Cloudflare Demo Shop

Zero Trust Access (VPN Replacement)

Replace your legacy VPN with identity-aware, per-application access. Every request is verified against user identity, device posture, and policy — no implicit network trust.

Why is a flat-network VPN a security and productivity problem?

Traditional VPNs put every authenticated user on the corporate network, granting broad access far beyond what any one role actually needs. One compromised credential or stolen laptop becomes a lateral-movement event. On top of that, VPN concentrators become single points of failure and add real latency for remote employees, contractors, and partners — all while creating friction every time someone needs to reach an internal app.

How it fits together

Legacy VPN architecture: a flat corporate network reachable through a VPN concentrator, with branch offices connected via site-to-site VPN/MPLS, creating lateral-movement risk once any device or credential is on the network.⤢ Click to enlarge
Legacy VPN: flat network access, a concentrator bottleneck, and site-to-site links that put every branch and remote user on the same trusted network.
Cloudflare Tunnel architecture: outbound-only cloudflared connectors expose private apps without open inbound ports, with Access enforcing identity- and posture-checked, per-application authorization for remote users, WARP clients, and clientless browser access.⤢ Click to enlarge
Cloudflare Tunnel: outbound-only connectors, per-application Access policies, and explicit allow/deny — no inbound ports, no implicit network trust.
Cloudflare Mesh architecture: any-to-any bidirectional connectivity between sites and services over private Mesh IP addresses, including a service-initiated connection and a CIDR route advertised via a mesh node.⤢ Click to enlarge
Cloudflare Mesh: any-to-any bidirectional connectivity between sites and services over private Mesh IPs — useful when traffic must originate from either side.
Cloudflare WAN architecture: branch offices connect via a Cloudflare One Appliance or an existing router/firewall, with any-to-any backbone routing to data centers, cloud VPCs, and remote users.⤢ Click to enlarge
Cloudflare WAN: branches connect via a Cloudflare One Appliance or your existing router/firewall, with any-to-any routing across Cloudflare's backbone.
Cloudflare Network Interconnect architecture: a private cross-connect (Direct, Partner, or Cloud CNI) with BGP peering that feeds into the Cloudflare WAN backbone.⤢ Click to enlarge
Cloudflare Network Interconnect (CNI): a private cross-connect — Direct, Partner, or Cloud CNI — with BGP peering into Cloudflare's backbone.

How Cloudflare solves it

Common questions

Do I have to rip out my existing VPN on day one?
No. The typical migration runs Access alongside the legacy VPN, app by app. Start with one or two high-value internal apps, prove the workflow, then expand. Most customers retire their VPN over 3–6 months.
What about non-HTTP apps like SSH, RDP, or databases?
Cloudflare Tunnel and Access for Infrastructure handle TCP and UDP traffic. Users can connect via the WARP client or, for SSH/RDP, through a browser-rendered terminal that requires no native client.
Does this work for contractors and partners who aren't in our IdP?
Yes. You can add one-time PIN (email OTP) as an identity source for guest users, or federate with their IdP. Access policies can require additional signals (country, device posture, MFA) on top.
How is this different from a typical IdP + SSO setup?
SSO authenticates the user once into individual apps. Zero Trust Access sits in front of every app and enforces continuous policy on every request — identity, device, location, time of day, and more — and protects apps that don't natively support SSO.

Try it live

Demo coming soon

An interactive demo for Zero Trust Access (VPN Replacement) is being built. In the meantime, check the "Dive Deeper" section below for the official docs and product blogs.

Docs & blogs

← Back to all solutions