Lộ trình đang học Current learning path Current learning path

Cloudflare One Cloudflare One Cloudflare One

Bảo vệ users, access, SaaS và networks — follow-along từ tài khoản đến go-live. Secure users, access, SaaS, and networks — follow along from account to go-live. Secure users, access, SaaS, and networks — follow along from account to go-live.

Về trang lộ trình Track home Track home

Phần 9: Tham chiếu — thực hành tốt và sổ tay cấu hình Part 9: Reference — best practices and configuration runbook Part 9: Reference — best practices and configuration runbook · Bài 2/2 Lesson 2/2 មេរៀន 2/2

Sổ tay cấu hình (configuration runbook) Configuration runbook Configuration runbook

Cloudflare Zero Trust — Sổ tay cấu hình từng bước

Tài liệu thực hành đi kèm Hướng dẫn triển khai & thực hành tốt khi onboarding. Khi hướng dẫn giải thích tại sao và theo thứ tự nào, sổ tay này đưa đường dẫn điều hướng chính xác, thiết lập từng trường, lệnh, và snippet cấu hình để gõ hoặc nhấp. Chữ cái các phần ánh xạ tới các mục đánh số của hướng dẫn.

Bảng điều khiển Zero Trust: https://one.dash.cloudflare.com · Account: https://dash.cloudflare.com
Team domain https://<team-name>.cloudflareaccess.com (dùng trong mọi IdP callback URL)
Cập nhật lần cuối 2026-06-08

Cách đọc sổ tay này

  • Path: A → B → C nghĩa là nhấp lần lượt các menu dashboard đó.
  • Bảng trường liệt kê mọi thiết lập trên một màn hình, giá trị khuyến nghị, và ghi chú. Thay <placeholders> bằng giá trị của bạn.
  • ⭐ = giá trị thực hành tốt khuyến nghị · ⚠️ = sai lầm thường gặp.
  • Nhãn menu thay đổi; nếu một nhãn đã được di chuyển, dùng mục gần nhất (đường dẫn dưới Settings, Integrations, Access controls, Traffic policies).

A. Tạo tài khoản & thiết lập tổ chức (Hướng dẫn §2)

A.1 Kích hoạt Zero Trust

  1. Đăng nhập tại https://dash.cloudflare.com → left nav Zero Trust (hoặc vào https://one.dash.cloudflare.com).
  2. Choose a plan → nhập team name khi được nhắc → thêm phương thức thanh toán (bắt buộc kể cả trên Free).

A.2 Đặt team name

Path: Settings → Custom Pages / Settings → Team name and domain

Field Value Notes
Team name <your-company-short-name> ⭐ Ổn định, dễ nhận; trở thành https://<team-name>.cloudflareaccess.com. ⚠️ Đổi tên sau này làm hỏng mọi IdP callback URL + cấu hình MDM

A.3 Mặc định tổ chức cần đặt ngày đầu

Setting Path Recommended
Account MFA dash.cloudflare.com → My Profile → Authentication ⭐ Bật cho mọi admin trước bất cứ việc gì khác
Admin roles dash.cloudflare.com → Manage Account → Members ⭐ ≥2 Super Admins (break-glass); đặc quyền tối thiểu cho người khác
Custom login/block pages Settings → Custom Pages Gắn thương hiệu — giảm ticket helpdesk
Logpush (Access + Gateway) Settings → Logs → Logpush (hoặc Logs → Logpush) ⭐ Nối tới SIEM/R2/S3 ngay bây giờ, đừng để sau

Kiểm tra: https://<team-name>.cloudflareaccess.com hiện trang đăng nhập tổ chức; Settings → General hiện đúng gói + team name.


B. Tích hợp nhà cung cấp danh tính (IdP) (Hướng dẫn §3)

Mọi IdP dựa trên OIDC dùng cùng callback (redirect) URL của Cloudflare:

https://<your-team-name>.cloudflareaccess.com/cdn-cgi/access/callback

Google cũng cần Authorized JavaScript origin: https://<your-team-name>.cloudflareaccess.com

B.1 Microsoft Entra ID (Azure AD) — hướng dẫn đầy đủ

Bước 1 — Đăng ký ứng dụng (Entra admin center https://entra.microsoft.com)

  1. Applications → Enterprise applications → New application → Create your own application.
  2. Đặt tên (vd. Cloudflare Access) → chọn Register an application to integrate with Microsoft Entra ID (App you're developing) → Create. ⚠️ Không chọn gallery app.
  3. Dưới Redirect URI, platform = Web, value =
    https://<your-team-name>.cloudflareaccess.com/cdn-cgi/access/callback
    
  4. Register.
  5. Vào Applications → App registrations → All applications → ứng dụng của bạn. Sao chép Application (client) ID và Directory (tenant) ID.
  6. Client credentials → Add a certificate or secret → New client secret → đặt tên, đặt hạn → sao chép Value ngay (chỉ hiện một lần). ⚠️ Khi hết hạn, mọi đăng nhập thất bại — đặt lịch gia hạn.

Bước 2 — API permissions App registrations → All applications → ứng dụng của bạn → API permissions → Add a permission → Microsoft Graph → Delegated permissions, bật 7 quyền này:

Permission Purpose
email Email người dùng
offline_access Refresh tokens
openid Đăng nhập OIDC
profile Hồ sơ cơ bản
User.Read Đọc người dùng đang đăng nhập
Directory.Read.All Đọc directory
GroupMember.Read.All ⭐ Đọc thành viên nhóm (bắt buộc cho chính sách nhóm)

Rồi Add permissions → Grant admin consent.

Bước 3 — Thêm vào Cloudflare Zero Trust → Integrations → Identity providers → Add new identity provider → Azure AD:

Field Value
Application (client) ID từ Bước 1.5
Client secret từ Bước 1.6
Directory (tenant) ID từ Bước 1.5
⭐ Support Groups On — cho Cloudflare đọc thành viên nhóm Entra
Proof Key for Code Exchange (PKCE) On
Enable SCIM ⭐ On để đồng bộ user/group tự động + thu hồi session
Email claim vd. preferred_username nếu UPN ≠ email

Save → Test (xác nhận email + groups trong identity payload).

Phương án API: POST https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/access/identity_providers với {"name":"Entra ID","type":"azureAD","config":{"client_id":"…","client_secret":"…","directory_id":"…","support_groups":true}} (token cần Access: Organizations, Identity Providers, and Groups — Write).

B.2 Okta (OIDC) — hướng dẫn đầy đủ

  1. Trong Okta, tạo tích hợp ứng dụng OIDC → Web. Đặt Sign-in redirect URIs =
    https://<your-team-name>.cloudflareaccess.com/cdn-cgi/access/callback
    
  2. Trong tab General của ứng dụng, sao chép Client ID và Client secret.
  3. Trong Cloudflare Zero Trust → Integrations → Identity providers → Add new → Okta:
Field Value
App ID Okta Client ID
Client secret Okta Client secret
Okta account URL domain Okta của bạn, vd. https://my-company.okta.com
Authorization Server ID từ Okta (nếu dùng custom auth server)
Okta API token (optional) ⭐ Bắt buộc nếu bạn có >100 nhóm Okta (token chỉ đọc ngăn lookup nhóm thất bại)

Save → Test.

B.3 Google Workspace (OIDC) — hướng dẫn đầy đủ

  1. Trong Google Cloud Console → APIs & Services → Credentials → Create OAuth client ID → Web application.
  2. Authorized JavaScript origins: https://<your-team-name>.cloudflareaccess.com
  3. Authorized redirect URIs: https://<your-team-name>.cloudflareaccess.com/cdn-cgi/access/callback
  4. Create → sao chép OAuth Client ID và Client secret.
  5. Trong Cloudflare Identity providers → Add new → Google Workspace: nhập Client ID + Secret; cung cấp admin email / thiết lập domain-wide để Cloudflare đọc được Groups.
  6. Save → Test.

B.4 MFA toàn cục / độc lập

Path: Zero Trust → Access controls → Access settings

Setting Recommended
Allow MFA methods Chọn các phương thức đã duyệt
Authentication duration vd. 24h (ngắn hơn cho dữ liệu nhạy cảm)
Use identity provider MFA ⭐ On — tôn trọng claim amr của IdP, tránh hỏi hai lần
Apply global MFA settings by default ⭐ On

Kiểm tra mọi IdP: nút Test trả về email + groups mong đợi; vô hiệu hóa một user thử trong IdP thu hồi truy cập trong cửa sổ đồng bộ SCIM.


