Mô-đun 8 — Cloudflare WAN (Kết nối văn phòng & trung tâm dữ liệu)
Mục tiêu: Kết nối cả site — văn phòng, trung tâm dữ liệu, mạng đám mây — với Cloudflare, để toàn bộ lưu lượng của chúng (không chỉ laptop có ứng dụng WARP) được định tuyến và bảo vệ, thay thế liên kết MPLS đắt đỏ và lưới VPN site-to-site.
|
|
| 👤 Ai làm việc này |
Nhóm mạng (cần quyền truy cập router/tường lửa) |
| ⏱️ Thời gian |
~90 phút mỗi site |
| 🎯 Kết thúc bạn sẽ có |
Một site kết nối với Cloudflare qua tunnel dư thừa, với lưu lượng được lọc bởi chính sách của bạn |
| ✋ Trước khi bắt đầu |
Gói bổ sung mạng Enterprise (Cloudflare WAN) đang hoạt động; quyền quản trị router/tường lửa của site; kế hoạch địa chỉ IP của bạn |
⚠️ Mô-đun này chạm vào mạng sản xuất. Lên lịch cửa sổ bảo trì, có quyền truy cập console tới router, và kế hoạch rollback. Làm một site trước.
Chúng ta sẽ làm: (0) kiểm tra trước MSS → (A) chọn on-ramp → (B) xây tunnel → (C) định tuyến → (D) bảo mật → (E) kiểm tra & failover.
Phần 0 — Kiểm tra trước: MSS clamping (đừng bỏ qua!)
Vì Cloudflare bọc gói tin của bạn trong một header thêm, các gói lớn có thể bị loại bỏ im lặng trừ khi bạn giới hạn kích thước phân đoạn TCP (MSS) trên thiết bị biên.
Đặt điều này trên router/tường lửa trước khi đưa tunnel lên:
| Loại tunnel |
Đặt MSS thành |
| GRE |
1436 bytes |
| IPsec |
1360 bytes |
Ví dụ (Cisco): ip tcp adjust-mss 1436 · (Juniper): set … tcp-mss 1436
⚠️ Triệu chứng kinh điển khi quên điều này: các site http:// thuần hoạt động nhưng các site https:// treo hoặc hết thời gian. Nếu sau này bạn thấy vậy, hãy quay lại đây.
Phần A — Chọn on-ramp của bạn
Chọn cách mỗi site kết nối:
| On-ramp |
Phù hợp nhất với |
Ghi chú |
| Cloudflare WAN Connector |
Văn phòng chi nhánh, đơn giản nhất |
Một thiết bị Cloudflare nhỏ (phần cứng hoặc ảo); gần như zero-touch |
| IPsec tunnel |
Site đã có tường lửa/router |
Được mã hóa; hỗ trợ định tuyến động (BGP) |
| GRE tunnel |
Trung tâm dữ liệu, thông lượng cao |
Không mã hóa; hỗ trợ BGP |
| CNI (Direct Connect) |
Liên kết băng thông cao riêng |
Cross-connect vật lý/ảo |
| Cloud (MNC) |
VPC AWS/Azure/GCP |
On-ramp đám mây tự động |
Hướng dẫn này đi qua một IPsec tunnel (phổ biến nhất với tường lửa sẵn có). GRE gần như giống hệt.
Phần B — Xây tunnel (có dư thừa)
⭐ Luôn xây HAI tunnel từ HAI router riêng tại mỗi site. Phía Cloudflare là "anycast" — một tunnel đã tới mọi địa điểm Cloudflare — nên dư thừa là để bảo vệ khi phần cứng của bạn hỏng.
Bước B1 — Tạo IPsec tunnel đầu tiên trong Cloudflare
- 👉 Cloudflare dashboard → Cloudflare WAN → Configuration → Tunnels.
- 👉 Nhấp Create → IPsec tunnel.
- ⌨️ Điền:
| Trường |
Giá trị |
| Tunnel name |
hq-london-fw1 |
| Customer endpoint |
IP công khai của tường lửa bạn (để trống nếu sau NAT) |
| Cloudflare endpoint |
anycast IP mà Cloudflare gán cho bạn |
| Interface address |
/31 nhỏ mà Cloudflare cung cấp cho tunnel |
| Pre-shared key (PSK) |
nhấp generate, hoặc dán khóa của bạn — lưu an toàn |
| Health check |
On (khuyến nghị) |
- 👉 Nhấp Save.
Bước B2 — Khớp các thiết lập này trên tường lửa của bạn
Cấu hình IPsec tunnel tương ứng trên thiết bị của bạn bằng đúng các giá trị này:
| Tham số |
Giá trị |
| IKE version |
IKEv2 (only) |
| Phase 1 & 2 encryption |
AES-256-GCM-16 |
| Phase 1 & 2 integrity / PRF |
SHA2-256 |
| Phase 1 & 2 DH group (PFS) |
Group 20 |
| Pre-shared key |
PSK từ B1 |
| Cloudflare peer IP |
endpoint anycast từ B1 |
(NAT traversal trên UDP 500→4500 được xử lý tự động.)
