Lộ trình đang học Current learning path Current learning path

Cloudflare One Cloudflare One Cloudflare One

Bảo vệ users, access, SaaS và networks — follow-along từ tài khoản đến go-live. Secure users, access, SaaS, and networks — follow along from account to go-live. Secure users, access, SaaS, and networks — follow along from account to go-live.

Về trang lộ trình Track home Track home

Phần 5: Gateway — lọc web và Shadow IT Part 5: Gateway — web filtering and Shadow IT Part 5: Gateway — web filtering and Shadow IT · Bài 2/4 Lesson 2/4 មេរៀន 2/4

Egress policies và phiên bản IP Egress policies and IP version Egress policies and IP version

Module 5b — Chính sách Egress & kiểm soát phiên bản IP

Mục tiêu: Kiểm soát IP nguồn mà lưu lượng người dùng thoát khỏi Cloudflare (để nhà cung cấp SaaS có thể allowlist bạn), và kiểm soát phiên bản IP (IPv4/IPv6) mà Gateway dùng — bao gồm một chính sách để tắt IPv6.

👤 Ai làm việc này Đội bảo mật / mạng
⏱️ Thời gian ~30 phút
🎯 Kết thúc bạn sẽ có Một chính sách egress chuyên dụng đưa lưu lượng đã chọn ra một IP cố định, một chính sách catch-all, và một chính sách DNS "tắt IPv6"
✋ Trước khi bắt đầu Đã xong Module 5 (Gateway with WARP + lọc DNS). Dedicated egress IPs cần add-on Enterprise (hoặc BYOIP) — lấy chúng từ đội ngũ quản lý tài khoản của bạn.

Đây là phần đi sâu tùy chọn, xây trên Module 5. Chính sách egress chỉ áp dụng cho lưu lượng được Gateway proxy (thiết bị ở chế độ Gateway with WARP, hoặc một network on-ramp).


"Egress" nghĩa là gì ở đây

Khi người dùng đứng sau Cloudflare truy cập một trang, trang đó thấy một IP nguồn Cloudflare, không phải IP của người dùng. Mặc định đó là dải IP dùng chung của mọi khách hàng Zero Trust. Một chính sách egress cho phép bạn đổi điều đó theo từng loại lưu lượng:

Phương thức egress Đích thấy… Dùng cho
Default Cloudflare egress Một IP Cloudflare dùng chung (data center gần nhất) Duyệt web thông thường — hiệu năng tốt nhất
Dedicated egress IPs Một IP cố định thuộc về bạn (Cloudflare cấp hoặc BYOIP của bạn) Allowlist SaaS, truy cập đối tác/bên thứ ba yêu cầu IP nguồn đã biết

💡 Trường hợp kinh điển: một ứng dụng SaaS (Microsoft 365, Salesforce, Workday) mà bạn muốn chỉ chấp nhận kết nối duy nhất từ tổ chức bạn. Bạn định tuyến lưu lượng đó qua một dedicated egress IP và thêm IP đó vào allowlist của nhà cung cấp SaaS.


Phần A — Lấy dedicated egress IPs của bạn

  1. 👉 Nhờ đội ngũ quản lý tài khoản Cloudflare bật dedicated egress IPs (một add-on Enterprise), hoặc cấu hình BYOIP (bring your own IP).
  2. 📋 Ghi lại địa chỉ IPv4 và dải IPv6 được gán cho tài khoản của bạn.

✅ Điểm kiểm tra: Bạn có ít nhất một địa chỉ IPv4 chuyên dụng và một dải IPv6 đã ghi lại.

⚠️ Lưu ý: Nếu tab Egress policies hoặc tùy chọn "Use dedicated egress IPs" bị làm mờ, add-on chưa được kích hoạt trên tài khoản bạn — đó là rào cản số 1 ở đây.


Phần B — Tạo chính sách egress chuyên dụng (ví dụ allowlist SaaS)

Chúng ta sẽ gửi mọi lưu lượng destined cho một nhà cung cấp SaaS ra qua IP chuyên dụng của bạn.

