Lộ trình đang học Current learning path Current learning path

Cloudflare One Cloudflare One Cloudflare One

Bảo vệ users, access, SaaS và networks — follow-along từ tài khoản đến go-live. Secure users, access, SaaS, and networks — follow along from account to go-live. Secure users, access, SaaS, and networks — follow along from account to go-live.

Về trang lộ trình Track home Track home

Phần 8: Cloudflare WAN (tuỳ chọn) Part 8: Cloudflare WAN (optional) Part 8: Cloudflare WAN (optional) · Bài 2/2 Lesson 2/2 មេរៀន 2/2

Routing, Magic Firewall và gửi traffic qua Gateway Routing, Magic Firewall, and sending traffic through Gateway Routing, Magic Firewall, and sending traffic through Gateway

Mô-đun 8 — Cloudflare WAN (Kết nối văn phòng & trung tâm dữ liệu)

Mục tiêu: Kết nối cả site — văn phòng, trung tâm dữ liệu, mạng đám mây — với Cloudflare, để toàn bộ lưu lượng của chúng (không chỉ laptop có ứng dụng WARP) được định tuyến và bảo vệ, thay thế liên kết MPLS đắt đỏ và lưới VPN site-to-site.

👤 Ai làm việc này Nhóm mạng (cần quyền truy cập router/tường lửa)
⏱️ Thời gian ~90 phút mỗi site
🎯 Kết thúc bạn sẽ có Một site kết nối với Cloudflare qua tunnel dư thừa, với lưu lượng được lọc bởi chính sách của bạn
✋ Trước khi bắt đầu Gói bổ sung mạng Enterprise (Cloudflare WAN) đang hoạt động; quyền quản trị router/tường lửa của site; kế hoạch địa chỉ IP của bạn

⚠️ Mô-đun này chạm vào mạng sản xuất. Lên lịch cửa sổ bảo trì, có quyền truy cập console tới router, và kế hoạch rollback. Làm một site trước.

Chúng ta sẽ làm: (0) kiểm tra trước MSS → (A) chọn on-ramp → (B) xây tunnel → (C) định tuyến → (D) bảo mật → (E) kiểm tra & failover.


Phần 0 — Kiểm tra trước: MSS clamping (đừng bỏ qua!)

Vì Cloudflare bọc gói tin của bạn trong một header thêm, các gói lớn có thể bị loại bỏ im lặng trừ khi bạn giới hạn kích thước phân đoạn TCP (MSS) trên thiết bị biên.

Đặt điều này trên router/tường lửa trước khi đưa tunnel lên:

Loại tunnel Đặt MSS thành
GRE 1436 bytes
IPsec 1360 bytes

Ví dụ (Cisco): ip tcp adjust-mss 1436 · (Juniper): set …​ tcp-mss 1436

⚠️ Triệu chứng kinh điển khi quên điều này: các site http:// thuần hoạt động nhưng các site https:// treo hoặc hết thời gian. Nếu sau này bạn thấy vậy, hãy quay lại đây.


Phần A — Chọn on-ramp của bạn

Chọn cách mỗi site kết nối:

On-ramp Phù hợp nhất với Ghi chú
Cloudflare WAN Connector Văn phòng chi nhánh, đơn giản nhất Một thiết bị Cloudflare nhỏ (phần cứng hoặc ảo); gần như zero-touch
IPsec tunnel Site đã có tường lửa/router Được mã hóa; hỗ trợ định tuyến động (BGP)
GRE tunnel Trung tâm dữ liệu, thông lượng cao Không mã hóa; hỗ trợ BGP
CNI (Direct Connect) Liên kết băng thông cao riêng Cross-connect vật lý/ảo
Cloud (MNC) VPC AWS/Azure/GCP On-ramp đám mây tự động

Hướng dẫn này đi qua một IPsec tunnel (phổ biến nhất với tường lửa sẵn có). GRE gần như giống hệt.


Phần B — Xây tunnel (có dư thừa)

⭐ Luôn xây HAI tunnel từ HAI router riêng tại mỗi site. Phía Cloudflare là "anycast" — một tunnel đã tới mọi địa điểm Cloudflare — nên dư thừa là để bảo vệ khi phần cứng của bạn hỏng.

