Vertrauen ist kein Ort.Trust is not a place.

Dein Netzwerk vertraut dir nicht mehrYour network doesn't trust you anymore

Und das ist gut so.And that is exactly the point.

/protected
Scroll runter und logge dich gleich wirklich ein. Diese Seite hat einen echten geschützten Bereich hinter Cloudflare Access. Kein Mockup: Du klickst, wirst umgeleitet und bekommst einen One-Time-PIN per Mail. So erlebst du ZTNA an dir selbst. Das Netz fragt nicht „bist du drin?". Es fragt: „bist du du, im richtigen Kontext, für diese App?" Scroll down and actually log in in a moment. This page has a real protected area behind Cloudflare Access. No mockup: you click, you are redirected and you receive a one-time PIN by email. That way you experience ZTNA on yourself. The network never asks „are you inside?". It asks: „are you you, in the right context, for this app?"
Cloudflare DACH SE · Zero Trust / SASE · zero-trust.bacarda.de · Stand 2026As of 2026
Abschnitt 1Section 1

Zero Trust AccessZero Trust Access

Eine Zahl trägt die halbe Zero-Trust-Story. Rund 31 % aller Sicherheitsvorfälle der letzten zehn Jahre gingen auf gestohlene Zugangsdaten zurück. Keine Zero-Days, keine exotischen Exploits: geklaute Passwörter und Session-Tokens. One number carries half the Zero Trust story. About 31 % of all security incidents over the past ten years traced back to stolen credentials. Not zero-days, not exotic exploits: stolen passwords and session tokens.

31 %
der Breaches starten mit einer gültigen, aber gestohlenen Identität. Das klassische VPN lässt genau diese Identität nach dem Login flächig ins Netz. So wird es zum Brandbeschleuniger für laterale Bewegung. of breaches start with a valid but stolen identity. The classic VPN lets exactly that identity spread across the network after login. That turns it into an accelerant for lateral movement.

Zero Trust vs. ZTNAZero Trust vs. ZTNA

Zero Trust ist das Prinzip: niemals implizites Vertrauen. ZTNA ist die Umsetzung für den App-Zugriff. Der Unterschied zum VPN in drei Punkten. Zero Trust is the principle: never implicit trust. ZTNA is how you apply it to app access. The difference from a VPN in three points.

VPN · altes ModellVPN · old model
  • Vertrauen einmalig beim LoginTrust granted once, at login
  • Zugriff aufs ganze Netz: ein Account genügt für laterale BewegungAccess to the whole network: one account enables lateral movement
  • Ein zentraler Zugangspunkt: Umweg über den Konzentrator, mehr LatenzOne central access point: detour through the concentrator, more latency
ZTNA · Cloudflare AccessZTNA · Cloudflare Access
  • Vertrauen pro Request, jedes Mal neu geprüftTrust re-checked on every single request
  • Zugriff nur auf die eine App: Kompromittierung bleibt eingesperrtAccess to one app only: a breach stays boxed in
  • Verbindung an der nächsten Edge: kein Backhaul, schnellerConnects at the nearest edge: no backhaul, faster

Drei Prüfungen, ein PrinzipThree checks, one principle

Least Privilege ist kein Slogan, sondern ein Mechanismus. Genau diese drei Prüfungen bei jedem Request setzen ihn technisch um. Wer sie besteht, bekommt Zugriff auf genau eine Sache. Nicht mehr. Least privilege is not a slogan but a mechanism. These three checks on every request are what implement it. Whoever passes them gets access to exactly one thing. Nothing more.

IdentitätIdentity
Der neue Perimeter ist wer, nicht wo. Das Netz ist kein Vertrauensanker mehr.The new perimeter is who, not where. The network is no longer a trust anchor.
Device PostureDevice posture
Der Zustand des Geräts zählt mit: OS, Verschlüsselung, EDR. Identität allein reicht nicht.The state of the device counts too: OS, encryption, EDR. Identity alone is not enough.
KontextContext
Standort, Tageszeit, Risiko. Vertrauen ist dynamisch und gilt pro Request, nicht einmalig beim Login.Location, time of day, risk. Trust is dynamic and applies per request, not once at login.
Least Privilege Least Privilege heißt: Jede Identität bekommt genau den Zugriff, den sie für ihre Aufgabe braucht. Nicht mehr. ZTNA macht das zum Standard. Ein VPN kann es technisch nicht, weil es Netz-Zugang gewährt, keinen App-Zugang. Least privilege means every identity gets exactly the access its task needs. Nothing more. ZTNA makes that the default. A VPN cannot, because it grants network access, not app access.
Abschnitt 2 · Section 2 · LIVE

