From b1fd328dfca6319d82e6555843e663058c1d2ac1 Mon Sep 17 00:00:00 2001
From: Ranbel Sun
Date: Mon, 16 Mar 2026 13:05:53 -0400
Subject: [PATCH 01/15] [ZT] Rename WARP to Cloudflare One Client across
cloudflare-one docs, partials, and cross-references
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Applies WARP Client → Cloudflare One Client rename to ~241 files across
cloudflare-one docs (excluding already-done cloudflare-one-client/ and
warp-connector/), all partials, and cross-product references.
Preserves safe-list items: WARP tunnel, WARP Connector, warp-cli, warp-svc,
dashboard UI labels, API field names, code blocks, changelog prose,
WARP session/authentication feature names, and consumer WARP references.
---
.../concepts/global-acceleration.mdx | 8 +--
.../access-settings/session-management.mdx | 2 +-
.../application-token.mdx | 4 +-
.../applications/http-apps/index.mdx | 2 +-
.../cloudflared-authentication/index.mdx | 2 +-
.../applications/non-http/index.mdx | 6 +-
.../non-http/infrastructure-apps.mdx | 12 ++--
.../non-http/self-hosted-private-app.mdx | 8 +--
.../access-controls/policies/index.mdx | 10 ++--
.../policies/isolate-application.mdx | 2 +-
.../mutual-tls-authentication.mdx | 2 +-
.../docs/cloudflare-one/account-limits.mdx | 3 +-
.../dlp-policies/common-policies.mdx | 2 +-
.../data-loss-prevention/index.mdx | 2 +-
.../docs/cloudflare-one/faq/devices-faq.mdx | 14 ++---
.../faq/getting-started-faq.mdx | 8 +--
src/content/docs/cloudflare-one/faq/index.mdx | 2 +-
.../cloudflare-one/faq/troubleshooting.mdx | 56 +++++++++----------
src/content/docs/cloudflare-one/index.mdx | 2 +-
.../cloudflare-one/insights/dex/index.mdx | 4 +-
.../insights/dex/ip-visibility.mdx | 4 +-
.../insights/dex/monitoring.mdx | 18 +++---
.../insights/dex/tests/http.mdx | 4 +-
.../insights/dex/tests/index.mdx | 2 +-
.../insights/dex/tests/traceroute.mdx | 6 +-
.../insights/logs/gateway-logs/index.mdx | 26 ++++-----
.../cloudflare-one/insights/logs/logpush.mdx | 10 ++--
.../insights/logs/posture-logs.mdx | 10 ++--
.../identity-providers/okta-saml.mdx | 2 +-
.../integrations/service-providers/custom.mdx | 8 +--
.../integrations/service-providers/index.mdx | 4 +-
.../tunnel-availability/index.mdx | 2 +-
.../system-requirements.mdx | 4 +-
.../deployment-guides/aws.mdx | 2 +-
.../deployment-guides/azure.mdx | 2 +-
.../google-cloud-platform.mdx | 2 +-
.../tunnel-useful-commands.mdx | 4 +-
.../get-started/tunnel-useful-terms.mdx | 2 +-
.../private-net/cloudflared/connect-cidr.mdx | 2 +-
.../cloudflared/connect-private-hostname.mdx | 8 +--
.../private-net/cloudflared/index.mdx | 2 +-
.../private-net/cloudflared/private-dns.mdx | 8 +--
.../cloudflared/tunnel-virtual-networks.mdx | 14 ++---
.../cloudflare-tunnel/private-net/index.mdx | 4 +-
.../private-net/warp-connector/index.mdx | 8 +--
.../private-net/warp-connector/tips.mdx | 4 +-
.../warp-connector/user-to-site.mdx | 14 ++---
.../private-net/warp-to-warp.mdx | 18 +++---
.../troubleshoot-tunnels/common-errors.mdx | 4 +-
.../cloudflare-tunnel/use-cases/grpc.mdx | 10 ++--
.../cloudflare-tunnel/use-cases/rdp/index.mdx | 2 +-
.../use-cases/rdp/rdp-browser.mdx | 4 +-
.../rdp/rdp-cloudflared-authentication.mdx | 2 +-
.../use-cases/rdp/rdp-warp-to-tunnel.mdx | 10 ++--
.../cloudflare-tunnel/use-cases/smb.mdx | 10 ++--