Bước B1 — Tạo IPsec tunnel đầu tiên trong Cloudflare

  1. 👉 Cloudflare dashboard → Cloudflare WAN → Configuration → Tunnels.
  2. 👉 Nhấp Create → IPsec tunnel.
  3. ⌨️ Điền:
    Trường Giá trị
    Tunnel name hq-london-fw1
    Customer endpoint IP công khai của tường lửa bạn (để trống nếu sau NAT)
    Cloudflare endpoint anycast IP mà Cloudflare gán cho bạn
    Interface address /31 nhỏ mà Cloudflare cung cấp cho tunnel
    Pre-shared key (PSK) nhấp generate, hoặc dán khóa của bạn — lưu an toàn
    Health check On (khuyến nghị)
  4. 👉 Nhấp Save.

Bước B2 — Khớp các thiết lập này trên tường lửa của bạn

Cấu hình IPsec tunnel tương ứng trên thiết bị của bạn bằng đúng các giá trị này:

Tham số Giá trị
IKE version IKEv2 (only)
Phase 1 & 2 encryption AES-256-GCM-16
Phase 1 & 2 integrity / PRF SHA2-256
Phase 1 & 2 DH group (PFS) Group 20
Pre-shared key PSK từ B1
Cloudflare peer IP endpoint anycast từ B1

(NAT traversal trên UDP 500→4500 được xử lý tự động.)

Bước B3 — Lặp lại cho tunnel thứ hai

👉 Tạo hq-london-fw2 trên router thứ hai của bạn và một tunnel thứ hai tương ứng trong Cloudflare.

✅ Điểm kiểm tra: Trong Cloudflare WAN → Tunnels, cả hai tunnel hiển thị Healthy (health check đang đạt).


Phần C — Nói với Cloudflare cách định tuyến mạng của bạn

  1. 👉 Cloudflare WAN → Configuration → Routes.
  2. Chọn cách tiếp cận của bạn:

Tùy chọn 1 — Static routes (site đơn giản, ổn định)

  1. 👉 Nhấp Create route.
  2. ⌨️ Điền:
    Trường Giá trị
    Prefix subnet của site bạn, ví dụ 10.10.0.0/16
    Tunnel / next hop hq-london-fw1
    Priority 100 (thấp hơn = được ưu tiên)
    Weight để chia tải giữa cả hai tunnel (ECMP)
  3. 👉 Thêm route tương ứng qua hq-london-fw2 (ví dụ cũng priority 100 để chia tải, hoặc 200 cho standby).
  1. 👉 Bật BGP trên tunnel và cấu hình eBGP peer: ASN của router bạn, ASN của Cloudflare, và mật khẩu MD5.
  2. 📺 Route giờ được trao đổi tự động — thêm subnet tại site và nó lan truyền mà không cần sửa dashboard.

⚠️ Lưu ý: Lập kế hoạch không gian IP. Nếu hai site dùng subnet chồng lấp (ví dụ cả hai 192.168.1.0/24), định tuyến Cloudflare WAN bị hỏng. Đổi IP lại hoặc dùng dải duy nhất.

✅ Điểm kiểm tra: Subnet site của bạn xuất hiện trong bảng định tuyến Magic, tới được qua các tunnel.


Phần D — Thêm bảo mật & gửi lưu lượng qua Gateway

  1. Lọc lưu lượng mạng bằng tường lửa: 👉 vào Magic Firewall → Create rule để cho phép/từ chối lưu lượng ở lớp mạng (L3/L4). ⚠️ Cho đến khi bạn thêm rule, lưu lượng mạng này chưa được lọc.
  2. Áp dụng chính sách web cho cả site: định tuyến lưu lượng internet-bound của site qua Gateway để các chính sách DNS/HTTP/DLP từ Mô-đun 5–6 bảo vệ mọi thiết bị tại site — kể cả những thiết bị không có ứng dụng WARP.
  3. Nhận cảnh báo: 👉 Cloudflare Notifications → Add → Magic Tunnel Health → chọn tunnel của bạn → thêm người nhận, để bạn biết sự cố tunnel trước người dùng.

