<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Cloudflare One Handbook — Things Worth Sharing</title><description>A Cloudflare One handbook — foundations through advanced, with real-world deployment context.</description><link>https://cloudsecop.net/</link><item><title>What is Cloudflare One, and why SASE matters</title><link>https://cloudsecop.net/en/blog/what-is-cloudflare-one/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/what-is-cloudflare-one/</guid><description>A practical overview of Cloudflare One: SASE, SSE, Zero Trust, the six main product groups, how it compares to Zscaler and Netskope, and the mental model to have before deployment.</description><pubDate>Thu, 23 Jan 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>SASE</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>SASE, SSE, Zero Trust, ZTNA: getting the terminology right</title><link>https://cloudsecop.net/en/blog/sase-sse-zero-trust-terminology/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/sase-sse-zero-trust-terminology/</guid><description>Four terms routinely conflated in RFPs, design docs, and vendor marketing. Their scope, when Gartner/Forrester defined them, how to use each correctly, and a decision tree.</description><pubDate>Fri, 31 Jan 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>SASE</category><category>SSE</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>The four-layer mental model — Client, Identity, Policy, Resource</title><link>https://cloudsecop.net/en/blog/client-identity-policy-resource-mental-model/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/client-identity-policy-resource-mental-model/</guid><description>A framework for reasoning about every Cloudflare One feature: every request traverses four layers producing signals, and policy yields one of five outcomes. Rollout and debugging.</description><pubDate>Sat, 08 Feb 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Zero Trust</category><category>Architecture</category><author>KhaVan</author></item><item><title>Cloudflare Access — ZTNA fundamentals in 30 minutes</title><link>https://cloudsecop.net/en/blog/cloudflare-access-ztna-fundamentals/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/cloudflare-access-ztna-fundamentals/</guid><description>Replacing VPN for internal apps with Cloudflare Access: anatomy, login flow, 5-step setup (application, IdP, policy, Tunnel, test), policy evaluation order, and troubleshooting.</description><pubDate>Thu, 27 Feb 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Cloudflare Access</category><category>ZTNA</category><author>KhaVan</author></item><item><title>IdP integration — Okta, Entra ID, Google Workspace, generic SAML</title><link>https://cloudsecop.net/en/blog/identity-provider-integration-guide/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/identity-provider-integration-guide/</guid><description>A matrix of the four most common IdPs with Cloudflare Access: OIDC vs SAML, per-IdP group claim pitfalls, claim mapping, group sync timing, multi-IdP patterns, prod checklist.</description><pubDate>Mon, 03 Mar 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Identity</category><category>Okta</category><category>Entra ID</category><author>KhaVan</author></item><item><title>Service tokens and mTLS: auth for CI/CD, bots, devices</title><link>https://cloudsecop.net/en/blog/service-tokens-mtls-for-non-human/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/service-tokens-mtls-for-non-human/</guid><description>When the client is not a user. Service tokens vs mTLS, setup for both, a zero-downtime rotation strategy, audit logs, and common anti-patterns.</description><pubDate>Fri, 14 Mar 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Cloudflare Access</category><category>mTLS</category><category>DevOps</category><author>KhaVan</author></item><item><title>SCIM and group sync: automated off-boarding for leavers</title><link>https://cloudsecop.net/en/blog/scim-and-group-sync/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/scim-and-group-sync/</guid><description>SCIM closes the stale window: the IdP pushes updates in near-real time instead of Cloudflare pulling claims at login. Okta/Entra/Google setup, lifecycle phases, conflicts.</description><pubDate>Tue, 18 Mar 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Identity</category><category>SCIM</category><category>Lifecycle</category><author>KhaVan</author></item><item><title>Cloudflare Tunnel deep dive — safely exposing internal services</title><link>https://cloudsecop.net/en/blog/cloudflare-tunnel-deep-dive-guide/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/cloudflare-tunnel-deep-dive-guide/</guid><description>cloudflared daemon, ingress rules, HA replicas, non-HTTP (SSH/RDP/SMB), VPN migration, and troubleshooting six common cases. Tunnel is the connectivity foundation for Zero Trust.</description><pubDate>Wed, 26 Mar 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Cloudflare Tunnel</category><category>Networking</category><author>KhaVan</author></item><item><title>WARP client and the device enrollment flow</title><link>https://cloudsecop.net/en/blog/warp-client-device-enrollment/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/warp-client-device-enrollment/</guid><description>WARP architecture, enrollment flow, device posture checkers (built-in vs CrowdStrike/Intune), split tunnel modes, Local Domain Fallback, DNS, MDM deployment, troubleshooting.</description><pubDate>Mon, 07 Apr 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>WARP</category><category>Device Posture</category><author>KhaVan</author></item><item><title>Magic WAN: connecting sites and clouds over the backbone</title><link>https://cloudsecop.net/en/blog/magic-wan-bgp-over-gre/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/magic-wan-bgp-over-gre/</guid><description>Magic WAN deep dive: a network-layer replacement for SD-WAN/MPLS. Four tunnel options (IPsec, GRE, Anycast IP, CNI), BGP peering, multi-cloud, realistic migration playbook.