.../cloudflare-tunnel/use-cases/ssh/index.mdx | 6 +-
.../use-cases/ssh/ssh-browser-rendering.mdx | 2 +-
.../ssh/ssh-cloudflared-authentication.mdx | 2 +-
.../ssh/ssh-infrastructure-access.mdx | 8 +--
.../use-cases/ssh/ssh-warp-to-tunnel.mdx | 16 +++---
.../zero-trust/cloudflare-gateway.mdx | 4 +-
.../cloudflare-wan/zero-trust/index.mdx | 2 +-
.../cloudflare-wan/zero-trust/warp.mdx | 4 +-
.../dns/dns-over-https.mdx | 2 +-
.../dns/locations/dns-resolver-ips.mdx | 2 +-
.../dns/locations/index.mdx | 2 +-
.../proxy-endpoints/index.mdx | 6 +-
.../networks/routes/reserved-ips.mdx | 18 +++---
.../setup/clientless-browser-isolation.mdx | 6 +-
.../remote-browser-isolation/setup/index.mdx | 6 +-
.../setup/non-identity.mdx | 4 +-
.../custom-pages/gateway-block-page.mdx | 2 +-
.../posture-checks/access-integrations.mdx | 2 +-
.../posture-checks/index.mdx | 14 ++---
.../warp-client-checks/antivirus.mdx | 8 +--
.../warp-client-checks/application-check.mdx | 14 ++---
.../warp-client-checks/carbon-black.mdx | 6 +-
.../warp-client-checks/client-certificate.mdx | 16 +++---
.../warp-client-checks/corp-device.mdx | 6 +-
.../warp-client-checks/device-uuid.mdx | 6 +-
.../warp-client-checks/disk-encryption.mdx | 6 +-
.../warp-client-checks/domain-joined.mdx | 6 +-
.../warp-client-checks/file-check.mdx | 10 ++--
.../warp-client-checks/firewall.mdx | 12 ++--
.../warp-client-checks/index.mdx | 36 ++++++------
.../warp-client-checks/os-version.mdx | 10 ++--
.../warp-client-checks/require-gateway.mdx | 10 ++--
.../warp-client-checks/require-warp.mdx | 10 ++--
.../warp-client-checks/sentinel-one.mdx | 8 +--
.../warp-client-checks/tanium.mdx | 2 +-
.../docs/cloudflare-one/roles-permissions.mdx | 4 +-
.../setup/replace-vpn/device-to-device.mdx | 14 ++---
.../setup/replace-vpn/device-to-network.mdx | 12 ++--
.../devices/device-registration.mdx | 12 ++--
.../automated-deployment.mdx | 32 +++++------
.../custom-certificate.mdx | 2 +-
.../devices/user-side-certificates/index.mdx | 4 +-
.../manual-deployment.mdx | 16 +++---
.../team-and-resources/users/scim.mdx | 2 +-
.../team-and-resources/users/users.mdx | 4 +-
.../traffic-policies/dns-policies/index.mdx | 2 +-
.../egress-policies/dedicated-egress-ips.mdx | 4 +-
.../egress-policies/egress-cloudflared.mdx | 10 ++--
.../egress-policies/host-selectors.mdx | 16 +++---
.../egress-policies/index.mdx | 4 +-
.../traffic-policies/get-started/dns.mdx | 4 +-
.../traffic-policies/get-started/http.mdx | 6 +-
.../traffic-policies/get-started/network.mdx | 10 ++--
.../traffic-policies/global-policies.mdx | 4 +-
.../http-policies/antivirus-scanning.mdx | 2 +-
.../traffic-policies/http-policies/index.mdx | 8 +--
.../http-policies/tenant-control.mdx | 2 +-
.../http-policies/tls-decryption.mdx | 2 +-
.../traffic-policies/identity-selectors.mdx | 8 +--
.../cloudflare-one/traffic-policies/index.mdx | 2 +-
.../network-policies/common-policies.mdx | 2 +-
.../network-policies/index.mdx | 4 +-
.../network-policies/protocol-detection.mdx | 2 +-
.../network-policies/ssh-logging.mdx | 6 +-
.../cloudflare-one/traffic-policies/proxy.mdx | 6 +-
.../traffic-policies/resolver-policies.mdx | 2 +-
.../traffic-policies/troubleshoot-gateway.mdx | 4 +-
.../clientless-access-private-dns.mdx | 4 +-