Phần E — Kiểm tra và chứng minh failover

Kiểm tra 1 — kết nối

  1. 👉 Từ một máy tại site, tới được thứ gì đó qua tunnel (site khác, hoặc internet qua Cloudflare).
  2. 👉 Chạy curl http://ifconfig.me và curl https://ifconfig.me.
  3. 📺 Cả hai đều phải trả về nhanh. Nếu http hoạt động nhưng https treo → MSS clamp của bạn sai (Phần 0).

Kiểm tra 2 — failover

  1. 👉 Tắt tunnel thứ nhất (hoặc đưa router 1 offline) trong một kiểm tra có kiểm soát.
  2. 📺 Lưu lượng phải hội tụ lại qua tunnel thứ hai trong vài giây; dashboard đánh dấu tunnel 1 unhealthy.
  3. 👉 Bật lại và xác nhận nó phục hồi.

✅ Điểm kiểm tra: Kết nối site hoạt động, HTTPS khỏe (MSS đúng), failover hoạt động, và lưu lượng site được lọc bởi Gateway. 🎉


✅ Hoàn thành Mô-đun 8!

Bây giờ bạn có:

  • ✅ MSS clamping đã đặt đúng
  • ✅ Tunnel dư thừa (hai router) hiển thị healthy
  • ✅ Định tuyến đã cấu hình (static hoặc BGP) với kế hoạch IP sạch
  • ✅ Rule Magic Firewall + lưu lượng site chảy qua Gateway
  • ✅ Đã xác minh kết nối và failover, cộng cảnh báo sức khỏe

Khắc phục nhanh

Vấn đề Cách khắc phục
https:// treo, http:// hoạt động MSS clamp sai — GRE 1436 / IPsec 1360 (Phần 0)
Tunnel không lên được Thiết lập Phase 1/2 không khớp — kiểm tra lại IKEv2 / AES-256-GCM-16 / SHA2-256 / DH 20 (Phần B2)
Tunnel lên nhưng không có lưu lượng Thiếu/sai route, hoặc subnet chồng lấp (Phần C)
Mất kết nối từng lúc Định tuyến bất đối xứng hoặc MTU không khớp — xác minh route và MSS của cả hai tunnel
Lưu lượng mạng chưa được lọc Thêm rule Magic Firewall và/hoặc định tuyến tới Gateway (Phần D)

🏁 Bạn đã đến cuối hướng dẫn triển khai!

Quay lại Master checklist và xác nhận mọi ô đã được đánh dấu. Các mục go-live cuối cùng:

  • [ ] Log đang chảy tới SIEM của bạn (Logpush)
  • [ ] Thí điểm đã xác thực, triển khai đã mở rộng toàn công ty
  • [ ] VPN cũ đã ngừng cho các ứng dụng đã chuyển
  • [ ] Đã đặt nhắc gia hạn cho mọi IdP client secret / chứng chỉ

Chúc mừng — bạn đã triển khai Cloudflare Zero Trust từ đầu đến cuối. 🎉

Module 8 — Cloudflare WAN (Connect Offices & Data Centers)

Goal: Connect entire sites — offices, data centers, cloud networks — to Cloudflare, so all their traffic (not just laptops with the WARP app) is routed and protected, replacing expensive MPLS links and site-to-site VPN meshes.

👤 Who does this Network team (needs router/firewall access)
⏱️ Time ~90 minutes per site
🎯 You'll finish with A site connected to Cloudflare over redundant tunnels, with traffic filtered by your policies
✋ Before you begin Enterprise network add-on (Cloudflare WAN) active; admin access to the site's router/firewall; your IP address plan

⚠️ This module touches production networking. Schedule a maintenance window, have console access to your router, and a rollback plan. Do one site first.

We'll do: (0) pre-flight MSS → (A) pick an on-ramp → (B) build tunnels → (C) routing → (D) security → (E) test & failover.


Part 0 — Pre-flight: MSS clamping (don't skip this!)

Because Cloudflare wraps your packets in an extra header, large packets can get silently dropped unless you cap the TCP segment size (MSS) on your edge device.