Logg dich wirklich einLog in for real

Gleich erlebst du den Sprung an dir selbst. Hier hört die Theorie auf. Der Button unten führt auf einen echten, per Cloudflare Access geschützten Pfad. Du wirst zu deinem Access-Login umgeleitet und gibst deine Mail ein. Du bekommst einen 6-stelligen One-Time-PIN zugeschickt. Danach siehst du deine eigenen Identitäts-Claims aus dem Access-JWT. In a moment you'll experience the shift on yourself. This is where the theory ends. The button below leads to a real path protected by Cloudflare Access. You are redirected to your Access login and enter your email. You receive a 6-digit one-time PIN. Then you see your own identity claims from the Access JWT.

Echter ZTNA-LoginReal ZTNA login
Geschützten Bereich öffnenOpen the protected area

Cloudflare Access fängt den Request vor dieser Anwendung ab. Ohne gültige Identität kommst du nicht durch. Mit gültiger Identität zeigt dir die Zielseite, als wer und an welchem Standort Cloudflare dich geprüft hat. Cloudflare Access intercepts the request before this application. Without a valid identity you don't get through. With a valid identity the target page shows you as whom and at which location Cloudflare verified you.

🔒 Geschützten Bereich öffnenOpen the protected area

Du bist gerade verbunden über deinen nächsten Cloudflare-Standort. Genau diesen prüft Access beim Login mit. You're currently connected via your nearest Cloudflare location. That's exactly what Access checks along with the login.

Der ZTNA-Flow in fünf StationenThe ZTNA flow in five stations

Genau das passiert technisch zwischen deinem Klick und der geschützten Seite. Wähle ein Szenario, um den Ablauf durchlaufen zu sehen. SIMULIERT: Nur der echte Login oben löst tatsächlich Access aus. Device Posture ist hier reine Animation. This is exactly what happens technically between your click and the protected page. Pick a scenario to watch the flow run. SIMULATED: Only the real login above actually triggers Access. Device posture here is pure animation.

User / Request → Access → Identity → Posture → Application
👤
User / Request
GET /protected
→
🛡️
Access
Policy-Eval
→
📧
Identity
IdP / OTP
→
💻
Device Posture
optional
→
🎯
Application
/protected
Wähle ein Szenario oder klick „Ablauf abspielen". Die Stationen leuchten der Reihe nach auf.Pick a scenario or click „Play flow". The stations light up one after another.

Warum keine offenen Ports nötig sindWhy no open ports are needed

Cloudflare Tunnel / cloudflared baut eine ausgehende Verbindung von der App zu Cloudflare auf. Die Origin braucht keine offenen Inbound-Ports. Sie bleibt damit unsichtbar im offenen Netz. Für Netz-zu-Netz gibt es Cloudflare Mesh (vormals WARP Connector). Cloudflare Tunnel / cloudflared establishes an outbound connection from the app to Cloudflare. The origin needs no open inbound ports. That keeps it invisible on the open internet. For network-to-network there is Cloudflare Mesh (formerly WARP Connector).

Was die geschützte Seite dir zeigtWhat the protected page shows you

Nach dem Login dekodiert der Worker das Access-JWT. Es steckt im Cookie CF_Authorization oder im Header Cf-Access-Jwt-Assertion. Der Worker zeigt deine Claims an, ungefähr so: After login the Worker decodes the Access JWT. It sits in the cookie CF_Authorization or in the header Cf-Access-Jwt-Assertion. The Worker displays your claims, roughly like this:

email → du@example.com
geprüft anverified at → Cloudflare Access · Standort FRACloudflare Access · location FRA
issued at → 2026-…T…Z
issuer → <team>.cloudflareaccess.com

Die Signatur prüft der Worker nicht. Das hat Cloudflare Access davor bereits getan. Hier geht es nur um die Anzeige der Claims, damit der Effekt sichtbar wird. The Worker does not verify the signature. Cloudflare Access already did that beforehand. Here it is only about displaying the claims, so the effect becomes visible.

