logo

Introducing simple and secure egress policies by hostname in Cloudflare’s SASE platform

ID: 873e96e7-024e-5848-8a3a-89197aa71609

STIX ID: report--873e96e7-024e-5848-8a3a-89197aa71609

Feed Name: Cloudflare Blog

Date Published: 2025-07-07

Date Updated: 2026-04-27

Author: Ankur Aggarwal

...
...

Cloudflare announced an open beta enabling its SASE Gateway to enforce egress policies by hostname, domain, content category, and application, simplifying control over source IP and egress location for external services. Because egress decisions occur at L4, the team built a DNS-based “initial resolved IP” mechanism that returns synthetic IPs from CGNAT ranges to tag flows and then rewrites to the real destination, enabling scalable, dynamic hostname mapping (including wildcards). The feature currently requires DNS and network traffic to land on the same server via the same tunnel, with plans to expand on-ramps and extend hostname-based rulesets across the platform.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.