Set this on your router/firewall before bringing tunnels up:

Tunnel type Set MSS to
GRE 1436 bytes
IPsec 1360 bytes

Example (Cisco): ip tcp adjust-mss 1436 · (Juniper): set …​ tcp-mss 1436

⚠️ The classic symptom of forgetting this: plain http:// sites work but https:// sites hang or time out. If you see that later, come back here.


Part A — Choose your on-ramp

Pick how each site connects:

On-ramp Best for Notes
Cloudflare WAN Connector Branch offices, simplest A small Cloudflare appliance (hardware or virtual); near zero-touch
IPsec tunnel Sites with an existing firewall/router Encrypted; supports dynamic routing (BGP)
GRE tunnel Data centers, high throughput Not encrypted; supports BGP
CNI (Direct Connect) Private high-bandwidth link Physical/virtual cross-connect
Cloud (MNC) AWS/Azure/GCP VPCs Automated cloud on-ramp

This guide walks through an IPsec tunnel (most common with existing firewalls). GRE is nearly identical.


Part B — Build the tunnels (with redundancy)

⭐ Always build TWO tunnels from TWO separate routers at each site. Cloudflare's side is "anycast" — one tunnel already reaches every Cloudflare location — so redundancy is about protecting against your hardware failing.

Step B1 — Create the first IPsec tunnel in Cloudflare

  1. 👉 Cloudflare dashboard → Cloudflare WAN → Configuration → Tunnels.
  2. 👉 Click Create → IPsec tunnel.
  3. ⌨️ Fill in:
    Field Value
    Tunnel name hq-london-fw1
    Customer endpoint your firewall's public IP (leave blank if behind NAT)
    Cloudflare endpoint the anycast IP Cloudflare assigns you
    Interface address the small /31 Cloudflare provides for the tunnel
    Pre-shared key (PSK) click generate, or paste your own — store it safely
    Health check On (recommended)
  4. 👉 Click Save.

Step B2 — Match these settings on your firewall

Configure the matching IPsec tunnel on your device using exactly these:

Parameter Value
IKE version IKEv2 (only)
Phase 1 & 2 encryption AES-256-GCM-16
Phase 1 & 2 integrity / PRF SHA2-256
Phase 1 & 2 DH group (PFS) Group 20
Pre-shared key the PSK from B1
Cloudflare peer IP the anycast endpoint from B1

(NAT traversal on UDP 500→4500 is handled automatically.)

Step B3 — Repeat for the second tunnel

👉 Create hq-london-fw2 on your second router and a matching second tunnel in Cloudflare.

✅ Checkpoint: In Cloudflare WAN → Tunnels, both tunnels show Healthy (health checks passing).


Part C — Tell Cloudflare how to route your networks

  1. 👉 Cloudflare WAN → Configuration → Routes.
  2. Choose your approach:

Option 1 — Static routes (simple, stable sites)

  1. 👉 Click Create route.
  2. ⌨️ Fill in:
    Field Value
    Prefix your site's subnet, e.g. 10.10.0.0/16
    Tunnel / next hop hq-london-fw1
    Priority 100 (lower = preferred)
    Weight for sharing load across both tunnels (ECMP)
  3. 👉 Add a matching route via hq-london-fw2 (e.g. priority 100 too, for load-sharing, or 200 for standby).
  1. 👉 Enable BGP on the tunnel and configure an eBGP peer: your router's ASN, Cloudflare's ASN, and an MD5 password.
  2. 📺 Routes are now exchanged automatically — add a subnet at the site and it propagates without dashboard edits.

⚠️ Watch out: Plan your IP space. If two sites use overlapping subnets (e.g. both 192.168.1.0/24), Cloudflare WAN routing breaks. Re-IP or use unique ranges.

✅ Checkpoint: Your site subnets appear in the Magic routing table, reachable via the tunnels.


Part D — Add security & send traffic through Gateway

  1. Firewall the network traffic: 👉 go to Magic Firewall → Create rule to allow/deny traffic at the network layer (L3/L4). ⚠️ Until you add rules, this network traffic is unfiltered.
  2. Apply your web policies to the whole site: route the site's internet-bound traffic through Gateway so the DNS/HTTP/DLP policies from Modules 5–6 protect every device at the site — even those without the WARP app.
  3. Get alerted: 👉 Cloudflare Notifications → Add → Magic Tunnel Health → pick your tunnels → add recipients, so you hear about a tunnel problem before users do.

