Module 5b — Chính sách Egress & kiểm soát phiên bản IP
Mục tiêu: Kiểm soát IP nguồn mà lưu lượng người dùng thoát khỏi Cloudflare (để nhà cung cấp SaaS có thể allowlist bạn), và kiểm soát phiên bản IP (IPv4/IPv6) mà Gateway dùng — bao gồm một chính sách để tắt IPv6.
|
|
| 👤 Ai làm việc này |
Đội bảo mật / mạng |
| ⏱️ Thời gian |
~30 phút |
| 🎯 Kết thúc bạn sẽ có |
Một chính sách egress chuyên dụng đưa lưu lượng đã chọn ra một IP cố định, một chính sách catch-all, và một chính sách DNS "tắt IPv6" |
| ✋ Trước khi bắt đầu |
Đã xong Module 5 (Gateway with WARP + lọc DNS). Dedicated egress IPs cần add-on Enterprise (hoặc BYOIP) — lấy chúng từ đội ngũ quản lý tài khoản của bạn. |
Đây là phần đi sâu tùy chọn, xây trên Module 5. Chính sách egress chỉ áp dụng cho lưu lượng được Gateway proxy (thiết bị ở chế độ Gateway with WARP, hoặc một network on-ramp).
"Egress" nghĩa là gì ở đây
Khi người dùng đứng sau Cloudflare truy cập một trang, trang đó thấy một IP nguồn Cloudflare, không phải IP của người dùng. Mặc định đó là dải IP dùng chung của mọi khách hàng Zero Trust. Một chính sách egress cho phép bạn đổi điều đó theo từng loại lưu lượng:
| Phương thức egress |
Đích thấy… |
Dùng cho |
| Default Cloudflare egress |
Một IP Cloudflare dùng chung (data center gần nhất) |
Duyệt web thông thường — hiệu năng tốt nhất |
| Dedicated egress IPs |
Một IP cố định thuộc về bạn (Cloudflare cấp hoặc BYOIP của bạn) |
Allowlist SaaS, truy cập đối tác/bên thứ ba yêu cầu IP nguồn đã biết |
💡 Trường hợp kinh điển: một ứng dụng SaaS (Microsoft 365, Salesforce, Workday) mà bạn muốn chỉ chấp nhận kết nối duy nhất từ tổ chức bạn. Bạn định tuyến lưu lượng đó qua một dedicated egress IP và thêm IP đó vào allowlist của nhà cung cấp SaaS.
Phần A — Lấy dedicated egress IPs của bạn
- 👉 Nhờ đội ngũ quản lý tài khoản Cloudflare bật dedicated egress IPs (một add-on Enterprise), hoặc cấu hình BYOIP (bring your own IP).
- 📋 Ghi lại địa chỉ IPv4 và dải IPv6 được gán cho tài khoản của bạn.
✅ Điểm kiểm tra: Bạn có ít nhất một địa chỉ IPv4 chuyên dụng và một dải IPv6 đã ghi lại.
⚠️ Lưu ý: Nếu tab Egress policies hoặc tùy chọn "Use dedicated egress IPs" bị làm mờ, add-on chưa được kích hoạt trên tài khoản bạn — đó là rào cản số 1 ở đây.
Phần B — Tạo chính sách egress chuyên dụng (ví dụ allowlist SaaS)
Chúng ta sẽ gửi mọi lưu lượng destined cho một nhà cung cấp SaaS ra qua IP chuyên dụng của bạn.
-
👉 Trong bảng điều khiển, vào Zero Trust → Traffic policies → Egress policies.
-
👉 Nhấp Add a policy.
-
⌨️ Policy name: Egress — Salesforce via dedicated IP.
-
👉 Xây quy tắc khớp (lưu lượng nào áp dụng):
| Selector |
Operator |
Value |
| Destination IP |
in |
các dải IP công bố của nhà cung cấp SaaS |
💡 Hoặc dùng selector Application (Beta) để khớp nhà cung cấp theo tên thay vì dải IP.
-
👉 Dưới Select an egress IP, chọn Use dedicated Cloudflare egress IPs.
-
👉 Chọn địa chỉ primary IPv4 và IPv6 của bạn từ các dropdown.
-
👉 Đặt một secondary IPv4 address (bắt buộc để có khả năng phục hồi):
0.0.0.0 → nếu data center của primary gặp sự cố, lưu lượng thoát từ vị trí gần người dùng nhất, hoặc
- một specific Cloudflare location khác với primary của bạn.
- 💡 Secondary IPv6 không bắt buộc — IPv6 có thể thoát từ bất kỳ data center Cloudflare nào.
