Module 5c — Remote Browser Isolation (RBI)
Mục tiêu: Chạy việc duyệt web rủi ro hoặc nhạy cảm bên trong một remote browser trên mạng Cloudflare thay vì trên thiết bị người dùng — để malware không bao giờ tới endpoint, và bạn có thể tắt copy/paste, tải xuống, in, và nhập bàn phím để ngăn mất dữ liệu.
|
|
| 👤 Ai làm việc này |
Đội bảo mật |
| ⏱️ Thời gian |
~30 phút |
| 🎯 Kết thúc bạn sẽ có |
Một chính sách Isolate kết xuất các trang đã chọn trong remote browser, cộng (tùy chọn) clientless isolation cho thiết bị không được quản lý |
| ✋ Trước khi bắt đầu |
Đã xong Module 5 (thiết bị ở chế độ Gateway with WARP, TLS decryption bật). RBI cần Browser Isolation seats trên gói của bạn. |
🧭 Cách hoạt động: Khi một trang được cách ly, một headless browser chạy trên mạng Cloudflare và đóng vai "bản sao" của trình duyệt người dùng. Chỉ các lệnh vẽ an toàn được stream tới thiết bị — không có mã website nào thực thi cục bộ. Vì mọi yêu cầu được cách ly vẫn đi qua Gateway, tất cả chính sách DNS/HTTP/DLP của bạn vẫn áp dụng.
Vì sao dùng RBI
| Trường hợp dùng |
Cách ly mang lại gì |
| Trang rủi ro / chưa phân loại / mới thấy |
Người dùng vẫn mở được, nhưng mã chạy từ xa — khai thác trình duyệt zero-day không chạm được thiết bị |
| Thiết bị không quản lý / BYOD / nhà thầu |
Cung cấp truy cập trình duyệt an toàn, clientless với không cần cài phần mềm |
| Ngăn mất dữ liệu |
Tắt copy/paste, tải xuống, tải lên, in theo từng chính sách |
| Bảo vệ chống rò dữ liệu AI |
Cho phép ChatGPT v.v. nhưng tắt paste/upload để dữ liệu độc quyền không vào được |
| Bảo vệ chống phishing |
Tắt nhập bàn phím trên các trang đáng ngờ để không gõ được thông tin đăng nhập |
Hai cách để cách ly
| Chế độ |
Người dùng tới bằng cách nào |
Tốt nhất cho |
| In-line |
URL bình thường, được Gateway kiểm tra (cần Cloudflare One Client, tệp PAC / proxy endpoint, hoặc Cloudflare WAN) |
Thiết bị được quản lý — liền mạch, người dùng không nhận ra |
| Prefixed URL (clientless) |
Người dùng truy cập https://<team-name>.cloudflareaccess.com/browser/<URL> |
Không quản lý / BYOD / nhà thầu — không cần cài đặt |
Chúng ta sẽ thiết lập in-line isolation trước (Phần A–C), rồi tùy chọn bật clientless (Phần D).
Phần A — Tìm tổng quan Browser Isolation
- 👉 Trong bảng điều khiển (
https://one.dash.cloudflare.com), tìm Browser Isolation ở thanh điều hướng trái.
- 📺 Bạn sẽ thấy: trang Browser Isolation Overview — nơi tập trung để thiết lập chính sách cách ly, thử clientless isolation, và giám sát mức dùng cùng các hành động bị chặn.
✅ Điểm kiểm tra: Bạn thấy được tổng quan Browser Isolation. (Nếu thiếu hoặc bị làm mờ, gói của bạn không có RBI seats — liên hệ đội ngũ quản lý tài khoản.)
Phần B — Tạo chính sách Isolate
Cách ly chỉ là một Action bên trong chính sách Gateway HTTP (cùng nơi bạn xây quy tắc ở Module 5).
-
👉 Vào Traffic policies → Firewall policies → HTTP (hoặc Gateway → Firewall Policies → HTTP).
-
👉 Nhấp Add a policy.
-
⌨️ Policy name: Isolate risky browsing.
-
👉 Xây quy tắc — ví dụ, cách ly các trang chưa phân loại và mới thấy:
| Selector |
Operator |
Value |
| Content Categories |
in |
Newly Seen Domains, Unreachable/Uncategorized |
-
👉 Action: Isolate.
-
👉 Nhấp Create policy.
📺 Điều gì xảy ra: các trang khớp giờ mở trong một remote browser. Người dùng duyệt bình thường — hầu hết thậm chí không nhận ra.
