Data centers · full LAN exposed once authenticated
SaaS · Internet
M365 · Salesforce · web — still routed through your DC
The pattern
Round-trip from Singapore to a US-east app: ~490ms. Every problem — security, performance, cost — gets forced through the same box. You can't fix one without buying a bigger one.
Talk track · ~60 seconds
Anchor the story."Three groups of users on the left. Three categories of destinations on the right. Everything in the middle is the box you're paying to maintain."
Name the cost layers inside the box."This isn't just a VPN. It's a concentrator, plus firewall, plus cert store, plus MFA appliance. When capacity runs out, you're not replacing one box — you're replacing all of them."
The cloud-egress punchline. Point at the "Your Cloud" box on the right. "Your AWS workloads get hairpinned too. You're paying egress fees to route AWS traffic back through your data center."
Close."The architecture forces every problem through the same box. You can't fix one without making the others worse. Let me show you what changes when the middle changes."
AFTER · With Cloudflare
What Cloudflare delivers
After
Same users. Same destinations. The middle is now a globally distributed network — not a single box.
Users
Employee
WARP client · hits closest PoP, anywhere
Contractor
WARP or clientless browser · no install
Branch Office
IPsec / GRE / Magic WAN · same control plane
→
CLOUDFLARE GLOBAL NETWORK
Policy at the edge
Nearest PoP · 330+ cities · no backhaul
✓ WARP Check
✓ Identity Check
✓ Access Policy
✓ Gateway Security
✓ DLP Scan
✓ CASB Control
✓ Email Security
✓ Browser Isolation
→
Destinations
Your Cloud
AWS · Azure · GCP — direct via tunnel or CNI
On-Prem
Data centers · cloudflared agent, per-app policy
SaaS · Internet
M365 · Salesforce · web — direct, CASB-aware
The flip
Same round-trip from Singapore: ~212ms — a 57% reduction. The chokepoint is gone. Identity, policy, and inspection all happen at the nearest PoP — closer to the user than your old data center ever was.
Talk track · ~60 seconds
Anchor on what hasn't changed."Look at the left side — same three user types. Look at the right — same destinations. Customers don't migrate to escape their apps. They migrate to escape the middle."
The middle is now a network, not a box."Cloudflare runs in 330+ cities. Every user hits the closest one. Identity, policy, and inspection all happen there — not at headquarters."
Make the locality concrete."Your contractor in Singapore hits a Singapore PoP. Your engineer in Dublin hits a Dublin PoP. Same security policy, locally enforced. No backhaul."
Close."Same shape as the last diagram. Same users, same destinations. But the middle stopped fighting you. Want to see how a user actually experiences this?"
Do the math · Latency & bottlenecks
Why the architecture matters
Same scenario: contractor in Singapore reaching an app in AWS us-east-1. We trace every hop, both ways.
VPN path · ~490ms round-trip
Hop
What happens
ms
1
Laptop → VPN tunnel handshake
40
2
Singapore internet → US concentrator
180
3
Concentrator → firewall → DPI
20
4
Firewall → us-east-1 (AWS app)
5
5
Return path (reversed)
245
Round-trip total
490ms
Cloudflare path · ~212ms round-trip
Hop
What happens
ms
1
Laptop → Singapore Cloudflare PoP
8
2
Identity + policy + inspection (at PoP)
3
3
Singapore PoP → us-east-1 (CF backbone)
95
4
App response → PoP → laptop
106
No tunnel handshake. No concentrator hairpin. No backhaul.
Round-trip total
212ms
A note on physics
Singapore to Virginia is ~15,000 km. The speed of light in fiber caps the one-way latency at ~75ms — no vendor breaks that. About ~180ms of the 212ms total is just the cross-Pacific physical round-trip, and Cloudflare can't make it disappear. What Cloudflare eliminates is the avoidable hops: 180ms of backhaul to a central concentrator, 40ms of tunnel handshake, and 20ms of stateful inspection. That's the 278ms we save — every request, every user.
