn — "on-ramps". Cloudflare Zero Trust bảo vệ lưu lượng sau khi nó tới Cloudflare. Một connector là đường lên (on-ramp) đưa lưu lượng nội bộ tới đó một cách an toàn. Bạn đã gặp Cloudflare Tunnel ngắn gọn ở Mô-đun 4; mô-đun này bao phủ cả họ connector để bạn kết nối một ứng dụng, một mesh đầy đủ, hoặc cả một văn phòng.


Tôi dùng connector nào?

Connector Kết nối Chạy trên Phù hợp nhất cho
Cloudflare Tunnel (cloudflared) Một ứng dụng, máy chủ, subnet hoặc mạng riêng Daemon nhẹ trên host/VM Xuất bản ứng dụng nội bộ, SSH/RDP, kết nối VPC hoặc subnet — chỉ chiều ra, không cổng vào
Cloudflare Mesh (trước đây là WARP Connector) Thiết bị và mạng với nhau — mesh đầy đủ, kể cả client-to-client Phần mềm trên host Linux (mesh node) Site-to-site, device-to-device, thay VPN mesh / bastion host
Cloudflare One Appliance (trước đây là Magic WAN Connector) Cả một chi nhánh Appliance phần cứng hoặc ảo cắm vào mạng văn phòng Kết nối cả văn phòng/trung tâm dữ liệu — mọi thiết bị, không cần client từng máy

💡 Quy tắc nhanh: Tunnel cho ứng dụng và máy chủ, Mesh cho kết nối any-to-any giữa host và thiết bị, Appliance cho cả một site. Chúng có thể kết hợp trên cùng một mạng.

Mọi thứ bên dưới đều chạy qua Cloudflare, nên chính sách Gateway, device posture và quy tắc Access áp dụng cho mọi kết nối bất kể connector nào.


Phần A — Cloudflare Tunnel

cloudflared tạo kết nối an toàn, chỉ chiều ra từ hạ tầng của bạn tới Cloudflare — nên bạn không bao giờ mở cổng firewall vào hoặc phơi IP công cộng.

A1 — Hai kiểu quản lý

  • Remotely-managed (khuyến nghị): tạo và cấu hình tunnel trong bảng điều khiển; connector kéo cấu hình từ Cloudflare. Dễ vận hành nhất.
  • Locally-managed: bạn quản lý config.yml và credentials trên host (CLI). Kiểm soát nhiều hơn, hữu ích cho GitOps/tự động hóa.

A2 — Tạo tunnel (bảng điều khiển)

  1. 👉 Trong bảng điều khiển Cloudflare, vào Networking → Tunnels.
  2. 👉 Nhấp Create a tunnel → chọn Cloudflared → Next.
  3. ⌨️ Đặt tên theo thứ nó kết nối, ví dụ enterprise-vpc-01 → Save tunnel.
  4. 👉 Chọn operating system của máy chủ, sao chép install command, và chạy trong terminal trên máy origin.
  5. 📺 Đợi connector báo Connected / Healthy, rồi nhấp Continue.

⚠️ Kiểm tra trước: host phải tới được Cloudflare chiều ra trên cổng 7844. Nếu nó nằm sau firewall chặt, hãy cho phép cổng đó trước.

A3 — Rồi chọn thứ cần kết nối

Tùy chọn 1 — Xuất bản ứng dụng (tới được tại một hostname):

  1. 👉 Trên tab Routes của tunnel → Add route → Published application.
  2. ⌨️ Nhập subdomain + chọn một Domain (zone phải nằm trong tài khoản của bạn).
  3. ⌨️ Service URL = nơi ứng dụng chạy cục bộ, ví dụ http://localhost:8000.
  4. 👉 Save. Rồi chặn bằng một Access application (Mô-đun 4) để chỉ đúng người vào được.

