Cloudflare One Client software logo
Cloudflare One Client software logo

Secure Windows Traffic Through Cloudflare

Cloudflare One Client securely connects Windows devices to Cloudflare’s network so organizations can filter traffic, enforce Zero Trust policies, and protect access to Internet and private resources. Formerly known as WARP, the agent creates encrypted connections between an endpoint and Cloudflare using supported tunneling technology while its DNS proxy can send queries through encrypted DNS. Administrators can enroll managed devices into Cloudflare Zero Trust and apply Gateway or Access policies using network, identity, and device context. Cloudflare One Client is especially relevant to distributed workforces because policy enforcement can follow enrolled endpoints beyond an office network instead of depending primarily on a traditional network perimeter.

Cloudflare One Client supports several operating modes so administrators can choose how much endpoint traffic is handled by Cloudflare. Traffic and DNS mode provides the broadest filtering coverage, while DNS-only, traffic-only, local proxy, and posture-only modes serve more specialized deployments. Split Tunnels can include or exclude selected addresses and domains from IP tunneling, which is useful when existing VPNs or private routing requirements must coexist with Cloudflare. Teams using Dropbox for ordinary file synchronization can keep those storage workflows separate from endpoint traffic inspection and Zero Trust access controls. Cloudflare also provides command-line and administrative deployment options that help organizations manage client behavior across Windows devices.

Benefits of Using Cloudflare One Client

Cloudflare One Client gives organizations consistent endpoint security controls wherever enrolled Windows devices connect, reducing reliance on office-based network boundaries. Routing eligible traffic through Cloudflare allows administrators to apply centrally managed DNS, network, and web policies without requiring users to return to a corporate location. Encrypted tunneling and DNS transport protect connections between endpoints and Cloudflare’s network, while multiple client modes let teams adopt only the traffic handling required by their environment. Split Tunnel controls help accommodate applications, private destinations, or existing VPN arrangements that need different routing. Cloudflare One Client can also contribute device posture information to security decisions, allowing policies to consider endpoint condition alongside user identity. Access to private resources through Cloudflare’s Zero Trust architecture can reduce the need to expose internal applications publicly, while centralized configuration gives administrators a clearer way to maintain consistent controls across remote and distributed users.

Cloudflare One Client Software Information

  • Developer: Cloudflare, Inc.
  • Current Version: 26.7.1376.0
  • File Size: 56.7 MB
  • Language: English
  • Downloads: 2M
  • Platform: Windows

System Requirements

  • Processor: 2-core CPU
  • RAM: 2 GB RAM
  • Storage: 1.5 GB
  • Graphics / GPU: Not required

Visit the official Cloudflare One Client website

Cloudflare One Client Features

Encrypted Device Tunnel

Cloudflare One Client creates an encrypted tunnel between the Windows endpoint and Cloudflare’s network using supported tunnel protocols such as MASQUE or WireGuard. Eligible Internet and private network traffic can travel through this connection, helping protect traffic in transit while allowing Cloudflare Gateway policies to evaluate permitted connections.

Encrypted DNS Filtering

The client can send device DNS queries to Cloudflare through an encrypted DNS proxy, where Gateway DNS policies can evaluate requested domains. Administrators can therefore block or control destinations at the DNS layer without relying entirely on local network resolvers, and DNS-only mode is available for deployments that do not require traffic tunneling.

Multiple Client Modes

Cloudflare One Client provides traffic and DNS, DNS-only, traffic-only, local proxy, and posture-only operating modes. Each mode changes which traffic reaches Cloudflare and which Zero Trust capabilities are available, giving administrators a practical way to match endpoint behavior to different security architectures instead of enforcing one routing model everywhere.

Split Tunnel Control

Split Tunnels let administrators include or exclude selected IP addresses and domains from the IP traffic sent through the Cloudflare tunnel. This helps Cloudflare One Client coexist with existing VPNs, private networks, or applications that require direct routing, while giving administrators explicit control over which connections receive network-level Cloudflare inspection.

Device Posture Checks

The client can report endpoint health information that administrators reference in Cloudflare Access and Gateway policies. Supported posture signals can help determine whether a device satisfies organizational requirements before access is granted, allowing security decisions to incorporate endpoint condition alongside identity rather than treating every authenticated device as equally trusted.

Private Resource Access

Cloudflare One Client can connect enrolled users to private applications and networks made reachable through Cloudflare’s Zero Trust architecture. Organizations can provide remote access without placing those resources directly on the public Internet, while identity, device, and traffic policies determine which users and endpoints are permitted to reach protected destinations.

Centralized Policy Enforcement

Traffic routed through Cloudflare Gateway can be evaluated against centrally configured DNS, network, and HTTP policies according to the selected client mode. This gives administrators a consistent policy layer for remote Windows endpoints and reduces dependence on users being physically connected to an office network for organizational filtering rules to apply.

Command Line Management

Cloudflare installs command-line utilities alongside the desktop client, including tools for managing settings and collecting diagnostic information. Administrators and support teams can use these utilities to inspect configuration, control client connectivity, and gather troubleshooting data, which is useful for scripted workflows and diagnosing endpoint connectivity problems without relying only on the graphical interface.

Cloudflare One Client Old Versions

Version 26.7.1343.0   Updated: 2026-08-19   Download

Version 26.6.905.0   Updated: 2026-08-10   Download

Version 26.6.880.0   Updated: 2026-07-21   Download

Version 26.6.850.0   Updated: 2026-07-07   Download

Version 26.6.822.0   Updated: 2026-06-29   Download

Cloudflare One Client FAQs

What is Cloudflare One Client used for?

Cloudflare One Client connects endpoints securely to Cloudflare’s network for encrypted traffic routing, DNS filtering, Zero Trust policy enforcement, device posture assessment, and controlled access to Internet or private resources.

Is it the same client as WARP?

Yes. Cloudflare’s current Zero Trust documentation describes the endpoint software as the client formerly known as WARP. Organizational deployments can integrate it with Cloudflare Gateway, Access, device enrollment, and centrally managed security policies.

Which tunnel protocols are supported?

Cloudflare documents MASQUE and WireGuard as supported protocols for the device tunnel. The exact protocol used can depend on the deployment configuration and client mode.

Can it perform only DNS filtering?

Yes. DNS-only mode forwards DNS resolution to Cloudflare for policy evaluation without routing general network traffic through the device tunnel. This is useful when an organization wants Cloudflare DNS filtering while retaining its existing traffic-routing setup.

Does it support split tunneling?

Yes. Administrators can configure Split Tunnels to include or exclude specified IP addresses or domains from IP traffic routed through the client. DNS handling remains separate, so DNS policies and related fallback settings should also be considered when planning exceptions.