Cloudflare Zero Trust — Sổ tay cấu hình từng bước
Tài liệu thực hành đi kèm Hướng dẫn triển khai & thực hành tốt khi onboarding. Khi hướng dẫn giải thích tại sao và theo thứ tự nào, sổ tay này đưa đường dẫn điều hướng chính xác, thiết lập từng trường, lệnh, và snippet cấu hình để gõ hoặc nhấp. Chữ cái các phần ánh xạ tới các mục đánh số của hướng dẫn.
|
|
| Bảng điều khiển |
Zero Trust: https://one.dash.cloudflare.com · Account: https://dash.cloudflare.com |
| Team domain |
https://<team-name>.cloudflareaccess.com (dùng trong mọi IdP callback URL) |
| Cập nhật lần cuối |
2026-06-08 |
Cách đọc sổ tay này
- Path:
A → B → C nghĩa là nhấp lần lượt các menu dashboard đó.
- Bảng trường liệt kê mọi thiết lập trên một màn hình, giá trị khuyến nghị, và ghi chú. Thay
<placeholders> bằng giá trị của bạn.
- ⭐ = giá trị thực hành tốt khuyến nghị · ⚠️ = sai lầm thường gặp.
- Nhãn menu thay đổi; nếu một nhãn đã được di chuyển, dùng mục gần nhất (đường dẫn dưới Settings, Integrations, Access controls, Traffic policies).
A. Tạo tài khoản & thiết lập tổ chức (Hướng dẫn §2)
A.1 Kích hoạt Zero Trust
- Đăng nhập tại
https://dash.cloudflare.com → left nav Zero Trust (hoặc vào https://one.dash.cloudflare.com).
- Choose a plan → nhập team name khi được nhắc → thêm phương thức thanh toán (bắt buộc kể cả trên Free).
A.2 Đặt team name
Path: Settings → Custom Pages / Settings → Team name and domain
| Field |
Value |
Notes |
| Team name |
<your-company-short-name> |
⭐ Ổn định, dễ nhận; trở thành https://<team-name>.cloudflareaccess.com. ⚠️ Đổi tên sau này làm hỏng mọi IdP callback URL + cấu hình MDM |
A.3 Mặc định tổ chức cần đặt ngày đầu
| Setting |
Path |
Recommended |
| Account MFA |
dash.cloudflare.com → My Profile → Authentication |
⭐ Bật cho mọi admin trước bất cứ việc gì khác |
| Admin roles |
dash.cloudflare.com → Manage Account → Members |
⭐ ≥2 Super Admins (break-glass); đặc quyền tối thiểu cho người khác |
| Custom login/block pages |
Settings → Custom Pages |
Gắn thương hiệu — giảm ticket helpdesk |
| Logpush (Access + Gateway) |
Settings → Logs → Logpush (hoặc Logs → Logpush) |
⭐ Nối tới SIEM/R2/S3 ngay bây giờ, đừng để sau |
Kiểm tra: https://<team-name>.cloudflareaccess.com hiện trang đăng nhập tổ chức; Settings → General hiện đúng gói + team name.
B. Tích hợp nhà cung cấp danh tính (IdP) (Hướng dẫn §3)
Mọi IdP dựa trên OIDC dùng cùng callback (redirect) URL của Cloudflare:
https://<your-team-name>.cloudflareaccess.com/cdn-cgi/access/callback
Google cũng cần Authorized JavaScript origin: https://<your-team-name>.cloudflareaccess.com
B.1 Microsoft Entra ID (Azure AD) — hướng dẫn đầy đủ
Bước 1 — Đăng ký ứng dụng (Entra admin center https://entra.microsoft.com)
Applications → Enterprise applications → New application → Create your own application.
- Đặt tên (vd.
Cloudflare Access) → chọn Register an application to integrate with Microsoft Entra ID (App you're developing) → Create. ⚠️ Không chọn gallery app.
- Dưới Redirect URI, platform = Web, value =
https://<your-team-name>.cloudflareaccess.com/cdn-cgi/access/callback
- Register.
- Vào
Applications → App registrations → All applications → ứng dụng của bạn. Sao chép Application (client) ID và Directory (tenant) ID.
- Client credentials → Add a certificate or secret → New client secret → đặt tên, đặt hạn → sao chép Value ngay (chỉ hiện một lần). ⚠️ Khi hết hạn, mọi đăng nhập thất bại — đặt lịch gia hạn.
Bước 2 — API permissions
App registrations → All applications → ứng dụng của bạn → API permissions → Add a permission → Microsoft Graph → Delegated permissions, bật 7 quyền này:
| Permission |
Purpose |
email |
Email người dùng |
offline_access |
Refresh tokens |
openid |
Đăng nhập OIDC |
profile |
Hồ sơ cơ bản |
User.Read |
Đọc người dùng đang đăng nhập |
Directory.Read.All |
Đọc directory |
GroupMember.Read.All |
⭐ Đọc thành viên nhóm (bắt buộc cho chính sách nhóm) |
Rồi Add permissions → Grant admin consent.
Bước 3 — Thêm vào Cloudflare
Zero Trust → Integrations → Identity providers → Add new identity provider → Azure AD:
| Field |
Value |
| Application (client) ID |
từ Bước 1.5 |
| Client secret |
từ Bước 1.6 |
| Directory (tenant) ID |
từ Bước 1.5 |
| ⭐ Support Groups |
On — cho Cloudflare đọc thành viên nhóm Entra |
| Proof Key for Code Exchange (PKCE) |
On |
| Enable SCIM |
⭐ On để đồng bộ user/group tự động + thu hồi session |
| Email claim |
vd. preferred_username nếu UPN ≠ email |
Save → Test (xác nhận email + groups trong identity payload).
Phương án API: POST https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/access/identity_providers với {"name":"Entra ID","type":"azureAD","config":{"client_id":"…","client_secret":"…","directory_id":"…","support_groups":true}} (token cần Access: Organizations, Identity Providers, and Groups — Write).
B.2 Okta (OIDC) — hướng dẫn đầy đủ
- Trong Okta, tạo tích hợp ứng dụng OIDC → Web. Đặt Sign-in redirect URIs =
https://<your-team-name>.cloudflareaccess.com/cdn-cgi/access/callback
- Trong tab General của ứng dụng, sao chép Client ID và Client secret.
- Trong Cloudflare
Zero Trust → Integrations → Identity providers → Add new → Okta:
| Field |
Value |
| App ID |
Okta Client ID |
| Client secret |
Okta Client secret |
| Okta account URL |
domain Okta của bạn, vd. https://my-company.okta.com |
| Authorization Server ID |
từ Okta (nếu dùng custom auth server) |
| Okta API token (optional) |
⭐ Bắt buộc nếu bạn có >100 nhóm Okta (token chỉ đọc ngăn lookup nhóm thất bại) |
Save → Test.
B.3 Google Workspace (OIDC) — hướng dẫn đầy đủ
- Trong Google Cloud Console → APIs & Services → Credentials → Create OAuth client ID → Web application.
- Authorized JavaScript origins:
https://<your-team-name>.cloudflareaccess.com
- Authorized redirect URIs:
https://<your-team-name>.cloudflareaccess.com/cdn-cgi/access/callback
- Create → sao chép OAuth Client ID và Client secret.
- Trong Cloudflare
Identity providers → Add new → Google Workspace: nhập Client ID + Secret; cung cấp admin email / thiết lập domain-wide để Cloudflare đọc được Groups.
- Save → Test.
B.4 MFA toàn cục / độc lập
Path: Zero Trust → Access controls → Access settings
| Setting |
Recommended |
| Allow MFA methods |
Chọn các phương thức đã duyệt |
| Authentication duration |
vd. 24h (ngắn hơn cho dữ liệu nhạy cảm) |
| Use identity provider MFA |
⭐ On — tôn trọng claim amr của IdP, tránh hỏi hai lần |
| Apply global MFA settings by default |
⭐ On |
Kiểm tra mọi IdP: nút Test trả về email + groups mong đợi; vô hiệu hóa một user thử trong IdP thu hồi truy cập trong cửa sổ đồng bộ SCIM.
