Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Cloudflare Zero Trust is not a complete security program you get by switching on one product. It is an architecture and set of policies: decide which applications and traffic to protect, which identity and device signals to trust, and what conditions must be met before a request is allowed. Cloudflare describes Cloudflare One as its SASE platform, with Access, Gateway, the Cloudflare One Client, identity providers, and device posture checks working together to apply least privilege.

What Cloudflare Zero Trust does—and what your team must design

Cloudflare describes Cloudflare One as a SASE platform that unifies enterprise networking and security through a control plane. Its product set includes Access, Secure Web Gateway, Cloudflare Tunnel, data loss prevention, Remote Browser Isolation, CASB, email security, Digital Experience Monitoring, Cloudflare WAN, and related network controls. Cloudflare defines its Zero Trust model around least privilege: authenticate and authorize requests using identity and context rather than assuming that network location alone establishes trust.

In an enterprise deployment, Access controls reachability to applications through policies. Gateway filters traffic. The Cloudflare One Client provides an endpoint path for routing and filtering traffic and supplying posture-related signals. An identity provider (IdP) supplies identity and, where configured and supported, group or authentication-method information. Your team still has to select the signals, write and test policy logic, deploy client and certificate settings, and govern exceptions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How Access policies decide who can reach an application

Cloudflare states that Access determines who can reach an application by applying the policies an administrator configures. Each policy combines an action—Allow, Block, Bypass, or Service Auth—with rule types (Include, Require, and Exclude), selectors, and values. Selectors can use email addresses, IdP groups, authentication method, Gateway status, and device posture.

#1 Best Overall
FortiGate-40F Firewall Appliance plus 1 Year FortiCare Premium and FortiGuard Unified Threat Protection (UTP) (FG-40F-BDL-950-12)
  • INTEGRATED FIREWALL APPLIANCE AND SECURITY SERVICES: Comes with FortiGate-40F Firewall Appliance, 1 year of FortiCare Premium, and FortiGuard Unified Threat Protection.
  • UTP SECURITY FEATURES: Offers protection from advanced threats with DNS filtering, URL filtering, video filtering, and controls against botnets.
  • IDEAL FOR SMALLER SETTINGS: Best suited for small to mid-sized businesses needing reliable security without the complexity of larger systems.
  • CONTINUOUS SUPPORT AND MAINTENANCE: FortiCare Premium ensures that technical help is readily available to manage and troubleshoot issues.
  • COMPACT AND EFFECTIVE: Provides a powerful, yet compact security solution that effectively protects against a wide range of cyber threats.

Policy order matters, and a broad Include rule can unintentionally admit everyone or all valid email login methods. Treat each application policy as an explicit access decision, not as a general-purpose security baseline.

A least-privilege policy design example

For a hypothetical internal application, an administrator might configure an Allow policy that Includes a named workforce group, Requires an approved authentication method and an organization-Gateway device check, and Excludes a specifically identified account or group that must not have access. The exact selectors and values depend on the identity provider, client configuration, and application. This example illustrates how the policy components fit together; it is not a complete baseline or a recommended universal rule.

Before rollout, test both intended access and denial cases. Use representative accounts in and out of the allowed group, accounts with and without the required authentication signal, and enrolled and unenrolled devices. Check policy order and confirm that a broad Include, an unexpected Exclude, or a Bypass rule does not change the result. Validate the actual IdP claims and the policy behavior in your own configuration rather than assuming that a group name or MFA setting is being passed as expected.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

Choose the application type around the access and session boundary

Cloudflare Access supports self-hosted, SaaS, and infrastructure applications, as well as bookmarks. Select the type according to what you are protecting and the authorization or session behavior you need.

  • Self-hosted applications: Use for applications your organization operates and wants to put behind Access policies.
  • SaaS applications: Access can apply policies at initial sign-on and when reissuing the SaaS session. Once a user has authenticated to the SaaS service, that service controls its own session management; Access does not take over the application’s ongoing session.
  • Infrastructure applications: Use for infrastructure access scenarios, where the supported authentication method can differ from browser-based application sign-in.
  • Bookmarks: Use when users need a managed link destination. A bookmark by itself should not be mistaken for an access policy protecting an application.

