Cloudflare Docs
Cloudflare Zero Trust
Edit this page on GitHub
Set theme to dark (⇧+D)

WARP modes

You can deploy the WARP client in different modes to control the types of traffic sent to Cloudflare Gateway. The WARP mode determines which Zero Trust features are available on the device.

​​ Gateway with WARP (default)

This mode is best suited for organizations that want to use advanced firewall/proxy functionalities and enforce device posture rules.

DNS filteringHTTP filteringFeatures enabled
YesYesDNS policies, HTTP policies, Browser Isolation, identity-based policies, device posture checks, AV scanning, and Data Loss Prevention

​​ Gateway with DoH

This mode is best suited for organizations that only want to apply DNS filtering to outbound traffic from their company devices. Network and HTTP traffic is handled by the default mechanisms on your devices.

DNS filteringHTTP filteringFeatures enabled
YesNoDNS policies

​​ Secure Web Gateway without DNS filtering

This mode is best suited for organizations that want to proxy network and HTTP traffic but keep their existing DNS filtering software. DNS traffic is handled by the default mechanism on your device.

DNS filteringHTTP filteringFeatures enabled
NoYesHTTP policies, Browser Isolation, identity-based policies, device posture checks, AV scanning, and Data Loss Prevention

​​ Proxy mode

This mode is best suited for organizations that want to filter traffic directed to specific applications.

DNS filteringHTTP filteringFeatures enabled
NoYesHTTP policies, Browser Isolation, identity-based policies, AV scanning, and Data Loss Prevention for traffic sent through localhost proxy

​​ Device Information Only

This mode is best suited for organizations that only want to enforce WARP client device posture checks for zones in your account. DNS, Network and HTTP traffic is handled by the default mechanisms on your devices. To setup Device Information Only mode, refer to the dedicated page.

DNS filteringHTTP filteringFeatures enabled
NoNoDevice posture rules in Access policies