💡 Các đích hữu ích khác: cách ly một danh mục Security Risks, một Domain rủi ro cụ thể, hoặc một Application (vd. cách ly mọi công cụ AI). Bạn cũng có thể dùng action Do not Isolate để khoét ngoại lệ phía trên một quy tắc Isolate rộng.
Phần C — Thêm kiểm soát bảo vệ dữ liệu (policy settings)
Đây là nơi RBI trở thành công cụ chống mất dữ liệu. Khi chỉnh một chính sách Isolate, mở policy settings của nó và bật bất kỳ mục nào sau đây:
| Thiết lập |
Nó ngăn gì |
Rất tốt cho |
| Disable copy / paste |
Sao chép giữa trang từ xa và thiết bị cục bộ |
Ngăn dán mã độc quyền vào chatbot bên thứ ba |
| Disable file downloads |
Tải tệp từ trang được cách ly |
Ngăn đưa dữ liệu ra ngoài từ các trang rủi ro |
| Disable file uploads |
Tải tệp cục bộ lên trang được cách ly |
Ngăn tài liệu nhạy cảm rời đi qua upload web |
| Disable printing |
In trang từ xa |
Ngăn nhà thầu in thông tin mật |
| Disable keyboard input |
Gõ vào trang từ xa |
Trang phishing — người dùng không nhập được thông tin đăng nhập |
- 👉 Mở chính sách Isolate của bạn → policy settings.
- 👉 Bật các kiểm soát bạn cần (vd. Disable copy/paste + Disable file downloads cho các danh mục rủi ro).
- 👉 Save.
💡 Mẹo (bảo vệ dữ liệu AI): tạo một chính sách Isolate cho ứng dụng AI (ChatGPT, Gemini, Claude…) với Disable copy/paste và Disable file uploads — mọi người vẫn dùng AI được, nhưng không thể đưa dữ liệu nhạy cảm vào. Điều này đi tốt với Module 7.
Phần D — Clientless isolation (cho thiết bị không quản lý, không cần cài)
Cung cấp cho nhà thầu hoặc người dùng BYOD một trình duyệt an toàn qua một liên kết đơn giản — không cần Cloudflare One Client.
D1 — Bật truy cập clientless
- 👉 Vào Settings → Browser Isolation (hoặc tổng quan Browser Isolation).
- 👉 Bật Allow users to open a remote browser without the device client.
- ✅ Đảm bảo Browser Isolation (RBI) seats đã được gán cho tài khoản của bạn.
D2 — Chia sẻ prefixed URL
Người dùng tới bất kỳ trang nào một cách an toàn bằng cách thêm tiền tố tên miền nhóm của bạn:
https://<team-name>.cloudflareaccess.com/browser/https://example.com
Với Acme: https://acme.cloudflareaccess.com/browser/https://example.com
📺 Trang tải bên trong một tab remote browser. Đăng nhập Access của bạn có thể kiểm soát ai được phép dùng.
💡 Thưởng — cách ly một ứng dụng riêng tư (ZTNA): bạn cũng có thể kết xuất một ứng dụng Access tự lưu trữ trong remote browser để thiết bị không quản lý có truy cập mà không phơi bày ứng dụng. Cấu hình qua Access → Applications → (your app) → policies → Isolate — một phương án dự phòng tuyệt cho kịch bản "thiết bị không quản lý" từ Module 4.
Phần E — Xác nhận cách ly đang hoạt động
Trên một thiết bị được chính sách của bạn bao phủ:
- 👉 Truy cập một trang khớp quy tắc Isolate (vd. một tên miền mới đăng ký, hoặc dùng prefixed URL clientless).
- 👉 Xác nhận nó được cách ly bằng một trong hai cách:
- Nhấp ổ khóa trên thanh địa chỉ → chứng chỉ được cấp bởi Cloudflare Root CA.
- Nhấp phải trang → menu ngữ cảnh hiện các tùy chọn isolated-browser.
- 👉 Thử các kiểm soát: thử sao chép văn bản hoặc tải một tệp — chúng phải bị chặn nếu bạn đã bật các thiết lập đó.
- 👉 Kiểm tra Browser Isolation overview (hoặc Logs → Gateway → HTTP) để xem hoạt động cách ly và các hành động bị chặn.
✅ Điểm kiểm tra: Các trang khớp được kết xuất trong remote browser, các công tắc bảo vệ dữ liệu được thực thi, và hoạt động cách ly hiện trên bảng điều khiển. 🎉
✅ Hoàn thành Module 5c!
