Cloudflare Docs
Magic WAN
Edit this page
Report an issue with this page
Log into the Cloudflare dashboard
Set theme to dark (⇧+D)

Cloudflare Magic WAN

Improve security and performance for your entire corporate networking, reducing cost and operation complexity.
Enterprise-only

Magic WAN provides secure, performant connectivity and routing for your entire corporate networking, reducing cost and operation complexity. Magic Firewall integrates smoothly with Magic WAN, enabling you to enforce network firewall policies at Cloudflare’s global network, across traffic from any entity within your network.

With Magic WAN, you can securely connect any traffic source — data centers, offices, devices, cloud properties — to Cloudflare’s network and configure routing policies to get the bits where they need to go, all within one SaaS solution.

Magic WAN supports a variety of on-ramps including any device that supports Anycast GRE or IPsec tunnels. To make it easier to onboard your cloud properties, you can use Magic Cloud Networking, which automates the process of creating on-ramps from your cloud networks.

Refer to On-ramps for a full list of supported on-ramps.


​​ Features

​​ Magic WAN Connector

Use Magic WAN Connector to automatically connect, steer, and shape any IP traffic.

​​ Connect with third-party device

Magic WAN is compatible with a host of third-party devices. If you do not have Magic WAN Connector, start here to learn how to set up Magic WAN manually.

​​ Tunnel health checks

Magic WAN sends health check probes to monitor network status and the health of specific network components.

​​ Automatic cloud on-ramps

Automate resource discovery, and reduce management burden when connecting to your public cloud.

​​ Network analytics

Network analytics allows you to check traffic patterns and DDoS attacks in near real-time, to troubleshoot IP traffic issues.