Tunnels & encapsulation
Magic WAN uses and tunnels to transmit packets from Cloudflare’s edge to your origin network. Cloudflare sets up tunnel endpoints on edge servers inside your network namespace, and you on routers at your data center.
This works because the Anycast protocol is stateless — each packet is processed independently and does not require any negotiation or coordination between tunnel endpoints. Tunnel endpoints are technically bound to IP addresses but do not need to be bound to specific devices. Any device that can strip off the outer headers and then route the inner packet can handle any packet sent over the tunnel.
Cloudflare’s Anycast architecture provides a conduit to your Anycast tunnel for every server in every data center on Cloudflare’s global edge network.