Tùy chọn 2 — Kết nối mạng riêng (tới bằng IP qua WARP):

  1. 👉 Networking → Routes → Create route → Tunnel CIDR.
  2. 👉 Chọn tunnel của bạn, nhập dải riêng (ví dụ 10.0.0.0/24).
  3. 👉 (Tùy chọn) chọn một virtual network nếu dải này chồng một route khác trong tài khoản.
  4. 👉 Create route. Người dùng trên Cloudflare One Client nay tới được các IP đó (thêm chính sách mạng Gateway để kiểm soát truy cập).

A4 — High availability

Chạy nhiều bản sao cloudflared (host khác nhau, cùng tunnel) để dự phòng; có hướng dẫn triển khai cho Docker và Kubernetes.

✅ Điểm kiểm tra: tunnel hiện Healthy; bạn tới được hostname của ứng dụng đã xuất bản, hoặc ping/tới được IP riêng qua WARP.

🔧 Nếu chưa được: connector không Healthy → kiểm tra chiều ra 7844; route ứng dụng 502 → sai Service URL/port; IP riêng không tới được → thiếu route Tunnel CIDR hoặc dải chồng (dùng virtual network).


Phần B — Cloudflare Mesh (trước đây là WARP Connector)

📖 Tên gọi: WARP Connector nay gọi là Cloudflare Mesh (đổi tên 2026). Các WARP Connector hiện có nay là mesh nodes — không cần migrate.

Cloudflare Mesh tạo mạng riêng, mã hóa hậu lượng tử (post-quantum-encrypted) trên máy chủ, thiết bị và site của bạn. Thay vì phơi từng ứng dụng, mỗi bên tham gia nhận một Mesh IP riêng và có thể tới bất kỳ bên tham gia nào khác bằng IP — kể cả client-to-client — không cần bastion host hay VPN concentrator.

Mesh mang lại gì

  • Một Mesh IP riêng cho mọi thiết bị đã đăng ký và mesh node.
  • Khả năng tới any-to-any bằng IP (thiết bị↔thiết bị, thiết bị↔mạng, mạng↔mạng).
  • CIDR routes để tới cả subnet phía sau một mesh node.
  • High availability qua replica node active-passive cho các subnet được định tuyến.
  • Mọi kết nối vẫn chảy qua Cloudflare, nên chính sách mạng Gateway + device posture + quy tắc Access đều áp dụng.
  • Tối đa 50 mesh nodes mỗi tài khoản.

B1 — Thiết lập mesh node

  1. 👉 Trong bảng điều khiển, vào Networking → Mesh và bắt đầu setup wizard (bản đồ mạng tương tác, quản lý node, chẩn đoán).
  2. 👉 Thêm một mesh node và làm theo wizard để cài phần mềm connector trên một Linux host trong mạng bạn muốn nối vào mesh.
  3. ⌨️ (Tùy chọn) thêm CIDR routes trên node để các subnet phía sau nó (ví dụ 192.168.20.0/24) tới được xuyên mesh.
  4. 👉 Với subnet được định tuyến phải luôn online, thêm node active-passive replica cho high availability.

B2 — Xác minh

  • 👉 Sau khi cài, ping LAN IP của chính mesh node — nó trả lời trực tiếp, cho bạn kiểm tra khả năng tới nhanh trước khi thử dịch vụ phía sau.
  • 👉 Trên thiết bị đã đăng ký (Cloudflare One Client đã kết nối), tới một bên tham gia khác bằng Mesh IP của nó.

✅ Điểm kiểm tra: node xuất hiện trên bản đồ mạng Mesh; bạn ping được node và tới được thiết bị/subnet xuyên mesh.

💡 Mesh so với Tunnel: Tunnel là một chiều (đưa ứng dụng/subnet tới Cloudflare và người dùng tới nó). Mesh là hai chiều và any-to-any — lý tưởng để nối các site với nhau và cho phép lưu lượng device-to-device.