Abschnitt 3Section 3

Wie kommt eine Anwendung hinter Cloudflare?How does an app get behind Cloudflare?

Im VPN-Ersatz-Gespräch kommt fast immer dieselbe Frage. Schön und gut, aber wie binde ich denn jetzt diese konkrete App an Access an? Es gibt drei saubere Antworten. Welche passt, hängt an zwei Dingen: wer die App hostet und was sie technisch kann. Die Anbindung läuft über Access controls › Applications in Cloudflare One. In the VPN-replacement conversation almost the same question always comes up. Fine in theory, but how do I actually wire up this concrete app to Access? There are three clean answers. Which one fits hangs on two things: who hosts the app and what it can do technically. You wire it up under Access controls › Applications in Cloudflare One.

Drei Anbindungs-SzenarienThree onboarding scenarios

🚇 Self-hosted · Cloudflare TunnelSelf-hosted · Cloudflare Tunnel
Über cloudflaredVia cloudflared
Origin → Cloudflare · ausgehendorigin → Cloudflare · outbound
  • cloudflared läuft am Origin und baut eine ausgehende QUIC-Verbindung zur Edge auf. Fällt QUIC weg, greift HTTP/2.cloudflared runs on the origin and opens an outbound QUIC connection to the edge. If QUIC is unavailable it falls back to HTTP/2.
  • Kein eingehender Port. Der Origin bleibt privat hinter NAT und ist aus dem Internet nicht erreichbar.No inbound port. The origin stays private behind NAT and is unreachable from the internet.
  • DNS ist ein CNAME auf <UUID>.cfargotunnel.com. Es gibt keine öffentliche Angriffsfläche, also auch keinen Bypass.DNS is a CNAME to <UUID>.cfargotunnel.com. There is no public attack surface, so there is no bypass.
🟠 Self-hosted · Reverse-ProxySelf-hosted · reverse proxy
Orange CloudOrange cloud
Cloudflare → Origin · eingehendCloudflare → origin · inbound
  • Der Origin hat einen öffentlich erreichbaren HTTPS-Endpoint. Der Hostname ist ein A/AAAA-Record, proxied (orange cloud), und löst auf Cloudflares Anycast-IPs auf.The origin exposes a public HTTPS endpoint. The hostname is an A/AAAA record, proxied (orange cloud), resolving to Cloudflare's anycast IPs.
  • Cloudflare nimmt den Request an, erzwingt Access und verbindet dann eingehend zum öffentlichen Origin.Cloudflare receives the request, enforces Access then connects inbound to the public origin.
  • Wer die echte Origin-IP kennt, kann Cloudflare umgehen. Riegle den Origin ab: Cloudflare-IP-Allowlist und Authenticated Origin Pulls (mTLS).Anyone who knows the real origin IP can bypass Cloudflare. Lock the origin down with a Cloudflare IP allowlist and Authenticated Origin Pulls (mTLS).
🔗 SaaS · Access for SaaSSaaS · Access for SaaS
SAML- / OIDC-FöderationSAML / OIDC federation
nur Login-Redirectslogin redirects only
  • Die App wird nicht geproxied. Cloudflare wird zum IdP gegenüber der App und föderiert dahinter zum echten Upstream-IdP (Entra, Okta, Google).The app is not proxied. Cloudflare becomes the IdP toward the app and federates behind it to the real upstream IdP (Entra, Okta, Google).
  • SAML ist SP-initiiert: Die App schickt einen AuthnRequest, Access prüft die Policies und leitet zum echten IdP. Cloudflare signiert dann Response und Assertion (SHA-256) und postet an die ACS-URL.SAML is SP-initiated: the app sends an AuthnRequest, Access checks the policies then redirects to the real IdP. Cloudflare signs both the response and the assertion (SHA-256) then posts to the ACS URL.
  • OIDC läuft analog als Authorization-Code-Flow mit Client-ID, Secret und redirect_uri. Nur der Login-Handshake läuft über Cloudflare. Der App-Verkehr fließt direkt Browser ↔ Provider.OIDC works the same way as an authorization-code flow with client ID, secret and redirect_uri. Only the login handshake goes through Cloudflare. The app traffic flows directly browser ↔ provider.
MehrMore Zwei ergänzende Wege runden das Bild ab. Für Maschine-zu-Maschine-Zugriff ohne interaktives Login nutzt du Service Tokens oder mTLS. Für Nicht-HTTP-Protokolle und private Netze greifen die Nutzer per Cloudflare One Client (vormals WARP-Client) über cloudflared auf private Hostnames zu. Standort- und Netzanbindung übernimmt Cloudflare Mesh (vormals WARP Connector). Für BYOD und clientlosen Zugriff bleiben die drei Szenarien oben der Fokus. Two more paths round out the picture. For machine-to-machine access without an interactive login you use service tokens or mTLS. For non-HTTP protocols and private networks users reach private hostnames through cloudflared with the Cloudflare One Client (formerly WARP client). Site and network connectivity runs over Cloudflare Mesh (formerly WARP Connector). For BYOD and clientless access the three scenarios above stay the focus.

