Und das ist gut so.And that is exactly the point.
Eine Zahl trägt die halbe Zero-Trust-Story. Rund 31 % aller Sicherheitsvorfälle der letzten zehn Jahre gingen auf gestohlene Zugangsdaten zurück. Keine Zero-Days, keine exotischen Exploits: geklaute Passwörter und Session-Tokens. One number carries half the Zero Trust story. About 31 % of all security incidents over the past ten years traced back to stolen credentials. Not zero-days, not exotic exploits: stolen passwords and session tokens.
Zero Trust ist das Prinzip: niemals implizites Vertrauen. ZTNA ist die Umsetzung für den App-Zugriff. Der Unterschied zum VPN in drei Punkten. Zero Trust is the principle: never implicit trust. ZTNA is how you apply it to app access. The difference from a VPN in three points.
Least Privilege ist kein Slogan, sondern ein Mechanismus. Genau diese drei Prüfungen bei jedem Request setzen ihn technisch um. Wer sie besteht, bekommt Zugriff auf genau eine Sache. Nicht mehr. Least privilege is not a slogan but a mechanism. These three checks on every request are what implement it. Whoever passes them gets access to exactly one thing. Nothing more.
Gleich erlebst du den Sprung an dir selbst. Hier hört die Theorie auf. Der Button unten führt auf einen echten, per Cloudflare Access geschützten Pfad. Du wirst zu deinem Access-Login umgeleitet und gibst deine Mail ein. Du bekommst einen 6-stelligen One-Time-PIN zugeschickt. Danach siehst du deine eigenen Identitäts-Claims aus dem Access-JWT. In a moment you'll experience the shift on yourself. This is where the theory ends. The button below leads to a real path protected by Cloudflare Access. You are redirected to your Access login and enter your email. You receive a 6-digit one-time PIN. Then you see your own identity claims from the Access JWT.
Cloudflare Access fängt den Request vor dieser Anwendung ab. Ohne gültige Identität kommst du nicht durch. Mit gültiger Identität zeigt dir die Zielseite, als wer und an welchem Standort Cloudflare dich geprüft hat. Cloudflare Access intercepts the request before this application. Without a valid identity you don't get through. With a valid identity the target page shows you as whom and at which location Cloudflare verified you.
🔒 Geschützten Bereich öffnenOpen the protected areaDu bist gerade verbunden über deinen nächsten Cloudflare-Standort. Genau diesen prüft Access beim Login mit. You're currently connected via your nearest Cloudflare location. That's exactly what Access checks along with the login.
Genau das passiert technisch zwischen deinem Klick und der geschützten Seite. Wähle ein Szenario, um den Ablauf durchlaufen zu sehen. SIMULIERT: Nur der echte Login oben löst tatsächlich Access aus. Device Posture ist hier reine Animation. This is exactly what happens technically between your click and the protected page. Pick a scenario to watch the flow run. SIMULATED: Only the real login above actually triggers Access. Device posture here is pure animation.
Cloudflare Tunnel / cloudflared baut eine ausgehende Verbindung von der App zu Cloudflare auf. Die Origin braucht keine offenen Inbound-Ports. Sie bleibt damit unsichtbar im offenen Netz. Für Netz-zu-Netz gibt es Cloudflare Mesh (vormals WARP Connector). Cloudflare Tunnel / cloudflared establishes an outbound connection from the app to Cloudflare. The origin needs no open inbound ports. That keeps it invisible on the open internet. For network-to-network there is Cloudflare Mesh (formerly WARP Connector).
Nach dem Login dekodiert der Worker das Access-JWT. Es steckt im Cookie
CF_Authorization oder im Header Cf-Access-Jwt-Assertion. Der
Worker zeigt deine Claims an, ungefähr so:
After login the Worker decodes the Access JWT. It sits in the cookie
CF_Authorization or in the header Cf-Access-Jwt-Assertion. The
Worker displays your claims, roughly like this:
Die Signatur prüft der Worker nicht. Das hat Cloudflare Access davor bereits getan. Hier geht es nur um die Anzeige der Claims, damit der Effekt sichtbar wird. The Worker does not verify the signature. Cloudflare Access already did that beforehand. Here it is only about displaying the claims, so the effect becomes visible.