.../tutorials/m365-dedicated-egress-ips.mdx | 2 +-
.../tutorials/mysql-network-policy.mdx | 10 ++--
...regional-private-dns-resolver-policies.mdx | 4 +-
.../tutorials/user-selectable-egress-ips.mdx | 8 +--
.../tutorials/warp-on-headless-linux.mdx | 22 ++++----
src/content/docs/cloudflare-wan/changelog.mdx | 8 +--
.../docs/cloudflare-wan/zero-trust/index.mdx | 2 +-
.../docs/cloudflare-wan/zero-trust/warp.mdx | 4 +-
src/content/docs/containers/local-dev.mdx | 8 +--
.../docs/data-localization/compatibility.mdx | 2 +-
.../data-localization/how-to/zero-trust.mdx | 8 +--
.../migrate-to-email-security.mdx | 2 +-
.../concepts/traffic-flow-cloudflare.mdx | 2 +-
.../fundamentals/manage-members/roles.mdx | 2 +-
.../docs/fundamentals/reference/partners.mdx | 2 +-
.../series/china-express-overview-2.mdx | 2 +-
.../alternative-onramps/clientless-rbi.mdx | 4 +-
.../replace-vpn/build-policies/block-page.mdx | 8 +--
.../build-policies/session-timeouts.mdx | 4 +-
.../test-your-first-application.mdx | 26 ++++-----
.../enable-tls-decryption.mdx | 2 +-
.../replace-vpn/connect-devices/index.mdx | 2 +-
.../connect-devices/install-agent.mdx | 2 +-
.../connect-private-network/cloudflared.mdx | 2 +-
.../connection-methods.mdx | 2 +-
.../overlapping-ips.mdx | 2 +-
.../warp-connector.mdx | 2 +-
.../replace-vpn/get-started/index.mdx | 2 +-
.../replace-vpn/get-started/prerequisites.mdx | 4 +-
.../build-dns-policies/create-policy.mdx | 2 +-
.../build-dns-policies/index.mdx | 2 +-
.../build-dns-policies/test-policy.mdx | 2 +-
.../deploy-egress-ips.mdx | 2 +-
.../recommended-network-policies.mdx | 2 +-
.../configure-device-agent/pac-files.mdx | 4 +-
.../choose-on-ramp.mdx | 4 +-
.../install-agent.mdx | 2 +-
.../initial-setup/prerequisites.mdx | 4 +-
.../layer-security.mdx | 6 +-
.../sso-front-door.mdx | 2 +-
.../load-balancing/load-balancers/index.mdx | 2 +-
.../load-balancing/private-network/index.mdx | 4 +-
.../private-network/warp-to-tunnel.mdx | 12 ++--
.../tutorials/encrypt-network-flow-data.mdx | 2 +-
.../cloudflare-sase-with-crowdstrike.mdx | 2 +-
.../cloudflare-sase-with-sentinelone.mdx | 14 ++---
.../architectures/sase.mdx | 20 +++----
.../architectures/security.mdx | 2 +-
.../designing-ztna-access-policies.mdx | 14 ++---
.../design-guides/zero-trust-for-startups.mdx | 6 +-
.../sase/augment-access-with-serverless.mdx | 2 +-
...-hosted-VoIP-services-for-hybrid-users.mdx | 4 +-
.../api-content-types/parameters.mdx | 2 +-
.../docs/tunnel/deployment-guides/aws.mdx | 2 +-
.../docs/tunnel/deployment-guides/azure.mdx | 2 +-
.../google-cloud-platform.mdx | 2 +-
src/content/docs/tunnel/integrations.mdx | 4 +-
.../cloudflare-one/access/bookmarks.mdx | 4 +-
.../access/one-time-pin-warning.mdx | 2 +-
.../access/scim-requires-login.mdx | 2 +-
.../access/self-hosted-app/create-app.mdx | 2 +-
.../dex/http-test-create-steps.mdx | 2 +-
.../partials/cloudflare-one/dex/intro.mdx | 2 +-
.../dex/notifications-intro.mdx | 2 +-
.../cloudflare-one/dex/pcaps-check.mdx | 2 +-
.../dex/pcaps-run-availability.mdx | 4 +-
.../partials/cloudflare-one/dex/pcaps-run.mdx | 2 +-
.../dex/pcaps-view-warp-diag.mdx | 12 ++--
.../cloudflare-one/dex/tests-intro.mdx | 2 +-
.../add-locations-static-ip-warning.mdx | 2 +-
.../gateway/client-notifications.mdx | 8 +--
.../gateway/doh-instructions.mdx | 2 +-