Phần C — Cloudflare One Appliance (trước đây là Magic WAN Connector)

Khi bạn muốn kết nối cả một văn phòng hoặc trung tâm dữ liệu — mọi thiết bị trên LAN, không cần phần mềm từng máy — dùng Cloudflare One Appliance (phần cứng hoặc ảo). Đây là on-ramp chi nhánh cho Cloudflare WAN.

Nó làm gì

  • Cắm vào mạng chi nhánh và kết nối cả site tới Cloudflare qua các tunnel được xây tự động.
  • Bootstrap qua DHCP (cắm là chạy) hoặc static IP bằng serial console.
  • Nhiều WAN ports với kiểm soát breakout traffic — ví dụ ghim ứng dụng nhạy độ trễ (Zoom, Teams) vào uplink nhanh nhất, với failover tự động nếu cổng đó xuống.
  • DHCP server có sẵn cho chi nhánh (với máy chủ DNS dự phòng).
  • Tự động tạo tới hai tunnel mỗi cổng WAN khi bạn có hơn một anycast IP — để tin cậy, không cần cấu hình thêm.

C1 — Nhìn nhanh

  1. 👉 Đặt hàng/triển khai hardware appliance, hoặc triển khai virtual appliance trong hypervisor/cloud của bạn.
  2. 👉 Cắm cáp cổng WAN (Internet) và LAN (mạng của bạn); bật nguồn.
  3. 👉 Nó bootstraps (DHCP theo mặc định; static IP qua serial console nếu cần) và đăng ký vào tài khoản của bạn.
  4. 👉 Cấu hình subnet LAN, DHCP và chính sách WAN/breakout trong bảng điều khiển.

📘 Appliance là một phần của Cloudflare WAN — kết nối cả site, định tuyến, dự phòng (hai appliance), và Magic Firewall được đề cập trong Mô-đun 8 — Cloudflare WAN. Phần này là tổng quan họ connector; làm Mô-đun 8 cho triển khai chi nhánh đầy đủ.

✅ Điểm kiểm tra: appliance hiện healthy trong bảng điều khiển và thiết bị chi nhánh tới Internet/tài nguyên nội bộ qua Cloudflare.


Phần D — Ghép lại với nhau

Doanh nghiệp điển hình dùng nhiều hơn một connector:

  Internal web app / SSH  ──── Cloudflare Tunnel ────┐
  Linux servers + laptops ──── Cloudflare Mesh ──────┼──►  CLOUDFLARE  ──►  Zero Trust
  Whole branch office     ──── Cloudflare One Appliance┘   (Identity · Access · Gateway · DLP)
  • Xuất bản ứng dụng / tới một subnet → Cloudflare Tunnel (Phần A)
  • Kết nối host và thiết bị any-to-any → Cloudflare Mesh (Phần B)
  • Đưa cả một site lên mạng → Cloudflare One Appliance / Cloudflare WAN (Phần C → Mô-đun 8)

Dù bạn chọn cái nào, lưu lượng hạ cánh tại Cloudflare và chính sách Access, Gateway, DLP và posture áp dụng thống nhất.


✅ Mô-đun 4b hoàn tất!

Bạn hiện hiểu:

  • ✅ Cloudflare Tunnel — connector chỉ chiều ra cho ứng dụng, máy chủ và subnet
  • ✅ Cloudflare Mesh — mạng riêng any-to-any (trước đây là WARP Connector)
  • ✅ Cloudflare One Appliance — on-ramp cả site cho Cloudflare WAN
  • ✅ Connector nào khớp tình huống nào

Tham chiếu nhanh

Nhu cầu Connector Ở đâu
Xuất bản một ứng dụng web nội bộ Tunnel → Published application Networking → Tunnels
Tới subnet riêng bằng IP Tunnel → Tunnel CIDR route Networking → Routes
Site-to-site + device-to-device Cloudflare Mesh Networking → Mesh
Kết nối cả một văn phòng chi nhánh Cloudflare One Appliance Cloudflare WAN (Mô-đun 8)

👉 Tiếp theo: Mô-đun 5 — Gateway (Web Filtering)

Chặn mối đe dọa và lọc lưu lượng DNS/web cho mọi thứ nay đã kết nối.