C. Đăng ký thiết bị — Cloudflare One Client (WARP) (Hướng dẫn §4)
C.1 Device enrollment permissions (cổng — làm việc này trước)
Path: Settings → WARP Client → Device enrollment permissions → Manage → Add a rule
| Field |
Value |
Notes |
| Rule name |
Corporate employees |
|
| Rule action |
Allow |
(dùng Service Auth cho enrollment fleet/server bằng token) |
| Selector |
Emails ending in |
|
| Value |
@yourco.com |
|
| Authentication / Login methods |
chọn IdP của bạn |
⚠️ Không có quy tắc khớp → người dùng thấy "you are not allowed to enroll" |
Với enrollment fleet MDM im lặng, tạo quy tắc Service Auth và một service token (Access → Service Auth → Service Tokens). ⚠️ Service tokens yêu cầu quy tắc Service Auth — quy tắc Allow sẽ không hoạt động với chúng.
C.2 Thiết lập device profile
Path: Settings → WARP Client → Device settings → (sửa profile Default hoặc Add a profile)
| Setting |
⭐ Recommended (managed) |
Notes |
| Service mode |
Gateway with WARP |
Lọc L3/L7 + DNS đầy đủ (enterprise chuẩn) |
| Switch lock |
On (managed) |
Ngăn người dùng tắt WARP |
| Auto connect |
1–5 phút |
Bật lại sau ngắt ngắn (vd. captive portal). Giá trị 0 = giữ tắt cho đến khi người dùng kết nối lại |
| Captive portal detection |
On |
Cho phép người dùng tới trang đăng nhập khách sạn/sân bay |
| Allowed device protocols |
theo chính sách |
vd. allow/deny WARP trên protocol cụ thể |
| Mode switch / admin override |
Locked (managed) |
|
Tạo profile riêng cho Servers, BYOD, Contractors và khớp chúng bằng selector posture/identity.
C.3 Split Tunnels
Path: trong một device profile → Split Tunnels
| Scenario |
Mode |
What to configure |
| Laptop được quản lý |
Exclude (mặc định) |
Mọi thứ đi tunnel trừ các ngoại lệ được liệt kê. Danh sách mặc định đã loại 100.64.0.0/10 (CGNAT dùng bởi Cloudflare One). ⭐ Thêm lại mọi dải RFC-1918/CGNAT local bạn thực sự dùng |
| BYOD / cá nhân |
Include |
⭐ Chỉ IP/domain công ty được liệt kê đi tunnel — lưu lượng cá nhân vẫn riêng tư. Thêm domain ứng dụng + CIDR nội bộ |
⚠️ Mục Include quá rộng (hoặc loại trừ subnet local bạn dựa vào) có thể black-hole lưu lượng LAN/Wi-Fi khi chuyển mạng — test Ethernet↔Wi-Fi.
C.4 Phân phối Cloudflare root CA (bắt buộc cho HTTPS filtering / DLP / AI prompt inspection)
Path: Settings → Resources (tải chứng chỉ Cloudflare) → đẩy tới trust store OS/trình duyệt qua MDM trước khi bật TLS decryption (§F.3). ⚠️ Decryption trước khi CA được tin cậy làm gãy HTTPS trên toàn fleet.
C.5 Triển khai MDM (im lặng, đã xác thực trước)
Đẩy client kèm tham số. Windows dùng mdm.xml; macOS dùng com.cloudflare.warp.plist. ⚠️ Thiết lập thiết bị local ưu tiên hơn thiết lập dashboard.
Tham số phổ biến
| Parameter |
Type |
⭐ Value / purpose |
organization |
string |
Team name của bạn (bắt buộc cho managed enrollment) |
auth_client_id |
string |
Service-token client ID, vd. 88bf3b6d….access |
auth_client_secret |
string |
Service-token secret. ⚠️ Token cần quyền enrollment Service Auth, không phải Allow |
service_mode |
string |
warp (Gateway with WARP) |
onboarding |
boolean |
false → ẩn màn hình chào (cài im lặng) |
auto_connect |
integer |
1 (kết nối ngay; 0 = cho phép tắt vô thời hạn). ⚠️ Thay enabled đã deprecated — bạn phải gỡ enabled nếu dùng cái này |
switch_locked |
boolean |
true trên thiết bị quản lý |
display_name |
string |
Biệt danh tổ chức trong GUI client (bắt buộc trong mảng configs) |
support_url |
string |
Liên kết helpdesk hiện trong client |
unique_client_id |
string |
Định danh thiết bị ổn định cho ánh xạ posture/serial |
enable_post_quantum |
boolean |
true để bật crypto tunnel PQ |
enable_netbt |
boolean |
false (mặc định; chỉ bật cho ứng dụng NetBIOS legacy) |
environment |
string |
normal hoặc fedramp_high |
organization_configs / configs[] |
dict/array |
Chuyển multi-org / config (client mới hơn) |
Ví dụ macOS .plist (service-token enrollment, im lặng):
<dict>
<key>organization</key> <string>your-team-name</string>
<key>auth_client_id</key> <string>88bf3b6d86161464f6509f7219099e57.access</string>
<key>auth_client_secret</key> <string>bdd31cbc4dec990953e39163fbbb194c93313ca9f0a6e420346af9d326b1d2a5</string>
<key>service_mode</key> <string>warp</string>
<key>onboarding</key> <false/>
<key>auto_connect</key> <integer>1</integer>
<key>switch_locked</key> <true/>
<key>support_url</key> <string>https://help.yourco.com</string>
</dict>
Windows mdm.xml tương đương dùng cùng các key trong XML <RegistrationData>.
C.6 Device posture checks
Path: Settings → WARP Client → Device posture (hoặc Reusable components → Posture checks → Add)
| Category |
Examples |
Usable in |
| Client checks (Cloudflare One Client) |
OS version, Disk encryption, Firewall, Client certificate, File/Registry/Application present, Serial number list, Domain joined |
Access và Gateway |
| Service-to-service (bên thứ ba) |
CrowdStrike, SentinelOne, Microsoft Intune, Tanium |
Access (⚠️ Tanium không được hỗ trợ trong Gateway) |
| Access integrations |
(các loại) |
Chỉ Access |
⭐ Với kiểm tra phiên bản OS dùng latest qualified stable (vd. macOS ≥ 15.1), không phải bản mới nhất tuyệt đối, để một bản OS ra cùng ngày không khóa người dùng.
Kiểm tra: thiết bị hiện Connected với đúng profile; xuất hiện dưới My Team → Devices; một posture check (vd. mã hóa đĩa) báo đúng.
D. Kết nối ứng dụng/mạng nội bộ — Cloudflare Tunnel & Connector (Hướng dẫn §5.1)
D.1 Cloudflare Tunnel qua dashboard (quản lý từ xa — khuyến nghị)
Path: Networks → Tunnels → Create a tunnel → Cloudflared → đặt tên → Save → sao chép lệnh cài cho OS của bạn. Rồi ánh xạ route Public Hostname hoặc Private Network trong dashboard.
Cài connector một dòng (token từ dashboard):
brew install cloudflared && sudo cloudflared service install <YOUR_TUNNEL_TOKEN>
sudo cloudflared service install <YOUR_TUNNEL_TOKEN>
D.2 Cloudflare Tunnel qua CLI (quản lý local)
cloudflared tunnel login
cloudflared tunnel create <NAME>
cloudflared tunnel list
~/.cloudflared/config.yml:
tunnel: <TUNNEL-UUID>
credentials-file: /root/.cloudflared/<TUNNEL-UUID>.json
ingress:
- hostname: wiki.yourco.com
service: http://localhost:3000
- hostname: ssh.yourco.com
service: ssh://localhost:22
- service: http_status:404
cloudflared tunnel route dns <NAME> wiki.yourco.com
cloudflared tunnel ingress validate
cloudflared tunnel run <NAME>
sudo cloudflared service install
⭐ Chạy hai replica cloudflared (host khác nhau) mỗi tunnel để có sẵn sàng cao.