C. Đăng ký thiết bị — Cloudflare One Client (WARP) (Hướng dẫn §4)

C.1 Device enrollment permissions (cổng — làm việc này trước)

Path: Settings → WARP Client → Device enrollment permissions → Manage → Add a rule

Field Value Notes
Rule name Corporate employees
Rule action Allow (dùng Service Auth cho enrollment fleet/server bằng token)
Selector Emails ending in
Value @yourco.com
Authentication / Login methods chọn IdP của bạn ⚠️ Không có quy tắc khớp → người dùng thấy "you are not allowed to enroll"

Với enrollment fleet MDM im lặng, tạo quy tắc Service Auth và một service token (Access → Service Auth → Service Tokens). ⚠️ Service tokens yêu cầu quy tắc Service Auth — quy tắc Allow sẽ không hoạt động với chúng.

C.2 Thiết lập device profile

Path: Settings → WARP Client → Device settings → (sửa profile Default hoặc Add a profile)

Setting ⭐ Recommended (managed) Notes
Service mode Gateway with WARP Lọc L3/L7 + DNS đầy đủ (enterprise chuẩn)
Switch lock On (managed) Ngăn người dùng tắt WARP
Auto connect 1–5 phút Bật lại sau ngắt ngắn (vd. captive portal). Giá trị 0 = giữ tắt cho đến khi người dùng kết nối lại
Captive portal detection On Cho phép người dùng tới trang đăng nhập khách sạn/sân bay
Allowed device protocols theo chính sách vd. allow/deny WARP trên protocol cụ thể
Mode switch / admin override Locked (managed)

Tạo profile riêng cho Servers, BYOD, Contractors và khớp chúng bằng selector posture/identity.

C.3 Split Tunnels

Path: trong một device profile → Split Tunnels

Scenario Mode What to configure
Laptop được quản lý Exclude (mặc định) Mọi thứ đi tunnel trừ các ngoại lệ được liệt kê. Danh sách mặc định đã loại 100.64.0.0/10 (CGNAT dùng bởi Cloudflare One). ⭐ Thêm lại mọi dải RFC-1918/CGNAT local bạn thực sự dùng
BYOD / cá nhân Include ⭐ Chỉ IP/domain công ty được liệt kê đi tunnel — lưu lượng cá nhân vẫn riêng tư. Thêm domain ứng dụng + CIDR nội bộ

⚠️ Mục Include quá rộng (hoặc loại trừ subnet local bạn dựa vào) có thể black-hole lưu lượng LAN/Wi-Fi khi chuyển mạng — test Ethernet↔Wi-Fi.

C.4 Phân phối Cloudflare root CA (bắt buộc cho HTTPS filtering / DLP / AI prompt inspection)

Path: Settings → Resources (tải chứng chỉ Cloudflare) → đẩy tới trust store OS/trình duyệt qua MDM trước khi bật TLS decryption (§F.3). ⚠️ Decryption trước khi CA được tin cậy làm gãy HTTPS trên toàn fleet.

C.5 Triển khai MDM (im lặng, đã xác thực trước)

Đẩy client kèm tham số. Windows dùng mdm.xml; macOS dùng com.cloudflare.warp.plist. ⚠️ Thiết lập thiết bị local ưu tiên hơn thiết lập dashboard.

Tham số phổ biến

Parameter Type ⭐ Value / purpose
organization string Team name của bạn (bắt buộc cho managed enrollment)
auth_client_id string Service-token client ID, vd. 88bf3b6d…​.access
auth_client_secret string Service-token secret. ⚠️ Token cần quyền enrollment Service Auth, không phải Allow
service_mode string warp (Gateway with WARP)
onboarding boolean false → ẩn màn hình chào (cài im lặng)
auto_connect integer 1 (kết nối ngay; 0 = cho phép tắt vô thời hạn). ⚠️ Thay enabled đã deprecated — bạn phải gỡ enabled nếu dùng cái này
switch_locked boolean true trên thiết bị quản lý
display_name string Biệt danh tổ chức trong GUI client (bắt buộc trong mảng configs)
support_url string Liên kết helpdesk hiện trong client
unique_client_id string Định danh thiết bị ổn định cho ánh xạ posture/serial
enable_post_quantum boolean true để bật crypto tunnel PQ
enable_netbt boolean false (mặc định; chỉ bật cho ứng dụng NetBIOS legacy)
environment string normal hoặc fedramp_high
organization_configs / configs[] dict/array Chuyển multi-org / config (client mới hơn)

Ví dụ macOS .plist (service-token enrollment, im lặng):

<dict>
  <key>organization</key>          <string>your-team-name</string>
  <key>auth_client_id</key>        <string>88bf3b6d86161464f6509f7219099e57.access</string>
  <key>auth_client_secret</key>    <string>bdd31cbc4dec990953e39163fbbb194c93313ca9f0a6e420346af9d326b1d2a5</string>
  <key>service_mode</key>          <string>warp</string>
  <key>onboarding</key>            <false/>
  <key>auto_connect</key>          <integer>1</integer>
  <key>switch_locked</key>         <true/>
  <key>support_url</key>           <string>https://help.yourco.com</string>
</dict>

Windows mdm.xml tương đương dùng cùng các key trong XML <RegistrationData>.

C.6 Device posture checks

Path: Settings → WARP Client → Device posture (hoặc Reusable components → Posture checks → Add)

Category Examples Usable in
Client checks (Cloudflare One Client) OS version, Disk encryption, Firewall, Client certificate, File/Registry/Application present, Serial number list, Domain joined Access và Gateway
Service-to-service (bên thứ ba) CrowdStrike, SentinelOne, Microsoft Intune, Tanium Access (⚠️ Tanium không được hỗ trợ trong Gateway)
Access integrations (các loại) Chỉ Access

⭐ Với kiểm tra phiên bản OS dùng latest qualified stable (vd. macOS ≥ 15.1), không phải bản mới nhất tuyệt đối, để một bản OS ra cùng ngày không khóa người dùng.

Kiểm tra: thiết bị hiện Connected với đúng profile; xuất hiện dưới My Team → Devices; một posture check (vd. mã hóa đĩa) báo đúng.


D. Kết nối ứng dụng/mạng nội bộ — Cloudflare Tunnel & Connector (Hướng dẫn §5.1)

Path: Networks → Tunnels → Create a tunnel → Cloudflared → đặt tên → Save → sao chép lệnh cài cho OS của bạn. Rồi ánh xạ route Public Hostname hoặc Private Network trong dashboard.

Cài connector một dòng (token từ dashboard):

# macOS
brew install cloudflared && sudo cloudflared service install <YOUR_TUNNEL_TOKEN>
# Linux (Debian/RPM package already installed)
sudo cloudflared service install <YOUR_TUNNEL_TOKEN>

D.2 Cloudflare Tunnel qua CLI (quản lý local)

cloudflared tunnel login                      # authenticate + pick a zone
cloudflared tunnel create <NAME>              # creates tunnel + credentials JSON
cloudflared tunnel list                       # note the tunnel UUID

~/.cloudflared/config.yml:

tunnel: <TUNNEL-UUID>
credentials-file: /root/.cloudflared/<TUNNEL-UUID>.json
ingress:
  - hostname: wiki.yourco.com
    service: http://localhost:3000
  - hostname: ssh.yourco.com
    service: ssh://localhost:22
  - service: http_status:404          # required catch-all
cloudflared tunnel route dns <NAME> wiki.yourco.com   # create the DNS record
cloudflared tunnel ingress validate                   # validate config
cloudflared tunnel run <NAME>                          # test in foreground
sudo cloudflared service install                       # run as a service (production)

⭐ Chạy hai replica cloudflared (host khác nhau) mỗi tunnel để có sẵn sàng cao.