</description><pubDate>Tue, 22 Apr 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Magic WAN</category><category>Networking</category><category>SD-WAN</category><author>KhaVan</author></item><item><title>Gateway DNS filtering — the first layer of a Secure Web Gateway</title><link>https://cloudsecop.net/en/blog/gateway-dns-policies/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/gateway-dns-policies/</guid><description>Gateway DNS deep dive: resolver architecture, policy order, DoH per-device vs DNS location per-site, threat categories, custom lists, OS bypasses, SIEM pipeline, prod checklist.</description><pubDate>Sat, 03 May 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Gateway</category><category>DNS</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Gateway HTTP filtering and TLS decryption — when DNS isn&apos;t enough</title><link>https://cloudsecop.net/en/blog/gateway-http-filtering-tls-decryption/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/gateway-http-filtering-tls-decryption/</guid><description>HTTP inspection deep dive: installing the root CA (MDM, GPO), cert pinning gotchas, DLP patterns, CASB tenant control, legal/privacy guardrails, staged rollout, prod checklist.</description><pubDate>Wed, 07 May 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Gateway</category><category>TLS</category><category>DLP</category><category>CASB</category><author>KhaVan</author></item><item><title>Network policy L4 — blocking non-HTTP, DoH bypass, and app rules</title><link>https://cloudsecop.net/en/blog/network-policy-l4/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/network-policy-l4/</guid><description>Network policy deep dive: blocking non-HTTP (SSH, RDP, SMTP), preventing DoH bypass, app rules for SaaS, WARP keeping user traffic on Gateway, prod checklist, hardening playbook.</description><pubDate>Mon, 19 May 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Gateway</category><category>Networking</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>End-to-end logs pipeline: Logpush, R2, SIEM correlation</title><link>https://cloudsecop.net/en/blog/logs-pipeline-siem/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/logs-pipeline-siem/</guid><description>Logs deep dive for Cloudflare One: datasets, Logpush destinations (R2/S3/Splunk/Sentinel), cross-layer correlation, tiered retention, cost control, sample SIEM detection rules.</description><pubDate>Tue, 27 May 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Logs</category><category>SIEM</category><category>Observability</category><author>KhaVan</author></item><item><title>DEX — Digital Experience Monitoring: reactive to SLOs</title><link>https://cloudsecop.net/en/blog/dex-experience-monitoring/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/dex-experience-monitoring/</guid><description>DEX deep dive for Cloudflare One: when control plane says UP but users say SLOW, latency-leg diagnosis (DNS/TCP/TLS/TTFB), SLO framework, and 5 failure modes DEX misses.</description><pubDate>Tue, 03 Jun 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>DEX</category><category>Observability</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Device posture and continuous verification: every request</title><link>https://cloudsecop.net/en/blog/device-posture-every-request/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/device-posture-every-request/</guid><description>Device posture deep dive for Zero Trust: WARP checks (OS, disk encryption, firewall), EDR integration, continuous verification in Access policy, and response to posture loss.</description><pubDate>Wed, 11 Jun 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Zero Trust</category><category>Device Posture</category><category>EDR</category><author>KhaVan</author></item><item><title>Browser Isolation (RBI) — rendering risky web in a remote sandbox</title><link>https://cloudsecop.net/en/blog/browser-isolation-deep-dive/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/browser-isolation-deep-dive/</guid><description>Browser Isolation deep dive for Cloudflare One: remote browser architecture (NVR), isolation triggers, data controls (copy/paste/print/download/keyboard), compliance, cost model.</description><pubDate>Sun, 15 Jun 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Browser Isolation</category><category>RBI</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>CASB: SaaS posture for Google Workspace, M365, Salesforce</title><link>https://cloudsecop.net/en/blog/casb-saas-posture/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/casb-saas-posture/</guid><description>CASB deep-dive for Cloudflare One from 3 rollouts: the 4 Gartner pillars, inline vs API, 8,000-finding first-scan shock, shadow IT, tenant-lock, when not to use CASB.</description><pubDate>Thu, 26 Jun 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>CASB</category><category>SaaS Security</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>DLP — patterns, classification, and the 55% false positive</title><link>https://cloudsecop.net/en/blog/dlp-data-loss-prevention/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/dlp-data-loss-prevention/</guid><description>DLP deep-dive for Cloudflare One: tuning from 55% to 3% false positives, regex vs Luhn vs context vs EDM, custom CCCD profile, Gateway HTTP inline vs CASB API.</description><pubDate>Fri, 04 Jul 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>DLP</category><category>Data Classification</category><category>Zero Trust</category><author>KhaVan</author></item><item><title>Email Security: phishing, BEC, and the DMARC forwarder</title><link>https://cloudsecop.net/en/blog/email-security-area1/</link><guid isPermaLink="true">https://cloudsecop.net/en/blog/email-security-area1/</guid><description>Email Security deep-dive for Cloudflare One: MX inline vs API journaling, the DMARC forwarder/subdomain trap, homoglyph FP calibration, user-report → retract under 1h.</description><pubDate>Sat, 12 Jul 2025 00:00:00 GMT</pubDate><category>Cloudflare</category><category>Cloudflare One</category><category>Email Security</category><category>Phishing</category><author>KhaVan</author></item></channel></rss>