-
👉 Nhấp Create policy.
Sau đó allowlist IP tại nhà cung cấp
- 👉 Trong bảng quản trị của nhà cung cấp SaaS, thêm dedicated egress IP(s) của bạn vào allowlist / trusted IPs, để nó chỉ chấp nhận kết nối đến từ tổ chức bạn.
💡 Thực hành tốt: ghép điều này với một chính sách HTTP (Module 5) — vd. chặn upload tới tenant cá nhân, thực thi DLP, hoặc yêu cầu device posture — để truy cập vừa từ IP của bạn vừa được kiểm tra.
Phần C — Thêm chính sách catch-all (quan trọng)
Không có catch-all, mọi lưu lượng không khớp chính sách nào sẽ cố dùng vị trí dedicated egress gần nhất, có thể gây ra IP nguồn không mong muốn. Ghim phần lưu lượng còn lại vào egress mặc định (nhanh, dùng chung).
-
👉 Egress policies → Add a policy.
-
⌨️ Policy name: Default egress policy.
-
👉 Rule:
| Selector |
Operator |
Value |
| Protocol |
in |
All options |
-
👉 Egress method: Use default Cloudflare egress method.
-
👉 Nhấp Create policy.
-
👉 Kéo chính sách này xuống tận cùng của danh sách.
⚠️ Lưu ý: Chính sách egress được đánh giá từ trên → xuống, khớp đầu tiên thắng. Giữ các chính sách cụ thể (Phần B) phía trên catch-all, nếu không mọi thứ sẽ khớp catch-all trước.
✅ Điểm kiểm tra: Danh sách egress của bạn hiện các chính sách cụ thể ở trên và Default egress policy ở dưới cùng.
Phần D — Tắt IPv6 (ép IPv4)
Một số dịch vụ upstream hoạt động kém trên IPv6, hoặc bạn có thể chỉ muốn một phiên bản IP duy nhất, dễ dự đoán. Bạn "tắt IPv6" bằng cách chặn phân giải bản ghi DNS AAAA (IPv6) với một chính sách DNS — người dùng khi đó chỉ kết nối qua IPv4.
-
👉 Trước hết xác nhận bạn đang lọc lưu lượng DNS (Module 5, Phần A) — chính sách này là một chính sách DNS.
-
👉 Vào Zero Trust → Traffic policies → DNS → Add a policy.
-
⌨️ Policy name: Disable IPv6 (Force IPv4).
-
👉 Xây quy tắc:
| Selector |
Operator |
Value |
Action |
| Query Record Type |
is |
AAAA |
Block |
-
👉 Nhấp Create policy.
-
⚠️ Quan trọng: hãy tắt Modify Gateway block behavior (trong thiết lập của chính sách / Gateway settings) để các tra cứu AAAA bị chặn fallback sạch sang IPv4 thay vì trả về trang chặn.
💡 Thu hẹp phạm vi nếu cần: thêm selector Domain để chỉ ép IPv4 cho các trang cụ thể thay vì mọi nơi.
💡 Ngược lại (ép IPv6): cùng chính sách nhưng Query Record Type is A → Block.
Xác minh
- 👉 Trên một thiết bị đã kết nối, chạy:
nslookup -type=AAAA cloudflare.com
nslookup -type=A cloudflare.com
- 👉 Hoặc truy cập
https://ipv6.google.com → nó phải không tải được trong khi các trang IPv4 bình thường vẫn hoạt động.
- 👉 Kiểm tra Logs → Gateway → DNS — bạn sẽ thấy các truy vấn
AAAA bị chặn.
✅ Điểm kiểm tra: Tra cứu AAAA bị chặn, tra cứu A hoạt động, và các trang thử nghiệm chỉ IPv6 không tải.
Phần E — Xác minh egress IP của bạn
- 👉 Trên một thiết bị được định tuyến qua chính sách dedicated-egress, truy cập một trang echo IP:
https://ifconfig.me hoặc https://www.cloudflare.com/cdn-cgi/trace/.
- 📺 IP nguồn được báo cáo phải là dedicated egress IP của bạn (với lưu lượng khớp Phần B), và dải mặc định cho mọi thứ khác.
✅ Điểm kiểm tra: Lưu lượng khớp hiện IP chuyên dụng của bạn; lưu lượng không khớp hiện egress mặc định; ứng dụng SaaS chấp nhận kết nối đã được allowlist.
✅ Hoàn thành Module 5b!