Bây giờ bạn có:
- ✅ Một chính sách Isolate kết xuất các trang rủi ro trong remote browser
- ✅ Kiểm soát bảo vệ dữ liệu (copy/paste, tải xuống, tải lên, in, bàn phím) đã áp dụng
- ✅ (Tùy chọn) Clientless isolation cho thiết bị không quản lý/BYOD
- ✅ Một bài thử cách ly đã xác minh và khả năng quan sát trên overview
Khắc phục nhanh
| Vấn đề |
Cách khắc phục |
| Không có Browser Isolation trong menu / Isolate bị làm mờ |
Gói của bạn thiếu RBI seats — liên hệ đội ngũ quản lý tài khoản |
| In-line isolation không kích hoạt |
Thiết bị phải ở chế độ Gateway with WARP với TLS decryption on (Module 5–6); xác nhận selector của chính sách khớp |
| Prefixed URL clientless thất bại |
Bật Allow users to open a remote browser without the device client và gán RBI seats (Phần D1) |
| Một trang hỏng khi được cách ly |
Một số trang không kết xuất tốt từ xa — thêm chính sách Do not Isolate phía trên quy tắc Isolate cho tên miền đó |
| Copy/paste vẫn hoạt động |
Kiểm tra lại policy settings của chính sách Isolate và lưu; thử trong một phiên cách ly mới |
Phát hiện và ngăn dữ liệu nhạy cảm rời khỏi tổ chức của bạn.
Module 5c — Remote Browser Isolation (RBI)
Goal: Run risky or sensitive web browsing inside a remote browser on Cloudflare's network instead of on the user's device — so malware never reaches the endpoint, and you can disable copy/paste, downloads, printing, and keyboard input to stop data loss.
|
|
| 👤 Who does this |
Security team |
| ⏱️ Time |
~30 minutes |
| 🎯 You'll finish with |
An Isolate policy that renders chosen sites in a remote browser, plus (optionally) clientless isolation for unmanaged devices |
| ✋ Before you begin |
Module 5 done (devices in Gateway with WARP, TLS decryption on). RBI requires Browser Isolation seats on your plan. |
🧭 How it works: When a page is isolated, a headless browser runs on Cloudflare's network and acts as a "clone" of the user's browser. Only safe draw commands are streamed to the device — no website code ever executes locally. Because every isolated request still passes through Gateway, all your DNS/HTTP/DLP policies keep applying.
Why use RBI
| Use case |
What isolation gives you |
| Risky / uncategorized / newly-seen sites |
Users can still open them, but code runs remotely — zero-day browser exploits can't touch the device |
| Unmanaged / BYOD / contractor devices |
Give secure, clientless browser access with no software install |
| Stop data loss |
Disable copy/paste, downloads, uploads, printing per policy |
| Protect against AI data leaks |
Allow ChatGPT etc. but disable paste/upload so proprietary data can't go in |
| Phishing protection |
Disable keyboard input on suspicious sites so credentials can't be typed |
The two ways to isolate
| Mode |
How users reach it |
Best for |
| In-line |
Normal URLs, inspected by Gateway (needs the Cloudflare One Client, a PAC file / proxy endpoint, or Cloudflare WAN) |
Managed devices — seamless, users don't notice |
| Prefixed URL (clientless) |
Users visit https://<team-name>.cloudflareaccess.com/browser/<URL> |
Unmanaged / BYOD / contractors — no install needed |
We'll set up in-line isolation first (Part A–C), then optionally enable clientless (Part D).
Part A — Find the Browser Isolation overview
- 👉 In the dashboard (
https://one.dash.cloudflare.com), find Browser Isolation in the left navigation.
- 📺 What you'll see: the Browser Isolation Overview page — a central place to set up isolation policies, test clientless isolation, and monitor usage and blocked actions.
✅ Checkpoint: You can see the Browser Isolation overview. (If it's missing or greyed out, your plan doesn't have RBI seats — contact your account team.)
Part B — Create an Isolate policy
Isolation is just an Action inside a Gateway HTTP policy (the same place you built rules in Module 5).
-
👉 Go to Traffic policies → Firewall policies → HTTP (or Gateway → Firewall Policies → HTTP).
-
👉 Click Add a policy.
-
⌨️ Policy name: Isolate risky browsing.
-
👉 Build the rule — for example, isolate uncategorized and newly-seen sites:
| Selector |
Operator |
Value |
| Content Categories |
in |
Newly Seen Domains, Unreachable/Uncategorized |
-
👉 Action: Isolate.
