Connect services and devices with post-quantum encrypted private networking through Cloudflare.
Cloudflare Mesh gives every enrolled server, laptop, and phone a private Mesh IP. Participants can communicate by IP over TCP, UDP, or ICMP, including device-to-device connections that do not require customer-managed networking infrastructure.
Mesh nodes run the Cloudflare One Client in headless mode on Linux. They can also advertise routes to make private subnets and hostnames reachable from other Mesh participants.
For details about how Mesh works, protocol requirements, and Mesh IP assignment, refer to Concepts.
- Connect enrolled devices to each other by private IP.
- Provide bidirectional connectivity between servers, cloud networks, and sites.
- Route traffic to devices that cannot run the Cloudflare One Client.
- Preserve long-lived TCP connections for databases, replication, ERP systems, and remote administration.
Set up Cloudflare Mesh
Configure your account and connect your first participant.
Understand Mesh
Learn how participants, Mesh IPs, routing, and policies work.
Explore features
Configure routes and high availability for Mesh nodes.
Follow a guide
Connect client devices or deploy Mesh in containers.
Use Mesh when participants need bidirectional private IP connectivity or when a workload requires stable, long-lived connections. Use Cloudflare Tunnel when you want to publish specific applications, hostnames, or IP routes through an outbound-only connector.
For a detailed comparison, refer to How Cloudflare Mesh works.