D.3 WARP Connector (site-to-site / mesh trên host Linux)
sudo warp-cli connector new <TOKEN> && sudo warp-cli connect
warp-cli status
E. ZTNA — Ứng dụng & chính sách Access (Hướng dẫn §5)
E.1 Thêm ứng dụng self-hosted
Path: Access → Applications → Add an application → Self-hosted
| Field |
Value / recommendation |
| Application name |
Internal Wiki |
| Session Duration |
⭐ 24h chuẩn; 15m–No duration cho ứng dụng crown-jewel |
| Application domain |
wiki.yourco.com (phải resolve tới tunnel/zone) |
| Identity providers |
chọn IdP được phép cho ứng dụng này |
| Instant Auth |
On nếu một IdP duy nhất (bỏ qua chooser) |
| App Launcher visibility |
On (hiện trong cổng người dùng) |
| Accept all available identity providers |
Off nếu bạn scoped theo ứng dụng |
E.2 Xây chính sách Access
Path: trong ứng dụng → Policies → Add a policy
| Field |
Value |
| Policy name |
⭐ Allow — Full-time employees (dùng quy ước đặt tên tái sử dụng) |
| Action |
Allow / Block / Bypass / Service Auth |
| Session duration |
kế thừa hoặc ghi đè |
Rules — kết hợp Include / Require / Exclude (Exclude ghi đè tất cả):
| Rule group |
Selector |
Operator |
Value |
| Include |
IdP Groups |
in |
Engineering |
| Require |
Device Posture |
in |
Disk encryption, Firewall on |
| Require |
Authentication Method |
in |
mfa |
| Exclude |
Emails (List) |
in |
List: Offboarding |
⭐ Thêm chính sách thứ hai, ưu tiên thấp nhất Block — Everyone (Action = Block, Include = Everyone) làm lưới default-deny. ⚠️ Chính sách đánh giá từ trên xuống; giữ chính sách Block/Exclude phía trên Allow rộng.
Bảng tra Selector (dùng nhiều nhất):
| Selector |
Use it for |
| Emails / Emails ending in |
Người dùng / domain cụ thể |
| IdP Groups |
⭐ Truy cập theo nhóm (cần group claims) |
| Device Posture |
Yêu cầu thiết bị tuân thủ |
| Gateway |
Yêu cầu lưu lượng đã đi through Gateway (client/RBI/WAN site) |
| Country / IP ranges |
Hạn chế geo / mạng |
| Authentication Method / MFA |
Yêu cầu auth mạnh |
| mTLS Certificate |
Service Auth (máy-với-máy) |
| Cloudflare Account Member |
Giới hạn thành viên tài khoản của bạn |
E.3 Khối xây dựng tái sử dụng (làm thế này, không viết rule từng ứng dụng)
| Component |
Path |
Use |
| Access Groups |
Access controls → Policies → Groups → Add a group |
⭐ Khối rule có tên, tái sử dụng (vd. Secure employees = nhóm + 3 posture checks). Tham chiếu trên nhiều ứng dụng |
| Lists |
Reusable components → Lists |
Emails, serial number thiết bị, IP — cập nhật qua UI hoặc API (tích hợp HR/MDM) |
| Posture checks |
Reusable components → Posture checks |
Định nghĩa một lần, dùng trong Access và Gateway |
E.4 RBI fallback cho thiết bị không quản lý
Giữ Allow bình thường (nhân viên tuân thủ) và thêm chính sách Gateway HTTP với action Isolate khớp cùng hostname ứng dụng, để thiết bị không tuân thủ nhận phiên remote-browser thay vì bị chặn cứng.
Kiểm tra: người dùng được phép tới được ứng dụng sau đăng nhập; người không thuộc nhóm bị chặn; Access → Logs (Logpush) hiện allow/block kèm identity + posture.
F. Secure Web Gateway (Gateway) (Hướng dẫn §6)
Xây chính sách từ dưới lên stack: DNS → Network → HTTP.
F.1 Chính sách DNS (bắt đầu ở đây)
Path: Gateway → Firewall Policies → DNS → Add a policy
| Field |
Value |
| Policy name |
Block security threats |
| Selector |
Security Categories |
| Operator |
in |
| Value |
⭐ Malware, Phishing, Command & Control, Cryptomining, DGA Domains, DNS Tunneling, New Domains |
| Action |
Block |
Thêm chính sách DNS thứ hai cho Content Categories (Adult, Gambling, v.v.) theo AUP của bạn.
DNS Locations (site không có client): Gateway → DNS Locations → Add a location → trỏ resolver của mạng tới các endpoint IPv4/IPv6, DoH (https://<id>.cloudflare-gateway.com/dns-query), hoặc DoT được hiện.
F.2 Chính sách Network (L4)
Path: Gateway → Firewall Policies → Network → Add a policy
| Example |
Selector / Operator / Value |
Action |
| Chặn SMTP outbound từ client |
Destination Port in 25 |
Block |
| Hạn chế egress RDP |
Destination Port in 3389 + Identity not in IT |
Block |
F.3 TLS decryption + chính sách HTTP
- Bật decryption:
Settings → Network → Firewall → TLS decryption → On. ⚠️ Yêu cầu Cloudflare root CA trên thiết bị (§C.4).
- Tạo ngoại lệ Do Not Inspect TRƯỚC (
Gateway → Firewall Policies → HTTP → Add a policy, Action = Do Not Inspect):
| Exception |
Selector / Value |
| Ứng dụng cert-pinned |
Application in Do Not Inspect (loại ứng dụng Cloudflare duy trì) |
| Microsoft 365 |
⭐ Bật tích hợp lưu lượng one-click Microsoft 365 (tự bypass M365) |
| Ngân hàng / ứng dụng native |
Application hoặc Domain in danh sách cert-pinned của bạn |
- Ví dụ chính sách HTTP filtering:
| Field |
Value |
| Policy name |
Block risky uploads |
| Selector |
Application in <risky app> · hoặc Content Category · hoặc File Type |
| Action |
Block / Isolate / Allow / Do Not Scan |
- Application granular controls (trong một chính sách HTTP): cho phép ứng dụng nhưng chặn hành động cụ thể — vd. ChatGPT → block File upload, Google Drive → block Download to non-corporate tenant. Đây cũng là móc cho AI controls (§H).
Kiểm tra: duyệt một danh mục bị chặn → block page của Cloudflare; Gateway → Logs hiện mục HTTPS với chi tiết decrypted (chứng minh CA + decryption).
G. Data Loss Prevention (DLP) (Hướng dẫn §7 — Enterprise)
G.1 Chọn / xây một profile
Path: DLP → DLP Profiles
- Predefined: mở vd. Credentials and Secrets, Financial Information, PII → bật/tắt từng entry.
- Custom:
Create profile → thêm detection entries (detector định sẵn, custom regex, dictionaries, dataset EDM, nhãn Microsoft Purview).
G.2 Tinh chỉnh độ nhạy (theo entry / profile)
| Setting |
Where |
⭐ Recommendation |
| Confidence threshold |
theo từng detection entry |
Low / Medium / High (tăng bởi proximity keywords, vd. "SSN" gần một số 9 chữ số) |
| Minimum match count |
theo profile/entry |
vd. 10 → chỉ kích hoạt ở 11+ khớp (giảm nhiễu) |
| AI context analysis |
DLP → Settings |
On (mô hình pretrained điều chỉnh confidence; chỉ HTTP/HTTPS) |
| OCR |
DLP → Settings |
On để quét văn bản trong ảnh (.jpg/.png, 4 KB–1 MB) |
Profile PII Record đặc biệt: nó chỉ kích hoạt khi ≥3 entry duy nhất xuất hiện gần nhau — kiểm soát false-positive tích hợp.