Die drei im direkten VergleichThe three side by side

KriteriumCriterion Tunnel Reverse-ProxyReverse proxy Access for SaaS
Wer hostet typischerweise?Who typically hosts? selbstyou selbstyou Dritter (SaaS)third party (SaaS)
VerbindungsrichtungConnection direction ausgehendoutbound eingehendinbound nur Login-Redirectslogin redirects only
Offener Port am Origin nötig?Open port on origin needed? neinno jayes n/a
Datenverkehr durch Cloudflare?Traffic through Cloudflare? jayes jayes nein, nur Authno, auth only
DNS-/CNAME-Setup nötig?DNS / CNAME setup needed? CNAME auf TunnelCNAME to tunnel Hostname proxiedhostname proxied neinno
Inline-Kontrolle (DLP/Inspektion)?Inline control (DLP/inspection)? jayes jayes neinno
Bypass-SchutzBypass protection ja, by designyes, by design nur mit Origin-Lockdownonly with origin lockdown n/a
Voraussetzung beim KundenCustomer prerequisite cloudflared-Hostcloudflared host öffentl. Origin + Lockdownpublic origin + lockdown App kann SAML/OIDCapp supports SAML/OIDC

Welches Szenario passt? Zwei FragenWhich scenario fits? Two questions

Beantworte die zwei Fragen. Die passende Karte oben leuchtet auf. ENTSCHEIDUNGSHILFE: eine Daumenregel, kein Ersatz für die konkrete App-Bewertung. Answer the two questions. The matching card above lights up. DECISION AID: a rule of thumb, not a substitute for assessing the concrete app.

Entscheidungshilfe · AnbindungDecision aid · onboarding
1Wer hostet die App?Who hosts the app?
2Kann die App SAML- oder OIDC-SSO?Can the app do SAML or OIDC SSO?
Zwei Fragen führen zur passenden Karte. Wähle oben, um die Empfehlung zu sehen.Two questions lead to the right card. Choose above to see the recommendation.
Eine Tür, drei Wege hindurch. Self-hosted mit Tunnel ist der Goldstandard ohne offene Ports. Reverse-Proxy passt für bereits öffentliche Origins, braucht aber den Lockdown. Access for SaaS sichert fremde Apps am Login, ganz ohne Proxy. Alle drei enden an derselben Stelle: deiner Access-Policy. One door, three ways through it. Self-hosted with a tunnel is the gold standard with no open ports. A reverse proxy fits origins that are already public, yet it needs the lockdown. Access for SaaS secures third-party apps at the login, with no proxy at all. All three end at the same place: your Access policy.
Abschnitt 4Section 4

SASE: eine Plattform, alle BausteineSASE: one platform, every building block

Access war die eine Tür, der Zugriff nach innen zu deinen Apps. Die andere Tür ist der Weg nach außen. Sie regelt, was deine Nutzer und Geräte im Internet tun dürfen. Beide Türen gehören zu einer einzigen Plattform. Ihr Name ist SASE. Sie führt Sicherheit und Networking aus demselben Netz zusammen und trägt die Kapitel, die jetzt folgen. Access was the one door, access inward to your apps. The other door is the way outward. It governs what your users and devices may do on the internet. Both doors belong to a single platform. Its name is SASE. It brings security and networking together from the same network and carries the chapters that follow.