Im VPN-Ersatz-Gespräch kommt fast immer dieselbe Frage. Schön und gut, aber wie binde ich denn jetzt diese konkrete App an Access an? Es gibt drei saubere Antworten. Welche passt, hängt an zwei Dingen: wer die App hostet und was sie technisch kann. Die Anbindung läuft über Access controls › Applications in Cloudflare One. In the VPN-replacement conversation almost the same question always comes up. Fine in theory, but how do I actually wire up this concrete app to Access? There are three clean answers. Which one fits hangs on two things: who hosts the app and what it can do technically. You wire it up under Access controls › Applications in Cloudflare One.
cloudflared läuft am Origin und baut eine ausgehende QUIC-Verbindung zur Edge auf. Fällt QUIC weg, greift HTTP/2.cloudflared runs on the origin and opens an outbound QUIC connection to the edge. If QUIC is unavailable it falls back to HTTP/2.<UUID>.cfargotunnel.com. Es gibt keine öffentliche Angriffsfläche, also auch keinen Bypass.DNS is a CNAME to <UUID>.cfargotunnel.com. There is no public attack surface, so there is no bypass.redirect_uri. Nur der Login-Handshake läuft über Cloudflare. Der App-Verkehr fließt direkt Browser ↔ Provider.OIDC works the same way as an authorization-code flow with client ID, secret and redirect_uri. Only the login handshake goes through Cloudflare. The app traffic flows directly browser ↔ provider.cloudflared auf private Hostnames zu. Standort- und Netzanbindung
übernimmt Cloudflare Mesh (vormals WARP Connector). Für BYOD und clientlosen
Zugriff bleiben die drei Szenarien oben der Fokus.
Two more paths round out the picture. For machine-to-machine access without an
interactive login you use service tokens or mTLS. For non-HTTP protocols and
private networks users reach private hostnames through cloudflared with the
Cloudflare One Client (formerly WARP client). Site and network connectivity
runs over Cloudflare Mesh (formerly WARP Connector). For BYOD and clientless
access the three scenarios above stay the focus.
| KriteriumCriterion | Tunnel | Reverse-ProxyReverse proxy | Access for SaaS |
|---|---|---|---|
| Wer hostet typischerweise?Who typically hosts? | selbstyou | selbstyou | Dritter (SaaS)third party (SaaS) |
| VerbindungsrichtungConnection direction | ausgehendoutbound | eingehendinbound | nur Login-Redirectslogin redirects only |
| Offener Port am Origin nötig?Open port on origin needed? | neinno | jayes | n/a |
| Datenverkehr durch Cloudflare?Traffic through Cloudflare? | jayes | jayes | nein, nur Authno, auth only |
| DNS-/CNAME-Setup nötig?DNS / CNAME setup needed? | CNAME auf TunnelCNAME to tunnel | Hostname proxiedhostname proxied | neinno |
| Inline-Kontrolle (DLP/Inspektion)?Inline control (DLP/inspection)? | jayes | jayes | neinno |
| Bypass-SchutzBypass protection | ja, by designyes, by design | nur mit Origin-Lockdownonly with origin lockdown | n/a |
| Voraussetzung beim KundenCustomer prerequisite | cloudflared-Hostcloudflared host | öffentl. Origin + Lockdownpublic origin + lockdown | App kann SAML/OIDCapp supports SAML/OIDC |
Beantworte die zwei Fragen. Die passende Karte oben leuchtet auf. ENTSCHEIDUNGSHILFE: eine Daumenregel, kein Ersatz für die konkrete App-Bewertung. Answer the two questions. The matching card above lights up. DECISION AID: a rule of thumb, not a substitute for assessing the concrete app.
Access war die eine Tür, der Zugriff nach innen zu deinen Apps. Die andere Tür ist der Weg nach außen. Sie regelt, was deine Nutzer und Geräte im Internet tun dürfen. Beide Türen gehören zu einer einzigen Plattform. Ihr Name ist SASE. Sie führt Sicherheit und Networking aus demselben Netz zusammen und trägt die Kapitel, die jetzt folgen. Access was the one door, access inward to your apps. The other door is the way outward. It governs what your users and devices may do on the internet. Both doors belong to a single platform. Its name is SASE. It brings security and networking together from the same network and carries the chapters that follow.
Bevor wir in jeden Baustein eintauchen, hier die ganze Landkarte. Jeder Baustein ist ein Stück desselben SASE. Cloudflare deckt sie alle ab und liefert sie aus demselben Netz. Klick einen an, um direkt ins Kapitel zu springen. Before we dive into each building block, here is the whole map. Every block is one piece of the same SASE. Cloudflare covers them all and delivers them from the same network. Click one to jump straight into its chapter.
