Cloudflare Questions

Info

rbl q/a 2022-03-07


Table of contents


Cloudflare Help Center

DNS

"1.1.1.1 is a public DNS resolver operated by Cloudflare that offers a fast and private way to browse the Internet. Unlike most DNS resolvers, 1.1.1.1 does not sell user data to advertisers. In addition, 1.1.1.1 has been measured to be the fastest DNS resolver available."

"WARP is an optional app built on top of 1.1.1.1. WARP creates a secure connection between personal devices (like computers and smartphones) and the services you access on the Internet. While 1.1.1.1 only secures DNS queries, WARP secures all traffic coming from your device.

WARP does this by routing your traffic over the Cloudflare network rather than the public Internet. Cloudflare automatically encrypts all traffic, and is often able to accelerate it by routing it over Cloudflare’s low-latency paths. In this way, WARP offers some of the security benefits of a virtual public network (VPN) service, without the performance penalties and data privacy concerns that many for-profit VPNs bring."

Firewall

Web Connection

  • Browse to Wordpress. What is the return path using CF?
    • User uses WARP to send Wordpress website request to CF. CF is a reverse proxy server. After a 1.1.1.1 DNS lookup, CF sends website request to Wordpress. CF receives return information from Wordpress and checks it before sending back to the user.

CF Tunnels

What is the on premisses CF tunnel end point?

  • The on premisses firewall

How do users get to end point?

  • Connect to the CF Gateway using WARP

Cloudflare Services for the Critical Infrastructure Defense Project

Cloudflare 1.1.1.2

Phishing, malware

Harden authoritative DNS infrastructure

Protect public applications from attack OWASP Top Ten, DDoS, account takeover, zero-day vulnerabilities