Was SASE zusammenführtWhat SASE brings together

SASE SASE (Secure Access Service Edge) bündelt Netzwerk und Sicherheit in einem Cloud-Dienst an der Edge. Es hat zwei Hälften: SSE für Sicherheit (Access, SWG, CASB, DLP, Browser Isolation) und Networking (Magic WAN). Zero Trust ist das Prinzip darunter. SASE (Secure Access Service Edge) merges networking and security into one cloud service at the edge. It has two halves: SSE for security (Access, SWG, CASB, DLP, Browser Isolation) and networking (Magic WAN). Zero Trust is the principle underneath.

Alle Bausteine im ÜberblickEvery building block at a glance

Bevor wir in jeden Baustein eintauchen, hier die ganze Landkarte. Jeder Baustein ist ein Stück desselben SASE. Cloudflare deckt sie alle ab und liefert sie aus demselben Netz. Klick einen an, um direkt ins Kapitel zu springen. Before we dive into each building block, here is the whole map. Every block is one piece of the same SASE. Cloudflare covers them all and delivers them from the same network. Click one to jump straight into its chapter.

§1§1
Zero Trust AccessZero Trust Access
Die Tür nach innen. Jeder App-Zugriff neu geprüft auf Identität, Gerät und Kontext.The door inward. Every app request re-checked on identity, device and context.
§5§5
Secure Web Gateway
Der Weg nach außen. DNS, Netzwerk und HTTP gefiltert, single-pass.The way outward. DNS, network and HTTP filtered, single-pass.
§6§6
DLP
Dieselbe Prüfung für Daten in Bewegung. Sensible Muster bleiben im Haus.The same check for data in motion. Sensitive patterns stay in the building.
§7§7
CASB
Dieselbe Prüfung für ruhende SaaS-Daten, out-of-band per API.The same check for SaaS data at rest, out-of-band via API.
§8§8
Browser Isolation
Riskanter Code läuft an der Edge, nie auf dem Gerät.Risky code runs at the edge, never on the device.
NETWORKINGNETWORKING
Magic WAN
Die andere Hälfte. Standorte und Clouds als ein WAN über dasselbe Netz.The other half. Sites and clouds as one WAN over the same network.
Ein Prinzip, eine Plattform. Zero Trust prüft jede Anfrage neu auf Identität, Gerät und Kontext. Dasselbe Prinzip trägt jeden Baustein, von der Tür bis zum letzten Klick ins offene Netz. Cloudflare liefert alle aus einer Hand, aus demselben Netz. One principle, one platform. Zero Trust re-checks every request on identity, device and context. The same principle carries every building block, from the door to the last click out into the open. Cloudflare delivers them all from one hand, from the same network.
Abschnitt 5 · Section 5 · SIMULIERT

Secure Web GatewaySecure Web Gateway

ÜbergangTransition Die Tür steht. Aber Zero Trust hört nicht an der Türschwelle auf. Jetzt drehen wir uns um und sichern alles, was hinter der Tür passiert: jeden Klick deiner Leute ins offene Internet. The door is in place. But Zero Trust does not stop at the threshold. Now we turn around and secure everything that happens behind the door: every click your people make out into the open internet.

Das Secure Web Gateway ist die Cloud-SWG für jeden ausgehenden Request. Es filtert in drei Stufen, immer in dieser Reihenfolge: zuerst DNS, dann Netzwerk auf Layer 4, dann HTTP auf Layer 7. Diese Reihenfolge gilt seit Juli 2025. Alles läuft single-pass an über 330 Standorten, am selben Ort, an dem auch dein Login lief. The Secure Web Gateway is the cloud SWG for every outbound request. It filters in three stages, always in this order: first DNS, then network at layer 4, then HTTP at layer 7. This order has applied since July 2025. Everything runs single-pass across 330+ locations, in the same place your login ran.

Es ersetzt den klassischen Backhaul-Stack aus Appliances. Und es ist der Träger für alles Weitere: DLP-inline und RBI laufen auf genau diesem Gateway. It replaces the classic backhaul stack of appliances. It is also the carrier for everything that follows: inline DLP and RBI both run on exactly this gateway.

KundenproblemCustomer pain Der alte Stack holt jeden Zweig erst per Hairpin ins Rechenzentrum zurück. Das kostet Latenz bei jedem Aufruf. Und er ist blind für verschlüsselten Traffic und für SaaS, also für fast alles, was heute zählt. The old stack hairpins every branch back to the data center first. That adds latency on every request. It is also blind to encrypted traffic and to SaaS, which today is almost everything that matters.