Das Secure Web Gateway ist die Cloud-SWG für jeden ausgehenden Request. Es filtert in drei Stufen, immer in dieser Reihenfolge: zuerst DNS, dann Netzwerk auf Layer 4, dann HTTP auf Layer 7. Diese Reihenfolge gilt seit Juli 2025. Alles läuft single-pass an über 330 Standorten, am selben Ort, an dem auch dein Login lief. The Secure Web Gateway is the cloud SWG for every outbound request. It filters in three stages, always in this order: first DNS, then network at layer 4, then HTTP at layer 7. This order has applied since July 2025. Everything runs single-pass across 330+ locations, in the same place your login ran.
Es ersetzt den klassischen Backhaul-Stack aus Appliances. Und es ist der Träger für alles Weitere: DLP-inline und RBI laufen auf genau diesem Gateway. It replaces the classic backhaul stack of appliances. It is also the carrier for everything that follows: inline DLP and RBI both run on exactly this gateway.
Tipp eine Domain ein oder wähl eine der Schnellwahlen. Die Pipeline läuft DNS → Network → HTTP durch und stoppt auf der Stufe, die greift. SIMULIERT: Die Logik ist nachgebaut, damit die Enforcement-Reihenfolge greifbar wird. Echter Gateway-Traffic läuft hier nicht. Type a domain or pick one of the shortcuts. The pipeline runs DNS → network → HTTP and stops at the stage that fires. SIMULATED: the logic is rebuilt so the enforcement order becomes tangible. No real gateway traffic runs here.
DLP erkennt sensible Daten an zwei Stellen. In transit läuft es inline über die HTTP-Stufe des Gateways. Dafür braucht es TLS-Decryption, dann scannt es den Body des Requests. At rest erreicht es ruhende Daten über die CASB-API in deinen SaaS-Tenants. DLP spots sensitive data in two places. In transit it runs inline on the gateway's HTTP stage. That requires TLS decryption, then it scans the request body. At rest it reaches data sitting in your SaaS tenants through the CASB API.
Mitgeliefert kommen fertige Profile. Dazu eigene Profile, Dokument-Fingerprinting und OCR für Text in Bildern. It ships with predefined profiles. On top come custom profiles, document fingerprinting and OCR for text inside images.
Tipp links eine Nachricht oder simulier einen Upload. Rechts siehst du, was Cloudflare durchlässt. Erkannte Muster werden in Echtzeit geschwärzt und beschriftet. SIMULIERT: Die Erkennung läuft hier per JS-Regex im Browser, nicht über das echte Gateway. Type a message on the left or fake an upload. On the right you see what Cloudflare lets through. Detected patterns are redacted and labelled in real time. SIMULATED: detection here runs as a JS regex in the browser, not through the real gateway.
Der Cloud Access Security Broker arbeitet API-basiert und out-of-band. Er verbindet sich per API mit deinen SaaS-Diensten (Google Workspace, Microsoft 365, Salesforce und weitere) und scannt sie kontinuierlich. Er sucht nach Fehlkonfigurationen, nach riskanten Freigaben und, zusammen mit DLP, nach sensiblen ruhenden Daten. The Cloud Access Security Broker works API-based and out-of-band. It connects to your SaaS services through their APIs (Google Workspace, Microsoft 365, Salesforce and more) and scans them continuously. It looks for misconfigurations, for risky shares and, together with DLP, for sensitive data at rest.
Kein Inline-Traffic läuft durch CASB. Es sitzt neben dem Datenstrom, nicht darin. No inline traffic runs through CASB. It sits beside the data stream, not inside it.
Start den Scan auf einem fiktiven Tenant. Die Findings ploppen gestaffelt auf, jedes mit Severity-Ampel und einem Fix-Button. SIMULIERT: Tenant und Findings sind erfunden. Ein echter CASB-Scan greift live auf die SaaS-APIs zu. Start the scan on a fictional tenant. Findings appear in a staggered sequence, each with a severity light and a fix button. SIMULATED: tenant and findings are made up. A real CASB scan reaches into the live SaaS APIs.
contoso.example
Gehälter_2026.xlsx öffentlich geteiltpublic-shared
Google Drive
Remote Browser Isolation rendert riskante Seiten in einem Cloud-Browser an der Edge. Zum Gerät gehen nur Vektor-Zeichenbefehle (Network Vector Rendering, auch Canvas-Remoting). Aktiver Code erreicht das Endgerät nie. Das funktioniert in jedem HTML5-Browser, ganz ohne Client. Remote Browser Isolation renders risky pages in a cloud browser at the edge. Only vector drawing commands reach the device (network vector rendering, also called canvas remoting). Active code never reaches the endpoint. It works in any HTML5 browser, with no client at all.