D.3 WARP Connector (site-to-site / mesh trên host Linux)

sudo warp-cli connector new <TOKEN> && sudo warp-cli connect
warp-cli status        # expect "Status update: Connected"

E. ZTNA — Ứng dụng & chính sách Access (Hướng dẫn §5)

E.1 Thêm ứng dụng self-hosted

Path: Access → Applications → Add an application → Self-hosted

Field Value / recommendation
Application name Internal Wiki
Session Duration ⭐ 24h chuẩn; 15m–No duration cho ứng dụng crown-jewel
Application domain wiki.yourco.com (phải resolve tới tunnel/zone)
Identity providers chọn IdP được phép cho ứng dụng này
Instant Auth On nếu một IdP duy nhất (bỏ qua chooser)
App Launcher visibility On (hiện trong cổng người dùng)
Accept all available identity providers Off nếu bạn scoped theo ứng dụng

E.2 Xây chính sách Access

Path: trong ứng dụng → Policies → Add a policy

Field Value
Policy name ⭐ Allow — Full-time employees (dùng quy ước đặt tên tái sử dụng)
Action Allow / Block / Bypass / Service Auth
Session duration kế thừa hoặc ghi đè

Rules — kết hợp Include / Require / Exclude (Exclude ghi đè tất cả):

Rule group Selector Operator Value
Include IdP Groups in Engineering
Require Device Posture in Disk encryption, Firewall on
Require Authentication Method in mfa
Exclude Emails (List) in List: Offboarding

⭐ Thêm chính sách thứ hai, ưu tiên thấp nhất Block — Everyone (Action = Block, Include = Everyone) làm lưới default-deny. ⚠️ Chính sách đánh giá từ trên xuống; giữ chính sách Block/Exclude phía trên Allow rộng.

Bảng tra Selector (dùng nhiều nhất):

Selector Use it for
Emails / Emails ending in Người dùng / domain cụ thể
IdP Groups ⭐ Truy cập theo nhóm (cần group claims)
Device Posture Yêu cầu thiết bị tuân thủ
Gateway Yêu cầu lưu lượng đã đi through Gateway (client/RBI/WAN site)
Country / IP ranges Hạn chế geo / mạng
Authentication Method / MFA Yêu cầu auth mạnh
mTLS Certificate Service Auth (máy-với-máy)
Cloudflare Account Member Giới hạn thành viên tài khoản của bạn

E.3 Khối xây dựng tái sử dụng (làm thế này, không viết rule từng ứng dụng)

Component Path Use
Access Groups Access controls → Policies → Groups → Add a group ⭐ Khối rule có tên, tái sử dụng (vd. Secure employees = nhóm + 3 posture checks). Tham chiếu trên nhiều ứng dụng
Lists Reusable components → Lists Emails, serial number thiết bị, IP — cập nhật qua UI hoặc API (tích hợp HR/MDM)
Posture checks Reusable components → Posture checks Định nghĩa một lần, dùng trong Access và Gateway

E.4 RBI fallback cho thiết bị không quản lý

Giữ Allow bình thường (nhân viên tuân thủ) và thêm chính sách Gateway HTTP với action Isolate khớp cùng hostname ứng dụng, để thiết bị không tuân thủ nhận phiên remote-browser thay vì bị chặn cứng.

Kiểm tra: người dùng được phép tới được ứng dụng sau đăng nhập; người không thuộc nhóm bị chặn; Access → Logs (Logpush) hiện allow/block kèm identity + posture.


F. Secure Web Gateway (Gateway) (Hướng dẫn §6)

Xây chính sách từ dưới lên stack: DNS → Network → HTTP.

F.1 Chính sách DNS (bắt đầu ở đây)

Path: Gateway → Firewall Policies → DNS → Add a policy

Field Value
Policy name Block security threats
Selector Security Categories
Operator in
Value ⭐ Malware, Phishing, Command & Control, Cryptomining, DGA Domains, DNS Tunneling, New Domains
Action Block

Thêm chính sách DNS thứ hai cho Content Categories (Adult, Gambling, v.v.) theo AUP của bạn.

DNS Locations (site không có client): Gateway → DNS Locations → Add a location → trỏ resolver của mạng tới các endpoint IPv4/IPv6, DoH (https://<id>.cloudflare-gateway.com/dns-query), hoặc DoT được hiện.

F.2 Chính sách Network (L4)

Path: Gateway → Firewall Policies → Network → Add a policy

Example Selector / Operator / Value Action
Chặn SMTP outbound từ client Destination Port in 25 Block
Hạn chế egress RDP Destination Port in 3389 + Identity not in IT Block

F.3 TLS decryption + chính sách HTTP

  1. Bật decryption: Settings → Network → Firewall → TLS decryption → On. ⚠️ Yêu cầu Cloudflare root CA trên thiết bị (§C.4).
  2. Tạo ngoại lệ Do Not Inspect TRƯỚC (Gateway → Firewall Policies → HTTP → Add a policy, Action = Do Not Inspect):
Exception Selector / Value
Ứng dụng cert-pinned Application in Do Not Inspect (loại ứng dụng Cloudflare duy trì)
Microsoft 365 ⭐ Bật tích hợp lưu lượng one-click Microsoft 365 (tự bypass M365)
Ngân hàng / ứng dụng native Application hoặc Domain in danh sách cert-pinned của bạn
  1. Ví dụ chính sách HTTP filtering:
Field Value
Policy name Block risky uploads
Selector Application in <risky app> · hoặc Content Category · hoặc File Type
Action Block / Isolate / Allow / Do Not Scan
  1. Application granular controls (trong một chính sách HTTP): cho phép ứng dụng nhưng chặn hành động cụ thể — vd. ChatGPT → block File upload, Google Drive → block Download to non-corporate tenant. Đây cũng là móc cho AI controls (§H).

Kiểm tra: duyệt một danh mục bị chặn → block page của Cloudflare; Gateway → Logs hiện mục HTTPS với chi tiết decrypted (chứng minh CA + decryption).


G. Data Loss Prevention (DLP) (Hướng dẫn §7 — Enterprise)

G.1 Chọn / xây một profile

Path: DLP → DLP Profiles

  • Predefined: mở vd. Credentials and Secrets, Financial Information, PII → bật/tắt từng entry.
  • Custom: Create profile → thêm detection entries (detector định sẵn, custom regex, dictionaries, dataset EDM, nhãn Microsoft Purview).

G.2 Tinh chỉnh độ nhạy (theo entry / profile)

Setting Where ⭐ Recommendation
Confidence threshold theo từng detection entry Low / Medium / High (tăng bởi proximity keywords, vd. "SSN" gần một số 9 chữ số)
Minimum match count theo profile/entry vd. 10 → chỉ kích hoạt ở 11+ khớp (giảm nhiễu)
AI context analysis DLP → Settings On (mô hình pretrained điều chỉnh confidence; chỉ HTTP/HTTPS)
OCR DLP → Settings On để quét văn bản trong ảnh (.jpg/.png, 4 KB–1 MB)

Profile PII Record đặc biệt: nó chỉ kích hoạt khi ≥3 entry duy nhất xuất hiện gần nhau — kiểm soát false-positive tích hợp.

G.3 Thực thi qua chính sách Gateway HTTP (⭐ mẫu hai chính sách)

Path: Gateway → Firewall Policies → HTTP → Add a policy, dùng selector DLP Profile.

# Selector / Value Action Purpose
1 DLP Profile in Financial Info (Low confidence) Allow (+ log) ⭐ Visibility / baseline
2 DLP Profile in Financial Info (High confidence) + Destination Domain in dropbox.com, wetransfer.com + User Group in Finance Block Thực thi, đã scoped

⭐ Chạy monitor (Allow+log) 1–2 tuần, rồi bật Block. ⚠️ Luôn scoped theo đích/ứng dụng/nhóm — một profile Credentials rộng trên mọi lưu lượng ngập false positive. ⚠️ Không TLS decryption → DLP không thấy body HTTPS.

Kiểm tra: upload một pattern thử vô hại (SSN giả / số thẻ thử) tới đích được giám sát → detection xuất hiện trong Gateway → Logs / DLP với profile đã khớp + confidence.


H. Kiểm soát an toàn AI (Hướng dẫn §8)

H.1 Phát hiện shadow AI

Path: Gateway → Analytics → Shadow IT Discovery → xem danh mục ứng dụng Generative AI → đánh dấu ứng dụng Approved / Unapproved.