Module 4b — Connecting Your Networks: Tunnel, Mesh & Appliance

Goal: Understand and set up the three ways to connect your private resources to Cloudflare — Cloudflare Tunnel (apps & servers), Cloudflare Mesh (site-to-site and device mesh), and the Cloudflare One Appliance (whole branch sites) — and know which to use when.

👤 Who does this Network / infrastructure team
⏱️ Time ~45 minutes
🎯 You'll finish with A private network or site connected to Cloudflare with the right connector
✋ Before you begin Module 3 done (devices enrolled). For Tunnel: a server/VM that can reach your private network.

🧭 Big idea — "on-ramps". Cloudflare Zero Trust protects traffic after it reaches Cloudflare. A connector is the on-ramp that gets your private traffic there safely. You met Cloudflare Tunnel briefly in Module 4; this module covers the full connector family so you can connect a single app, a full mesh, or an entire office.


Which connector do I use?

Connector Connects Runs on Best for
Cloudflare Tunnel (cloudflared) A single app, server, subnet, or private network A lightweight daemon on a host/VM Publishing internal apps, SSH/RDP, connecting a VPC or subnet — outbound-only, no inbound ports
Cloudflare Mesh (was WARP Connector) Devices and networks to each other — full mesh, incl. client-to-client Software on a Linux host (mesh node) Site-to-site, device-to-device, replacing VPN mesh / bastion hosts
Cloudflare One Appliance (was Magic WAN Connector) An entire branch site A hardware or virtual appliance plugged into the office network Connecting a whole office/data center — all devices, no per-device client

💡 Rule of thumb: Tunnel for apps and servers, Mesh for any-to-any connectivity between hosts and devices, Appliance for a whole site. They can be combined across a network.

Everything below runs through Cloudflare, so your Gateway policies, device posture, and Access rules apply to every connection regardless of connector.


Part A — Cloudflare Tunnel

cloudflared makes a secure, outbound-only connection from your infrastructure to Cloudflare — so you never open an inbound firewall port or expose a public IP.

A1 — Two management styles

  • Remotely-managed (recommended): create and configure the tunnel in the dashboard; the connector pulls its config from Cloudflare. Easiest to operate.
  • Locally-managed: you manage a config.yml and credentials on the host (CLI). More control, useful for GitOps/automation.

A2 — Create a tunnel (dashboard)

  1. 👉 In the Cloudflare dashboard, go to Networking → Tunnels.
  2. 👉 Click Create a tunnel → choose Cloudflared → Next.
  3. ⌨️ Name it after what it connects, e.g. enterprise-vpc-01 → Save tunnel.
  4. 👉 Choose your server's operating system, copy the install command, and run it in a terminal on your origin server.
  5. 📺 Wait for the connector to report Connected / Healthy, then click Continue.

⚠️ Pre-check: the host must be able to reach Cloudflare outbound on port 7844. If it's behind a strict firewall, allow that first.

A3 — Then pick what to connect

Option 1 — Publish an application (reachable at a hostname):

  1. 👉 On the tunnel's Routes tab → Add route → Published application.
  2. ⌨️ Enter a subdomain + pick a Domain (the zone must be in your account).
  3. ⌨️ Service URL = where the app runs locally, e.g. http://localhost:8000.
  4. 👉 Save. Then gate it with an Access application (Module 4) so only the right people get in.

Option 2 — Connect a private network (reach it by IP through WARP):

  1. 👉 Networking → Routes → Create route → Tunnel CIDR.
  2. 👉 Select your tunnel, enter the private range (e.g. 10.0.0.0/24).
  3. 👉 (Optional) pick a virtual network if this range overlaps another route in your account.
  4. 👉 Create route. Users on the Cloudflare One Client can now reach those IPs (add Gateway network policies to control access).