Bây giờ bạn có:
- ✅ Một chính sách egress chuyên dụng đưa lưu lượng đã chọn ra một IP cố định
- ✅ IP chuyên dụng được allowlist tại nhà cung cấp SaaS
- ✅ Một chính sách catch-all giữ mọi thứ khác nhanh trên egress mặc định
- ✅ Một chính sách DNS tắt IPv6 (ép IPv4), đã xác minh
Khắc phục nhanh
| Vấn đề |
Cách khắc phục |
| Không có tab Egress policies / tùy chọn chuyên dụng bị làm mờ |
Add-on dedicated egress chưa được kích hoạt — liên hệ đội ngũ quản lý tài khoản (Phần A) |
| Lưu lượng thoát sai IP |
Kiểm tra thứ tự chính sách — một chính sách rộng hơn hoặc catch-all phía trên đã khớp trước (Phần C) |
| Ứng dụng SaaS vẫn chặn bạn |
Xác nhận đúng dedicated IP nằm trên allowlist của nhà cung cấp, và rằng chính sách của bạn thực sự khớp đích đó |
| Chặn AAAA trả về trang chặn |
Tắt Modify Gateway block behavior (Phần D) |
| IPv6 vẫn hoạt động sau chính sách |
Đảm bảo lọc DNS đang bật và thiết bị ở chế độ Gateway with WARP; thiết bị có thể đang cache DNS — thử lại sau một lúc |
| Dedicated egress nhưng không có failover |
Đặt một secondary IPv4 (0.0.0.0 hoặc một vị trí khác) — nó bắt buộc (Phần B) |
Phát hiện và ngăn dữ liệu nhạy cảm rời khỏi tổ chức của bạn.
Module 5b — Egress Policies & IP Version Control
Goal: Control the source IP your users' traffic exits Cloudflare with (so SaaS providers can allowlist you), and control which IP version (IPv4/IPv6) Gateway uses — including a policy to disable IPv6.
|
|
| 👤 Who does this |
Security / network team |
| ⏱️ Time |
~30 minutes |
| 🎯 You'll finish with |
A dedicated egress policy sending chosen traffic out a fixed IP, a catch-all policy, and a "disable IPv6" DNS policy |
| ✋ Before you begin |
Module 5 done (Gateway with WARP + DNS filtering). Dedicated egress IPs require an Enterprise add-on (or BYOIP) — get them from your account team. |
This is an optional deep-dive that builds on Module 5. Egress policies only apply to traffic proxied by Gateway (devices in Gateway with WARP mode, or a network on-ramp).
What "egress" means here
When a user behind Cloudflare visits a site, the site sees a Cloudflare source IP, not the user's. By default that's a shared IP range used by all Zero Trust customers. An egress policy lets you change that per traffic type:
| Egress method |
The destination sees… |
Use it for |
| Default Cloudflare egress |
A shared Cloudflare IP (nearest data center) |
General browsing — best performance |
| Dedicated egress IPs |
A fixed IP that's yours (Cloudflare-assigned or your own BYOIP) |
SaaS allowlisting, partner/3rd-party access that requires a known source IP |
💡 The classic use case: a SaaS app (Microsoft 365, Salesforce, Workday) that you want to accept connections only from your organization. You route that traffic through a dedicated egress IP and add that IP to the SaaS provider's allowlist.
Part A — Get your dedicated egress IPs
- 👉 Ask your Cloudflare account team to enable dedicated egress IPs (an Enterprise add-on), or configure BYOIP (bring your own IP).
- 📋 Note the IPv4 address(es) and IPv6 range assigned to your account.
✅ Checkpoint: You have at least one dedicated IPv4 address and an IPv6 range written down.
⚠️ Watch out: If the Egress policies tab or the "Use dedicated egress IPs" option is greyed out, the add-on isn't active on your account yet — that's the #1 blocker here.
Part B — Create a dedicated egress policy (SaaS allowlisting example)
We'll send all traffic destined for a SaaS provider out through your dedicated IP.
-
👉 In the dashboard, go to Zero Trust → Traffic policies → Egress policies.
-
👉 Click Add a policy.
-
⌨️ Policy name: Egress — Salesforce via dedicated IP.
-
👉 Build the match rule (what traffic this applies to):
| Selector |
Operator |
Value |
| Destination IP |
in |
the SaaS provider's published IP ranges |
💡 Or use the Application selector (Beta) to match the provider by name instead of IP ranges.
-
👉 Under Select an egress IP, choose Use dedicated Cloudflare egress IPs.
-
👉 Choose your primary IPv4 and IPv6 addresses from the dropdowns.
-
👉 Set a secondary IPv4 address (required for resilience):
0.0.0.0 → if your primary's data center is down, traffic exits from the location closest to the user, or
- a specific Cloudflare location different from your primary.