  1. 👉 Trong bảng điều khiển, vào Zero Trust → Traffic policies → Egress policies.

  2. 👉 Nhấp Add a policy.

  3. ⌨️ Policy name: Egress — Salesforce via dedicated IP.

  4. 👉 Xây quy tắc khớp (lưu lượng nào áp dụng):

    Selector Operator Value
    Destination IP in các dải IP công bố của nhà cung cấp SaaS

    💡 Hoặc dùng selector Application (Beta) để khớp nhà cung cấp theo tên thay vì dải IP.

  5. 👉 Dưới Select an egress IP, chọn Use dedicated Cloudflare egress IPs.

  6. 👉 Chọn địa chỉ primary IPv4 và IPv6 của bạn từ các dropdown.

  7. 👉 Đặt một secondary IPv4 address (bắt buộc để có khả năng phục hồi):

    • 0.0.0.0 → nếu data center của primary gặp sự cố, lưu lượng thoát từ vị trí gần người dùng nhất, hoặc
    • một specific Cloudflare location khác với primary của bạn.
    • 💡 Secondary IPv6 không bắt buộc — IPv6 có thể thoát từ bất kỳ data center Cloudflare nào.
  8. 👉 Nhấp Create policy.

Sau đó allowlist IP tại nhà cung cấp

  1. 👉 Trong bảng quản trị của nhà cung cấp SaaS, thêm dedicated egress IP(s) của bạn vào allowlist / trusted IPs, để nó chỉ chấp nhận kết nối đến từ tổ chức bạn.

💡 Thực hành tốt: ghép điều này với một chính sách HTTP (Module 5) — vd. chặn upload tới tenant cá nhân, thực thi DLP, hoặc yêu cầu device posture — để truy cập vừa từ IP của bạn vừa được kiểm tra.


Phần C — Thêm chính sách catch-all (quan trọng)

Không có catch-all, mọi lưu lượng không khớp chính sách nào sẽ cố dùng vị trí dedicated egress gần nhất, có thể gây ra IP nguồn không mong muốn. Ghim phần lưu lượng còn lại vào egress mặc định (nhanh, dùng chung).

  1. 👉 Egress policies → Add a policy.

  2. ⌨️ Policy name: Default egress policy.

  3. 👉 Rule:

    Selector Operator Value
    Protocol in All options
  4. 👉 Egress method: Use default Cloudflare egress method.

  5. 👉 Nhấp Create policy.

  6. 👉 Kéo chính sách này xuống tận cùng của danh sách.

⚠️ Lưu ý: Chính sách egress được đánh giá từ trên → xuống, khớp đầu tiên thắng. Giữ các chính sách cụ thể (Phần B) phía trên catch-all, nếu không mọi thứ sẽ khớp catch-all trước.

✅ Điểm kiểm tra: Danh sách egress của bạn hiện các chính sách cụ thể ở trên và Default egress policy ở dưới cùng.


Phần D — Tắt IPv6 (ép IPv4)

Một số dịch vụ upstream hoạt động kém trên IPv6, hoặc bạn có thể chỉ muốn một phiên bản IP duy nhất, dễ dự đoán. Bạn "tắt IPv6" bằng cách chặn phân giải bản ghi DNS AAAA (IPv6) với một chính sách DNS — người dùng khi đó chỉ kết nối qua IPv4.

  1. 👉 Trước hết xác nhận bạn đang lọc lưu lượng DNS (Module 5, Phần A) — chính sách này là một chính sách DNS.

  2. 👉 Vào Zero Trust → Traffic policies → DNS → Add a policy.

  3. ⌨️ Policy name: Disable IPv6 (Force IPv4).

  4. 👉 Xây quy tắc:

    Selector Operator Value Action
    Query Record Type is AAAA Block
  5. 👉 Nhấp Create policy.