H.2 Quản trị việc dùng ứng dụng AI (allow + restrict, đừng block)

Path: Gateway → Firewall Policies → HTTP → Add a policy

Field Value
Selector Application in ChatGPT, Google Gemini, Claude, Perplexity
Application granular controls ⭐ Block File upload / hạn chế hành động (giữ ứng dụng dùng được)
DLP Profile thêm AI Prompt: PII / AI Prompt: AI Security
Action Allow (kèm granular block) hoặc Block khi khớp DLP

H.3 AI Prompt Protection (DLP cho prompt)

Path: DLP → Detection entries → AI prompt topics → bật chủ đề Content (PII, Source Code, Credentials & Secrets, Financial Information, Customer Data) và chủ đề Intent (jailbreak, malicious-code, PII-extraction). Hoặc chọn một predefined profile AI Prompt, rồi tham chiếu nó trong chính sách HTTP H.2. ⭐ Bắt đầu ở chế độ monitor.

H.4 DLP for AI Gateway (AI programmatic/API — không cần decryption)

Path: AI → AI Gateway → gateway của bạn → Features → DLP → Set up → gắn DLP profiles. Quét văn bản request + response tới nhà cung cấp AI mà không cần Gateway HTTP filtering hay TLS decryption.

H.5 AI Security for Apps (WAF — cho AI bạn phơi bày)

Path: your zone → Security → Settings / WAF → Detections → AI Security for Apps → bật detection prompt injection + unsafe topic, rồi viết WAF custom rule tác động trên các trường detection. Bổ trợ DLP (tấn công tầng mô hình vs. phát hiện dữ liệu).

H.6 MCP server portals (quản trị AI agents)

Path: Access → AI controls → MCP server portals → thêm một portal → xuất bản/cổng kiểm soát/đổi tên tools sau một chính sách Access.


I. Cloudflare WAN (Hướng dẫn §9 — Enterprise)

I.0 Pre-flight: MSS clamping (đặt trên edge TRƯỚC khi đưa tunnel lên)

On-ramp TCP MSS clamp Why
GRE 1,436 bytes (interface nội bộ) Chỗ cho GRE header
IPsec tối đa 1,360 bytes Chỗ cho overhead ESP/mã hóa

Cú pháp vendor: Cisco ip tcp adjust-mss 1436, Juniper tcp-mss 1436. ⚠️ Triệu chứng khi bỏ sót clamp: http:// hoạt động nhưng https:// treo — test bằng curl http://ifconfig.me vs curl https://ifconfig.me.

I.1 Thêm IPsec tunnel

Path: Cloudflare WAN → Configuration → Tunnels → Create → IPsec tunnel

Field Value
Tunnel name site-a-primary
Customer endpoint IP public của router (bỏ nếu sau NAT)
Cloudflare endpoint anycast IP được gán cho tài khoản của bạn
Interface address /31 (hoặc /30) Cloudflare cung cấp cho tunnel
Pre-shared key (PSK) tạo / dán; lưu trong secrets manager
Health check On ⭐ (rate Low/Mid/High; target = tunnel interface)
Replay protection Off trừ khi thiết bị không tắt được (thì On)

Tham số IKEv2 được hỗ trợ (khớp chúng trên thiết bị của bạn):

Parameter Value
IKE version IKEv2 only
Phase 1 encryption AES256-GCM-16
Phase 2 encryption AES256-GCM-16
Phase 1 integrity / PRF SHA2-256
Phase 2 integrity SHA2-256
Phase 1 DH group 20
Phase 2 DH group (PFS) 20
NAT-T UDP 500 → 4500 (auto)

I.2 Thêm GRE tunnel (phương án khác)

Cùng path → GRE tunnel. Cung cấp Customer endpoint, Cloudflare anycast endpoint, interface address (/31), và bật health checks. GRE không trạng thái (không mã hóa) — dùng IPsec khi cần bảo mật nội dung.

I.3 Cấu hình routing

Path: Cloudflare WAN → Configuration → Routes

Approach How Use
Static routes Thêm prefix (subnet site/DC) → next-hop = tunnel → đặt Priority (thấp hơn = ưu tiên) + Weight cho ECMP Site đơn giản, ổn định
BGP (over GRE/IPsec) Bật BGP trên tunnel; cấu hình eBGP peer + ASN + auth MD5 ⭐ Đa site / động; tự thêm/gỡ route

⭐ Dư thừa: tạo hai tunnel từ hai router riêng. Đầu Cloudflare là anycast (một tunnel đã tới mọi PoP Cloudflare), nên độ bền là về phần cứng on-prem của bạn. ⚠️ Lên kế hoạch không gian IP — subnet chồng lấn giữa các site làm gãy Magic routing.

I.4 Thêm bảo mật + gửi lưu lượng site tới Gateway

  • Magic Firewall: Magic Firewall → Add rule (allow/deny L3/L4 trên lưu lượng Cloudflare WAN). ⚠️ Lưu lượng mạng không được lọc cho đến khi bạn thêm rule.
  • Route Internet-bound traffic to Gateway để site không client nhận cùng chính sách DNS/Network/HTTP/DLP như người dùng có client.

I.5 Cảnh báo health

Path: Notifications → Add → Magic Tunnel Health → chọn tunnel (lọc theo GRE / IPsec / CNI) → đặt người nhận.

Kiểm tra: tunnel hiện Healthy; route xuất hiện trong Magic routing table; curl https://ifconfig.me thành công (MSS đúng); tắt một tunnel failover sang cái kia; lưu lượng Internet của site được Gateway lọc.


J. Lệnh kiểm tra & khắc phục sự cố

# Cloudflare One Client (WARP) state
warp-cli status                 # expect: Connected
warp-cli settings               # mode, org, split-tunnel
warp-cli account                # enrolled org / posture
# Confirm you are egressing via Cloudflare (managed device)
curl https://www.cloudflare.com/cdn-cgi/trace/   # look for warp=on, gateway=on

# DNS over HTTPS location test
curl -H 'accept: application/dns-json' \
  'https://<location-id>.cloudflare-gateway.com/dns-query?name=example.com&type=A'

# Cloudflare WAN MSS / tunnel sanity
curl http://ifconfig.me         # works
curl https://ifconfig.me        # hangs => MSS clamp too high (GRE 1436 / IPsec 1360)

# Cloudflare Tunnel
cloudflared tunnel info <NAME>          # connector + connection status
cloudflared tunnel ingress validate     # config check
Symptom Likely cause Fix
"Not allowed to enroll" Không có quy tắc device enrollment permission Thêm quy tắc Allow/Service-Auth (§C.1)
HTTPS gãy sau decryption Root CA chưa được tin cậy Đẩy CA qua MDM, rồi decrypt (§C.4)
Chính sách nhóm không bao giờ khớp Thiếu group claims / không SCIM Chạy lại IdP Test; bật Support Groups + SCIM (§B)
Ứng dụng được allow trong khi phải bị block Thứ tự chính sách Đưa Block/Exclude lên trên Allow rộng (§E.2)
Selector DLP bị xám Không phải Enterprise / vai trò Xác minh gói + vai trò admin
https:// treo trên Cloudflare WAN MSS clamp GRE 1,436 / IPsec 1,360 (§I.0)

K. Tham chiếu thiết lập nhanh (một màn hình)

Thing Exact value
Zero Trust dashboard https://one.dash.cloudflare.com
Team domain https://<team-name>.cloudflareaccess.com
OIDC callback URL https://<team-name>.cloudflareaccess.com/cdn-cgi/access/callback
Google JS origin https://<team-name>.cloudflareaccess.com
Entra Graph delegated perms email, offline_access, openid, profile, User.Read, Directory.Read.All, GroupMember.Read.All
Okta read-only API token Bắt buộc nếu >100 groups
WARP mode (enterprise) Gateway with WARP
Split tunnel — managed / BYOD Exclude / Include
Default excluded CGNAT 100.64.0.0/10
Service-token enrollment perm Service Auth (không phải Allow)
MDM silent install keys onboarding=false, auto_connect=1, switch_locked=true
OCR image size .jpg/.png, 4 KB–1 MB
PII Record threshold ≥3 entry duy nhất ở gần nhau
Cloudflare WAN IPsec ciphers IKEv2 · AES256-GCM-16 · SHA2-256 · DH group 20
MSS clamp GRE 1436 / IPsec 1360
IPsec NAT-T UDP 500 → 4500

Soạn 2026-06-08. Tên trường và đường dẫn menu chính xác phản ánh tài liệu Cloudflare hiện hành (Cloudflare One / Cloudflare WAN) và có thể thay đổi; xác minh trên dashboard của bạn và xác nhận entitlement Enterprise (DLP, advanced posture, Cloudflare WAN) trước khi triển khai production. Thay mọi <placeholders> và secret ví dụ bằng giá trị của bạn — không bao giờ tái sử dụng token mẫu được hiện.