.../gateway/egress-selector-onramps.mdx | 2 +-
.../gateway/egress-selector-warp-version.mdx | 4 +-
.../get-started/create-network-policy.mdx | 4 +-
.../network/enforce-device-posture.mdx | 2 +-
.../gateway/selectors/users.mdx | 2 +-
.../gateway/selectors/virtual-network.mdx | 2 +-
.../posture/prereqs-warp-is-deployed.mdx | 2 +-
.../posture/service-provider-intro.mdx | 2 +-
.../tunnel/catch-all-policy.mdx | 2 +-
.../deployment-guides/cloud-private-ip.mdx | 6 +-
.../deployment-guides/deploy-kubernetes.mdx | 2 +-
.../tunnel/filter-network-traffic.mdx | 2 +-
.../locally-managed/configuration-file.mdx | 2 +-
.../cloudflare-one/tunnel/protocols-table.mdx | 4 +-
.../tunnel/troubleshoot-private-networks.mdx | 18 +++---
.../tunnel/virtual-networks-intro.mdx | 2 +-
.../tunnel/warp-connector-install.mdx | 6 +-
.../tunnel/warp-to-tunnel-client.mdx | 2 +-
.../tunnel/warp-to-tunnel-route-ips.mdx | 6 +-
.../warp/device-enrollment-mtls.mdx | 2 +-
.../cloudflare-one/warp/enroll-desktop.mdx | 8 +--
.../warp/service-token-enrollment.mdx | 2 +-
.../china-network-overview-navigation.mdx | 2 +-
.../configure-device-agent-description.mdx | 2 +-
.../configure-device-agent-objectives.mdx | 2 +-
.../zero-trust/connect-devices-objectives.mdx | 2 +-
.../device-enrollment-permissions.mdx | 2 +-
.../zero-trust/device-profiles.mdx | 4 +-
.../zero-trust/enable-proxy-intro.mdx | 2 +-
.../zero-trust/install-agent.mdx | 8 +--
.../learning-paths/zero-trust/private-dns.mdx | 4 +-
.../zero-trust/split-tunnel-settings.mdx | 4 +-
.../analytics/network-analytics.mdx | 6 +-
.../cloudflare-one-connectivity-options.mdx | 56 +++++++++----------
.../reference/bandwidth-measurement.mdx | 2 +-
.../cloudflare-wan/wan-transformation.mdx | 2 +-
.../cloudflare-wan/zero-trust/gateway.mdx | 8 +--
.../cloudflare-wan/zero-trust/warp.mdx | 38 ++++++-------
.../breakout-prioritized.mdx | 2 +-
.../app-aware-policies/warp-traffic.mdx | 2 +-
.../partials/networking-services/mnm/faqs.mdx | 2 +-
.../tutorials/encrypt-network-flow-data.mdx | 28 +++++-----
.../reference/traffic-steering.mdx | 4 +-
.../routing/bgp-config-steps.mdx | 2 +-
.../configure-cloudflare-source-ips.mdx | 4 +-
.../routing/traceroute.mdx | 4 +-
241 files changed, 740 insertions(+), 741 deletions(-)
diff --git a/src/content/docs/china-network/concepts/global-acceleration.mdx b/src/content/docs/china-network/concepts/global-acceleration.mdx
index b76d3332e5f..889b81d61f1 100644
--- a/src/content/docs/china-network/concepts/global-acceleration.mdx
+++ b/src/content/docs/china-network/concepts/global-acceleration.mdx
@@ -30,7 +30,7 @@ Global Acceleration can support the following scenarios:
| Service | Scenario |
| --------------------------------------------------------------- | ------------------------------------------------------------------- |
| [CDN Global Acceleration](#cdn-global-acceleration) | Elevated performance of global dynamic assets on China Network CDN. |
-| [WARP Global Acceleration](#warp-global-acceleration) | WARP client used in Mainland China. |
+| [WARP Global Acceleration](#warp-global-acceleration) | Cloudflare One Client used in Mainland China. |
| [Cloudflare WAN Global Acceleration](#cloudflare-wan-global-acceleration) | Cloudflare WAN used in Mainland China. |
| [ICP](#icp-services) | China Network prerequisite. |
