Cloudflare One Gateway 策略新增流量来源选择器
Gateway, Cloudflare One - Traffic Source selector in Gateway policies
Cloudflare One 用户注意:Gateway 策略新增流量来源选择器,可按入口方式(如 WARP、MCP 门户)精细控制策略,建议管理员评估并利用此能力优化现有策略。
Gateway HTTP and Network policies now include a Traffic Source selector that identifies how traffic reaches Cloudflare. This allows administrators to write policies that target specific on-ramp methods - for example, applying different rules to traffic arriving via the Cloudflare One Client compared to traffic routed through an MCP portal or a proxy endpoint.
Gateway HTTP 和网络策略现在包含一个流量来源选择器,用于识别流量如何到达 Cloudflare。这允许管理员编写针对特定入口方法的策略——例如,对通过 Cloudflare One 客户端到达的流量与通过 MCP 门户或代理端点路由的流量应用不同的规则。
Available traffic source values
可用的流量来源值
| UI name | API value | Description |
|---|---|---|
| Device client | device_client | Traffic from the Cloudflare One Client (WARP) |
| Mesh | mesh | Traffic from a Cloudflare Mesh connector |
| Cloudflare WAN | cloudflare_wan | Traffic from Cloudflare WAN (Magic WAN) |
| Clientless RDP | clientless_rdp | Traffic from a clientless RDP session |
| Proxy endpoint | proxy_endpoint | Traffic from a proxy endpoint (PAC file) |
| Clientless Browser Isolation | agentless_biso | Traffic from clientless Browser Isolation |
| MCP portal | mcp_portal | Traffic from an MCP portal |
| UI 名称 | API 值 | 描述 |
|---|---|---|
| 设备客户端 | device_client | 来自 Cloudflare One 客户端(WARP)的流量 |
| 网格 | mesh | 来自 Cloudflare Mesh 连接器的流量 |
| Cloudflare WAN | cloudflare_wan | 来自 Cloudflare WAN(Magic WAN)的流量 |
| 无客户端 RDP | clientless_rdp | 来自无客户端 RDP 会话的流量 |
| 代理端点 | proxy_endpoint | 来自代理端点(PAC 文件)的流量 |
| 无客户端浏览器隔离 | agentless_biso | 来自无客户端浏览器隔离的流量 |
| MCP 门户 | mcp_portal | 来自 MCP 门户的流量 |
The selector uses the net.onramp.type API field in both HTTP and Network policies.
该选择器在 HTTP 和网络策略中使用 net.onramp.type API 字段。
| UI name | API example |
|---|---|
| Traffic Source | net.onramp.type == "device_client" |
| UI 名称 | API 示例 |
|---|---|
| 流量来源 | net.onramp.type == "device_client" |
Browser Isolation selector
浏览器隔离选择器
A Browser Isolation selector is also available in Network and HTTP policies. This selector identifies whether the current session is running inside Remote Browser Isolation, allowing administrators to apply different policy behavior to isolated traffic.
网络和 HTTP 策略中也可使用浏览器隔离选择器。此选择器识别当前会话是否在远程浏览器隔离中运行,允许管理员对隔离流量应用不同的策略行为。
| UI name | API example |
|---|---|
| Browser Isolation | net.is_isolated == true |
| UI 名称 | API 示例 |
|---|---|
| 浏览器隔离 | net.is_isolated == true |
For more information, refer to HTTP policies and Network policies.
有关更多信息,请参阅 HTTP 策略和网络策略。
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力