Part E — Test and prove failover

Test 1 — connectivity

  1. 👉 From a machine at the site, reach something across the tunnel (another site, or the internet via Cloudflare).
  2. 👉 Run curl http://ifconfig.me and curl https://ifconfig.me.
  3. 📺 Both should return quickly. If http works but https hangs → your MSS clamp is wrong (Part 0).

Test 2 — failover

  1. 👉 Disable the first tunnel (or take router 1 offline) in a controlled test.
  2. 📺 Traffic should re-converge over the second tunnel within seconds; the dashboard marks tunnel 1 unhealthy.
  3. 👉 Re-enable it and confirm it recovers.

✅ Checkpoint: Site connectivity works, HTTPS is healthy (MSS correct), failover works, and site traffic is filtered by Gateway. 🎉


✅ Module 8 complete!

You now have:

  • ✅ MSS clamping set correctly
  • ✅ Redundant tunnels (two routers) showing healthy
  • ✅ Routing configured (static or BGP) with a clean IP plan
  • ✅ Magic Firewall rules + site traffic flowing through Gateway
  • ✅ Verified connectivity and failover, plus health alerts

Quick troubleshooting

Problem Fix
https:// hangs, http:// works MSS clamp wrong — GRE 1436 / IPsec 1360 (Part 0)
Tunnel won't come up Phase 1/2 settings mismatch — re-check IKEv2 / AES-256-GCM-16 / SHA2-256 / DH 20 (Part B2)
Tunnel up but no traffic Missing/incorrect route, or overlapping subnets (Part C)
Intermittent drops Asymmetric routing or MTU mismatch — verify both tunnels' routes and MSS
Network traffic unfiltered Add Magic Firewall rules and/or route to Gateway (Part D)

🏁 You've reached the end of the onboarding!

Go back to the Master checklist and confirm every box is ticked. Final go-live items:

  • [ ] Logs flowing to your SIEM (Logpush)
  • [ ] Pilot validated, rollout expanded company-wide
  • [ ] Old VPN decommissioned for migrated apps
  • [ ] Renewal reminders set for any IdP client secrets / certificates

Congratulations — you've deployed Cloudflare Zero Trust end to end. 🎉

Nguồn cộng đồng — không phải tài liệu chính thức của Cloudflare: https://zerotrust.cfsase.workers.dev Community source — not an official Cloudflare publication: https://zerotrust.cfsase.workers.dev

Ví dụ triển khai (Cloudflare Resources) Deployment examples (Cloudflare Resources) Deployment examples (Cloudflare Resources)

Ví dụ chính thức từ Cloudflare Resources — gợi ý theo chủ đề bài học trong lộ trình này. Official examples from Cloudflare Resources — matched to this lesson within this path. Official examples from Cloudflare Resources — matched to this lesson within this path.

Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Access một ứng dụng web thông qua tên máy chủ riêng của nó mà không có Cloudflare One Client Access a web application via its private hostname without the Cloudflare One Client Access កម្មវិធីបណ្តាញតាមរយៈឈ្មោះម៉ាស៊ីនឯកជនរបស់វាដោយគ្មាន Cloudflare One Client

Với Cloudflare cách ly trình duyệt và các chính sách giải quyết, người dùng có thể kết nối với các ứng dụng dựa trên web riêng tư thông qua tên máy chủ riêng của họ.

With Cloudflare Browser Isolation and resolver policies, users can connect to private web-based applications via their private hostnames.

