SSE / ZTNA / Cloudflare

Cloudflare One: Access and Gateway

Cloudflare Access applies authorization policy to protected applications, while Gateway applies outbound DNS, network and HTTP controls. A deployment needs the right client or connector path as well as the policy itself.

Identity-aware private access and web traffic policyResearch reviewed

What you are evaluating

The scored scope is Access plus Gateway HTTP filtering with the required client, tunnel and TLS trust configuration. DLP, browser isolation, CASB API scanning and WAN services are excluded from the selected baseline.

A useful evaluation context

Consider for teams seeking clearly separated application authorization and outbound traffic policy within one cloud platform.

Documented capabilities

The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.

  • Access policy combines actions with user, group and contextual selectors.
  • Gateway HTTP policy can inspect supported web requests when traffic routing and certificate trust are configured.
  • Separate authentication, Gateway and administrative log categories support investigation.

Where it fits in the work

  1. Publish a lab application through a supported connector and require an approved test identity.
  2. Steer a managed endpoint’s web traffic through Gateway and configure its trust certificate.
  3. Test a denied application request and a blocked web request, then inspect the different logs.

APPLY THE IDEA / ILLUSTRATIVE EXERCISE

Make the outcome observable.

A lab user can open one private application but cannot upload a harmless file to a blocked test destination.

Evidence to look for

Show the Access decision separately from the Gateway HTTP decision and identify whether content inspection was enabled.

Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.

Questions for your evaluation

  1. Which client mode and split-tunnel rules apply to this resource?
  2. Is HTTPS decrypted, bypassed or unsupported on this path?
  3. What log retention and export entitlements meet the investigation requirement?

Names you may encounter: Cloudflare Access · Cloudflare Gateway. Historical names do not establish current availability or feature equivalence.

Find your next idea.

Tip: press / to open search. Escape closes this window.