Cloudflare · Solutions Engineering
A high-level introduction

Cloudflare SASE

Securing a distributed workforce and its applications — from one global network.

Press Space to advance · back · S for presenter notes · F full-screen · Esc overview

Why now

Your perimeter dissolved.

Users, applications, and data used to sit inside one building. Now they're everywhere at once.

16regions you operate in
Everywhereyour people work from
  • Employees work from home, branch offices, and the road
  • Apps live in SaaS, public cloud, and your own data centres
  • Contractors and BYOD need access without a laptop rebuild
  • Every one of those connections is a door to secure
The problem with the old way

Backhauling traffic doesn't scale.

◈ Castle-and-moat

  • VPN hairpins remote users back to HQ
  • Stacks of appliances at each site
  • Once inside the VPN, users see everything
  • Slow for users, expensive to run, hard to scale to 16 regions

◆ Secure at the edge

  • Users connect to the nearest edge location
  • Security runs in the cloud, not in boxes
  • Access is per-application, never "the whole network"
  • Fast for users, one policy everywhere
The definition

SASE = Networking + Security, delivered from the cloud.

Secure Access Service Edge. Instead of buying network and security products separately and wiring them together, you get them as one cloud service that sits between your users and everything they connect to.

Think of it as a smart, secure on-ramp to the internet and your apps — the same on every continent.
How it fits together — Cloudflare One

Every user and device, connected safely to every resource — through one network.

Users & Devices Cloudflare Global Network Your Resources Remote worker Managed laptop Office / branch 16 regions Contractor BYOD · clientless Cloudflare One One platform · every service in every location WARP agent / clientless Gateway Secure web gateway Access ZTNA CASB SaaS posture DLP Data protection Browser Isolation Email Security CES Internal apps Data centre / cloud SaaS apps M365, Salesforce… Public internet Any website Email M365 / Google
Traffic never goes straight to a resource. It flows through Cloudflare first — where identity, threats, and data are all checked. Press Space to walk through each service.
How it works — the journey of one request

Connect once. Verified every time.

01

Connect

The user's device or browser reaches the nearest Cloudflare location — one of 337+ cities.

02

Verify

Identity and device health are checked. Access decides — per app — whether to allow it.

03

Inspect

Gateway, DLP, and CASB filter threats and protect data in the same pass.

04

Deliver

Only clean, authorised traffic reaches the app, SaaS, or site — fast.

No hairpin, no appliance stack. The decision happens next to the user, then the request goes straight to its destination.
Start here — the VPN replacement

Zero Trust access to internal apps.

  • Per-app, not per-network — users reach only the apps they're entitled to
  • Identity + device posture checked on every request
  • Clientless option for contractors and BYOD — just a browser
  • No more VPN to scale, patch, or hairpin
See it live →
A working demo: log in to an internal app, gated by Cloudflare Access.
Filtering the open internet

A secure gateway for all outbound traffic.

  • DNS & HTTP filtering — block malware and phishing destinations
  • Category & content policy — consistent acceptable-use everywhere
  • Inspect once — the same policy for every user in every region
Gateway is the outbound counterpart to Access. Access controls who gets in; Gateway controls where users can go out.
Because email is how attacks start

Cloudflare Email Security (CES).

  • Phishing & business email compromise — catches what native filters miss
  • Layers on top of Microsoft 365 & Google — you don't rip anything out
  • Flexible deployment — inline (MX) or API/journaling with no mail-flow change
  • Feeds the same platform — links can open in Browser Isolation, findings enrich Zero Trust
#1Email is the top initial attack vector
A great, low-risk first project: it sits beside your existing mail, so you see value before changing anything.
Why Cloudflare

Every service. Every location. One dashboard.

337+cities worldwide
500 Tbpsnetwork capacity
~230Bthreats blocked / day

Because every Cloudflare location runs every service, there are no regional gaps and no appliances to deploy. Your team in any of 16 regions gets the same protection at local speed.

A sensible first step

Crawl, walk, run.

1 · Crawl

ZTNA / Access on a few internal apps. Immediate VPN relief, fast to prove. And CES beside your mail — value with no mail-flow change.

2 · Walk

Gateway for DNS/web filtering and WARP on managed devices. Now outbound traffic is covered too.

3 · Run

CASB, DLP, Browser Isolation for full data protection across SaaS and the web. The complete SASE picture.

You don't buy SASE in one go. Each step stands on its own and builds on the last — same platform, same dashboard.

Let's see it in action.

corven.onelab.win →
Live Zero Trust demo — log in to an internal app through Cloudflare Access.

Suggested first step for Prophecy: a short ZTNA + Email Security proof of value on a handful of apps and your mail.

Thank you · Kai Foong Chow & David Cox · Cloudflare