ជាមួយនឹង Cloudflare គោលការណ៍ញែកកម្មវិធីរុករក និងដំណោះស្រាយ អ្នកប្រើប្រាស់អាចភ្ជាប់ទៅកម្មវិធីដែលមានមូលដ្ឋានលើបណ្តាញឯកជនតាមរយៈឈ្មោះម៉ាស៊ីនឯកជនរបស់ពួកគេ។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Access và bảo mật cơ sở dữ liệu MySQL bằng cách sử dụng Cloudflare Tunnel và chính sách mạng Access and secure a MySQL database using Cloudflare Tunnel and network policies Access និងធានានូវមូលដ្ឋានទិន្នន័យ MySQL ដោយប្រើ Cloudflare Tunnel និងគោលការណ៍បណ្តាញ

Sử dụng mạng riêng của Cloudflare Tunnel, người dùng có thể kết nối với các ứng dụng dựa trên TCP/UDP, chẳng hạn như cơ sở dữ liệu. Bạn có thể thiết lập chính sách mạng thực hiện các điều khiển zero trust để xác định ai và những gì access có thể sử dụng các ứng dụng đó bằng cách sử dụng Cloudflare One Client.

Using Cloudflare Tunnel's private networks, users can connect to arbitrary non-browser based TCP/UDP applications, like databases. You can set up network policies that implement zero trust controls to define who and what can access those applications using the Cloudflare One Client.

ដោយប្រើបណ្តាញឯកជនរបស់ Cloudflare Tunnel អ្នកប្រើប្រាស់អាចភ្ជាប់ទៅកម្មវិធី TCP/UDP ដែលមានមូលដ្ឋានលើកម្មវិធីរុករកតាមអំពើចិត្ត ដូចជាមូលដ្ឋានទិន្នន័យជាដើម។ អ្នកអាចរៀបចំគោលការណ៍បណ្តាញដែលអនុវត្តការគ្រប់គ្រង zero trust ដើម្បីកំណត់ថាតើនរណា និងអ្វីដែលអាច access កម្មវិធីទាំងនោះដោយប្រើ Cloudflare One Client ។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Tạo API thành access D1 bằng cách sử dụng Proxy Worker Build an API to access D1 using a proxy Worker បង្កើត API ទៅ access D1 ដោយប្រើប្រូកស៊ីកម្មករ

Hướng dẫn này cho thấy cách tạo một API cho phép bạn chạy truy vấn an toàn chống lại một cơ sở dữ liệu D1. API có thể được sử dụng để tùy chỉnh các điều khiển access và/hoặc giới hạn các bảng có thể được truy vấn.

This tutorial shows how to create an API that allows you to securely run queries against a D1 database. The API can be used to customize access controls and/or limit what tables can be queried.

ការបង្រៀននេះបង្ហាញពីរបៀបបង្កើត API ដែលអនុញ្ញាតឱ្យអ្នកដំណើរការសំណួរដោយសុវត្ថិភាពប្រឆាំងនឹងមូលដ្ឋានទិន្នន័យ D1 ។ API អាចត្រូវបានប្រើដើម្បីប្ដូរតាមបំណង access គ្រប់គ្រង និង/ឬកំណត់តារាងដែលអាចសួរបាន។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Kết nối thông qua Cloudflare Access bằng cách sử dụng CLI Connect through Cloudflare Access using a CLI ការភ្ជាប់តាម Cloudflare Access ដោយប្រើ CLI

Công cụ dòng lệnh đám mây của Cloudflare cho phép bạn tương tác với các điểm cuối được bảo vệ bởi Cloudflare Access.

Cloudflare's cloudflared command-line tool allows you to interact with endpoints protected by Cloudflare Access.

Cloudflare ឧបករណ៍បន្ទាត់បញ្ជាទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យ

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម

Xem thêm ví dụ trong lộ trình → More examples in this path → More examples in this path →

Tài liệu Cloudflare Developers Cloudflare Developer docs Cloudflare Developer docs

Sản phẩm liên quan Related products Related products

Học xong hoặc muốn đổi hướng? Finished or want a different path? Finished or want a different path?

Ba lộ trình độc lập — mỗi lộ trình chỉ gồm bài học và tài liệu trong phạm vi đó. Chọn lộ trình khác khi sẵn sàng, không cần học song song. Three independent paths — each includes only lessons and materials for that scope. Switch when you are ready; no need to study paths in parallel. Three independent paths — each includes only lessons and materials for that scope. Switch when you are ready; no need to study paths in parallel.

Chưa chắc — làm bài chọn lộ trình Not sure — use the path selector Not sure — use the path selector · So sánh cả ba lộ trình Compare all three paths Compare all three paths