Cloudflare Zero Trust — Step-by-Step Configuration Runbook

Hands-on companion to the Implementation & Best-Practice Onboarding Guide. Where the guide explains why and in what order, this runbook gives the exact navigation paths, field-by-field settings, commands, and config snippets to type or click. Section letters map to the guide's numbered sections.

Dashboards Zero Trust: https://one.dash.cloudflare.com · Account: https://dash.cloudflare.com
Team domain https://<team-name>.cloudflareaccess.com (used in every IdP callback URL)
Last reviewed 2026-06-08

How to read this runbook

  • Path: A → B → C means click through those dashboard menus in order.
  • Field tables list every setting on a screen, its recommended value, and notes. Replace <placeholders> with your values.
  • ⭐ = recommended best-practice value · ⚠️ = common mistake.
  • Menu labels evolve; if a label moved, use the nearest equivalent (paths under Settings, Integrations, Access controls, Traffic policies).

A. Account creation & organization setup (Guide §2)

A.1 Activate Zero Trust

  1. Sign in at https://dash.cloudflare.com → left nav Zero Trust (or go to https://one.dash.cloudflare.com).
  2. Choose a plan → enter a team name when prompted → add a payment method (required even on Free).

A.2 Set the team name

Path: Settings → Custom Pages / Settings → Team name and domain

Field Value Notes
Team name <your-company-short-name> ⭐ Stable, recognizable; becomes https://<team-name>.cloudflareaccess.com. ⚠️ Renaming later breaks every IdP callback URL + MDM config

A.3 Organization defaults to set on day one

Setting Path Recommended
Account MFA dash.cloudflare.com → My Profile → Authentication ⭐ Enable for all admins before anything else
Admin roles dash.cloudflare.com → Manage Account → Members ⭐ ≥2 Super Admins (break-glass); least-privilege for others
Custom login/block pages Settings → Custom Pages Brand them — reduces helpdesk tickets
Logpush (Access + Gateway) Settings → Logs → Logpush (or Logs → Logpush) ⭐ Wire to SIEM/R2/S3 now, not later

Validate: https://<team-name>.cloudflareaccess.com shows your org login page; Settings → General shows the correct plan + team name.


B. Identity provider (IdP) integration (Guide §3)

All OIDC-based IdPs use the same Cloudflare callback (redirect) URL:

https://<your-team-name>.cloudflareaccess.com/cdn-cgi/access/callback

Google also needs the Authorized JavaScript origin: https://<your-team-name>.cloudflareaccess.com

B.1 Microsoft Entra ID (Azure AD) — full walkthrough

Step 1 — Register the app (Entra admin center https://entra.microsoft.com)

  1. Applications → Enterprise applications → New application → Create your own application.
  2. Name it (e.g. Cloudflare Access) → select Register an application to integrate with Microsoft Entra ID (App you're developing) → Create. ⚠️ Do not pick a gallery app.
  3. Under Redirect URI, platform = Web, value =
    https://<your-team-name>.cloudflareaccess.com/cdn-cgi/access/callback
    
  4. Register.
  5. Go to Applications → App registrations → All applications → your app. Copy Application (client) ID and Directory (tenant) ID.
  6. Client credentials → Add a certificate or secret → New client secret → name it, set an expiry → copy the Value immediately (shown once). ⚠️ When it expires, all logins fail — calendar the renewal.

Step 2 — API permissions App registrations → All applications → your app → API permissions → Add a permission → Microsoft Graph → Delegated permissions, enable these 7:

Permission Purpose
email User email
offline_access Refresh tokens
openid OIDC sign-in
profile Basic profile
User.Read Read the signed-in user
Directory.Read.All Read directory
GroupMember.Read.All ⭐ Read group membership (required for group policies)

Then Add permissions → Grant admin consent.

Step 3 — Add to Cloudflare Zero Trust → Integrations → Identity providers → Add new identity provider → Azure AD:

Field Value
Application (client) ID from Step 1.5
Client secret from Step 1.6
Directory (tenant) ID from Step 1.5
⭐ Support Groups On — lets Cloudflare read Entra group membership
Proof Key for Code Exchange (PKCE) On
Enable SCIM ⭐ On for auto user/group sync + session revocation
Email claim e.g. preferred_username if UPN ≠ email

Save → Test (confirms email + groups in the identity payload).

API alternative: POST https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/access/identity_providers with {"name":"Entra ID","type":"azureAD","config":{"client_id":"…","client_secret":"…","directory_id":"…","support_groups":true}} (token needs Access: Organizations, Identity Providers, and Groups — Write).

B.2 Okta (OIDC) — full walkthrough

  1. In Okta, create an OIDC → Web app integration. Set Sign-in redirect URIs =
    https://<your-team-name>.cloudflareaccess.com/cdn-cgi/access/callback
    
  2. In the app's General tab, copy the Client ID and Client secret.
  3. In Cloudflare Zero Trust → Integrations → Identity providers → Add new → Okta:
Field Value
App ID Okta Client ID
Client secret Okta Client secret
Okta account URL your Okta domain, e.g. https://my-company.okta.com
Authorization Server ID from Okta (if using a custom auth server)
Okta API token (optional) ⭐ Required if you have >100 Okta groups (read-only token prevents group lookup failures)

Save → Test.

B.3 Google Workspace (OIDC) — full walkthrough

  1. In Google Cloud Console → APIs & Services → Credentials → Create OAuth client ID → Web application.
  2. Authorized JavaScript origins: https://<your-team-name>.cloudflareaccess.com
  3. Authorized redirect URIs: https://<your-team-name>.cloudflareaccess.com/cdn-cgi/access/callback
  4. Create → copy the OAuth Client ID and Client secret.
  5. In Cloudflare Identity providers → Add new → Google Workspace: enter Client ID + Secret; provide the admin email / domain-wide settings so Cloudflare can read Groups.
  6. Save → Test.

B.4 Global / independent MFA

Path: Zero Trust → Access controls → Access settings

Setting Recommended
Allow MFA methods Select your approved methods
Authentication duration e.g. 24h (shorter for sensitive)
Use identity provider MFA ⭐ On — honors IdP amr claim, avoids double-prompt
Apply global MFA settings by default ⭐ On

Validate every IdP: the Test button returns the expected email + groups; disabling a test user in the IdP revokes access within the SCIM sync window.


C. Device enrollment — Cloudflare One Client (WARP) (Guide §4)

C.1 Device enrollment permissions (the gate — do this first)

Path: Settings → WARP Client → Device enrollment permissions → Manage → Add a rule

Field Value Notes
Rule name Corporate employees
Rule action Allow (use Service Auth for token-based fleet/server enrollment)
Selector Emails ending in
Value @yourco.com
Authentication / Login methods select your IdP(s) ⚠️ No matching rule → users see "you are not allowed to enroll"

For silent MDM fleet enrollment, create a Service Auth rule and a service token (Access → Service Auth → Service Tokens). ⚠️ Service tokens require a Service Auth rule — an Allow rule will not work for them.

C.2 Device profile settings

Path: Settings → WARP Client → Device settings → (edit Default profile or Add a profile)

Setting ⭐ Recommended (managed) Notes
Service mode Gateway with WARP Full L3/L7 + DNS filtering (standard enterprise)
Switch lock On (managed) Prevents users disabling WARP
Auto connect 1–5 min Re-enables after brief disconnect (e.g. captive portal). Value 0 = stays off until user reconnects
Captive portal detection On Lets users reach hotel/airport login pages
Allowed device protocols per policy e.g. allow/deny WARP over specific protocols
Mode switch / admin override Locked (managed)

Create separate profiles for Servers, BYOD, Contractors and match them by posture/identity selectors.