Bước B3 — Lặp lại cho tunnel thứ hai
👉 Tạo hq-london-fw2 trên router thứ hai của bạn và một tunnel thứ hai tương ứng trong Cloudflare.
✅ Điểm kiểm tra: Trong Cloudflare WAN → Tunnels, cả hai tunnel hiển thị Healthy (health check đang đạt).
Phần C — Nói với Cloudflare cách định tuyến mạng của bạn
- 👉 Cloudflare WAN → Configuration → Routes.
- Chọn cách tiếp cận của bạn:
Tùy chọn 1 — Static routes (site đơn giản, ổn định)
- 👉 Nhấp Create route.
- ⌨️ Điền:
| Trường |
Giá trị |
| Prefix |
subnet của site bạn, ví dụ 10.10.0.0/16 |
| Tunnel / next hop |
hq-london-fw1 |
| Priority |
100 (thấp hơn = được ưu tiên) |
| Weight |
để chia tải giữa cả hai tunnel (ECMP) |
- 👉 Thêm route tương ứng qua
hq-london-fw2 (ví dụ cũng priority 100 để chia tải, hoặc 200 cho standby).
Tùy chọn 2 — BGP (khuyến nghị cho nhiều site / site hay đổi)
- 👉 Bật BGP trên tunnel và cấu hình eBGP peer: ASN của router bạn, ASN của Cloudflare, và mật khẩu MD5.
- 📺 Route giờ được trao đổi tự động — thêm subnet tại site và nó lan truyền mà không cần sửa dashboard.
⚠️ Lưu ý: Lập kế hoạch không gian IP. Nếu hai site dùng subnet chồng lấp (ví dụ cả hai 192.168.1.0/24), định tuyến Cloudflare WAN bị hỏng. Đổi IP lại hoặc dùng dải duy nhất.
✅ Điểm kiểm tra: Subnet site của bạn xuất hiện trong bảng định tuyến Magic, tới được qua các tunnel.
Phần D — Thêm bảo mật & gửi lưu lượng qua Gateway
- Lọc lưu lượng mạng bằng tường lửa: 👉 vào Magic Firewall → Create rule để cho phép/từ chối lưu lượng ở lớp mạng (L3/L4). ⚠️ Cho đến khi bạn thêm rule, lưu lượng mạng này chưa được lọc.
- Áp dụng chính sách web cho cả site: định tuyến lưu lượng internet-bound của site qua Gateway để các chính sách DNS/HTTP/DLP từ Mô-đun 5–6 bảo vệ mọi thiết bị tại site — kể cả những thiết bị không có ứng dụng WARP.
- Nhận cảnh báo: 👉 Cloudflare Notifications → Add → Magic Tunnel Health → chọn tunnel của bạn → thêm người nhận, để bạn biết sự cố tunnel trước người dùng.
Phần E — Kiểm tra và chứng minh failover
Kiểm tra 1 — kết nối
- 👉 Từ một máy tại site, tới được thứ gì đó qua tunnel (site khác, hoặc internet qua Cloudflare).
- 👉 Chạy
curl http://ifconfig.me và curl https://ifconfig.me.
- 📺 Cả hai đều phải trả về nhanh. Nếu
http hoạt động nhưng https treo → MSS clamp của bạn sai (Phần 0).
Kiểm tra 2 — failover
- 👉 Tắt tunnel thứ nhất (hoặc đưa router 1 offline) trong một kiểm tra có kiểm soát.
- 📺 Lưu lượng phải hội tụ lại qua tunnel thứ hai trong vài giây; dashboard đánh dấu tunnel 1 unhealthy.
- 👉 Bật lại và xác nhận nó phục hồi.
✅ Điểm kiểm tra: Kết nối site hoạt động, HTTPS khỏe (MSS đúng), failover hoạt động, và lưu lượng site được lọc bởi Gateway. 🎉
✅ Hoàn thành Mô-đun 8!