  6. ⚠️ Quan trọng: hãy tắt Modify Gateway block behavior (trong thiết lập của chính sách / Gateway settings) để các tra cứu AAAA bị chặn fallback sạch sang IPv4 thay vì trả về trang chặn.

💡 Thu hẹp phạm vi nếu cần: thêm selector Domain để chỉ ép IPv4 cho các trang cụ thể thay vì mọi nơi. 💡 Ngược lại (ép IPv6): cùng chính sách nhưng Query Record Type is A → Block.

Xác minh

  1. 👉 Trên một thiết bị đã kết nối, chạy:
    nslookup -type=AAAA cloudflare.com     # should return no IPv6 address (blocked)
    nslookup -type=A cloudflare.com        # should still resolve normally
    
  2. 👉 Hoặc truy cập https://ipv6.google.com → nó phải không tải được trong khi các trang IPv4 bình thường vẫn hoạt động.
  3. 👉 Kiểm tra Logs → Gateway → DNS — bạn sẽ thấy các truy vấn AAAA bị chặn.

✅ Điểm kiểm tra: Tra cứu AAAA bị chặn, tra cứu A hoạt động, và các trang thử nghiệm chỉ IPv6 không tải.


Phần E — Xác minh egress IP của bạn

  1. 👉 Trên một thiết bị được định tuyến qua chính sách dedicated-egress, truy cập một trang echo IP: https://ifconfig.me hoặc https://www.cloudflare.com/cdn-cgi/trace/.
  2. 📺 IP nguồn được báo cáo phải là dedicated egress IP của bạn (với lưu lượng khớp Phần B), và dải mặc định cho mọi thứ khác.

✅ Điểm kiểm tra: Lưu lượng khớp hiện IP chuyên dụng của bạn; lưu lượng không khớp hiện egress mặc định; ứng dụng SaaS chấp nhận kết nối đã được allowlist.


✅ Hoàn thành Module 5b!

Bây giờ bạn có:

  • ✅ Một chính sách egress chuyên dụng đưa lưu lượng đã chọn ra một IP cố định
  • ✅ IP chuyên dụng được allowlist tại nhà cung cấp SaaS
  • ✅ Một chính sách catch-all giữ mọi thứ khác nhanh trên egress mặc định
  • ✅ Một chính sách DNS tắt IPv6 (ép IPv4), đã xác minh

Khắc phục nhanh

Vấn đề Cách khắc phục
Không có tab Egress policies / tùy chọn chuyên dụng bị làm mờ Add-on dedicated egress chưa được kích hoạt — liên hệ đội ngũ quản lý tài khoản (Phần A)
Lưu lượng thoát sai IP Kiểm tra thứ tự chính sách — một chính sách rộng hơn hoặc catch-all phía trên đã khớp trước (Phần C)
Ứng dụng SaaS vẫn chặn bạn Xác nhận đúng dedicated IP nằm trên allowlist của nhà cung cấp, và rằng chính sách của bạn thực sự khớp đích đó
Chặn AAAA trả về trang chặn Tắt Modify Gateway block behavior (Phần D)
IPv6 vẫn hoạt động sau chính sách Đảm bảo lọc DNS đang bật và thiết bị ở chế độ Gateway with WARP; thiết bị có thể đang cache DNS — thử lại sau một lúc
Dedicated egress nhưng không có failover Đặt một secondary IPv4 (0.0.0.0 hoặc một vị trí khác) — nó bắt buộc (Phần B)

👉 Tiếp theo: Module 6 — DLP

Phát hiện và ngăn dữ liệu nhạy cảm rời khỏi tổ chức của bạn.

Module 5b — Egress Policies & IP Version Control

Goal: Control the source IP your users' traffic exits Cloudflare with (so SaaS providers can allowlist you), and control which IP version (IPv4/IPv6) Gateway uses — including a policy to disable IPv6.