C.3 Split Tunnels

Path: within a device profile → Split Tunnels

Scenario Mode What to configure
Managed laptops Exclude (default) Everything tunnels except listed exceptions. Default list already excludes 100.64.0.0/10 (CGNAT used by Cloudflare One). ⭐ Add back any local RFC-1918/CGNAT ranges you actually use
BYOD / personal Include ⭐ Only listed corporate IPs/domains tunnel — personal traffic stays private. Add your app domains + private CIDRs

⚠️ Over-broad Include entries (or excluding local subnets you rely on) can black-hole LAN/Wi-Fi traffic when switching networks — test Ethernet↔Wi-Fi.

C.4 Distribute the Cloudflare root CA (required for HTTPS filtering / DLP / AI prompt inspection)

Path: Settings → Resources (download the Cloudflare certificate) → push to OS/browser trust stores via MDM before enabling TLS decryption (§F.3). ⚠️ Decryption before the CA is trusted breaks HTTPS fleet-wide.

C.5 MDM deployment (silent, pre-authenticated)

Push the client with parameters. Windows uses mdm.xml; macOS uses com.cloudflare.warp.plist. ⚠️ Local device settings take precedence over dashboard settings.

Common parameters

Parameter Type ⭐ Value / purpose
organization string Your team name (required for managed enrollment)
auth_client_id string Service-token client ID, e.g. 88bf3b6d…​.access
auth_client_secret string Service-token secret. ⚠️ Token needs Service Auth enrollment permission, not Allow
service_mode string warp (Gateway with WARP)
onboarding boolean false → suppress welcome screens (silent install)
auto_connect integer 1 (connect immediately; 0 = allow off indefinitely). ⚠️ Replaces deprecated enabled — you must remove enabled if you use this
switch_locked boolean true on managed devices
display_name string Org nickname in the client GUI (required inside a configs array)
support_url string Helpdesk link shown in client
unique_client_id string Stable device identifier for posture/serial mapping
enable_post_quantum boolean true to enable PQ tunnel crypto
enable_netbt boolean false (default; only enable for legacy NetBIOS apps)
environment string normal or fedramp_high
organization_configs / configs[] dict/array Multi-org / config switching (newer clients)

macOS .plist example (service-token enrollment, silent):

<dict>
  <key>organization</key>          <string>your-team-name</string>
  <key>auth_client_id</key>        <string>88bf3b6d86161464f6509f7219099e57.access</string>
  <key>auth_client_secret</key>    <string>bdd31cbc4dec990953e39163fbbb194c93313ca9f0a6e420346af9d326b1d2a5</string>
  <key>service_mode</key>          <string>warp</string>
  <key>onboarding</key>            <false/>
  <key>auto_connect</key>          <integer>1</integer>
  <key>switch_locked</key>         <true/>
  <key>support_url</key>           <string>https://help.yourco.com</string>
</dict>

The equivalent Windows mdm.xml uses the same keys in <RegistrationData> XML.

C.6 Device posture checks

Path: Settings → WARP Client → Device posture (or Reusable components → Posture checks → Add)

Category Examples Usable in
Client checks (Cloudflare One Client) OS version, Disk encryption, Firewall, Client certificate, File/Registry/Application present, Serial number list, Domain joined Access and Gateway
Service-to-service (3rd-party) CrowdStrike, SentinelOne, Microsoft Intune, Tanium Access (⚠️ Tanium not supported in Gateway)
Access integrations (various) Access only

⭐ For OS-version checks use the latest qualified stable (e.g. macOS ≥ 15.1), not the absolute newest, so a same-day OS release doesn't lock users out.

Validate: device shows Connected with the right profile; appears under My Team → Devices; a posture check (e.g. disk encryption) reports correctly.


D. Connect private apps/networks — Cloudflare Tunnel & Connector (Guide §5.1)

Path: Networks → Tunnels → Create a tunnel → Cloudflared → name it → Save → copy the install command for your OS. Then map Public Hostname or Private Network routes in the dashboard.

One-line connector install (token from the dashboard):

# macOS
brew install cloudflared && sudo cloudflared service install <YOUR_TUNNEL_TOKEN>
# Linux (Debian/RPM package already installed)
sudo cloudflared service install <YOUR_TUNNEL_TOKEN>

D.2 Cloudflare Tunnel via CLI (locally-managed)

cloudflared tunnel login                      # authenticate + pick a zone
cloudflared tunnel create <NAME>              # creates tunnel + credentials JSON
cloudflared tunnel list                       # note the tunnel UUID

~/.cloudflared/config.yml:

tunnel: <TUNNEL-UUID>
credentials-file: /root/.cloudflared/<TUNNEL-UUID>.json
ingress:
  - hostname: wiki.yourco.com
    service: http://localhost:3000
  - hostname: ssh.yourco.com
    service: ssh://localhost:22
  - service: http_status:404          # required catch-all
cloudflared tunnel route dns <NAME> wiki.yourco.com   # create the DNS record
cloudflared tunnel ingress validate                   # validate config
cloudflared tunnel run <NAME>                          # test in foreground
sudo cloudflared service install                       # run as a service (production)

⭐ Run two cloudflared replicas (different hosts) per tunnel for high availability.

D.3 WARP Connector (site-to-site / mesh on a Linux host)

sudo warp-cli connector new <TOKEN> && sudo warp-cli connect
warp-cli status        # expect "Status update: Connected"

E. ZTNA — Access applications & policies (Guide §5)

E.1 Add a self-hosted application

Path: Access → Applications → Add an application → Self-hosted

Field Value / recommendation
Application name Internal Wiki
Session Duration ⭐ 24h standard; 15m–No duration for crown-jewel apps
Application domain wiki.yourco.com (must resolve to a tunnel/zone)
Identity providers select the IdP(s) allowed for this app
Instant Auth On if a single IdP (skips the chooser)
App Launcher visibility On (shows in the user portal)
Accept all available identity providers Off if you scope per-app

E.2 Build an Access policy

Path: within the app → Policies → Add a policy

Field Value
Policy name ⭐ Allow — Full-time employees (use a reused naming convention)
Action Allow / Block / Bypass / Service Auth
Session duration inherit or override

Rules — combine Include / Require / Exclude (Exclude overrides all):

Rule group Selector Operator Value
Include IdP Groups in Engineering
Require Device Posture in Disk encryption, Firewall on
Require Authentication Method in mfa
Exclude Emails (List) in List: Offboarding

⭐ Add a second, lowest-priority policy Block — Everyone (Action = Block, Include = Everyone) as a default-deny net. ⚠️ Policies evaluate top-down; keep Block/Exclude policies above broad Allows.

Selector cheat-sheet (most-used):

Selector Use it for
Emails / Emails ending in Specific users / domain
IdP Groups ⭐ Group-based access (needs group claims)
Device Posture Require compliant devices
Gateway Require traffic came through Gateway (client/RBI/WAN site)
Country / IP ranges Geo / network restrictions
Authentication Method / MFA Require strong auth
mTLS Certificate Service Auth (machine-to-machine)
Cloudflare Account Member Restrict to your account members

E.3 Reusable building blocks (do this, not per-app rules)

Component Path Use
Access Groups Access controls → Policies → Groups → Add a group ⭐ Named, reusable rule block (e.g. Secure employees = group + 3 posture checks). Reference across many apps
Lists Reusable components → Lists Emails, device serial numbers, IPs — update via UI or API (HR/MDM integration)
Posture checks Reusable components → Posture checks Define once, use in Access and Gateway

E.4 RBI fallback for unmanaged devices

Keep the normal Allow (compliant employees) and add a Gateway HTTP policy with action Isolate matching the same app hostname, so non-compliant devices get a remote-browser session instead of a hard block.

Validate: a permitted user reaches the app post-login; a non-member is blocked; Access → Logs (Logpush) show allow/block with identity + posture.


F. Secure Web Gateway (Gateway) (Guide §6)

Build policies bottom-up the stack: DNS → Network → HTTP.

F.1 DNS policies (start here)

Path: Gateway → Firewall Policies → DNS → Add a policy

Field Value
Policy name Block security threats
Selector Security Categories
Operator in
Value ⭐ Malware, Phishing, Command & Control, Cryptomining, DGA Domains, DNS Tunneling, New Domains
Action Block

Add a second DNS policy for Content Categories (Adult, Gambling, etc.) per your AUP.

