Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -19,11 +19,9 @@ The WARP client allows organizations to have granular control over the applicati
| Connection | Protocol | Purpose |
| ---------------------------------------------------------------------------------------------------------------------------------------------- | -------- | --------------------------------------------------------------------------------------------------------------- |
| WARP tunnel ([via WireGuard or MASQUE](/cloudflare-one/connections/connect-devices/warp/configure-warp/warp-settings/#device-tunnel-protocol)) | UDP | Send IP packets to Gateway for network policy enforcement, HTTP policy enforcement, and private network access. |
| [DoH](https://www.cloudflare.com/learning/dns/dns-over-tls/) | HTTPS | Send DNS requests to Gateway for DNS policy enforcement. The DoH connection is maintained inside of the WARP tunnel.[^1] |
| [DoH](https://www.cloudflare.com/learning/dns/dns-over-tls/) | HTTPS | Send DNS requests to Gateway for DNS policy enforcement. The DoH connection is maintained inside of the WARP tunnel. |
| Device orchestration | HTTPS | Perform user registration, check device posture, apply WARP profile settings. |

[^1]: DoH is currently outside of the tunnel on iOS and Android/ChromeOS.

```mermaid
flowchart LR
subgraph Device
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -377,7 +377,7 @@ When `Enabled`, the operating system will register WARP's [local interface IP](#

If you use on-premise DNS infrastructure (such as Active Directory), we recommend turning this setting on for remote [device profiles](/cloudflare-one/connections/connect-devices/warp/configure-warp/device-profiles/) and turning it off for [managed network](/cloudflare-one/connections/connect-devices/warp/configure-warp/managed-networks/) device profiles. In this configuration, remote devices will register their WARP interface IP, while on-premise devices will only register their local DHCP address. This allows the on-premise DNS server to resolve device hostnames no matter where the device is located.

### SCCM VPN boundary support <Badge text="Beta" variant="caution"/>
### SCCM VPN boundary support

<Details header="Feature availability">

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -97,7 +97,7 @@ Identifies a Zero Trust organization in the WARP GUI when WARP is deployed with

**Value:** Organization nickname shown to users in the WARP GUI (for example, `Test environment`).

### `enable_post_quantum` <InlineBadge preset="beta" />
### `enable_post_quantum`

<Details header="Feature availability">

Expand All @@ -108,8 +108,8 @@ Identifies a Zero Trust organization in the WARP GUI when WARP is deployed with
| System | Availability | Minimum WARP version |
| -------- | ------------ | -------------------- |
| Windows || 2025.5.735.1 |
| macOS || 2025.5.735.1 |
| Linux || 2025.5.735.1 |
| macOS || 2025.5.735.1 |
| Linux || 2025.5.735.1 |
| iOS || 1.10 |
| Android || 2.4 |
| ChromeOS || 2.4 |
Expand Down