G.3 Thực thi qua chính sách Gateway HTTP (⭐ mẫu hai chính sách)
Path: Gateway → Firewall Policies → HTTP → Add a policy, dùng selector DLP Profile.
| # |
Selector / Value |
Action |
Purpose |
| 1 |
DLP Profile in Financial Info (Low confidence) |
Allow (+ log) |
⭐ Visibility / baseline |
| 2 |
DLP Profile in Financial Info (High confidence) + Destination Domain in dropbox.com, wetransfer.com + User Group in Finance |
Block |
Thực thi, đã scoped |
⭐ Chạy monitor (Allow+log) 1–2 tuần, rồi bật Block. ⚠️ Luôn scoped theo đích/ứng dụng/nhóm — một profile Credentials rộng trên mọi lưu lượng ngập false positive. ⚠️ Không TLS decryption → DLP không thấy body HTTPS.
Kiểm tra: upload một pattern thử vô hại (SSN giả / số thẻ thử) tới đích được giám sát → detection xuất hiện trong Gateway → Logs / DLP với profile đã khớp + confidence.
H. Kiểm soát an toàn AI (Hướng dẫn §8)
H.1 Phát hiện shadow AI
Path: Gateway → Analytics → Shadow IT Discovery → xem danh mục ứng dụng Generative AI → đánh dấu ứng dụng Approved / Unapproved.
H.2 Quản trị việc dùng ứng dụng AI (allow + restrict, đừng block)
Path: Gateway → Firewall Policies → HTTP → Add a policy
| Field |
Value |
| Selector |
Application in ChatGPT, Google Gemini, Claude, Perplexity |
| Application granular controls |
⭐ Block File upload / hạn chế hành động (giữ ứng dụng dùng được) |
| DLP Profile |
thêm AI Prompt: PII / AI Prompt: AI Security |
| Action |
Allow (kèm granular block) hoặc Block khi khớp DLP |
H.3 AI Prompt Protection (DLP cho prompt)
Path: DLP → Detection entries → AI prompt topics → bật chủ đề Content (PII, Source Code, Credentials & Secrets, Financial Information, Customer Data) và chủ đề Intent (jailbreak, malicious-code, PII-extraction). Hoặc chọn một predefined profile AI Prompt, rồi tham chiếu nó trong chính sách HTTP H.2. ⭐ Bắt đầu ở chế độ monitor.
H.4 DLP for AI Gateway (AI programmatic/API — không cần decryption)
Path: AI → AI Gateway → gateway của bạn → Features → DLP → Set up → gắn DLP profiles. Quét văn bản request + response tới nhà cung cấp AI mà không cần Gateway HTTP filtering hay TLS decryption.
H.5 AI Security for Apps (WAF — cho AI bạn phơi bày)
Path: your zone → Security → Settings / WAF → Detections → AI Security for Apps → bật detection prompt injection + unsafe topic, rồi viết WAF custom rule tác động trên các trường detection. Bổ trợ DLP (tấn công tầng mô hình vs. phát hiện dữ liệu).
H.6 MCP server portals (quản trị AI agents)
Path: Access → AI controls → MCP server portals → thêm một portal → xuất bản/cổng kiểm soát/đổi tên tools sau một chính sách Access.
I. Cloudflare WAN (Hướng dẫn §9 — Enterprise)
I.0 Pre-flight: MSS clamping (đặt trên edge TRƯỚC khi đưa tunnel lên)
| On-ramp |
TCP MSS clamp |
Why |
| GRE |
1,436 bytes (interface nội bộ) |
Chỗ cho GRE header |
| IPsec |
tối đa 1,360 bytes |
Chỗ cho overhead ESP/mã hóa |
Cú pháp vendor: Cisco ip tcp adjust-mss 1436, Juniper tcp-mss 1436. ⚠️ Triệu chứng khi bỏ sót clamp: http:// hoạt động nhưng https:// treo — test bằng curl http://ifconfig.me vs curl https://ifconfig.me.
I.1 Thêm IPsec tunnel
Path: Cloudflare WAN → Configuration → Tunnels → Create → IPsec tunnel
| Field |
Value |
| Tunnel name |
site-a-primary |
| Customer endpoint |
IP public của router (bỏ nếu sau NAT) |
| Cloudflare endpoint |
anycast IP được gán cho tài khoản của bạn |
| Interface address |
/31 (hoặc /30) Cloudflare cung cấp cho tunnel |
| Pre-shared key (PSK) |
tạo / dán; lưu trong secrets manager |
| Health check |
On ⭐ (rate Low/Mid/High; target = tunnel interface) |
| Replay protection |
Off trừ khi thiết bị không tắt được (thì On) |
Tham số IKEv2 được hỗ trợ (khớp chúng trên thiết bị của bạn):
| Parameter |
Value |
| IKE version |
IKEv2 only |
| Phase 1 encryption |
AES256-GCM-16 |
| Phase 2 encryption |
AES256-GCM-16 |
| Phase 1 integrity / PRF |
SHA2-256 |
| Phase 2 integrity |
SHA2-256 |
| Phase 1 DH group |
20 |
| Phase 2 DH group (PFS) |
20 |
| NAT-T |
UDP 500 → 4500 (auto) |
I.2 Thêm GRE tunnel (phương án khác)
Cùng path → GRE tunnel. Cung cấp Customer endpoint, Cloudflare anycast endpoint, interface address (/31), và bật health checks. GRE không trạng thái (không mã hóa) — dùng IPsec khi cần bảo mật nội dung.
Path: Cloudflare WAN → Configuration → Routes
| Approach |
How |
Use |
| Static routes |
Thêm prefix (subnet site/DC) → next-hop = tunnel → đặt Priority (thấp hơn = ưu tiên) + Weight cho ECMP |
Site đơn giản, ổn định |
| BGP (over GRE/IPsec) |
Bật BGP trên tunnel; cấu hình eBGP peer + ASN + auth MD5 |
⭐ Đa site / động; tự thêm/gỡ route |
⭐ Dư thừa: tạo hai tunnel từ hai router riêng. Đầu Cloudflare là anycast (một tunnel đã tới mọi PoP Cloudflare), nên độ bền là về phần cứng on-prem của bạn. ⚠️ Lên kế hoạch không gian IP — subnet chồng lấn giữa các site làm gãy Magic routing.
I.4 Thêm bảo mật + gửi lưu lượng site tới Gateway
- Magic Firewall:
Magic Firewall → Add rule (allow/deny L3/L4 trên lưu lượng Cloudflare WAN). ⚠️ Lưu lượng mạng không được lọc cho đến khi bạn thêm rule.
- Route Internet-bound traffic to Gateway để site không client nhận cùng chính sách DNS/Network/HTTP/DLP như người dùng có client.
I.5 Cảnh báo health
Path: Notifications → Add → Magic Tunnel Health → chọn tunnel (lọc theo GRE / IPsec / CNI) → đặt người nhận.
Kiểm tra: tunnel hiện Healthy; route xuất hiện trong Magic routing table; curl https://ifconfig.me thành công (MSS đúng); tắt một tunnel failover sang cái kia; lưu lượng Internet của site được Gateway lọc.