Net change per request
−278ms · −57%
For a typical user making 200 requests/minute, that's ~56 seconds of saved wait time every minute. Across an 8-hour shift: nearly 7.5 hours of compounded latency removed.
Talk track · ~60 seconds
Set the scenario."Contractor in Singapore. AWS app in us-east-1. Real geography, real numbers."
Walk the VPN table."40ms tunnel handshake. 180ms across the Pacific to your concentrator. 20ms through firewall and DPI. Five to AWS. Same return. Nearly half a second per round-trip."
The Cloudflare table."Eight ms to the nearest PoP. Three ms for identity, policy, and inspection — all local. 95ms across our private backbone to us-east-1. 212 total. Less than half."
Be honest about the physics."Singapore to Virginia is 15,000 kilometers. The speed of light caps that round-trip at about 180ms no matter who you use. What we eliminate is the avoidable stuff — backhauling through a central concentrator, tunnel handshakes, stateful inspection. That's where the 278ms savings comes from."
The business framing."Across 200 requests a minute, that's nearly a minute of saved wait time every minute. Compounded across an 8-hour shift, that's hours of latency removed from the user experience."
CDN + DNS vs Zero Trust · same network, different jobs
Public-internet side vs internal side
Use this with Oscar's question. Public-facing Cloudflare (CDN, DNS, WAF, DDoS) sits in front of your website; Zero Trust sits in front of everything that isn't public. Same network underneath, two different jobs on top.
↑ This is the same content as the standalone /cdn-vs-zerotrust page. Click Animate flow above to walk the comparison.
The Cloudflare platform & how everything connects
Platform + 6 on-ramps
One platform enforcing policy at the edge, sitting between every user and every app. Three on-ramps per side. Pick whichever fits each piece of your environment, they all hit the same security policy.
How to read this: the orange box in the middle is Cloudflare — policy enforced at the edge, on one global network. The cards on each side are how your people and your servers reach it. Three on-ramps per side. Click any card to see when to use that pattern.
User side · how people connect
01
💻
Managed employee laptop
Corporate device, fully under IT control. WARP client installed and managed via MDM.
Open with the platform."Before I get into Zero Trust specifically, quick picture of what Cloudflare actually is. Most folks know us from one angle, usually the CDN or the WAF, and that's a pretty small slice of what we do now. What's in the middle of this diagram is a handful of capabilities running on the same network. Zero Trust, network as a service, AI security, plus the developer side. You probably won't need all of these on day one, and that's the point. They're already here when you do."
Land the platform punchline."330-plus cities, one network, one control plane, one set of logs. That's what makes SASE work as architecture instead of as a slide."
Set up the on-ramps."Now the next question is always 'how does the user actually connect, and how does the server side hook in?' Three on-ramps per side. Let me show you each one."
U1, managed employee."Corporate laptop, fully under IT control. We push our WARP client through your MDM. Identity, posture, policy, all evaluated at the nearest PoP, automatically."
U2, contractor or BYOD."Their own laptop. Two options. Install WARP voluntarily, or just open the app URL in any browser and log in with their own identity. No agent, no install."
U3, branch office."Connect the whole site from the router via IPsec or GRE. Every device behind it gets policy enforcement. Replaces MPLS and site-to-site VPN concentrators."
S1, single server."One app, one box. Install cloudflared. Three commands. It dials out to Cloudflare, nothing inbound, no public IP, no firewall port."
S2, whole VPC."Install WARP Connector on one box. Tell it 'I represent this CIDR range.' Every server behind it is now reachable. No per-server agents."
S3, data center or region."Network-level. IPsec, GRE, or CNI for a literal direct connection. AWS Direct Connect, Azure ExpressRoute, GCP Partner Interconnect. Magic WAN orchestrates all of it."
The closing punchline."No public IP, no firewall rule, no port forwarded. Every connection from your infrastructure is outbound-only. The 'door' doesn't exist on the internet."