For SaaS, define the boundary clearly: Access can govern entry and session reissue, while the SaaS application governs the session after authentication. If your requirement depends on revoking or controlling an already established SaaS session, confirm that application’s own session controls as part of the design.

Select a Cloudflare One Client mode based on required coverage

The Cloudflare One Client was formerly called WARP. Its mode determines what traffic and endpoint controls are available. Choose according to the controls required, the existing DNS architecture, and your ability to deploy and manage the client; no single mode is right for every environment.

Rank #3
SonicWall NSa4700 Gen7 Firewall | High-Performance Enterprise Appliance with 18 Gbps Firewall Throughput, 9.5 Gbps UTM/Threat Protection, and Multi-Gig Ports Accelerator (02-SSC-4328)
  • SonicWall NSa4700 Appliance Only - No Service Subscription (02-SSC-4328) - Delivers very high firewall and threat prevention throughput with millions of concurrent connections for large enterprise networks and aggregation sites.
  • Defends against ransomware, zero-day exploits, and encrypted malware with Capture ATP sandboxing and RTDMI for precise detection and blocking.
  • Enterprise connectivity with multiple 10 GbE SFP+ and 1 GbE ports supports bandwidth-heavy applications and east-west segmentation.
  • Scales for thousands of VPN tunnels and large remote workforces, enabling secure connectivity across global sites and data centers.
  • Redundant power options and high availability modes provide resiliency for mission-critical operations.
Mode Documented scope Design implication
Traffic and DNS Routes device traffic and supports DNS, network, and HTTP filtering, identity-based policies, and posture checks. Use when the design needs broad traffic filtering and device posture capabilities.
DNS-only Filters DNS queries; it does not inspect HTTP traffic or enforce device posture checks. May fit a DNS-focused deployment, but does not meet a requirement for HTTP inspection or posture enforcement.
Traffic-only Routes traffic without the broader DNS-and-traffic mode scope. Consider when traffic routing is needed but DNS filtering is handled separately.
Local proxy Provides filtering through a local proxy. Evaluate for environments designed around local proxy filtering.
Posture-only Provides posture checks without the broader traffic-filtering scope. Consider when posture signaling is needed for decisions but traffic filtering is provided another way.

Cloudflare’s setup guidance calls for creating a Zero Trust organization, choosing a login method—One-time PIN or a third-party identity provider—and configuring the client. The team name is required for many features, including HTTP policies, Browser Isolation, and device posture. During rollout, account for configuration drift: local device settings can take precedence over dashboard settings, so compare effective endpoint settings with the intended central configuration and manage precedence through your endpoint-management process.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use device posture to distinguish enrolled devices from any client

Posture checks add device context to Access decisions. Cloudflare documents a Require Gateway check that verifies requests come from devices running the organization-enrolled client whose traffic is filtered by the organization’s Gateway configuration. This is more specific than Require WARP, which can match consumer WARP as well. For company-owned assets, choose the organization-Gateway check when the requirement is specifically to verify the organization-managed client and filtering path.

Posture is only useful as a control if the signal is available in the selected client mode and the endpoint is configured to report it. Align the check with your device enrollment and support model, and test requests from both managed and unmanaged devices before relying on it.

Rank #4
OEM 150W 12V 12.5A Power Adapter Compatible with Sophos XGS 116 XGS 116w XGS 118 XGS 118w XGS 126 XGS 126w XGS 128 XGS 128w XGS 136 XGS 136w XGS 138 Enterprise Firewall Security Appliance Power Supply
  • 150W High Output Power Supply – Delivers stable 12V DC 12.5A output for Sophos XGS desktop firewall appliances requiring a 150W external power adapter. Designed for continuous network security operation in business and enterprise environments.
  • Compatible Sophos XGS Models – Compatible with Sophos XGS 116, XGS 116w, XGS 118, XGS 118w, XGS 126, XGS 126w, XGS 128, XGS 128w, XGS 136, XGS 136w and XGS 138 firewall security appliances.
  • Reliable Enterprise Performance – Built for firewall, network gateway and security appliance applications where stable power delivery is critical for uninterrupted network operation and security services.
  • Universal AC Input – Supports worldwide input voltage 100-240V AC, 50/60Hz for business, IT deployment and enterprise network installations across multiple regions.
  • Professional Replacement Power Solution – Ideal replacement for aging, damaged or missing power adapters used with Sophos XGS Series security appliances. Provides dependable power for long-term deployment in office, MSP, education and enterprise environments.