J. Lệnh kiểm tra & khắc phục sự cố
warp-cli status
warp-cli settings
warp-cli account
curl https://www.cloudflare.com/cdn-cgi/trace/
curl -H 'accept: application/dns-json' \
'https://<location-id>.cloudflare-gateway.com/dns-query?name=example.com&type=A'
curl http://ifconfig.me
curl https://ifconfig.me
cloudflared tunnel info <NAME>
cloudflared tunnel ingress validate
| Symptom |
Likely cause |
Fix |
| "Not allowed to enroll" |
Không có quy tắc device enrollment permission |
Thêm quy tắc Allow/Service-Auth (§C.1) |
| HTTPS gãy sau decryption |
Root CA chưa được tin cậy |
Đẩy CA qua MDM, rồi decrypt (§C.4) |
| Chính sách nhóm không bao giờ khớp |
Thiếu group claims / không SCIM |
Chạy lại IdP Test; bật Support Groups + SCIM (§B) |
| Ứng dụng được allow trong khi phải bị block |
Thứ tự chính sách |
Đưa Block/Exclude lên trên Allow rộng (§E.2) |
| Selector DLP bị xám |
Không phải Enterprise / vai trò |
Xác minh gói + vai trò admin |
https:// treo trên Cloudflare WAN |
MSS clamp |
GRE 1,436 / IPsec 1,360 (§I.0) |
K. Tham chiếu thiết lập nhanh (một màn hình)
| Thing |
Exact value |
| Zero Trust dashboard |
https://one.dash.cloudflare.com |
| Team domain |
https://<team-name>.cloudflareaccess.com |
| OIDC callback URL |
https://<team-name>.cloudflareaccess.com/cdn-cgi/access/callback |
| Google JS origin |
https://<team-name>.cloudflareaccess.com |
| Entra Graph delegated perms |
email, offline_access, openid, profile, User.Read, Directory.Read.All, GroupMember.Read.All |
| Okta read-only API token |
Bắt buộc nếu >100 groups |
| WARP mode (enterprise) |
Gateway with WARP |
| Split tunnel — managed / BYOD |
Exclude / Include |
| Default excluded CGNAT |
100.64.0.0/10 |
| Service-token enrollment perm |
Service Auth (không phải Allow) |
| MDM silent install keys |
onboarding=false, auto_connect=1, switch_locked=true |
| OCR image size |
.jpg/.png, 4 KB–1 MB |
| PII Record threshold |
≥3 entry duy nhất ở gần nhau |
| Cloudflare WAN IPsec ciphers |
IKEv2 · AES256-GCM-16 · SHA2-256 · DH group 20 |
| MSS clamp |
GRE 1436 / IPsec 1360 |
| IPsec NAT-T |
UDP 500 → 4500 |
Soạn 2026-06-08. Tên trường và đường dẫn menu chính xác phản ánh tài liệu Cloudflare hiện hành (Cloudflare One / Cloudflare WAN) và có thể thay đổi; xác minh trên dashboard của bạn và xác nhận entitlement Enterprise (DLP, advanced posture, Cloudflare WAN) trước khi triển khai production. Thay mọi <placeholders> và secret ví dụ bằng giá trị của bạn — không bao giờ tái sử dụng token mẫu được hiện.
Cloudflare Zero Trust — Step-by-Step Configuration Runbook
Hands-on companion to the Implementation & Best-Practice Onboarding Guide. Where the guide explains why and in what order, this runbook gives the exact navigation paths, field-by-field settings, commands, and config snippets to type or click. Section letters map to the guide's numbered sections.
|
|
| Dashboards |
Zero Trust: https://one.dash.cloudflare.com · Account: https://dash.cloudflare.com |
| Team domain |
https://<team-name>.cloudflareaccess.com (used in every IdP callback URL) |
| Last reviewed |
2026-06-08 |
How to read this runbook
- Path:
A → B → C means click through those dashboard menus in order.
- Field tables list every setting on a screen, its recommended value, and notes. Replace
<placeholders> with your values.
- ⭐ = recommended best-practice value · ⚠️ = common mistake.
- Menu labels evolve; if a label moved, use the nearest equivalent (paths under Settings, Integrations, Access controls, Traffic policies).
A. Account creation & organization setup (Guide §2)
A.1 Activate Zero Trust
- Sign in at
https://dash.cloudflare.com → left nav Zero Trust (or go to https://one.dash.cloudflare.com).
- Choose a plan → enter a team name when prompted → add a payment method (required even on Free).
A.2 Set the team name
Path: Settings → Custom Pages / Settings → Team name and domain
| Field |
Value |
Notes |
| Team name |
<your-company-short-name> |
⭐ Stable, recognizable; becomes https://<team-name>.cloudflareaccess.com. ⚠️ Renaming later breaks every IdP callback URL + MDM config |
A.3 Organization defaults to set on day one
| Setting |
Path |
Recommended |
| Account MFA |
dash.cloudflare.com → My Profile → Authentication |
⭐ Enable for all admins before anything else |
| Admin roles |
dash.cloudflare.com → Manage Account → Members |
⭐ ≥2 Super Admins (break-glass); least-privilege for others |
| Custom login/block pages |
Settings → Custom Pages |
Brand them — reduces helpdesk tickets |
| Logpush (Access + Gateway) |
Settings → Logs → Logpush (or Logs → Logpush) |
⭐ Wire to SIEM/R2/S3 now, not later |
Validate: https://<team-name>.cloudflareaccess.com shows your org login page; Settings → General shows the correct plan + team name.
B. Identity provider (IdP) integration (Guide §3)
All OIDC-based IdPs use the same Cloudflare callback (redirect) URL:
https://<your-team-name>.cloudflareaccess.com/cdn-cgi/access/callback
Google also needs the Authorized JavaScript origin: https://<your-team-name>.cloudflareaccess.com
B.1 Microsoft Entra ID (Azure AD) — full walkthrough
Step 1 — Register the app (Entra admin center https://entra.microsoft.com)
Applications → Enterprise applications → New application → Create your own application.
- Name it (e.g.
Cloudflare Access) → select Register an application to integrate with Microsoft Entra ID (App you're developing) → Create. ⚠️ Do not pick a gallery app.
- Under Redirect URI, platform = Web, value =
https://<your-team-name>.cloudflareaccess.com/cdn-cgi/access/callback
- Register.
- Go to
Applications → App registrations → All applications → your app. Copy Application (client) ID and Directory (tenant) ID.
- Client credentials → Add a certificate or secret → New client secret → name it, set an expiry → copy the Value immediately (shown once). ⚠️ When it expires, all logins fail — calendar the renewal.
Step 2 — API permissions
App registrations → All applications → your app → API permissions → Add a permission → Microsoft Graph → Delegated permissions, enable these 7:
| Permission |
Purpose |
email |
User email |
offline_access |
Refresh tokens |
openid |
OIDC sign-in |
profile |
Basic profile |
User.Read |
Read the signed-in user |
Directory.Read.All |
Read directory |
GroupMember.Read.All |
⭐ Read group membership (required for group policies) |
Then Add permissions → Grant admin consent.
Step 3 — Add to Cloudflare
Zero Trust → Integrations → Identity providers → Add new identity provider → Azure AD:
| Field |
Value |
| Application (client) ID |
from Step 1.5 |
| Client secret |
from Step 1.6 |
| Directory (tenant) ID |
from Step 1.5 |
| ⭐ Support Groups |
On — lets Cloudflare read Entra group membership |
| Proof Key for Code Exchange (PKCE) |
On |
| Enable SCIM |
⭐ On for auto user/group sync + session revocation |
| Email claim |
e.g. preferred_username if UPN ≠ email |
Save → Test (confirms email + groups in the identity payload).
API alternative: POST https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/access/identity_providers with {"name":"Entra ID","type":"azureAD","config":{"client_id":"…","client_secret":"…","directory_id":"…","support_groups":true}} (token needs Access: Organizations, Identity Providers, and Groups — Write).
B.2 Okta (OIDC) — full walkthrough
- In Okta, create an OIDC → Web app integration. Set Sign-in redirect URIs =
https://<your-team-name>.cloudflareaccess.com/cdn-cgi/access/callback
- In the app's General tab, copy the Client ID and Client secret.