Bây giờ bạn có:
- ✅ MSS clamping đã đặt đúng
- ✅ Tunnel dư thừa (hai router) hiển thị healthy
- ✅ Định tuyến đã cấu hình (static hoặc BGP) với kế hoạch IP sạch
- ✅ Rule Magic Firewall + lưu lượng site chảy qua Gateway
- ✅ Đã xác minh kết nối và failover, cộng cảnh báo sức khỏe
Khắc phục nhanh
| Vấn đề |
Cách khắc phục |
https:// treo, http:// hoạt động |
MSS clamp sai — GRE 1436 / IPsec 1360 (Phần 0) |
| Tunnel không lên được |
Thiết lập Phase 1/2 không khớp — kiểm tra lại IKEv2 / AES-256-GCM-16 / SHA2-256 / DH 20 (Phần B2) |
| Tunnel lên nhưng không có lưu lượng |
Thiếu/sai route, hoặc subnet chồng lấp (Phần C) |
| Mất kết nối từng lúc |
Định tuyến bất đối xứng hoặc MTU không khớp — xác minh route và MSS của cả hai tunnel |
| Lưu lượng mạng chưa được lọc |
Thêm rule Magic Firewall và/hoặc định tuyến tới Gateway (Phần D) |
🏁 Bạn đã đến cuối hướng dẫn triển khai!
Quay lại Master checklist và xác nhận mọi ô đã được đánh dấu. Các mục go-live cuối cùng:
- [ ] Log đang chảy tới SIEM của bạn (Logpush)
- [ ] Thí điểm đã xác thực, triển khai đã mở rộng toàn công ty
- [ ] VPN cũ đã ngừng cho các ứng dụng đã chuyển
- [ ] Đã đặt nhắc gia hạn cho mọi IdP client secret / chứng chỉ
Chúc mừng — bạn đã triển khai Cloudflare Zero Trust từ đầu đến cuối. 🎉
Module 8 — Cloudflare WAN (Connect Offices & Data Centers)
Goal: Connect entire sites — offices, data centers, cloud networks — to Cloudflare, so all their traffic (not just laptops with the WARP app) is routed and protected, replacing expensive MPLS links and site-to-site VPN meshes.
|
|
| 👤 Who does this |
Network team (needs router/firewall access) |
| ⏱️ Time |
~90 minutes per site |
| 🎯 You'll finish with |
A site connected to Cloudflare over redundant tunnels, with traffic filtered by your policies |
| ✋ Before you begin |
Enterprise network add-on (Cloudflare WAN) active; admin access to the site's router/firewall; your IP address plan |
⚠️ This module touches production networking. Schedule a maintenance window, have console access to your router, and a rollback plan. Do one site first.
We'll do: (0) pre-flight MSS → (A) pick an on-ramp → (B) build tunnels → (C) routing → (D) security → (E) test & failover.
Part 0 — Pre-flight: MSS clamping (don't skip this!)
Because Cloudflare wraps your packets in an extra header, large packets can get silently dropped unless you cap the TCP segment size (MSS) on your edge device.
Set this on your router/firewall before bringing tunnels up:
| Tunnel type |
Set MSS to |
| GRE |
1436 bytes |
| IPsec |
1360 bytes |
Example (Cisco): ip tcp adjust-mss 1436 · (Juniper): set … tcp-mss 1436
⚠️ The classic symptom of forgetting this: plain http:// sites work but https:// sites hang or time out. If you see that later, come back here.
Part A — Choose your on-ramp
Pick how each site connects:
| On-ramp |
Best for |
Notes |
| Cloudflare WAN Connector |
Branch offices, simplest |
A small Cloudflare appliance (hardware or virtual); near zero-touch |
| IPsec tunnel |
Sites with an existing firewall/router |
Encrypted; supports dynamic routing (BGP) |
| GRE tunnel |
Data centers, high throughput |
Not encrypted; supports BGP |
| CNI (Direct Connect) |
Private high-bandwidth link |
Physical/virtual cross-connect |
| Cloud (MNC) |
AWS/Azure/GCP VPCs |
Automated cloud on-ramp |
This guide walks through an IPsec tunnel (most common with existing firewalls). GRE is nearly identical.
Part B — Build the tunnels (with redundancy)
⭐ Always build TWO tunnels from TWO separate routers at each site. Cloudflare's side is "anycast" — one tunnel already reaches every Cloudflare location — so redundancy is about protecting against your hardware failing.
Step B1 — Create the first IPsec tunnel in Cloudflare
- 👉 Cloudflare dashboard → Cloudflare WAN → Configuration → Tunnels.
- 👉 Click Create → IPsec tunnel.
- ⌨️ Fill in:
| Field |
Value |
| Tunnel name |
hq-london-fw1 |
| Customer endpoint |
your firewall's public IP (leave blank if behind NAT) |
| Cloudflare endpoint |
the anycast IP Cloudflare assigns you |
| Interface address |
the small /31 Cloudflare provides for the tunnel |
| Pre-shared key (PSK) |
click generate, or paste your own — store it safely |
| Health check |
On (recommended) |
- 👉 Click Save.