A4 — High availability

Run multiple cloudflared replicas (different hosts, same tunnel) for redundancy; there are deployment guides for Docker and Kubernetes.

✅ Checkpoint: the tunnel shows Healthy; you can reach the published app's hostname, or ping/reach a private IP through WARP.

🔧 If it didn't work: connector not Healthy → check outbound 7844; app route 502 → wrong Service URL/port; private IP unreachable → missing Tunnel CIDR route or overlapping range (use a virtual network).


Part B — Cloudflare Mesh (formerly WARP Connector)

📖 Naming: WARP Connector is now called Cloudflare Mesh (renamed 2026). Existing WARP Connectors are now mesh nodes — nothing to migrate.

Cloudflare Mesh creates a private, post-quantum-encrypted network across your servers, devices, and sites. Instead of exposing apps one at a time, every participant gets a private Mesh IP and can reach any other participant by IP — including client-to-client — with no bastion hosts or VPN concentrators.

What Mesh gives you

  • A private Mesh IP for every enrolled device and mesh node.
  • Any-to-any reachability by IP (device↔device, device↔network, network↔network).
  • CIDR routes to reach whole subnets behind a mesh node.
  • High availability via active-passive replica nodes for routed subnets.
  • Every connection still flows through Cloudflare, so Gateway network policies + device posture + Access rules all apply.
  • Up to 50 mesh nodes per account.

B1 — Set up a mesh node

  1. 👉 In the dashboard, go to Networking → Mesh and start the setup wizard (interactive network map, node management, diagnostics).
  2. 👉 Add a mesh node and follow the wizard to install the connector software on a Linux host in the network you want to join to the mesh.
  3. ⌨️ (Optional) add CIDR routes on the node so the subnets behind it (e.g. 192.168.20.0/24) are reachable across the mesh.
  4. 👉 For a routed subnet that must stay online, add an active-passive replica node for high availability.

B2 — Verify

  • 👉 After install, ping the mesh node's own LAN IP — it responds directly, giving you a fast reachability check before testing downstream services.
  • 👉 On an enrolled device (Cloudflare One Client connected), reach another participant by its Mesh IP.

✅ Checkpoint: the node appears on the Mesh network map; you can ping the node and reach a device/subnet across the mesh.

💡 Mesh vs Tunnel: Tunnel is one-directional (bring an app/subnet to Cloudflare and users reach it). Mesh is bidirectional and any-to-any — ideal for connecting sites to each other and enabling device-to-device traffic.


Part C — Cloudflare One Appliance (formerly Magic WAN Connector)

When you want to connect an entire office or data center — every device on the LAN, with no per-device software — use the Cloudflare One Appliance (hardware or virtual). It's the branch on-ramp for Cloudflare WAN.

What it does

  • Plugs into your branch network and connects the whole site to Cloudflare over automatically-built tunnels.
  • Bootstrap via DHCP (plug-and-play) or a static IP using the serial console.
  • Multiple WAN ports with breakout traffic control — e.g. pin latency-sensitive apps (Zoom, Teams) to your fastest uplink, with automatic failover if that port goes down.
  • Built-in DHCP server for the branch (with redundant DNS servers).
  • Automatically creates up to two tunnels per WAN port when you have more than one anycast IP — for reliability, no extra config.

C1 — At a glance

  1. 👉 Order/deploy the hardware appliance, or deploy the virtual appliance in your hypervisor/cloud.
  2. 👉 Cable WAN (Internet) and LAN (your network) ports; power on.
  3. 👉 It bootstraps (DHCP by default; static IP via serial console if needed) and registers to your account.
  4. 👉 Configure LAN subnets, DHCP, and WAN/breakout policy in the dashboard.