- In Cloudflare
Zero Trust → Integrations → Identity providers → Add new → Okta:
| Field |
Value |
| App ID |
Okta Client ID |
| Client secret |
Okta Client secret |
| Okta account URL |
your Okta domain, e.g. https://my-company.okta.com |
| Authorization Server ID |
from Okta (if using a custom auth server) |
| Okta API token (optional) |
⭐ Required if you have >100 Okta groups (read-only token prevents group lookup failures) |
Save → Test.
B.3 Google Workspace (OIDC) — full walkthrough
- In Google Cloud Console → APIs & Services → Credentials → Create OAuth client ID → Web application.
- Authorized JavaScript origins:
https://<your-team-name>.cloudflareaccess.com
- Authorized redirect URIs:
https://<your-team-name>.cloudflareaccess.com/cdn-cgi/access/callback
- Create → copy the OAuth Client ID and Client secret.
- In Cloudflare
Identity providers → Add new → Google Workspace: enter Client ID + Secret; provide the admin email / domain-wide settings so Cloudflare can read Groups.
- Save → Test.
B.4 Global / independent MFA
Path: Zero Trust → Access controls → Access settings
| Setting |
Recommended |
| Allow MFA methods |
Select your approved methods |
| Authentication duration |
e.g. 24h (shorter for sensitive) |
| Use identity provider MFA |
⭐ On — honors IdP amr claim, avoids double-prompt |
| Apply global MFA settings by default |
⭐ On |
Validate every IdP: the Test button returns the expected email + groups; disabling a test user in the IdP revokes access within the SCIM sync window.
C. Device enrollment — Cloudflare One Client (WARP) (Guide §4)
C.1 Device enrollment permissions (the gate — do this first)
Path: Settings → WARP Client → Device enrollment permissions → Manage → Add a rule
| Field |
Value |
Notes |
| Rule name |
Corporate employees |
|
| Rule action |
Allow |
(use Service Auth for token-based fleet/server enrollment) |
| Selector |
Emails ending in |
|
| Value |
@yourco.com |
|
| Authentication / Login methods |
select your IdP(s) |
⚠️ No matching rule → users see "you are not allowed to enroll" |
For silent MDM fleet enrollment, create a Service Auth rule and a service token (Access → Service Auth → Service Tokens). ⚠️ Service tokens require a Service Auth rule — an Allow rule will not work for them.
C.2 Device profile settings
Path: Settings → WARP Client → Device settings → (edit Default profile or Add a profile)
| Setting |
⭐ Recommended (managed) |
Notes |
| Service mode |
Gateway with WARP |
Full L3/L7 + DNS filtering (standard enterprise) |
| Switch lock |
On (managed) |
Prevents users disabling WARP |
| Auto connect |
1–5 min |
Re-enables after brief disconnect (e.g. captive portal). Value 0 = stays off until user reconnects |
| Captive portal detection |
On |
Lets users reach hotel/airport login pages |
| Allowed device protocols |
per policy |
e.g. allow/deny WARP over specific protocols |
| Mode switch / admin override |
Locked (managed) |
|
Create separate profiles for Servers, BYOD, Contractors and match them by posture/identity selectors.
C.3 Split Tunnels
Path: within a device profile → Split Tunnels
| Scenario |
Mode |
What to configure |
| Managed laptops |
Exclude (default) |
Everything tunnels except listed exceptions. Default list already excludes 100.64.0.0/10 (CGNAT used by Cloudflare One). ⭐ Add back any local RFC-1918/CGNAT ranges you actually use |
| BYOD / personal |
Include |
⭐ Only listed corporate IPs/domains tunnel — personal traffic stays private. Add your app domains + private CIDRs |
⚠️ Over-broad Include entries (or excluding local subnets you rely on) can black-hole LAN/Wi-Fi traffic when switching networks — test Ethernet↔Wi-Fi.
C.4 Distribute the Cloudflare root CA (required for HTTPS filtering / DLP / AI prompt inspection)
Path: Settings → Resources (download the Cloudflare certificate) → push to OS/browser trust stores via MDM before enabling TLS decryption (§F.3). ⚠️ Decryption before the CA is trusted breaks HTTPS fleet-wide.
C.5 MDM deployment (silent, pre-authenticated)
Push the client with parameters. Windows uses mdm.xml; macOS uses com.cloudflare.warp.plist. ⚠️ Local device settings take precedence over dashboard settings.
Common parameters
| Parameter |
Type |
⭐ Value / purpose |
organization |
string |
Your team name (required for managed enrollment) |
auth_client_id |
string |
Service-token client ID, e.g. 88bf3b6d….access |
auth_client_secret |
string |
Service-token secret. ⚠️ Token needs Service Auth enrollment permission, not Allow |
service_mode |
string |
warp (Gateway with WARP) |
onboarding |
boolean |
false → suppress welcome screens (silent install) |
auto_connect |
integer |
1 (connect immediately; 0 = allow off indefinitely). ⚠️ Replaces deprecated enabled — you must remove enabled if you use this |
switch_locked |
boolean |
true on managed devices |
display_name |
string |
Org nickname in the client GUI (required inside a configs array) |
support_url |
string |
Helpdesk link shown in client |
unique_client_id |
string |
Stable device identifier for posture/serial mapping |
enable_post_quantum |
boolean |
true to enable PQ tunnel crypto |
enable_netbt |
boolean |
false (default; only enable for legacy NetBIOS apps) |
environment |
string |
normal or fedramp_high |
organization_configs / configs[] |
dict/array |
Multi-org / config switching (newer clients) |
macOS .plist example (service-token enrollment, silent):
<dict>
<key>organization</key> <string>your-team-name</string>
<key>auth_client_id</key> <string>88bf3b6d86161464f6509f7219099e57.access</string>
<key>auth_client_secret</key> <string>bdd31cbc4dec990953e39163fbbb194c93313ca9f0a6e420346af9d326b1d2a5</string>
<key>service_mode</key> <string>warp</string>
<key>onboarding</key> <false/>
<key>auto_connect</key> <integer>1</integer>
<key>switch_locked</key> <true/>
<key>support_url</key> <string>https://help.yourco.com</string>
</dict>
The equivalent Windows mdm.xml uses the same keys in <RegistrationData> XML.
C.6 Device posture checks
Path: Settings → WARP Client → Device posture (or Reusable components → Posture checks → Add)
| Category |
Examples |
Usable in |
| Client checks (Cloudflare One Client) |
OS version, Disk encryption, Firewall, Client certificate, File/Registry/Application present, Serial number list, Domain joined |
Access and Gateway |
| Service-to-service (3rd-party) |
CrowdStrike, SentinelOne, Microsoft Intune, Tanium |
Access (⚠️ Tanium not supported in Gateway) |
| Access integrations |
(various) |
Access only |
⭐ For OS-version checks use the latest qualified stable (e.g. macOS ≥ 15.1), not the absolute newest, so a same-day OS release doesn't lock users out.
Validate: device shows Connected with the right profile; appears under My Team → Devices; a posture check (e.g. disk encryption) reports correctly.
D. Connect private apps/networks — Cloudflare Tunnel & Connector (Guide §5.1)
D.1 Cloudflare Tunnel via dashboard (remotely-managed — recommended)
Path: Networks → Tunnels → Create a tunnel → Cloudflared → name it → Save → copy the install command for your OS. Then map Public Hostname or Private Network routes in the dashboard.
One-line connector install (token from the dashboard):
brew install cloudflared && sudo cloudflared service install <YOUR_TUNNEL_TOKEN>
sudo cloudflared service install <YOUR_TUNNEL_TOKEN>
D.2 Cloudflare Tunnel via CLI (locally-managed)
cloudflared tunnel login
cloudflared tunnel create <NAME>
cloudflared tunnel list
~/.cloudflared/config.yml:
tunnel: <TUNNEL-UUID>
credentials-file: /root/.cloudflared/<TUNNEL-UUID>.json
ingress:
- hostname: wiki.yourco.com
service: http://localhost:3000
- hostname: ssh.yourco.com
service: ssh://localhost:22
- service: http_status:404
cloudflared tunnel route dns <NAME> wiki.yourco.com
cloudflared tunnel ingress validate
cloudflared tunnel run <NAME>
sudo cloudflared service install
⭐ Run two cloudflared replicas (different hosts) per tunnel for high availability.