DNS Locations (sites without the client): Gateway → DNS Locations → Add a location → point the network's resolver at the assigned IPv4/IPv6, DoH (https://<id>.cloudflare-gateway.com/dns-query), or DoT endpoints shown.

F.2 Network (L4) policies

Path: Gateway → Firewall Policies → Network → Add a policy

Example Selector / Operator / Value Action
Block outbound SMTP from clients Destination Port in 25 Block
Restrict RDP egress Destination Port in 3389 + Identity not in IT Block

F.3 TLS decryption + HTTP policies

  1. Enable decryption: Settings → Network → Firewall → TLS decryption → On. ⚠️ Requires the Cloudflare root CA on devices (§C.4).
  2. Create Do Not Inspect exceptions FIRST (Gateway → Firewall Policies → HTTP → Add a policy, Action = Do Not Inspect):
Exception Selector / Value
Cert-pinned apps Application in Do Not Inspect (Cloudflare-maintained app type)
Microsoft 365 ⭐ Toggle the one-click Microsoft 365 traffic integration (auto-bypasses M365)
Banking / native apps Application or Domain in your pinned-cert list
  1. HTTP filtering policy example:
Field Value
Policy name Block risky uploads
Selector Application in <risky app> · or Content Category · or File Type
Action Block / Isolate / Allow / Do Not Scan
  1. Application granular controls (within an HTTP policy): allow an app but block specific actions — e.g. ChatGPT → block File upload, Google Drive → block Download to non-corporate tenant. This is also the hook for AI controls (§H).

Validate: browse a blocked category → Cloudflare block page; Gateway → Logs show HTTPS entries with decrypted detail (proves CA + decryption).


G. Data Loss Prevention (DLP) (Guide §7 — Enterprise)

G.1 Pick / build a profile

Path: DLP → DLP Profiles

  • Predefined: open e.g. Credentials and Secrets, Financial Information, PII → toggle individual entries on/off.
  • Custom: Create profile → add detection entries (predefined detectors, custom regex, dictionaries, EDM datasets, Microsoft Purview labels).

G.2 Tune sensitivity (per entry / profile)

Setting Where ⭐ Recommendation
Confidence threshold per detection entry Low / Medium / High (raised by proximity keywords, e.g. "SSN" near a 9-digit number)
Minimum match count per profile/entry e.g. 10 → fires only at 11+ matches (cuts noise)
AI context analysis DLP → Settings On (pretrained model adjusts confidence; HTTP/HTTPS only)
OCR DLP → Settings On to scan text in images (.jpg/.png, 4 KB–1 MB)

PII Record profile is special: it only fires when ≥3 unique entries appear in close proximity — a built-in false-positive control.

G.3 Enforce via a Gateway HTTP policy (⭐ two-policy pattern)

Path: Gateway → Firewall Policies → HTTP → Add a policy, use the DLP Profile selector.

# Selector / Value Action Purpose
1 DLP Profile in Financial Info (Low confidence) Allow (+ log) ⭐ Visibility / baseline
2 DLP Profile in Financial Info (High confidence) + Destination Domain in dropbox.com, wetransfer.com + User Group in Finance Block Enforcement, scoped

⭐ Run monitor (Allow+log) for 1–2 weeks, then enable the Block. ⚠️ Always scope by destination/app/group — a broad Credentials profile on all traffic floods false positives. ⚠️ No TLS decryption → DLP can't see HTTPS bodies.

Validate: upload a benign test pattern (fake SSN / test card number) to a monitored destination → detection appears in Gateway → Logs / DLP with the matched profile + confidence.


H. AI safety controls (Guide §8)

H.1 Discover shadow AI

Path: Gateway → Analytics → Shadow IT Discovery → review Generative AI app category → mark apps Approved / Unapproved.

H.2 Govern AI app usage (allow + restrict, don't block)

Path: Gateway → Firewall Policies → HTTP → Add a policy

Field Value
Selector Application in ChatGPT, Google Gemini, Claude, Perplexity
Application granular controls ⭐ Block File upload / restrict actions (keeps the app usable)
DLP Profile add AI Prompt: PII / AI Prompt: AI Security
Action Allow (with granular block) or Block on DLP match

H.3 AI Prompt Protection (DLP for prompts)

Path: DLP → Detection entries → AI prompt topics → enable Content topics (PII, Source Code, Credentials & Secrets, Financial Information, Customer Data) and Intent topics (jailbreak, malicious-code, PII-extraction). Or select a predefined AI Prompt profile, then reference it in the H.2 HTTP policy. ⭐ Start in monitor mode.

H.4 DLP for AI Gateway (programmatic/API AI — no decryption needed)

Path: AI → AI Gateway → your gateway → Features → DLP → Set up → attach DLP profiles. Scans request + response text to AI providers without Gateway HTTP filtering or TLS decryption.

H.5 AI Security for Apps (WAF — for AI you expose)

Path: your zone → Security → Settings / WAF → Detections → AI Security for Apps → enable prompt injection + unsafe topic detections, then write a WAF custom rule acting on the detection fields. Complements DLP (model-layer attacks vs. data detection).

H.6 MCP server portals (governing AI agents)

Path: Access → AI controls → MCP server portals → add a portal → publish/gate/rename tools behind an Access policy.


I. Cloudflare WAN (Guide §9 — Enterprise)

I.0 Pre-flight: MSS clamping (set on your edge BEFORE bringing tunnels up)

On-ramp TCP MSS clamp Why
GRE 1,436 bytes (internal interface) Room for GRE header
IPsec 1,360 bytes max Room for ESP/encryption overhead

Vendor syntax: Cisco ip tcp adjust-mss 1436, Juniper tcp-mss 1436. ⚠️ Symptom of a missed clamp: http:// works but https:// hangs — test with curl http://ifconfig.me vs curl https://ifconfig.me.

I.1 Add an IPsec tunnel

Path: Cloudflare WAN → Configuration → Tunnels → Create → IPsec tunnel

Field Value
Tunnel name site-a-primary
Customer endpoint your router's public IP (omit if behind NAT)
Cloudflare endpoint the anycast IP assigned to your account
Interface address the /31 (or /30) Cloudflare provides for the tunnel
Pre-shared key (PSK) generate / paste; store in your secrets manager
Health check On ⭐ (rate Low/Mid/High; target = the tunnel interface)
Replay protection Off unless your device can't disable it (then On)

Supported IKEv2 parameters (match these on your device):

Parameter Value
IKE version IKEv2 only
Phase 1 encryption AES256-GCM-16
Phase 2 encryption AES256-GCM-16
Phase 1 integrity / PRF SHA2-256
Phase 2 integrity SHA2-256
Phase 1 DH group 20
Phase 2 DH group (PFS) 20
NAT-T UDP 500 → 4500 (auto)

I.2 Add a GRE tunnel (alternative)

Same path → GRE tunnel. Provide Customer endpoint, Cloudflare anycast endpoint, interface address (/31), and enable health checks. GRE is stateless (no encryption) — use IPsec where confidentiality matters.

I.3 Configure routing

Path: Cloudflare WAN → Configuration → Routes

Approach How Use
Static routes Add prefix (your site/DC subnet) → next-hop = tunnel → set Priority (lower = preferred) + Weight for ECMP Simple, stable sites
BGP (over GRE/IPsec) Enable BGP on the tunnel; configure eBGP peer + ASNs + MD5 auth ⭐ Multi-site / dynamic; auto-adds/removes routes

⭐ Redundancy: create two tunnels from two separate routers. Cloudflare's end is anycast (one tunnel already reaches every Cloudflare PoP), so resilience is about your premises hardware. ⚠️ Plan IP space — overlapping subnets across sites break Magic routing.

I.4 Add security + send site traffic to Gateway

  • Magic Firewall: Magic Firewall → Add rule (L3/L4 allow/deny on Cloudflare WAN traffic). ⚠️ Network traffic is unfiltered until you add rules.
  • Route Internet-bound traffic to Gateway so clientless sites get the same DNS/Network/HTTP/DLP policies as client users.