Vignette: drei Stufen, ein DurchlaufVignette: three stages, one pass

Tipp eine Domain ein oder wähl eine der Schnellwahlen. Die Pipeline läuft DNS → Network → HTTP durch und stoppt auf der Stufe, die greift. SIMULIERT: Die Logik ist nachgebaut, damit die Enforcement-Reihenfolge greifbar wird. Echter Gateway-Traffic läuft hier nicht. Type a domain or pick one of the shortcuts. The pipeline runs DNS → network → HTTP and stops at the stage that fires. SIMULATED: the logic is rebuilt so the enforcement order becomes tangible. No real gateway traffic runs here.

🧭
DNS
Auflösungresolution
→
🔌
Network · L4
IP / Port / AppIP / port / app
→
🔎
HTTP · L7
Inspektioninspection
Weiter zu DLPOn to DLP Jetzt sehen wir den Traffic. Die nächste Frage ist nicht wohin, sondern was. Welche Daten verlassen gerade das Haus? Now we can see the traffic. The next question is not where to but what. Which data is leaving the building right now?
Abschnitt 6 · Section 6 · SIMULIERT

Data Loss PreventionData Loss Prevention

DLP erkennt sensible Daten an zwei Stellen. In transit läuft es inline über die HTTP-Stufe des Gateways. Dafür braucht es TLS-Decryption, dann scannt es den Body des Requests. At rest erreicht es ruhende Daten über die CASB-API in deinen SaaS-Tenants. DLP spots sensitive data in two places. In transit it runs inline on the gateway's HTTP stage. That requires TLS decryption, then it scans the request body. At rest it reaches data sitting in your SaaS tenants through the CASB API.

Mitgeliefert kommen fertige Profile. Dazu eigene Profile, Dokument-Fingerprinting und OCR für Text in Bildern. It ships with predefined profiles. On top come custom profiles, document fingerprinting and OCR for text inside images.

KundenproblemCustomer pain Kundendaten landen in ChatGPT. Quellcode wird privat nach GitHub geschoben. Die Gehaltsliste geht über WeTransfer raus. Drei alltägliche Wege, auf denen Daten ohne ein böses Wort das Unternehmen verlassen. Customer data ends up in ChatGPT. Source code gets pushed to a private GitHub. The payroll list goes out over WeTransfer. Three everyday paths where data leaves the company without a single malicious act.

Vignette: Schwärzung beim TippenVignette: redaction as you type

Tipp links eine Nachricht oder simulier einen Upload. Rechts siehst du, was Cloudflare durchlässt. Erkannte Muster werden in Echtzeit geschwärzt und beschriftet. SIMULIERT: Die Erkennung läuft hier per JS-Regex im Browser, nicht über das echte Gateway. Type a message on the left or fake an upload. On the right you see what Cloudflare lets through. Detected patterns are redacted and labelled in real time. SIMULATED: detection here runs as a JS regex in the browser, not through the real gateway.

Was du tippstWhat you type
Was Cloudflare durchlässtWhat Cloudflare lets through
FaktoidFactoid Das vordefinierte PII-Record-Profil schlägt erst an, wenn mehrere Treffer nah beieinander liegen. Das senkt False Positives spürbar. Die Quellcode-Erkennung deckt 12 Sprachen ab. OCR zieht Text auch aus Screenshots und Scans. The predefined PII record profile only fires when several detections sit close together. That cuts false positives noticeably. Source-code detection covers 12 languages. OCR pulls text out of screenshots and scans too.
Weiter zu CASBOn to CASB DLP fängt Daten in Bewegung. Aber das größte Leck sind oft die Daten, die falsch geteilt in der Cloud liegen und nie über unsere Leitung laufen. DLP catches data in motion. Yet the biggest leak is often the data that sits mis-shared in the cloud and never travels over our wire at all.
Abschnitt 7 · Section 7 · SIMULIERT

CASBCASB

Der Cloud Access Security Broker arbeitet API-basiert und out-of-band. Er verbindet sich per API mit deinen SaaS-Diensten (Google Workspace, Microsoft 365, Salesforce und weitere) und scannt sie kontinuierlich. Er sucht nach Fehlkonfigurationen, nach riskanten Freigaben und, zusammen mit DLP, nach sensiblen ruhenden Daten. The Cloud Access Security Broker works API-based and out-of-band. It connects to your SaaS services through their APIs (Google Workspace, Microsoft 365, Salesforce and more) and scans them continuously. It looks for misconfigurations, for risky shares and, together with DLP, for sensitive data at rest.