👤 Who does this Security / network team
⏱️ Time ~30 minutes
🎯 You'll finish with A dedicated egress policy sending chosen traffic out a fixed IP, a catch-all policy, and a "disable IPv6" DNS policy
✋ Before you begin Module 5 done (Gateway with WARP + DNS filtering). Dedicated egress IPs require an Enterprise add-on (or BYOIP) — get them from your account team.

This is an optional deep-dive that builds on Module 5. Egress policies only apply to traffic proxied by Gateway (devices in Gateway with WARP mode, or a network on-ramp).


What "egress" means here

When a user behind Cloudflare visits a site, the site sees a Cloudflare source IP, not the user's. By default that's a shared IP range used by all Zero Trust customers. An egress policy lets you change that per traffic type:

Egress method The destination sees… Use it for
Default Cloudflare egress A shared Cloudflare IP (nearest data center) General browsing — best performance
Dedicated egress IPs A fixed IP that's yours (Cloudflare-assigned or your own BYOIP) SaaS allowlisting, partner/3rd-party access that requires a known source IP

💡 The classic use case: a SaaS app (Microsoft 365, Salesforce, Workday) that you want to accept connections only from your organization. You route that traffic through a dedicated egress IP and add that IP to the SaaS provider's allowlist.


Part A — Get your dedicated egress IPs

  1. 👉 Ask your Cloudflare account team to enable dedicated egress IPs (an Enterprise add-on), or configure BYOIP (bring your own IP).
  2. 📋 Note the IPv4 address(es) and IPv6 range assigned to your account.

✅ Checkpoint: You have at least one dedicated IPv4 address and an IPv6 range written down.

⚠️ Watch out: If the Egress policies tab or the "Use dedicated egress IPs" option is greyed out, the add-on isn't active on your account yet — that's the #1 blocker here.


Part B — Create a dedicated egress policy (SaaS allowlisting example)

We'll send all traffic destined for a SaaS provider out through your dedicated IP.

  1. 👉 In the dashboard, go to Zero Trust → Traffic policies → Egress policies.

  2. 👉 Click Add a policy.

  3. ⌨️ Policy name: Egress — Salesforce via dedicated IP.

  4. 👉 Build the match rule (what traffic this applies to):

    Selector Operator Value
    Destination IP in the SaaS provider's published IP ranges

    💡 Or use the Application selector (Beta) to match the provider by name instead of IP ranges.

  5. 👉 Under Select an egress IP, choose Use dedicated Cloudflare egress IPs.

  6. 👉 Choose your primary IPv4 and IPv6 addresses from the dropdowns.

  7. 👉 Set a secondary IPv4 address (required for resilience):

    • 0.0.0.0 → if your primary's data center is down, traffic exits from the location closest to the user, or
    • a specific Cloudflare location different from your primary.
    • 💡 A secondary IPv6 is not required — IPv6 can exit from any Cloudflare data center.
  8. 👉 Click Create policy.

Then allowlist the IP at the provider

  1. 👉 In the SaaS provider's admin console, add your dedicated egress IP(s) to its allowlist / trusted IPs, so it only accepts connections coming from your organization.

💡 Best practice: pair this with an HTTP policy (Module 5) — e.g. block uploads to personal tenants, enforce DLP, or require device posture — so access is both from your IP and inspected.


Part C — Add a catch-all policy (important)

Without a catch-all, any traffic that doesn't match a policy will try to use the closest dedicated egress location, which can cause unexpected source IPs. Pin remaining traffic to the default (fast, shared) egress.

  1. 👉 Egress policies → Add a policy.

  2. ⌨️ Policy name: Default egress policy.

  3. 👉 Rule:

    Selector Operator Value
    Protocol in All options
  4. 👉 Egress method: Use default Cloudflare egress method.

  5. 👉 Click Create policy.

  6. 👉 Drag this policy to the very bottom of the list.

⚠️ Watch out: Egress policies evaluate top → bottom, first match wins. Keep specific policies (Part B) above the catch-all, or everything will match the catch-all first.

✅ Checkpoint: Your egress list shows specific policies on top and Default egress policy at the bottom.