📘 The Appliance is part of Cloudflare WAN — full site connectivity, routing, redundancy (dual appliances), and Magic Firewall are covered in Module 8 — Cloudflare WAN. This section is the connector-family overview; do Module 8 for the complete branch rollout.

✅ Checkpoint: the appliance shows healthy in the dashboard and branch devices reach the Internet/private resources through Cloudflare.


Part D — Putting it together

A typical enterprise uses more than one connector:

  Internal web app / SSH  ──── Cloudflare Tunnel ────┐
  Linux servers + laptops ──── Cloudflare Mesh ──────┼──►  CLOUDFLARE  ──►  Zero Trust
  Whole branch office     ──── Cloudflare One Appliance┘   (Identity · Access · Gateway · DLP)
  • Publish an app / reach a subnet → Cloudflare Tunnel (Part A)
  • Connect hosts and devices any-to-any → Cloudflare Mesh (Part B)
  • Bring a whole site online → Cloudflare One Appliance / Cloudflare WAN (Part C → Module 8)

Whichever you choose, traffic lands in Cloudflare and your Access, Gateway, DLP, and posture policies apply uniformly.


✅ Module 4b complete!

You now understand:

  • ✅ Cloudflare Tunnel — outbound-only connector for apps, servers, and subnets
  • ✅ Cloudflare Mesh — any-to-any private networking (formerly WARP Connector)
  • ✅ Cloudflare One Appliance — whole-site on-ramp for Cloudflare WAN
  • ✅ Which connector fits which scenario

Quick reference

Need Connector Where
Publish one internal web app Tunnel → Published application Networking → Tunnels
Reach a private subnet by IP Tunnel → Tunnel CIDR route Networking → Routes
Site-to-site + device-to-device Cloudflare Mesh Networking → Mesh
Connect an entire branch office Cloudflare One Appliance Cloudflare WAN (Module 8)

👉 Next: Module 5 — Gateway (Web Filtering)

Block threats and filter DNS/web traffic for everything now connected.

Nguồn cộng đồng — không phải tài liệu chính thức của Cloudflare: https://zerotrust.cfsase.workers.dev Community source — not an official Cloudflare publication: https://zerotrust.cfsase.workers.dev

Ví dụ triển khai (Cloudflare Resources) Deployment examples (Cloudflare Resources) Deployment examples (Cloudflare Resources)

Ví dụ chính thức từ Cloudflare Resources — gợi ý theo chủ đề bài học trong lộ trình này. Official examples from Cloudflare Resources — matched to this lesson within this path. Official examples from Cloudflare Resources — matched to this lesson within this path.

Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Access một ứng dụng web thông qua tên máy chủ riêng của nó mà không có Cloudflare One Client Access a web application via its private hostname without the Cloudflare One Client Access កម្មវិធីបណ្តាញតាមរយៈឈ្មោះម៉ាស៊ីនឯកជនរបស់វាដោយគ្មាន Cloudflare One Client

Với Cloudflare cách ly trình duyệt và các chính sách giải quyết, người dùng có thể kết nối với các ứng dụng dựa trên web riêng tư thông qua tên máy chủ riêng của họ.

With Cloudflare Browser Isolation and resolver policies, users can connect to private web-based applications via their private hostnames.

ជាមួយនឹង Cloudflare គោលការណ៍ញែកកម្មវិធីរុករក និងដំណោះស្រាយ អ្នកប្រើប្រាស់អាចភ្ជាប់ទៅកម្មវិធីដែលមានមូលដ្ឋានលើបណ្តាញឯកជនតាមរយៈឈ្មោះម៉ាស៊ីនឯកជនរបស់ពួកគេ។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Access và bảo mật cơ sở dữ liệu MySQL bằng cách sử dụng Cloudflare Tunnel và chính sách mạng Access and secure a MySQL database using Cloudflare Tunnel and network policies Access និងធានានូវមូលដ្ឋានទិន្នន័យ MySQL ដោយប្រើ Cloudflare Tunnel និងគោលការណ៍បណ្តាញ

Sử dụng mạng riêng của Cloudflare Tunnel, người dùng có thể kết nối với các ứng dụng dựa trên TCP/UDP, chẳng hạn như cơ sở dữ liệu. Bạn có thể thiết lập chính sách mạng thực hiện các điều khiển zero trust để xác định ai và những gì access có thể sử dụng các ứng dụng đó bằng cách sử dụng Cloudflare One Client.

