Skip to content

Commit b1cbaf3

Browse files
lfcassidyranbel
andauthored
Update include mode split tunnel advice (#24621)
* Update Zero Trust IP addresses * Update split-tunnels.mdx --------- Co-authored-by: ranbel <[email protected]>
1 parent fbe0bfb commit b1cbaf3

File tree

1 file changed

+17
-4
lines changed
  • src/content/docs/cloudflare-one/connections/connect-devices/warp/configure-warp/route-traffic

1 file changed

+17
-4
lines changed

src/content/docs/cloudflare-one/connections/connect-devices/warp/configure-warp/route-traffic/split-tunnels.mdx

Lines changed: 17 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -38,18 +38,31 @@ Do not exclude a site from Split Tunnels if you want to see the traffic in your
3838
- Solve connectivity issues with a specific website. For configuration guidance, refer to our [troubleshooting guide](/cloudflare-one/connections/connect-devices/warp/troubleshooting/common-issues/#cannot-connect-to-a-specific-app-or-website).
3939
- Solve performance issues with a specific website. Since Cloudflare operates within 50 milliseconds of 95% of the Internet-connected population, it is usually faster to send traffic through us. If you are encountering a performance-related issue, it is best to first explore your Gateway policies or reach out to Support.
4040

41-
## Cloudflare Zero Trust domains
41+
## Routes for Split Tunnels Include mode
4242

43-
Many Cloudflare Zero Trust services rely on traffic going through WARP, such as [device posture checks](/cloudflare-one/identity/devices/) and [WARP session durations](/cloudflare-one/connections/connect-devices/warp/configure-warp/warp-sessions/). If you are using Split Tunnels in Include mode, you will need to manually add the following domains in order for these features to function:
43+
Many Cloudflare Zero Trust services rely on traffic going through WARP, such as [device posture checks](/cloudflare-one/identity/devices/) and [WARP session durations](/cloudflare-one/connections/connect-devices/warp/configure-warp/warp-sessions/). If you are using Split Tunnels in Include mode, you will need to manually add Cloudflare Zero Trust domains and IPs in order for these features to function.
44+
45+
### Cloudflare Zero Trust domains
46+
47+
If you are using Split Tunnels in Include mode, you must include the following domains:
4448

4549
- The IdP used to authenticate to Cloudflare Zero Trust
4650
- `<your-team-name>.cloudflareaccess.com`
4751
- The application protected by the Access or Gateway policy
4852
- `edge.browser.run` if using [Browser Isolation](/cloudflare-one/policies/browser-isolation/)
4953

50-
## Cloudflare Zero Trust IP addresses
54+
### Cloudflare Zero Trust IP addresses
55+
56+
#### Block page
57+
58+
If you are using Split Tunnels in Include mode and have [DNS policies](/cloudflare-one/policies/gateway/dns-policies/) with the [block page](/cloudflare-one/policies/gateway/block-page/) enabled, you must include the IPs that blocked domains will resolve to. Unless you are using a [dedicated or BYOIP resolver IP](/cloudflare-one/connections/connect-devices/agentless/dns/locations/dns-resolver-ips/#dns-resolver-ip) the block page will resolve to:
59+
60+
- `162.159.36.12`
61+
- `162.159.46.12`
62+
63+
#### Team domain
5164

52-
In [Secure Web Gateway without DNS filtering](/cloudflare-one/connections/connect-devices/warp/configure-warp/warp-modes/#secure-web-gateway-without-dns-filtering) WARP mode, you cannot [add domains](/cloudflare-one/connections/connect-devices/warp/configure-warp/route-traffic/split-tunnels/#cloudflare-zero-trust-domains) to the Split Tunnel. If you are using Split Tunnels in Include mode, you must include the IPs that resolve to `<your-team-name>.cloudflareaccess.com` instead:
65+
In [Secure Web Gateway without DNS filtering](/cloudflare-one/connections/connect-devices/warp/configure-warp/warp-modes/#secure-web-gateway-without-dns-filtering) WARP mode, you cannot [add domains](/cloudflare-one/connections/connect-devices/warp/configure-warp/route-traffic/split-tunnels/#cloudflare-zero-trust-domains) to Split Tunnels. If you are using Split Tunnels in Include mode, you must include the IPs that resolve to `<your-team-name>.cloudflareaccess.com` instead:
5366

5467
- `104.19.194.29`
5568
- `104.19.195.29`

0 commit comments

Comments
 (0)