Solution design
VPN replacement with Cloudflare Access and Tunnel
Replace broad network access with per-application identity, device posture, and outbound-only private connectivity.
Use When
Use this pattern when users need access to private web apps, SSH/RDP, developer tools, dashboards, or internal portals without exposing origins or maintaining broad VPN routes.
Core Design
IdentityConnect corporate IdP, verify group claims, and enable SCIM for lifecycle control.
ConnectorPlace Cloudflare Tunnel near the private application and avoid inbound firewall exposure.
PolicyUse default-deny, reusable Access Groups, short sessions for sensitive apps, and posture where managed devices are required.
ValidationConfirm allowed users succeed, blocked users fail, logs show identity and posture context, and origin is not directly reachable.
Rollout Notes
Start with one low-risk app, migrate pilot users, compare helpdesk impact against VPN, then move app-by-app. Keep VPN available until critical workflows, logging, and rollback are proven.