Skip to content
Cloudflare for Teams
Visit Cloudflare for Teams on GitHub
Set theme to dark (⇧+D)

Arbitrary TCP

Cloudflare Access provides a mechanism for end users to authenticate with their single sign-on (SSO) provider and connect to resources over arbitrary TCP without being on a virtual private network (VPN).

This section will cover:

  1. How to connect the host to Cloudflare
  2. How to connect from a Client machine over arbitrary TCP

Connect the host to Cloudflare

1. Install the Cloudflare daemon

The Cloudflare daemon, cloudflared, will maintain a secure, persistent, outbound-only connection from the machine to Cloudflare. Arbitrary TCP traffic will be proxied over this connection using Argo Tunnel.

Follow these instructions to download and install cloudflared on the machine hosting the resource.

2. Authenticate the Cloudflare daemon

  1. Run the following command to authenticate cloudflared into your Cloudflare account.
$ cloudflared tunnel login

cloudflared will open a browser window and prompt you to log in to your Cloudflare account.

If you are working on a machine that does not have a browser, or a browser window does not launch, you can copy the URL from the command-line output and visit the URL in a browser on any machine.

  1. Once you login, Cloudflare will display the sites that you added to your account.

  2. Select the site where you will create a subdomain to represent the resource. For example, if you plan to share the service at select from the list.

  3. Once selected, cloudflared will download a wildcard certificate for the site. This certificate will allow cloudflared to create a DNS record for a subdomain of the site.

3. Secure the subdomain with Cloudflare Access

Next, protect the subdomain you plan to register with a Zero Trust policy. Follow these instructions to build a new policy to control who can connect to the resource.

For example, if you share the resource at, build a policy to only allow your team members to connect to that subdomain.

4. Connect the resource to Cloudflare

cloudflared can proxy connections to nonstandard ports.

Run the following command to connect the resource to Cloudflare, replacing the and 7870 values with your site and port.

$ cloudflared tunnel --hostname --url tcp://localhost:7870

cloudflared will confirm that the connection has been established. The process needs to be configured to stay alive and autostart. If the process is killed, end users will not be able to connect.

Connect from a client machine

1. Install the Cloudflare daemon on the client machine

Follow the same steps above to download and install cloudflared on the client desktop that will connect to the resource. cloudflared will need to be installed on each user device that will connect.

2. Connect to the resource

Run the following command to create a connection from the device to Cloudflare. Any available port can be specified.

$ cloudflared access tcp --hostname --url localhost:9210

This command can be wrapped as a desktop shortcut so that end users do not need to use the command line.

Point the client application to the selected port.

When the client launches, cloudflared will launch a browser window and prompt the user to authenticate with your SSO provider.