Step B2 — Match these settings on your firewall
Configure the matching IPsec tunnel on your device using exactly these:
| Parameter |
Value |
| IKE version |
IKEv2 (only) |
| Phase 1 & 2 encryption |
AES-256-GCM-16 |
| Phase 1 & 2 integrity / PRF |
SHA2-256 |
| Phase 1 & 2 DH group (PFS) |
Group 20 |
| Pre-shared key |
the PSK from B1 |
| Cloudflare peer IP |
the anycast endpoint from B1 |
(NAT traversal on UDP 500→4500 is handled automatically.)
Step B3 — Repeat for the second tunnel
👉 Create hq-london-fw2 on your second router and a matching second tunnel in Cloudflare.
✅ Checkpoint: In Cloudflare WAN → Tunnels, both tunnels show Healthy (health checks passing).
Part C — Tell Cloudflare how to route your networks
- 👉 Cloudflare WAN → Configuration → Routes.
- Choose your approach:
Option 1 — Static routes (simple, stable sites)
- 👉 Click Create route.
- ⌨️ Fill in:
| Field |
Value |
| Prefix |
your site's subnet, e.g. 10.10.0.0/16 |
| Tunnel / next hop |
hq-london-fw1 |
| Priority |
100 (lower = preferred) |
| Weight |
for sharing load across both tunnels (ECMP) |
- 👉 Add a matching route via
hq-london-fw2 (e.g. priority 100 too, for load-sharing, or 200 for standby).
Option 2 — BGP (recommended for multiple/changing sites)
- 👉 Enable BGP on the tunnel and configure an eBGP peer: your router's ASN, Cloudflare's ASN, and an MD5 password.
- 📺 Routes are now exchanged automatically — add a subnet at the site and it propagates without dashboard edits.
⚠️ Watch out: Plan your IP space. If two sites use overlapping subnets (e.g. both 192.168.1.0/24), Cloudflare WAN routing breaks. Re-IP or use unique ranges.
✅ Checkpoint: Your site subnets appear in the Magic routing table, reachable via the tunnels.
Part D — Add security & send traffic through Gateway
- Firewall the network traffic: 👉 go to Magic Firewall → Create rule to allow/deny traffic at the network layer (L3/L4). ⚠️ Until you add rules, this network traffic is unfiltered.
- Apply your web policies to the whole site: route the site's internet-bound traffic through Gateway so the DNS/HTTP/DLP policies from Modules 5–6 protect every device at the site — even those without the WARP app.
- Get alerted: 👉 Cloudflare Notifications → Add → Magic Tunnel Health → pick your tunnels → add recipients, so you hear about a tunnel problem before users do.
Part E — Test and prove failover
Test 1 — connectivity
- 👉 From a machine at the site, reach something across the tunnel (another site, or the internet via Cloudflare).
- 👉 Run
curl http://ifconfig.me and curl https://ifconfig.me.
- 📺 Both should return quickly. If
http works but https hangs → your MSS clamp is wrong (Part 0).
Test 2 — failover
- 👉 Disable the first tunnel (or take router 1 offline) in a controlled test.
- 📺 Traffic should re-converge over the second tunnel within seconds; the dashboard marks tunnel 1 unhealthy.
- 👉 Re-enable it and confirm it recovers.
✅ Checkpoint: Site connectivity works, HTTPS is healthy (MSS correct), failover works, and site traffic is filtered by Gateway. 🎉
✅ Module 8 complete!
You now have:
- ✅ MSS clamping set correctly
- ✅ Redundant tunnels (two routers) showing healthy
- ✅ Routing configured (static or BGP) with a clean IP plan
- ✅ Magic Firewall rules + site traffic flowing through Gateway
- ✅ Verified connectivity and failover, plus health alerts
Quick troubleshooting
| Problem |
Fix |
https:// hangs, http:// works |
MSS clamp wrong — GRE 1436 / IPsec 1360 (Part 0) |
| Tunnel won't come up |
Phase 1/2 settings mismatch — re-check IKEv2 / AES-256-GCM-16 / SHA2-256 / DH 20 (Part B2) |
| Tunnel up but no traffic |
Missing/incorrect route, or overlapping subnets (Part C) |
| Intermittent drops |
Asymmetric routing or MTU mismatch — verify both tunnels' routes and MSS |
| Network traffic unfiltered |
Add Magic Firewall rules and/or route to Gateway (Part D) |
🏁 You've reached the end of the onboarding!
Go back to the Master checklist and confirm every box is ticked. Final go-live items:
- [ ] Logs flowing to your SIEM (Logpush)
- [ ] Pilot validated, rollout expanded company-wide
- [ ] Old VPN decommissioned for migrated apps
- [ ] Renewal reminders set for any IdP client secrets / certificates
Congratulations — you've deployed Cloudflare Zero Trust end to end. 🎉
Nguồn cộng đồng — không phải tài liệu chính thức của Cloudflare: https://zerotrust.cfsase.workers.dev
Community source — not an official Cloudflare publication: https://zerotrust.cfsase.workers.dev