Skip to content

Cloudflare Mesh

Last updated View as MarkdownAgent setup

Connect services and devices with post-quantum encrypted private networking through Cloudflare.

Cloudflare Mesh gives every enrolled server, laptop, and phone a private Mesh IP. Participants can communicate by IP over TCP, UDP, or ICMP, including device-to-device connections that do not require customer-managed networking infrastructure.

Mesh nodes run the Cloudflare One Client in headless mode on Linux. They can also advertise routes to make private subnets and hostnames reachable from other Mesh participants.

The Mesh network map in the Cloudflare dashboard showing nodes and devices connected through Cloudflare

For details about how Mesh works, protocol requirements, and Mesh IP assignment, refer to Concepts.

Use cases

  • Connect enrolled devices to each other by private IP.
  • Provide bidirectional connectivity between servers, cloud networks, and sites.
  • Route traffic to devices that cannot run the Cloudflare One Client.
  • Preserve long-lived TCP connections for databases, replication, ERP systems, and remote administration.

Get started

Understand Mesh

Learn how participants, Mesh IPs, routing, and policies work.

Mesh vs. Cloudflare Tunnel

Use Mesh when participants need bidirectional private IP connectivity or when a workload requires stable, long-lived connections. Use Cloudflare Tunnel when you want to publish specific applications, hostnames, or IP routes through an outbound-only connector.

For a detailed comparison, refer to How Cloudflare Mesh works.

Was this helpful?