D.3 WARP Connector (site-to-site / mesh on a Linux host)
sudo warp-cli connector new <TOKEN> && sudo warp-cli connect
warp-cli status
E. ZTNA — Access applications & policies (Guide §5)
E.1 Add a self-hosted application
Path: Access → Applications → Add an application → Self-hosted
| Field |
Value / recommendation |
| Application name |
Internal Wiki |
| Session Duration |
⭐ 24h standard; 15m–No duration for crown-jewel apps |
| Application domain |
wiki.yourco.com (must resolve to a tunnel/zone) |
| Identity providers |
select the IdP(s) allowed for this app |
| Instant Auth |
On if a single IdP (skips the chooser) |
| App Launcher visibility |
On (shows in the user portal) |
| Accept all available identity providers |
Off if you scope per-app |
E.2 Build an Access policy
Path: within the app → Policies → Add a policy
| Field |
Value |
| Policy name |
⭐ Allow — Full-time employees (use a reused naming convention) |
| Action |
Allow / Block / Bypass / Service Auth |
| Session duration |
inherit or override |
Rules — combine Include / Require / Exclude (Exclude overrides all):
| Rule group |
Selector |
Operator |
Value |
| Include |
IdP Groups |
in |
Engineering |
| Require |
Device Posture |
in |
Disk encryption, Firewall on |
| Require |
Authentication Method |
in |
mfa |
| Exclude |
Emails (List) |
in |
List: Offboarding |
⭐ Add a second, lowest-priority policy Block — Everyone (Action = Block, Include = Everyone) as a default-deny net. ⚠️ Policies evaluate top-down; keep Block/Exclude policies above broad Allows.
Selector cheat-sheet (most-used):
| Selector |
Use it for |
| Emails / Emails ending in |
Specific users / domain |
| IdP Groups |
⭐ Group-based access (needs group claims) |
| Device Posture |
Require compliant devices |
| Gateway |
Require traffic came through Gateway (client/RBI/WAN site) |
| Country / IP ranges |
Geo / network restrictions |
| Authentication Method / MFA |
Require strong auth |
| mTLS Certificate |
Service Auth (machine-to-machine) |
| Cloudflare Account Member |
Restrict to your account members |
E.3 Reusable building blocks (do this, not per-app rules)
| Component |
Path |
Use |
| Access Groups |
Access controls → Policies → Groups → Add a group |
⭐ Named, reusable rule block (e.g. Secure employees = group + 3 posture checks). Reference across many apps |
| Lists |
Reusable components → Lists |
Emails, device serial numbers, IPs — update via UI or API (HR/MDM integration) |
| Posture checks |
Reusable components → Posture checks |
Define once, use in Access and Gateway |
E.4 RBI fallback for unmanaged devices
Keep the normal Allow (compliant employees) and add a Gateway HTTP policy with action Isolate matching the same app hostname, so non-compliant devices get a remote-browser session instead of a hard block.
Validate: a permitted user reaches the app post-login; a non-member is blocked; Access → Logs (Logpush) show allow/block with identity + posture.
F. Secure Web Gateway (Gateway) (Guide §6)
Build policies bottom-up the stack: DNS → Network → HTTP.
F.1 DNS policies (start here)
Path: Gateway → Firewall Policies → DNS → Add a policy
| Field |
Value |
| Policy name |
Block security threats |
| Selector |
Security Categories |
| Operator |
in |
| Value |
⭐ Malware, Phishing, Command & Control, Cryptomining, DGA Domains, DNS Tunneling, New Domains |
| Action |
Block |
Add a second DNS policy for Content Categories (Adult, Gambling, etc.) per your AUP.
DNS Locations (sites without the client): Gateway → DNS Locations → Add a location → point the network's resolver at the assigned IPv4/IPv6, DoH (https://<id>.cloudflare-gateway.com/dns-query), or DoT endpoints shown.
F.2 Network (L4) policies
Path: Gateway → Firewall Policies → Network → Add a policy
| Example |
Selector / Operator / Value |
Action |
| Block outbound SMTP from clients |
Destination Port in 25 |
Block |
| Restrict RDP egress |
Destination Port in 3389 + Identity not in IT |
Block |
F.3 TLS decryption + HTTP policies
- Enable decryption:
Settings → Network → Firewall → TLS decryption → On. ⚠️ Requires the Cloudflare root CA on devices (§C.4).
- Create Do Not Inspect exceptions FIRST (
Gateway → Firewall Policies → HTTP → Add a policy, Action = Do Not Inspect):
| Exception |
Selector / Value |
| Cert-pinned apps |
Application in Do Not Inspect (Cloudflare-maintained app type) |
| Microsoft 365 |
⭐ Toggle the one-click Microsoft 365 traffic integration (auto-bypasses M365) |
| Banking / native apps |
Application or Domain in your pinned-cert list |
- HTTP filtering policy example:
| Field |
Value |
| Policy name |
Block risky uploads |
| Selector |
Application in <risky app> · or Content Category · or File Type |
| Action |
Block / Isolate / Allow / Do Not Scan |
- Application granular controls (within an HTTP policy): allow an app but block specific actions — e.g. ChatGPT → block File upload, Google Drive → block Download to non-corporate tenant. This is also the hook for AI controls (§H).
Validate: browse a blocked category → Cloudflare block page; Gateway → Logs show HTTPS entries with decrypted detail (proves CA + decryption).
G. Data Loss Prevention (DLP) (Guide §7 — Enterprise)
G.1 Pick / build a profile
Path: DLP → DLP Profiles
- Predefined: open e.g. Credentials and Secrets, Financial Information, PII → toggle individual entries on/off.
- Custom:
Create profile → add detection entries (predefined detectors, custom regex, dictionaries, EDM datasets, Microsoft Purview labels).
G.2 Tune sensitivity (per entry / profile)
| Setting |
Where |
⭐ Recommendation |
| Confidence threshold |
per detection entry |
Low / Medium / High (raised by proximity keywords, e.g. "SSN" near a 9-digit number) |
| Minimum match count |
per profile/entry |
e.g. 10 → fires only at 11+ matches (cuts noise) |
| AI context analysis |
DLP → Settings |
On (pretrained model adjusts confidence; HTTP/HTTPS only) |
| OCR |
DLP → Settings |
On to scan text in images (.jpg/.png, 4 KB–1 MB) |
PII Record profile is special: it only fires when ≥3 unique entries appear in close proximity — a built-in false-positive control.
G.3 Enforce via a Gateway HTTP policy (⭐ two-policy pattern)
Path: Gateway → Firewall Policies → HTTP → Add a policy, use the DLP Profile selector.
| # |
Selector / Value |
Action |
Purpose |
| 1 |
DLP Profile in Financial Info (Low confidence) |
Allow (+ log) |
⭐ Visibility / baseline |
| 2 |
DLP Profile in Financial Info (High confidence) + Destination Domain in dropbox.com, wetransfer.com + User Group in Finance |
Block |
Enforcement, scoped |
⭐ Run monitor (Allow+log) for 1–2 weeks, then enable the Block. ⚠️ Always scope by destination/app/group — a broad Credentials profile on all traffic floods false positives. ⚠️ No TLS decryption → DLP can't see HTTPS bodies.
Validate: upload a benign test pattern (fake SSN / test card number) to a monitored destination → detection appears in Gateway → Logs / DLP with the matched profile + confidence.
H. AI safety controls (Guide §8)
H.1 Discover shadow AI
Path: Gateway → Analytics → Shadow IT Discovery → review Generative AI app category → mark apps Approved / Unapproved.