| [MLPS](#mlps-services) | MLPS certification services. |
@@ -42,7 +42,7 @@ CDN Global Acceleration provides stable and reliable connections for dynamic con
## WARP Global Acceleration
-WARP Global Acceleration enables [WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) access within China, allowing remote employees to maintain secure and consistent connections.
+WARP Global Acceleration enables [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) access within China, allowing remote employees to maintain secure and consistent connections.
## Cloudflare WAN Global Acceleration
@@ -58,7 +58,7 @@ The Multi-Level Protection Scheme (MLPS) service add-on streamlines the certific
### Travel SIM
-Travel SIM offers temporary, seamless WARP access for individual employees traveling to China, ensuring uninterrupted connectivity during their visit.
+Travel SIM offers temporary, seamless Cloudflare One Client access for individual employees traveling to China, ensuring uninterrupted connectivity during their visit.
---
@@ -66,7 +66,7 @@ Travel SIM offers temporary, seamless WARP access for individual employees trave
### 1. Validate prerequisites
-Ensure that you have a Cloudflare [Enterprise plan](https://www.cloudflare.com/plans/enterprise/) and [China Network](/china-network/), if you want CDN Global Acceleration. WARP and Cloudflare WAN licenses are required for WARP Connection or Cloudflare WAN Global Acceleration.
+Ensure that you have a Cloudflare [Enterprise plan](https://www.cloudflare.com/plans/enterprise/) and [China Network](/china-network/), if you want CDN Global Acceleration. the Cloudflare One Client and Cloudflare WAN licenses are required for the Cloudflare One Client Connection or Cloudflare WAN Global Acceleration.
### 2. Sign contract
diff --git a/src/content/docs/cloudflare-one/access-controls/access-settings/session-management.mdx b/src/content/docs/cloudflare-one/access-controls/access-settings/session-management.mdx
index 3a46db593f7..5fb8069993e 100644
--- a/src/content/docs/cloudflare-one/access-controls/access-settings/session-management.mdx
+++ b/src/content/docs/cloudflare-one/access-controls/access-settings/session-management.mdx
@@ -84,7 +84,7 @@ Users who match a policy configured with a _Same as application session timeout_
### WARP session duration
-When [WARP authentication identity](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/client-sessions/#configure-warp-sessions-in-access) is enabled for an Access application, the WARP session duration overrides the application and policy session durations. If the global session expires but the user already has a valid WARP session, the user will not need to reauthenticate with the IdP until the WARP session expires, given the user is running WARP.
+When [WARP authentication identity](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/client-sessions/#configure-warp-sessions-in-access) is enabled for an Access application, the WARP session duration overrides the application and policy session durations. If the global session expires but the user already has a valid WARP session, the user will not need to reauthenticate with the IdP until the WARP session expires, given the user is running the Cloudflare One Client.