Das ist der Schutz für ungemanagte Geräte: BYOD, Geräte von Contractors, alles ohne Agent. Copy, Paste, Download, Upload und Druck lassen sich pro Policy einzeln abschalten. This is the protection for unmanaged devices: BYOD, contractor laptops, anything without an agent. Copy, paste, download, upload and print can each be switched off per policy.
Diese zwei Buttons sind echt, anders als die simulierten
Vignetten davor. Sie öffnen einen neuen Tab auf die clientlose Web Isolation deines Teams
unter bacarda.cloudflareaccess.com/browser/<ziel>. Beim ersten Mal
kommt der Access-Login per OTP-Mail, wie bei /protected.
These two buttons are real, unlike the simulated vignettes
before. They open a new tab to your team's clientless Web Isolation at
bacarda.cloudflareaccess.com/browser/<target>. On first use the Access
login by OTP email appears, just like on /protected.
example.com isoliert. Der Kunde
sieht dieselbe Seite, nur remote gerendert. Beweisstück: der Hostname-Notch oben in der
Mitte. Aktiver Code lief auf der Edge, nicht auf dem Gerät.
Opens example.com in isolation. The customer sees the same
page, only rendered remotely. The proof is the hostname notch at the top center. Active code
ran at the edge, not on the device.
Damit beide Buttons live funktionieren, müssen im Dashboard ein paar Schalter
gesetzt sein. Alle Schritte und die genauen Zielwerte stehen in DEPLOY.md,
Abschnitt 5.
For both buttons to work live, a few switches must be set in the dashboard.
All steps and the exact target values are in DEPLOY.md, section 5.
All das, von der Tür bis zum isolierten Browser, läuft an einem Ort: an der Cloudflare-Edge. Zero Trust an der Edge ist nur so gut wie die Edge selbst. Derselbe Standort, der eben deinen Login geprüft hat, macht auch TLS, DNS, WAF und Routing. Ein Netz, alle Funktionen, überall. All of this, from the door to the isolated browser, runs in one place: the Cloudflare edge. Zero Trust at the edge is only as good as the edge itself. The same location that just verified your login also does TLS, DNS, WAF and routing. One network, all functions, everywhere.
Kunden vergleichen ohnehin. Hier die ehrliche Ein-Zeilen-Lesart je Anbieter. Nützlich, wenn das Gespräch auf „warum nicht einfach Zscaler?" kippt. Customers compare anyway. Here is the honest one-line reading per vendor. Useful when the conversation tips into „why not just Zscaler?"
| Stack | Single Network | Single Pass | In + Outbound | Separate SKUsSeparate SKUs |
|---|---|---|---|---|
| Cloudflare One | ✓ | ✓ | ✓ | neinno |
| Zscaler (ZIA / ZPA / ZDX) | ~ | ✕ | getrenntseparate | jayes |
| Palo Alto Prisma Access | GCP-basiertGCP-based | ~ | ~ | jayes |
| Netskope | ~ | ~ | CASB-UrsprungCASB origin | jayes |
| Cisco (Umbrella / Duo / …) | ✕ | ✕ | ~ | jayes |
| Cato Networks | ✓ | ✓ | ~ | teilspartly |
Neutral gelesen: Zscaler betreibt pro Produkt getrennte Clouds (ZIA/ZPA/ZDX) und ist historisch outbound-stark. Palo Alto Prisma trägt Appliance-Erbe und läuft auf GCP. Netskope kommt vom CASB und hat den schwächeren Netz-Footprint. Cisco ist eine Zukauf-Sammlung mit Integrationsreibung. Cato ist architektonisch am ähnlichsten und damit der fairste Vergleich. Cloudflares Unterschied: ein Netz, ein Durchlauf, inbound und outbound, ohne getrennte SKUs. Read neutrally: Zscaler runs separate clouds per product (ZIA/ZPA/ZDX) and is historically outbound-strong. Palo Alto Prisma carries appliance heritage and runs on GCP. Netskope comes from CASB and has the weaker network footprint. Cisco is an acquisition collection with integration friction. Cato is architecturally the most similar and therefore the fairest comparison. Cloudflare's difference: one network, one pass, inbound and outbound, with no separate SKUs.