Kein Inline-Traffic läuft durch CASB. Es sitzt neben dem Datenstrom, nicht darin. No inline traffic runs through CASB. It sits beside the data stream, not inside it.

KundenproblemCustomer pain Ein öffentlich geteilter Drive-Ordner. Ein Admin ohne MFA. Eine Domain ohne DMARC. Eine Lohnabrechnung, die für jeden mit Link sichtbar ist. Das sind Risiken, die kein Proxy je sieht, weil niemand dafür über die Leitung muss. A publicly shared Drive folder. An admin without MFA. A domain without DMARC. A payslip visible to anyone with the link. These are risks no proxy ever sees, because nobody has to cross the wire for them.

Vignette: Misconfiguration-ScanVignette: misconfiguration scan

Start den Scan auf einem fiktiven Tenant. Die Findings ploppen gestaffelt auf, jedes mit Severity-Ampel und einem Fix-Button. SIMULIERT: Tenant und Findings sind erfunden. Ein echter CASB-Scan greift live auf die SaaS-APIs zu. Start the scan on a fictional tenant. Findings appear in a staggered sequence, each with a severity light and a fix button. SIMULATED: tenant and findings are made up. A real CASB scan reaches into the live SaaS APIs.

Tenant (fiktiv):Tenant (fictional): contoso.example
Bereit. Klick „Scan starten", um den Tenant zu prüfen. Ready. Click „Start scan" to check the tenant.
Weiter zu Browser IsolationOn to Browser Isolation Wir haben Tür, Leitung, Inhalt und ruhende Daten. Bleibt das eine, das man nicht filtern kann: aktiver, gefährlicher Code im Browser. Den lassen wir gar nicht erst aufs Gerät. We have the door, the wire, the content and the data at rest. One thing remains that you cannot filter: active, dangerous code in the browser. We keep that off the device in the first place.
Abschnitt 8 · Section 8 · LIVE

Browser IsolationBrowser Isolation

Remote Browser Isolation rendert riskante Seiten in einem Cloud-Browser an der Edge. Zum Gerät gehen nur Vektor-Zeichenbefehle (Network Vector Rendering, auch Canvas-Remoting). Aktiver Code erreicht das Endgerät nie. Das funktioniert in jedem HTML5-Browser, ganz ohne Client. Remote Browser Isolation renders risky pages in a cloud browser at the edge. Only vector drawing commands reach the device (network vector rendering, also called canvas remoting). Active code never reaches the endpoint. It works in any HTML5 browser, with no client at all.

Das ist der Schutz für ungemanagte Geräte: BYOD, Geräte von Contractors, alles ohne Agent. Copy, Paste, Download, Upload und Druck lassen sich pro Policy einzeln abschalten. This is the protection for unmanaged devices: BYOD, contractor laptops, anything without an agent. Copy, paste, download, upload and print can each be switched off per policy.

LIVE  Echte Remote-Browser-DemoReal remote-browser demo
Im isolierten Browser öffnenOpen in the isolated browser

Diese zwei Buttons sind echt, anders als die simulierten Vignetten davor. Sie öffnen einen neuen Tab auf die clientlose Web Isolation deines Teams unter bacarda.cloudflareaccess.com/browser/<ziel>. Beim ersten Mal kommt der Access-Login per OTP-Mail, wie bei /protected. These two buttons are real, unlike the simulated vignettes before. They open a new tab to your team's clientless Web Isolation at bacarda.cloudflareaccess.com/browser/<target>. On first use the Access login by OTP email appears, just like on /protected.

RBI_DEMO_TARGET
RBI_BLOCK_TARGET
Button 1Button 1
Öffnet example.com isoliert. Der Kunde sieht dieselbe Seite, nur remote gerendert. Beweisstück: der Hostname-Notch oben in der Mitte. Aktiver Code lief auf der Edge, nicht auf dem Gerät. Opens example.com in isolation. The customer sees the same page, only rendered remotely. The proof is the hostname notch at the top center. Active code ran at the edge, not on the device.
Button 2Button 2
Öffnet ein Ziel, das im Account per Gateway-HTTP-Policy geblockt ist. Hier sieht der Kunde RBI und Gateway echt zusammen: Die echte Cloudflare-Block-Page erscheint im isolierten Browser. Voraussetzung ist aktive TLS-Decryption (siehe DEPLOY.md). Opens a target that the account blocks via a Gateway HTTP policy. Here the customer sees RBI and Gateway working together for real: the genuine Cloudflare block page appears inside the isolated browser. This requires active TLS decryption (see DEPLOY.md).

