跳到主内容
@wquguru
精选75Cloudflare One(Changelog)云与平台

Cloudflare One Gateway 策略新增流量来源选择器

Gateway, Cloudflare One - Traffic Source selector in Gateway policies

原文
发到 X
推荐理由

Cloudflare One 用户注意:Gateway 策略新增流量来源选择器,可按入口方式(如 WARP、MCP 门户)精细控制策略,建议管理员评估并利用此能力优化现有策略。

Gateway HTTP and Network policies now include a Traffic Source selector that identifies how traffic reaches Cloudflare. This allows administrators to write policies that target specific on-ramp methods - for example, applying different rules to traffic arriving via the Cloudflare One Client compared to traffic routed through an MCP portal or a proxy endpoint.

Gateway HTTP 和网络策略现在包含一个流量来源选择器,用于识别流量如何到达 Cloudflare。这允许管理员编写针对特定入口方法的策略——例如,对通过 Cloudflare One 客户端到达的流量与通过 MCP 门户或代理端点路由的流量应用不同的规则。

Available traffic source values

可用的流量来源值

UI nameAPI valueDescription
Device clientdevice_clientTraffic from the Cloudflare One Client (WARP)
MeshmeshTraffic from a Cloudflare Mesh connector
Cloudflare WANcloudflare_wanTraffic from Cloudflare WAN (Magic WAN)
Clientless RDPclientless_rdpTraffic from a clientless RDP session
Proxy endpointproxy_endpointTraffic from a proxy endpoint (PAC file)
Clientless Browser Isolationagentless_bisoTraffic from clientless Browser Isolation
MCP portalmcp_portalTraffic from an MCP portal
UI 名称API 值描述
设备客户端device_client来自 Cloudflare One 客户端(WARP)的流量
网格mesh来自 Cloudflare Mesh 连接器的流量
Cloudflare WANcloudflare_wan来自 Cloudflare WAN(Magic WAN)的流量
无客户端 RDPclientless_rdp来自无客户端 RDP 会话的流量
代理端点proxy_endpoint来自代理端点(PAC 文件)的流量
无客户端浏览器隔离agentless_biso来自无客户端浏览器隔离的流量
MCP 门户mcp_portal来自 MCP 门户的流量

The selector uses the net.onramp.type API field in both HTTP and Network policies.

该选择器在 HTTP 和网络策略中使用 net.onramp.type API 字段。

UI nameAPI example
Traffic Sourcenet.onramp.type == "device_client"
UI 名称API 示例
流量来源net.onramp.type == "device_client"

Browser Isolation selector

浏览器隔离选择器

A Browser Isolation selector is also available in Network and HTTP policies. This selector identifies whether the current session is running inside Remote Browser Isolation, allowing administrators to apply different policy behavior to isolated traffic.

网络和 HTTP 策略中也可使用浏览器隔离选择器。此选择器识别当前会话是否在远程浏览器隔离中运行,允许管理员对隔离流量应用不同的策略行为。

UI nameAPI example
Browser Isolationnet.is_isolated == true
UI 名称API 示例
浏览器隔离net.is_isolated == true

For more information, refer to HTTP policies and Network policies.

有关更多信息,请参阅 HTTP 策略和网络策略。

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

相似阅读

另一事件,读法相近