Using Cloudflare Tunnel's private networks, users can connect to arbitrary non-browser based TCP/UDP applications, like databases. You can set up network policies that implement zero trust controls to define who and what can access those applications using the Cloudflare One Client.

ដោយប្រើបណ្តាញឯកជនរបស់ Cloudflare Tunnel អ្នកប្រើប្រាស់អាចភ្ជាប់ទៅកម្មវិធី TCP/UDP ដែលមានមូលដ្ឋានលើកម្មវិធីរុករកតាមអំពើចិត្ត ដូចជាមូលដ្ឋានទិន្នន័យជាដើម។ អ្នកអាចរៀបចំគោលការណ៍បណ្តាញដែលអនុវត្តការគ្រប់គ្រង zero trust ដើម្បីកំណត់ថាតើនរណា និងអ្វីដែលអាច access កម្មវិធីទាំងនោះដោយប្រើ Cloudflare One Client ។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Tạo API thành access D1 bằng cách sử dụng Proxy Worker Build an API to access D1 using a proxy Worker បង្កើត API ទៅ access D1 ដោយប្រើប្រូកស៊ីកម្មករ

Hướng dẫn này cho thấy cách tạo một API cho phép bạn chạy truy vấn an toàn chống lại một cơ sở dữ liệu D1. API có thể được sử dụng để tùy chỉnh các điều khiển access và/hoặc giới hạn các bảng có thể được truy vấn.

This tutorial shows how to create an API that allows you to securely run queries against a D1 database. The API can be used to customize access controls and/or limit what tables can be queried.

ការបង្រៀននេះបង្ហាញពីរបៀបបង្កើត API ដែលអនុញ្ញាតឱ្យអ្នកដំណើរការសំណួរដោយសុវត្ថិភាពប្រឆាំងនឹងមូលដ្ឋានទិន្នន័យ D1 ។ API អាចត្រូវបានប្រើដើម្បីប្ដូរតាមបំណង access គ្រប់គ្រង និង/ឬកំណត់តារាងដែលអាចសួរបាន។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Kết nối thông qua Cloudflare Access bằng cách sử dụng CLI Connect through Cloudflare Access using a CLI ការភ្ជាប់តាម Cloudflare Access ដោយប្រើ CLI

Công cụ dòng lệnh đám mây của Cloudflare cho phép bạn tương tác với các điểm cuối được bảo vệ bởi Cloudflare Access.

Cloudflare's cloudflared command-line tool allows you to interact with endpoints protected by Cloudflare Access.

Cloudflare ឧបករណ៍បន្ទាត់បញ្ជាទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យ

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម

Xem thêm ví dụ trong lộ trình → More examples in this path → More examples in this path →

Tài liệu Cloudflare Developers Cloudflare Developer docs Cloudflare Developer docs

Sản phẩm liên quan Related products Related products

Học xong hoặc muốn đổi hướng? Finished or want a different path? Finished or want a different path?

Ba lộ trình độc lập — mỗi lộ trình chỉ gồm bài học và tài liệu trong phạm vi đó. Chọn lộ trình khác khi sẵn sàng, không cần học song song. Three independent paths — each includes only lessons and materials for that scope. Switch when you are ready; no need to study paths in parallel. Three independent paths — each includes only lessons and materials for that scope. Switch when you are ready; no need to study paths in parallel.

Chưa chắc — làm bài chọn lộ trình Not sure — use the path selector Not sure — use the path selector · So sánh cả ba lộ trình Compare all three paths Compare all three paths