Cloudflare
– Cloudflare

Cloudflare delivered unto the IT world its vision of the network of the future today with the launch of its Cloudflare One secure access service edge (SASE) platform.

The platform combines the company's Access zero-trust network access (ZTNA) and Gateway secure web gateway (SWG) products with its Warp gateway client, as well as its forthcoming next-generation firewall and remote browser isolation.

Cloudflare has been on this journey for more than two years, and during that time, it's launched the individual components that make up Cloudflare One, explained CEO Matthew Prince, in a blog post.

"The old model of the corporate network has been made obsolete by mobile, [software-as-a-service], and the public cloud. The events of 2020 have only accelerated the need for a new model," he wrote.

Cloudflare One is built around the principle of ZTNA, which provides access to applications and services only to those who have been authenticated. However, unlike other SASE vendors, Cloudflare is approaching the problem from two directions: on-ramps and filters.

On-ramps do just what the name suggests: connect users, devices, or locations to Cloudflare's edge. This can be achieved using the company's WARP agent, magic transit, or network interconnect. Each of these takes advantage of Cloudflare's Argo smart routing technology to accelerate traffic.

Once connected to Cloudflare's massive network, the company employs what it calls filters to shield networks from attacks, inspect traffic for threats, and apply least privilege rules to data and applications. Cloudflare's current offering includes ZTNA and SWG. The company plans to release Magic Firewall in the near future to provide an alternative to next-generation firewalls.

"Most competitors in this space focus on one area, which loses out on the efficiencies of combining them in a single solution," wrote Prince. "By integrating both sides of the challenge, we can give administrators a single place to manage and secure their networks."

The network of old is broken; ZTNA is its salvation

According to Prince, the middle ages of corporate security are over.

"Legacy corporate security followed a castle and moat approach," Prince wrote. "You put all your sensitive application[s] and data in the castle, you required all your employees to come to work in the castle every day, and then you built a metaphorical moat around the castle using firewalls, [distributed denial of service] appliances, gateways, and more."

According to Prince, the rise of a remote workforce, the adoption of public cloud, and SaaS applications have rendered this approach not only impractical but outright insufficient. Cloudflare says that the only way forward for enterprises is ZTNA.

"Rather than having to lease expensive MPLS circuits to connect branch offices – something that is literally impossible as people work from home – you instead require every use of every application to be authenticated," Prince wrote.

Partnering where it matters

While Cloudflare has developed much of its SASE stack in-house, the company believes there are two areas where it makes sense to partner: identity management and device integrity.

"Most organizations already have one or more identity management systems," wrote Prince. "Rather than requiring them to change, we are integrating with all the major providers."

Cloudflare One will support Okta, Ping Identity, OneLogin, Facebook, Google Workplace, GitHub, LinkedIn, and Microsoft Active Directory for identity management.

"Cloudflare One does not require you to standardize on just one identity provider," Prince explained, adding that the platform will support multiple identity providers.

Prince compared the philosophy to international travel and border control. "The identity provider issues passports, and Cloudflare One is the border agent that checks that they're valid."

Taking the metaphor a step further, he said that when device integrity is introduced, it is possible not only to control who enters based on their credentials but also on risk or health.

"It's like having a temperature screening and COVID-19 test when you enter a country," he wrote. "Even if you have a valid passport, if you're not healthy, then you will be turned away."

Cloudflare One currently supports VMware Carbon Black, CrowdStrike, SentinelOne, and Tanium for endpoint security and device posture.

More to come

Prince adds that today's announcement marks the beginning of Cloudflare's SASE journey.

In addition to the integration of Access, Gateway, and Warp, Cloudflare will be rolling out an alternative to SD-WAN and next-generation firewall appliances called Magic WAN and Magic Firewall, respectively, in the near future.

And on the security front, Prince teased that intrusion detection and data loss prevention capabilities are in the works.