Plan Gateway filtering and HTTPS inspection deliberately

Gateway can inspect and filter DNS, network, HTTP, and egress traffic. HTTPS inspection requires a Cloudflare root certificate on each client device so TLS traffic can be decrypted. The Cloudflare One Client can install the certificate on supported devices. If certificate installation is unsupported or inspection is unwanted, administrators can create Do Not Inspect exemptions.

Before enabling inspection broadly, plan certificate distribution and confirm application compatibility on the device types you support. Define who can approve an exemption, how exceptions are documented and reviewed, and how users are informed about inspection. An exemption is a deliberate reduction in visibility, so scope it to the applications or traffic that need it rather than treating exceptions as an informal workaround.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Decide where MFA is enforced and verify the signal

MFA can be enforced by an identity provider or independently in Access. If Access relies on the IdP to report the authentication method, validate that the method information is actually present and that the Access policy evaluates it as intended. Access can also enforce MFA directly without relying on the IdP for that requirement.

Best Value
Fortinet FortiGate-70G Firewall for Branch and Small Offices with 3-Year FortiGuard AI-Powered Enterprise Security Services (FG-70G-BDL-809-36)
  • Built on a purposed-built secure processor, this compact network firewall delivers the highest level of security performance and energy efficiency in its class – 2.5 Gbps IPS throughput | 1.3 Gbps threat protection | 1.4 Gbps SSL Inspection throughput.
  • User-friendly management console gives you centralized visibility and simplifies policy enforcement across your network. Its zero-touch deployment helps you optimize your onboarding experience.
  • Compact design equipped with 10 x GE RJ45 ports (including 7 x Internal Ports, 2 x WAN Ports, 1 x DMZ Port) provide essential connectivity and flexibility for various network configurations in branch offices.

Cloudflare documents authenticator applications, WebAuthn security keys, and device biometrics for independent MFA. PIV and FIDO2 keys are supported for SSH infrastructure applications only; these are distinct from browser-based WebAuthn security keys. Confirm that the method you choose is supported in the particular flow and application type instead of assuming one key works everywhere.

Roll out in stages and check operational details

  1. Map protected resources and access owners. Inventory self-hosted, SaaS, infrastructure, and link destinations; identify who owns each application and which user populations need access.
  2. Choose identity and login signals. Configure One-time PIN or a third-party IdP, then verify group provisioning and authentication-method claims where policies depend on them.
  3. Set up the organization and client configuration. Create the Zero Trust organization, establish its team name, select the client mode against the control requirements, and define how endpoint settings will be deployed and kept consistent.
  4. Build narrowly scoped application policies. Specify the action, Include, Require, and Exclude rules, selectors, and values for each application. Review ordering and check for broad inclusion or unintended bypass behavior.
  5. Validate both allowed and denied requests. Test users, groups, authentication methods, and device states that should pass, along with nearby cases that should fail. Confirm the actual outcome rather than relying on the policy’s appearance in the dashboard.
  6. Deploy Gateway controls and certificates where needed. Decide which traffic types to filter, distribute the root certificate to supported endpoints if HTTPS inspection is required, and establish a reviewed process for Do Not Inspect exceptions.
  7. Monitor configuration and access lifecycle. Compare effective device settings with central intent, investigate drift, and manage both authentication revocation and seat assignment when users leave or change roles.

Cloudflare’s getting-started FAQ says Zero Trust subscriptions consume seats when users authenticate to applications or enroll the client. Removing a seat and revoking authentication are separate actions: removing a seat alone does not permanently prevent future authentication. Plan offboarding around both actions. Pricing and plan entitlements can change, so check the current Cloudflare account and plan details before budgeting or committing to a feature.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.