Alright, let's talk about moving our company's crusty old on-prem network fortress into the 21st century with Cloudflare One. We're about 300 people, mostly remote, and our current setup involves a VPN that’s slower than a dial-up modem trying to download a 4K movie. We looked at ZTNA options and everyone kept pointing at Cloudflare. So we took the plunge.
Here’s the real talk they don’t put in the sales decks: **throughput is a fickle beast**. For plain HTTP/S traffic through WARP to an application protected by Access, it’s fantastic—basically line speed. But the moment you start tunneling *all* traffic (hello, Network Policies for our legacy junk), you hit the "magic" of GRE tunnels or their magic IPsec. We saw a very consistent, but very *meh*, 250-300 Mbps per tunnel endpoint. Support’s answer was essentially “add more tunnels” which, sure, works, but now you’re playing load-balancer config bingo. Not the “infinite cloud scale” dream I was sold.
Pricing is the other funny part. It looks simple until you realize you need about six different SKUs. The $7/user for Zero Trust is just the door fee. Need advanced DLP? That’s another line item. Magic WAN for the branch offices? Ka-ching. Our bill for 300 seats, with a couple of those add-ons and some reserved commit, landed around $4,500/month. It’s not cheap, but when you factor in the corpse of our MPLS circuit and the two firewalls we’re about to yeet into the sun, it’s probably a wash. Just don’t go in thinking it’s $7/user and a bag of chips.
The real win, honestly, has been the integration spaghetti. Getting our legacy LDAP to talk to Cloudflare, then piping logs to our SIEM, was almost… pleasant? Compared to the usual middleware horror show, I only cried a little. The Access policies are stupidly powerful, and killing the VPN for most folks has made me a temporary hero. Just manage those throughput expectations and read the fine print on the quote.
- Happy eval-ing
Spot on about the SKUs. The platform's modularity is a double-edged sword. You're essentially buying a la carte, and the bill of materials for a full SASE implementation with DLP, CASB, and Magic WAN is a separate conversation from the base Zero Trust seat.
The tunnel throughput ceiling you hit is the hardware limit of the virtual tunnel endpoints they provision. Their solution *is* to scale horizontally with more tunnels, but that shifts complexity and monitoring overhead to your team. It works, but it's not the hands-off experience implied.
Ah, the "add more tunnels" shuffle. Yep, we hit that exact same 250-300 Mbps wall with our GRE endpoints. It's like Cloudflare assumes your legacy traffic will politely stay under that ceiling, but try pushing a big file copy or a DB sync through there and suddenly you're back in VPN flashback territory.
I actually spent a weekend playing with their Anycast IPsec configs as an alternative. Got a bit more stable throughput per tunnel, but the setup docs read like a puzzle box and you lose some of the Magic WAN routing smarts. Ended up splitting our traffic: modern web apps through WARP, legacy junk through a couple parallel tunnels with a simple round-robin on our edge router. Works, but now I'm babysitting tunnel health dashboards instead of actually building anything.
On pricing, you're dead right about the SKU creep. We started at $7/user and by the time we added DLP and some basic network filtering the quote was closer to $15. Did your rep ever float the "all-in" Enterprise plan as a bundle? Ours did, and the jump in minimum commit made my eyes water.
Try everything, keep what works.
The weekend spent wrestling with Anycast IPsec configs is exactly where the real cost hides. It's not the $15 per seat, it's the billable hours for your team to become tunnel mechanics. You traded a slow, simple VPN for a fast, fragmented architecture that demands constant oversight.
That quote jump to an all-in Enterprise plan isn't a solution, it's a trap. The moment you sign that minimum commit, your leverage to push back on tunnel limits or demand better documentation evaporates. You're now a captive customer funding their roadmap, hoping your specific problems get solved eventually.
They sell simplicity, but you've just built a Rube Goldberg machine of traffic splitting and tunnel monitoring to achieve basic throughput. What happens when you need 500 Mbps for a single process? Just keep adding tunnels until your edge router config is unreadable?
Skeptic by default