I.5 Health alerts

Path: Notifications → Add → Magic Tunnel Health → choose tunnels (filter by GRE / IPsec / CNI) → set recipients.

Validate: tunnels show Healthy; routes appear in the Magic routing table; curl https://ifconfig.me succeeds (MSS correct); disabling one tunnel fails over to the other; site Internet traffic is filtered by Gateway.


J. Validation & troubleshooting commands

# Cloudflare One Client (WARP) state
warp-cli status                 # expect: Connected
warp-cli settings               # mode, org, split-tunnel
warp-cli account                # enrolled org / posture
# Confirm you are egressing via Cloudflare (managed device)
curl https://www.cloudflare.com/cdn-cgi/trace/   # look for warp=on, gateway=on

# DNS over HTTPS location test
curl -H 'accept: application/dns-json' \
  'https://<location-id>.cloudflare-gateway.com/dns-query?name=example.com&type=A'

# Cloudflare WAN MSS / tunnel sanity
curl http://ifconfig.me         # works
curl https://ifconfig.me        # hangs => MSS clamp too high (GRE 1436 / IPsec 1360)

# Cloudflare Tunnel
cloudflared tunnel info <NAME>          # connector + connection status
cloudflared tunnel ingress validate     # config check
Symptom Likely cause Fix
"Not allowed to enroll" No device enrollment permission rule Add Allow/Service-Auth rule (§C.1)
HTTPS broken after decryption Root CA not trusted Push CA via MDM, then decrypt (§C.4)
Group policy never matches Missing group claims / no SCIM Re-run IdP Test; enable Support Groups + SCIM (§B)
App allowed that should be blocked Policy order Move Block/Exclude above broad Allow (§E.2)
DLP selector greyed out Not Enterprise / role Verify plan + admin role
https:// hangs over Cloudflare WAN MSS clamp GRE 1,436 / IPsec 1,360 (§I.0)

K. Quick settings reference (one screen)

Thing Exact value
Zero Trust dashboard https://one.dash.cloudflare.com
Team domain https://<team-name>.cloudflareaccess.com
OIDC callback URL https://<team-name>.cloudflareaccess.com/cdn-cgi/access/callback
Google JS origin https://<team-name>.cloudflareaccess.com
Entra Graph delegated perms email, offline_access, openid, profile, User.Read, Directory.Read.All, GroupMember.Read.All
Okta read-only API token Required if >100 groups
WARP mode (enterprise) Gateway with WARP
Split tunnel — managed / BYOD Exclude / Include
Default excluded CGNAT 100.64.0.0/10
Service-token enrollment perm Service Auth (not Allow)
MDM silent install keys onboarding=false, auto_connect=1, switch_locked=true
OCR image size .jpg/.png, 4 KB–1 MB
PII Record threshold ≥3 unique entries in proximity
Cloudflare WAN IPsec ciphers IKEv2 · AES256-GCM-16 · SHA2-256 · DH group 20
MSS clamp GRE 1436 / IPsec 1360
IPsec NAT-T UDP 500 → 4500

Prepared 2026-06-08. Field names and exact menu paths reflect current Cloudflare docs (Cloudflare One / Cloudflare WAN) and may shift; verify against your dashboard and confirm Enterprise entitlements (DLP, advanced posture, Cloudflare WAN) before production rollout. Replace all <placeholders> and example secrets with your own values — never reuse the sample tokens shown.

Nguồn cộng đồng — không phải tài liệu chính thức của Cloudflare: https://zerotrust.cfsase.workers.dev Community source — not an official Cloudflare publication: https://zerotrust.cfsase.workers.dev

Ví dụ triển khai (Cloudflare Resources) Deployment examples (Cloudflare Resources) Deployment examples (Cloudflare Resources)

Ví dụ chính thức từ Cloudflare Resources — gợi ý theo chủ đề bài học trong lộ trình này. Official examples from Cloudflare Resources — matched to this lesson within this path. Official examples from Cloudflare Resources — matched to this lesson within this path.

Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Access một ứng dụng web thông qua tên máy chủ riêng của nó mà không có Cloudflare One Client Access a web application via its private hostname without the Cloudflare One Client Access កម្មវិធីបណ្តាញតាមរយៈឈ្មោះម៉ាស៊ីនឯកជនរបស់វាដោយគ្មាន Cloudflare One Client

Với Cloudflare cách ly trình duyệt và các chính sách giải quyết, người dùng có thể kết nối với các ứng dụng dựa trên web riêng tư thông qua tên máy chủ riêng của họ.

With Cloudflare Browser Isolation and resolver policies, users can connect to private web-based applications via their private hostnames.

ជាមួយនឹង Cloudflare គោលការណ៍ញែកកម្មវិធីរុករក និងដំណោះស្រាយ អ្នកប្រើប្រាស់អាចភ្ជាប់ទៅកម្មវិធីដែលមានមូលដ្ឋានលើបណ្តាញឯកជនតាមរយៈឈ្មោះម៉ាស៊ីនឯកជនរបស់ពួកគេ។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Phát triển Cloudflare One Client trên máy Linux không đầu Deploy the Cloudflare One Client on headless Linux machines ការផ្លាស់ប្តូរអតិថិជន Cloudflare One នៅលើម៉ាស៊ីន Linux មិនមែនជា headless

Hướng dẫn này giải thích cách triển khai Cloudflare One Client trên các thiết bị Linux không có đầu bằng cách sử dụng token dịch vụ và kịch bản cài đặt.

This tutorial explains how to deploy the Cloudflare One Client on headless Linux devices using a service token and an installation script.

វគ្គបណ្តុះបណ្តាលនេះបង្ហាញពីរបៀបដំឡើងអតិថិជន Cloudflare One នៅលើឧបករណ៍ Linux ដែលមិនមានក្បាលដោយប្រើគណនីសេវាកម្មនិងគណនីដំឡើង។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Sơ đồ kiến trúc Reference architecture diagram គំនូសស្ថាបត្យកម្មយោង Cloudflare One Cloudflare One Cloudflare One

Tùy chọn triển khai Cloudflare One Appliance Cloudflare One Appliance deployment options Cloudflare One Appliance deployment options

Cách triển khai Cloudflare One Appliance và đánh giá các lựa chọn: uplink H/A, dual connector, hybrid MPLS, split tunnel, segmentation.

Learn how to deploy Cloudflare One Appliance and evaluate your various deployment options.

Learn how to deploy Cloudflare One Appliance and evaluate your various deployment options.

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Tạo và bảo mật một agent wrapper AI bằng cách sử dụng AI Gateway và Zero Trust Create and secure an AI agent wrapper using AI Gateway and Zero Trust ការបង្កើតនិងការសុវត្ថិភាព agent wrapper AI ដោយប្រើ AI Gateway និង Zero Trust

Hướng dẫn này giải thích cách sử dụng Cloudflare AI Gateway và Zero Trust để tạo ra một trang web đóng gói chức năng và an toàn cho một đại lý AI.

This tutorial explains how to use Cloudflare AI Gateway and Zero Trust to create a functional and secure website wrapper for an AI agent.

វគ្គបណ្តុះបណ្តាលនេះបង្ហាញពីរបៀបដើម្បីប្រើ Cloudflare AI Gateway និង Zero Trust ដើម្បីបង្កើតវគ្គបណ្តុះបណ្តាលគេហទំព័រដែលមានប្រសិទ្ធិភាពនិងសុវត្ថិភាពសម្រាប់អេក្រង់ AI ។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម

Xem thêm ví dụ trong lộ trình → More examples in this path → More examples in this path →

Tài liệu Cloudflare Developers Cloudflare Developer docs Cloudflare Developer docs

Học xong hoặc muốn đổi hướng? Finished or want a different path? Finished or want a different path?

Ba lộ trình độc lập — mỗi lộ trình chỉ gồm bài học và tài liệu trong phạm vi đó. Chọn lộ trình khác khi sẵn sàng, không cần học song song. Three independent paths — each includes only lessons and materials for that scope. Switch when you are ready; no need to study paths in parallel. Three independent paths — each includes only lessons and materials for that scope. Switch when you are ready; no need to study paths in parallel.

Chưa chắc — làm bài chọn lộ trình Not sure — use the path selector Not sure — use the path selector · So sánh cả ba lộ trình Compare all three paths Compare all three paths