H.2 Govern AI app usage (allow + restrict, don't block)
Path: Gateway → Firewall Policies → HTTP → Add a policy
| Field |
Value |
| Selector |
Application in ChatGPT, Google Gemini, Claude, Perplexity |
| Application granular controls |
⭐ Block File upload / restrict actions (keeps the app usable) |
| DLP Profile |
add AI Prompt: PII / AI Prompt: AI Security |
| Action |
Allow (with granular block) or Block on DLP match |
H.3 AI Prompt Protection (DLP for prompts)
Path: DLP → Detection entries → AI prompt topics → enable Content topics (PII, Source Code, Credentials & Secrets, Financial Information, Customer Data) and Intent topics (jailbreak, malicious-code, PII-extraction). Or select a predefined AI Prompt profile, then reference it in the H.2 HTTP policy. ⭐ Start in monitor mode.
H.4 DLP for AI Gateway (programmatic/API AI — no decryption needed)
Path: AI → AI Gateway → your gateway → Features → DLP → Set up → attach DLP profiles. Scans request + response text to AI providers without Gateway HTTP filtering or TLS decryption.
H.5 AI Security for Apps (WAF — for AI you expose)
Path: your zone → Security → Settings / WAF → Detections → AI Security for Apps → enable prompt injection + unsafe topic detections, then write a WAF custom rule acting on the detection fields. Complements DLP (model-layer attacks vs. data detection).
H.6 MCP server portals (governing AI agents)
Path: Access → AI controls → MCP server portals → add a portal → publish/gate/rename tools behind an Access policy.
I. Cloudflare WAN (Guide §9 — Enterprise)
I.0 Pre-flight: MSS clamping (set on your edge BEFORE bringing tunnels up)
| On-ramp |
TCP MSS clamp |
Why |
| GRE |
1,436 bytes (internal interface) |
Room for GRE header |
| IPsec |
1,360 bytes max |
Room for ESP/encryption overhead |
Vendor syntax: Cisco ip tcp adjust-mss 1436, Juniper tcp-mss 1436. ⚠️ Symptom of a missed clamp: http:// works but https:// hangs — test with curl http://ifconfig.me vs curl https://ifconfig.me.
I.1 Add an IPsec tunnel
Path: Cloudflare WAN → Configuration → Tunnels → Create → IPsec tunnel
| Field |
Value |
| Tunnel name |
site-a-primary |
| Customer endpoint |
your router's public IP (omit if behind NAT) |
| Cloudflare endpoint |
the anycast IP assigned to your account |
| Interface address |
the /31 (or /30) Cloudflare provides for the tunnel |
| Pre-shared key (PSK) |
generate / paste; store in your secrets manager |
| Health check |
On ⭐ (rate Low/Mid/High; target = the tunnel interface) |
| Replay protection |
Off unless your device can't disable it (then On) |
Supported IKEv2 parameters (match these on your device):
| Parameter |
Value |
| IKE version |
IKEv2 only |
| Phase 1 encryption |
AES256-GCM-16 |
| Phase 2 encryption |
AES256-GCM-16 |
| Phase 1 integrity / PRF |
SHA2-256 |
| Phase 2 integrity |
SHA2-256 |
| Phase 1 DH group |
20 |
| Phase 2 DH group (PFS) |
20 |
| NAT-T |
UDP 500 → 4500 (auto) |
I.2 Add a GRE tunnel (alternative)
Same path → GRE tunnel. Provide Customer endpoint, Cloudflare anycast endpoint, interface address (/31), and enable health checks. GRE is stateless (no encryption) — use IPsec where confidentiality matters.
Path: Cloudflare WAN → Configuration → Routes
| Approach |
How |
Use |
| Static routes |
Add prefix (your site/DC subnet) → next-hop = tunnel → set Priority (lower = preferred) + Weight for ECMP |
Simple, stable sites |
| BGP (over GRE/IPsec) |
Enable BGP on the tunnel; configure eBGP peer + ASNs + MD5 auth |
⭐ Multi-site / dynamic; auto-adds/removes routes |
⭐ Redundancy: create two tunnels from two separate routers. Cloudflare's end is anycast (one tunnel already reaches every Cloudflare PoP), so resilience is about your premises hardware. ⚠️ Plan IP space — overlapping subnets across sites break Magic routing.
I.4 Add security + send site traffic to Gateway
- Magic Firewall:
Magic Firewall → Add rule (L3/L4 allow/deny on Cloudflare WAN traffic). ⚠️ Network traffic is unfiltered until you add rules.
- Route Internet-bound traffic to Gateway so clientless sites get the same DNS/Network/HTTP/DLP policies as client users.
I.5 Health alerts
Path: Notifications → Add → Magic Tunnel Health → choose tunnels (filter by GRE / IPsec / CNI) → set recipients.
Validate: tunnels show Healthy; routes appear in the Magic routing table; curl https://ifconfig.me succeeds (MSS correct); disabling one tunnel fails over to the other; site Internet traffic is filtered by Gateway.
J. Validation & troubleshooting commands
warp-cli status
warp-cli settings
warp-cli account
curl https://www.cloudflare.com/cdn-cgi/trace/
curl -H 'accept: application/dns-json' \
'https://<location-id>.cloudflare-gateway.com/dns-query?name=example.com&type=A'
curl http://ifconfig.me
curl https://ifconfig.me
cloudflared tunnel info <NAME>
cloudflared tunnel ingress validate
| Symptom |
Likely cause |
Fix |
| "Not allowed to enroll" |
No device enrollment permission rule |
Add Allow/Service-Auth rule (§C.1) |
| HTTPS broken after decryption |
Root CA not trusted |
Push CA via MDM, then decrypt (§C.4) |
| Group policy never matches |
Missing group claims / no SCIM |
Re-run IdP Test; enable Support Groups + SCIM (§B) |
| App allowed that should be blocked |
Policy order |
Move Block/Exclude above broad Allow (§E.2) |
| DLP selector greyed out |
Not Enterprise / role |
Verify plan + admin role |
https:// hangs over Cloudflare WAN |
MSS clamp |
GRE 1,436 / IPsec 1,360 (§I.0) |
K. Quick settings reference (one screen)
| Thing |
Exact value |
| Zero Trust dashboard |
https://one.dash.cloudflare.com |
| Team domain |
https://<team-name>.cloudflareaccess.com |
| OIDC callback URL |
https://<team-name>.cloudflareaccess.com/cdn-cgi/access/callback |
| Google JS origin |
https://<team-name>.cloudflareaccess.com |
| Entra Graph delegated perms |
email, offline_access, openid, profile, User.Read, Directory.Read.All, GroupMember.Read.All |
| Okta read-only API token |
Required if >100 groups |
| WARP mode (enterprise) |
Gateway with WARP |
| Split tunnel — managed / BYOD |
Exclude / Include |
| Default excluded CGNAT |
100.64.0.0/10 |
| Service-token enrollment perm |
Service Auth (not Allow) |
| MDM silent install keys |
onboarding=false, auto_connect=1, switch_locked=true |
| OCR image size |
.jpg/.png, 4 KB–1 MB |
| PII Record threshold |
≥3 unique entries in proximity |
| Cloudflare WAN IPsec ciphers |
IKEv2 · AES256-GCM-16 · SHA2-256 · DH group 20 |
| MSS clamp |
GRE 1436 / IPsec 1360 |
| IPsec NAT-T |
UDP 500 → 4500 |
Prepared 2026-06-08. Field names and exact menu paths reflect current Cloudflare docs (Cloudflare One / Cloudflare WAN) and may shift; verify against your dashboard and confirm Enterprise entitlements (DLP, advanced posture, Cloudflare WAN) before production rollout. Replace all <placeholders> and example secrets with your own values — never reuse the sample tokens shown.
Nguồn cộng đồng — không phải tài liệu chính thức của Cloudflare: https://zerotrust.cfsase.workers.dev
Community source — not an official Cloudflare publication: https://zerotrust.cfsase.workers.dev