Cloudflare Docs
Cloudflare Zero Trust
Edit this page on GitHub
Set theme to dark (⇧+D)

Require Gateway

With Require Gateway, you can allow access to your applications only to devices enrolled in your organization’s instance of Gateway. Unlike Require WARP, which will check for any WARP instance (including the consumer version), Require Gateway will only allow requests coming from devices whose traffic is filtered by your organization’s Cloudflare Gateway configuration. This policy is best used when you want to protect company-owned assets by only allowing access to employees.

​​ Prerequisites

  • Cloudflare WARP client is deployed on the device. For a list of supported modes and operating systems, refer to WARP client checks.

​​ Enable the Gateway check

  1. In Zero Trust, go to Settings > WARP Client.

  2. In WARP client checks, select Add new.

  3. Select Gateway, then select Save.

​​ Add the check to an Access policy

  1. In Zero Trust, go to Access > Applications.

  2. Select the application for which you want to require Gateway, then select Configure.

  3. To create a new Access policy, select Add a policy. To require Gateway for an existing policy, select a policy, then select Configure.

  4. Add an Include or Require rule which uses the Gateway selector. Select Save policy.

Before granting access to the application, your policy will now check that the device is running the WARP client and enrolled in your Zero Trust organization.