Part D — Disable IPv6 (force IPv4)

Some upstream services misbehave over IPv6, or you may simply want a single, predictable IP version. You "disable IPv6" by blocking AAAA (IPv6) DNS record resolution with a DNS policy — users then connect over IPv4 only.

  1. 👉 First confirm you're filtering DNS traffic (Module 5, Part A) — this policy is a DNS policy.

  2. 👉 Go to Zero Trust → Traffic policies → DNS → Add a policy.

  3. ⌨️ Policy name: Disable IPv6 (Force IPv4).

  4. 👉 Build the rule:

    Selector Operator Value Action
    Query Record Type is AAAA Block
  5. 👉 Click Create policy.

  6. ⚠️ Important: turn off Modify Gateway block behavior (in the policy's settings / Gateway settings) so blocked AAAA lookups cleanly fall back to IPv4 instead of returning a block page.

💡 Scope it if needed: add a Domain selector to force IPv4 only for specific sites rather than everywhere. 💡 The reverse (force IPv6): same policy but Query Record Type is A → Block.

Verify

  1. 👉 On a connected device, run:
    nslookup -type=AAAA cloudflare.com     # should return no IPv6 address (blocked)
    nslookup -type=A cloudflare.com        # should still resolve normally
    
  2. 👉 Or visit https://ipv6.google.com → it should fail to load while normal IPv4 sites work.
  3. 👉 Check Logs → Gateway → DNS — you'll see the blocked AAAA queries.

✅ Checkpoint: AAAA lookups are blocked, A lookups work, and IPv6-only test sites don't load.


Part E — Verify your egress IP

  1. 👉 On a device routed through the dedicated-egress policy, visit an IP-echo site: https://ifconfig.me or https://www.cloudflare.com/cdn-cgi/trace/.
  2. 📺 The reported source IP should be your dedicated egress IP (for traffic that matches Part B), and the default range for everything else.

✅ Checkpoint: Matched traffic shows your dedicated IP; unmatched traffic shows the default egress; the SaaS app accepts your allowlisted connection.


✅ Module 5b complete!

You now have:

  • ✅ A dedicated egress policy sending chosen traffic out a fixed IP
  • ✅ The dedicated IP allowlisted at your SaaS provider
  • ✅ A catch-all policy keeping everything else fast on the default egress
  • ✅ A disable-IPv6 (force IPv4) DNS policy, verified

Quick troubleshooting

Problem Fix
No Egress policies tab / dedicated option greyed out The dedicated egress add-on isn't active — contact your account team (Part A)
Traffic exits the wrong IP Check policy order — a broader policy or the catch-all above it matched first (Part C)
SaaS app still blocks you Confirm the exact dedicated IP is on the provider's allowlist, and that your policy actually matches that destination
AAAA block returns a block page Turn off Modify Gateway block behavior (Part D)
IPv6 still works after the policy Ensure DNS filtering is on and the device is in Gateway with WARP mode; the device may be caching DNS — retry after a moment
Dedicated egress but no failover Set a secondary IPv4 (0.0.0.0 or another location) — it's required (Part B)

👉 Next: Module 6 — DLP

Detect and stop sensitive data from leaving your organization.

Nguồn cộng đồng — không phải tài liệu chính thức của Cloudflare: https://zerotrust.cfsase.workers.dev Community source — not an official Cloudflare publication: https://zerotrust.cfsase.workers.dev

Ví dụ triển khai (Cloudflare Resources) Deployment examples (Cloudflare Resources) Deployment examples (Cloudflare Resources)

Ví dụ chính thức từ Cloudflare Resources — gợi ý theo chủ đề bài học trong lộ trình này. Official examples from Cloudflare Resources — matched to this lesson within this path. Official examples from Cloudflare Resources — matched to this lesson within this path.

Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Bảo vệ access đến Microsoft 365 với IP egress chuyên dụng Protect access to Microsoft 365 with dedicated egress IPs ការពារ access ទៅ Microsoft 365 ជាមួយនឹង IPs egress ដំណឹង

Hướng dẫn này bao gồm làm thế nào để bảo mật access cho các ứng dụng Microsoft 365 của bạn với Cloudflare Gateway IP chuyên dụng egress.

This tutorial covers how to secure access to your Microsoft 365 applications with Cloudflare Gateway dedicated egress IPs.

វគ្គបណ្តុះបណ្តាលនេះគ្របដណ្តប់អំពីរបៀបដើម្បីសុវត្ថិភាព access ទៅកម្មវិធី Microsoft 365 របស់អ្នកជាមួយ Cloudflare Gateway IPs egress ដំណឹង។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Tạo và bảo mật một agent wrapper AI bằng cách sử dụng AI Gateway và Zero Trust Create and secure an AI agent wrapper using AI Gateway and Zero Trust ការបង្កើតនិងការសុវត្ថិភាព agent wrapper AI ដោយប្រើ AI Gateway និង Zero Trust

Hướng dẫn này giải thích cách sử dụng Cloudflare AI Gateway và Zero Trust để tạo ra một trang web đóng gói chức năng và an toàn cho một đại lý AI.

This tutorial explains how to use Cloudflare AI Gateway and Zero Trust to create a functional and secure website wrapper for an AI agent.

វគ្គបណ្តុះបណ្តាលនេះបង្ហាញពីរបៀបដើម្បីប្រើ Cloudflare AI Gateway និង Zero Trust ដើម្បីបង្កើតវគ្គបណ្តុះបណ្តាលគេហទំព័រដែលមានប្រសិទ្ធិភាពនិងសុវត្ថិភាពសម្រាប់អេក្រង់ AI ។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Tạo AI Gateway đầu tiên bằng cách sử dụng Workers AI Create your first AI Gateway using Workers AI បង្កើត AI Gateway ជាលើកដំបូងរបស់អ្នកដោយប្រើ Workers AI

Hướng dẫn này hướng dẫn bạn qua việc tạo AI Gateway đầu tiên của bạn bằng cách sử dụng Workers AI trên bảng điều khiển Cloudflare.

This tutorial guides you through creating your first AI Gateway using Workers AI on the Cloudflare dashboard.

វគ្គបណ្តុះបណ្តាលនេះជួយអ្នកធ្វើឱ្យការបង្កើត AI Gateway ជាលើកដំបូងរបស់អ្នកដោយប្រើ Workers AI នៅលើ Cloudflare ឧបករណ៍បញ្ជា។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Xác định lưu lượng truy cập MCP trong nhật ký Gateway Detect MCP traffic in Gateway logs ការរកឃើញការដឹកជញ្ជូន MCP នៅលើប្រព័ន្ធប្រតិបត្តិការ Gateway

Quét Gateway nhật ký cho lưu lượng truy cập MCP không được ủy quyền.

Scan Gateway logs for unauthorized MCP traffic.

ការសាកល្បង Gateway សៀវភៅសម្រាប់ការដឹកជញ្ជូន MCP មិនបានអនុញ្ញាត។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម

Xem thêm ví dụ trong lộ trình → More examples in this path → More examples in this path →

Tài liệu Cloudflare Developers Cloudflare Developer docs Cloudflare Developer docs

Sản phẩm liên quan Related products Related products

Học xong hoặc muốn đổi hướng? Finished or want a different path? Finished or want a different path?

Ba lộ trình độc lập — mỗi lộ trình chỉ gồm bài học và tài liệu trong phạm vi đó. Chọn lộ trình khác khi sẵn sàng, không cần học song song. Three independent paths — each includes only lessons and materials for that scope. Switch when you are ready; no need to study paths in parallel. Three independent paths — each includes only lessons and materials for that scope. Switch when you are ready; no need to study paths in parallel.

Chưa chắc — làm bài chọn lộ trình Not sure — use the path selector Not sure — use the path selector · So sánh cả ba lộ trình Compare all three paths Compare all three paths