-
👉 Click Create policy.
📺 What happens: matching sites now open in a remote browser. Users browse normally — most won't even notice.
💡 Other useful targets: isolate a Security Risks category, a specific risky Domain, or an Application (e.g. isolate all AI tools). You can also use the Do not Isolate action to carve out exceptions above a broad Isolate rule.
Part C — Add data-protection controls (policy settings)
This is where RBI becomes a data-loss tool. When editing an Isolate policy, open its policy settings and toggle any of these:
| Setting |
What it stops |
Great for |
| Disable copy / paste |
Copying between the remote page and the local device |
Stop pasting proprietary code into third-party chatbots |
| Disable file downloads |
Downloading files from the isolated site |
Prevent data exfiltration from risky sites |
| Disable file uploads |
Uploading local files to the isolated site |
Stop sensitive docs leaving via web uploads |
| Disable printing |
Printing the remote page |
Prevent contractors printing confidential info |
| Disable keyboard input |
Typing into the remote page |
Phishing sites — users can't enter credentials |
- 👉 Open your Isolate policy → policy settings.
- 👉 Enable the controls you need (e.g. Disable copy/paste + Disable file downloads for risky categories).
- 👉 Save.
💡 Tip (AI data protection): create an Isolate policy for AI apps (ChatGPT, Gemini, Claude…) with Disable copy/paste and Disable file uploads — people can still use AI, but can't feed it your sensitive data. This pairs well with Module 7.
Part D — Clientless isolation (for unmanaged devices, no install)
Give contractors or BYOD users a safe browser through a simple link — no Cloudflare One Client required.
D1 — Turn on clientless access
- 👉 Go to Settings → Browser Isolation (or the Browser Isolation overview).
- 👉 Enable Allow users to open a remote browser without the device client.
- ✅ Make sure Browser Isolation (RBI) seats are assigned to your account.
D2 — Share the prefixed URL
Users reach any site safely by prefixing it with your team domain:
https://<team-name>.cloudflareaccess.com/browser/https://example.com
For Acme: https://acme.cloudflareaccess.com/browser/https://example.com
📺 The site loads inside a remote browser tab. Your Access login can gate who's allowed to use it.
💡 Bonus — isolate a private app (ZTNA): you can also render a self-hosted Access application in a remote browser so unmanaged devices get access without exposing your app. Configure this via Access → Applications → (your app) → policies → Isolate — a great fallback for the "unmanaged device" scenario from Module 4.
Part E — Verify isolation is working
On a device covered by your policy:
- 👉 Visit a site that matches your Isolate rule (e.g. a newly-registered domain, or use the clientless prefix URL).
- 👉 Confirm it's isolated using either method:
- Click the padlock in the address bar → the certificate is issued by the Cloudflare Root CA.
- Right-click the page → the context menu shows the isolated-browser options.
- 👉 Test your controls: try to copy text or download a file — they should be blocked if you enabled those settings.
- 👉 Check the Browser Isolation overview (or Logs → Gateway → HTTP) for isolation activity and blocked actions.
✅ Checkpoint: Matching sites render in a remote browser, your data-protection toggles are enforced, and isolation activity shows in the dashboard. 🎉
✅ Module 5c complete!
You now have:
- ✅ An Isolate policy rendering risky sites in a remote browser
- ✅ Data-protection controls (copy/paste, download, upload, print, keyboard) applied
- ✅ (Optional) Clientless isolation for unmanaged/BYOD devices
- ✅ A verified isolation test and visibility in the overview
Quick troubleshooting
| Problem |
Fix |
| No Browser Isolation in the menu / Isolate greyed out |
Your plan lacks RBI seats — contact your account team |
| In-line isolation doesn't trigger |
Device must be in Gateway with WARP with TLS decryption on (Module 5–6); confirm the policy selector matches |
| Clientless prefix URL fails |
Enable Allow users to open a remote browser without the device client and assign RBI seats (Part D1) |
| A site breaks when isolated |
Some sites don't render well remotely — add a Do not Isolate policy above the Isolate rule for that domain |
| Copy/paste still works |
Re-check the Isolate policy's policy settings and save; test in a fresh isolated session |
Detect and stop sensitive data from leaving your organization.
Nguồn cộng đồng — không phải tài liệu chính thức của Cloudflare: https://zerotrust.cfsase.workers.dev
Community source — not an official Cloudflare publication: https://zerotrust.cfsase.workers.dev