Cloudflare Docs
Learning Paths
Secure your Internet traffic and SaaS apps (Learning Path)
Edit this page on GitHub
Set theme to dark (⇧+D)

Proxy traffic through Gateway

  1 min read

With Cloudflare Gateway, you can log and filter DNS, network, and HTTP traffic from devices running the WARP client. This includes traffic to the public Internet and traffic directed to your private network. DNS filtering is enabled by default since the WARP client sends DNS queries to Cloudflare’s public DNS resolver, 1.1.1.1. To enable network and HTTP filtering, you will need to allow Cloudflare Gateway to proxy that traffic.

​​ Enable the proxy

  1. Go to Settings > Network.
  2. Enable Proxy for TCP.
  3. (Recommended) To proxy all port 443 traffic, including internal DNS queries, select UDP.
  4. (Optional) To scan file uploads and downloads for malware, enable anti-virus scanning.

Cloudflare will now proxy traffic from enrolled devices, except for the traffic excluded in your split tunnel settings. For more information on how Gateway forwards traffic, refer to Gateway proxy.