- 💡 A secondary IPv6 is not required — IPv6 can exit from any Cloudflare data center.
-
👉 Click Create policy.
Then allowlist the IP at the provider
- 👉 In the SaaS provider's admin console, add your dedicated egress IP(s) to its allowlist / trusted IPs, so it only accepts connections coming from your organization.
💡 Best practice: pair this with an HTTP policy (Module 5) — e.g. block uploads to personal tenants, enforce DLP, or require device posture — so access is both from your IP and inspected.
Part C — Add a catch-all policy (important)
Without a catch-all, any traffic that doesn't match a policy will try to use the closest dedicated egress location, which can cause unexpected source IPs. Pin remaining traffic to the default (fast, shared) egress.
-
👉 Egress policies → Add a policy.
-
⌨️ Policy name: Default egress policy.
-
👉 Rule:
| Selector |
Operator |
Value |
| Protocol |
in |
All options |
-
👉 Egress method: Use default Cloudflare egress method.
-
👉 Click Create policy.
-
👉 Drag this policy to the very bottom of the list.
⚠️ Watch out: Egress policies evaluate top → bottom, first match wins. Keep specific policies (Part B) above the catch-all, or everything will match the catch-all first.
✅ Checkpoint: Your egress list shows specific policies on top and Default egress policy at the bottom.
Part D — Disable IPv6 (force IPv4)
Some upstream services misbehave over IPv6, or you may simply want a single, predictable IP version. You "disable IPv6" by blocking AAAA (IPv6) DNS record resolution with a DNS policy — users then connect over IPv4 only.
-
👉 First confirm you're filtering DNS traffic (Module 5, Part A) — this policy is a DNS policy.
-
👉 Go to Zero Trust → Traffic policies → DNS → Add a policy.
-
⌨️ Policy name: Disable IPv6 (Force IPv4).
-
👉 Build the rule:
| Selector |
Operator |
Value |
Action |
| Query Record Type |
is |
AAAA |
Block |
-
👉 Click Create policy.
-
⚠️ Important: turn off Modify Gateway block behavior (in the policy's settings / Gateway settings) so blocked AAAA lookups cleanly fall back to IPv4 instead of returning a block page.
💡 Scope it if needed: add a Domain selector to force IPv4 only for specific sites rather than everywhere.
💡 The reverse (force IPv6): same policy but Query Record Type is A → Block.
Verify
- 👉 On a connected device, run:
nslookup -type=AAAA cloudflare.com
nslookup -type=A cloudflare.com
- 👉 Or visit
https://ipv6.google.com → it should fail to load while normal IPv4 sites work.
- 👉 Check Logs → Gateway → DNS — you'll see the blocked
AAAA queries.
✅ Checkpoint: AAAA lookups are blocked, A lookups work, and IPv6-only test sites don't load.
Part E — Verify your egress IP
- 👉 On a device routed through the dedicated-egress policy, visit an IP-echo site:
https://ifconfig.me or https://www.cloudflare.com/cdn-cgi/trace/.
- 📺 The reported source IP should be your dedicated egress IP (for traffic that matches Part B), and the default range for everything else.
✅ Checkpoint: Matched traffic shows your dedicated IP; unmatched traffic shows the default egress; the SaaS app accepts your allowlisted connection.
✅ Module 5b complete!
You now have:
- ✅ A dedicated egress policy sending chosen traffic out a fixed IP
- ✅ The dedicated IP allowlisted at your SaaS provider
- ✅ A catch-all policy keeping everything else fast on the default egress
- ✅ A disable-IPv6 (force IPv4) DNS policy, verified
Quick troubleshooting
| Problem |
Fix |
| No Egress policies tab / dedicated option greyed out |
The dedicated egress add-on isn't active — contact your account team (Part A) |
| Traffic exits the wrong IP |
Check policy order — a broader policy or the catch-all above it matched first (Part C) |
| SaaS app still blocks you |
Confirm the exact dedicated IP is on the provider's allowlist, and that your policy actually matches that destination |
| AAAA block returns a block page |
Turn off Modify Gateway block behavior (Part D) |
| IPv6 still works after the policy |
Ensure DNS filtering is on and the device is in Gateway with WARP mode; the device may be caching DNS — retry after a moment |
| Dedicated egress but no failover |
Set a secondary IPv4 (0.0.0.0 or another location) — it's required (Part B) |
Detect and stop sensitive data from leaving your organization.
Nguồn cộng đồng — không phải tài liệu chính thức của Cloudflare: https://zerotrust.cfsase.workers.dev
Community source — not an official Cloudflare publication: https://zerotrust.cfsase.workers.dev