Damit beide Buttons live funktionieren, müssen im Dashboard ein paar Schalter gesetzt sein. Alle Schritte und die genauen Zielwerte stehen in DEPLOY.md, Abschnitt 5. For both buttons to work live, a few switches must be set in the dashboard. All steps and the exact target values are in DEPLOY.md, section 5.

Abschnitt 9Section 9

FootprintFootprint

All das, von der Tür bis zum isolierten Browser, läuft an einem Ort: an der Cloudflare-Edge. Zero Trust an der Edge ist nur so gut wie die Edge selbst. Derselbe Standort, der eben deinen Login geprüft hat, macht auch TLS, DNS, WAF und Routing. Ein Netz, alle Funktionen, überall. All of this, from the door to the isolated browser, runs in one place: the Cloudflare edge. Zero Trust at the edge is only as good as the edge itself. The same location that just verified your login also does TLS, DNS, WAF and routing. One network, all functions, everywhere.

330+
Städtecities
in 125+ Ländernin 125+ countries
~50ms
zu 95 % der Internet-Bevölkerungto 95% of the internet-connected population
~13.000 vernetzte Netze · 449 Tbps~13,000 interconnected networks · 449 Tbps
67M+
DNS-Queries / SekundeDNS queries / second
> 50 Mio. HTTP-Requests/s> 50M HTTP requests/s
Das Killer-Argument: „every service on every server in every location." Jede Funktion läuft in jedem Standort. Single-Pass, kein Hairpinning, kein Umweg über eine zentrale Scrubbing-Cloud. Identität, Gerät, Policy und Filterung passieren im selben Durchlauf am selben Ort. The killer argument: „every service on every server in every location." Every function runs in every location. Single-pass, no hairpinning, no detour through a central scrubbing cloud. Identity, device, policy and filtering happen in the same pass in the same place.
SE-Modus · Wettbewerbsvergleich anzeigenSE mode · show competitor comparison

Kunden vergleichen ohnehin. Hier die ehrliche Ein-Zeilen-Lesart je Anbieter. Nützlich, wenn das Gespräch auf „warum nicht einfach Zscaler?" kippt. Customers compare anyway. Here is the honest one-line reading per vendor. Useful when the conversation tips into „why not just Zscaler?"

Stack Single Network Single Pass In + Outbound Separate SKUsSeparate SKUs
Cloudflare One ✓ ✓ ✓ neinno
Zscaler (ZIA / ZPA / ZDX) ~ ✕ getrenntseparate jayes
Palo Alto Prisma Access GCP-basiertGCP-based ~ ~ jayes
Netskope ~ ~ CASB-UrsprungCASB origin jayes
Cisco (Umbrella / Duo / …) ✕ ✕ ~ jayes
Cato Networks ✓ ✓ ~ teilspartly

Neutral gelesen: Zscaler betreibt pro Produkt getrennte Clouds (ZIA/ZPA/ZDX) und ist historisch outbound-stark. Palo Alto Prisma trägt Appliance-Erbe und läuft auf GCP. Netskope kommt vom CASB und hat den schwächeren Netz-Footprint. Cisco ist eine Zukauf-Sammlung mit Integrationsreibung. Cato ist architektonisch am ähnlichsten und damit der fairste Vergleich. Cloudflares Unterschied: ein Netz, ein Durchlauf, inbound und outbound, ohne getrennte SKUs. Read neutrally: Zscaler runs separate clouds per product (ZIA/ZPA/ZDX) and is historically outbound-strong. Palo Alto Prisma carries appliance heritage and runs on GCP. Netskope comes from CASB and has the weaker network footprint. Cisco is an acquisition collection with integration friction. Cato is architecturally the most similar and therefore the fairest comparison. Cloudflare's difference: one network, one pass, inbound and outbound, with no separate SKUs.