INTEGRITY Cloudflare Docs

Get started

This section covers best practices for setting up the following Gateway policy types:

For each type of policy, we recommend the following workflow:

  1. Connect the devices and/or networks that you want to apply policies to.
  2. Verify that Gateway is successfully proxying traffic from your devices.
  3. Set up basic security and compatibility policies (recommended for most use cases).
  4. Customize your configuration to the unique needs of your organization.

Most organizations roll out Gateway in phases, starting with the lowest-effort, highest-impact policy type and adding deeper inspection over time.

Phase 1: DNS filtering

DNS filtering requires the least deployment effort and provides immediate protection.

For setup instructions, refer to Set up DNS filtering.

Phase 2: Network policies

After DNS filtering is in place, add network-level controls for non-HTTP traffic.

For setup instructions, refer to Set up network filtering.

Phase 3: HTTP inspection

HTTP inspection provides the deepest visibility and the most granular controls, but it requires additional setup.

For setup instructions, refer to Set up HTTP filtering.

Phase 4: Egress control and full integration

With all policy layers active, extend Gateway to cover your full network and integrate with other Cloudflare One services.