Single-vendor SASE simplifies security, networking, and DevOps. Announcement >

Magic Firewall

Cloud-native network firewall for your enterprise WAN
Magic Firewall Illustration

Enforce consistent network security policies across your entire WAN, including headquarters, branch offices, and virtual private clouds. Deploy fine-grained filtering rules globally in under 500ms — all from a common dashboard.

Magic Firewall Illustration

No appliances to manage

Teams gateway build for the cloud spot illustration

With firewall-as-a-service (FWaaS) delivered from the Cloudflare global network, your security scales with your business needs. No more artificial choke points or downtime for appliance upgrades. A single dashboard and policy management interface simplifies firewall configuration and ensures consistent security policies from Toronto to Tokyo.

Learn More
Teams gateway build for the cloud spot illustration

Filter unwanted traffic before it reaches you

Ddos protection hero illustration

With Magic Firewall, your filtering policies are applied on the Cloudflare global edge network. Unwanted traffic is filtered in the cloud before it reaches your network, preventing it from congesting your network links or exploiting zero day vulnerabilities in your environment. Intelligent L3 DDoS protection can be enabled for your Internet traffic using Magic Transit.

Ddos protection hero illustration

Key Features

Configure and enforce consistent security policies across your entire WAN with a single dashboard.
Filtering rules based on protocol, port, IP addresses, packet length and bit field match
Fast propagation of rule changes in under 500ms
Traffic analytics per rule using dashboard or GraphQL API
Unlimited scale — no appliances to manage
Single dashboard to manage firewall and network configuration
Programmable API for automated deployment and management
DDoS protection with Magic Transit
Managed threat intelligence IP lists
Geo-blocking by country based on user location
Protocol validation rules to inspect traffic validity
Packet captures on demand for network troubleshooting
Optional upgrade to secure web gateway with Cloudflare One

Integrated with Cloudflare One

With Cloudflare One

Magic Firewall provides the cloud firewall foundation for Cloudflare One, our comprehensive solution for SASE.

Cloudflare One replaces a patchwork of legacy appliances and proprietary circuits with Magic WAN — a comprehensive cloud-based WAN-as-a-Service solution that provides built-in:

With Cloudflare One

Trusted by millions of Internet properties

Logo doordash trusted by gray
Logo garmin trusted by gray
Logo 23andme trusted by gray
Logo lending tree trusted by gray
NCR logo
Thomson Reuters logo
Logo zendesk trusted by gray

Ready to retire your legacy firewall appliances?