### Order of enforcement
diff --git a/src/content/docs/cloudflare-one/access-controls/applications/http-apps/authorization-cookie/application-token.mdx b/src/content/docs/cloudflare-one/access-controls/applications/http-apps/authorization-cookie/application-token.mdx
index 05bd4f9e0ea..425aca08dd6 100644
--- a/src/content/docs/cloudflare-one/access-controls/applications/http-apps/authorization-cookie/application-token.mdx
+++ b/src/content/docs/cloudflare-one/access-controls/applications/http-apps/authorization-cookie/application-token.mdx
@@ -99,8 +99,8 @@ Access will return a JSON structure containing the following data:
| service_token_id | The Client ID of the service token used for authentication. |
| service_token_status | True if authentication was through a service token instead of an IdP. |
| is_warp | True if the user enabled WARP. |
-| is_gateway | True if the user enabled WARP and authenticated to a Zero Trust team. |
-| gateway_account_id | An ID generated by the WARP client when authenticated to a Zero Trust team. |
+| is_gateway | True if the user enabled the Cloudflare One Client and authenticated to a Zero Trust team. |
+| gateway_account_id | An ID generated by the Cloudflare One Client when authenticated to a Zero Trust team. |
| device_id | The ID of the device used for authentication. |
| version | The version of the `get-identity` object. |
| device_sessions | A list of all sessions initiated by the user. |
diff --git a/src/content/docs/cloudflare-one/access-controls/applications/http-apps/index.mdx b/src/content/docs/cloudflare-one/access-controls/applications/http-apps/index.mdx
index a9af3da00ff..35e13ada7d6 100644
--- a/src/content/docs/cloudflare-one/access-controls/applications/http-apps/index.mdx
+++ b/src/content/docs/cloudflare-one/access-controls/applications/http-apps/index.mdx
@@ -17,7 +17,7 @@ You can protect the following types of web applications:
- **Self-hosted applications** consist of internal applications that you host in your own environment. These can be the data center versions of tools like the Atlassian suite or applications created by your own team. Setup requirements for a self-hosted application depend on whether the application is publicly accessible on the Internet or restricted to users on a private network.
- [**Public hostname applications**](/cloudflare-one/access-controls/applications/http-apps/self-hosted-public-app/) are web applications that have public DNS records. Anyone on the Internet can access the application by entering the URL in their browser and authenticating through Cloudflare Access. Securing access to a public website requires a Cloudflare DNS [full setup](/dns/zone-setups/full-setup/) or [partial CNAME setup](/dns/zone-setups/partial-setup/).
- - [**Private network applications**](/cloudflare-one/access-controls/applications/non-http/self-hosted-private-app/) do not have public DNS records, meaning they are not reachable from the public Internet. To connect using a private IP or private hostname, the user's traffic must route through Cloudflare Gateway. The preferred method is to install the WARP client on the user's device, but you could also forward device traffic from a [network location](/cloudflare-wan/) or use an agentless option such as [PAC files](/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/) or [Clientless Web Isolation](/cloudflare-one/remote-browser-isolation/setup/clientless-browser-isolation/).
+ - [**Private network applications**](/cloudflare-one/access-controls/applications/non-http/self-hosted-private-app/) do not have public DNS records, meaning they are not reachable from the public Internet. To connect using a private IP or private hostname, the user's traffic must route through Cloudflare Gateway. The preferred method is to install the Cloudflare One Client on the user's device, but you could also forward device traffic from a [network location](/cloudflare-wan/) or use an agentless option such as [PAC files](/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/) or [Clientless Web Isolation](/cloudflare-one/remote-browser-isolation/setup/clientless-browser-isolation/).
- [**Model Context Protocol (MCP) servers**](/cloudflare-one/access-controls/ai-controls/) are web applications that enable generative AI tools to read and write data within your business applications. For example, Salesforce provides an [MCP server](https://github.com/salesforcecli/mcp) for developers to interact with resources in their Salesforce tenant using GitHub Copilot or other AI code editors.
diff --git a/src/content/docs/cloudflare-one/access-controls/applications/non-http/cloudflared-authentication/index.mdx b/src/content/docs/cloudflare-one/access-controls/applications/non-http/cloudflared-authentication/index.mdx
index ba8041fe78b..f879bfc06a7 100644
--- a/src/content/docs/cloudflare-one/access-controls/applications/non-http/cloudflared-authentication/index.mdx
+++ b/src/content/docs/cloudflare-one/access-controls/applications/non-http/cloudflared-authentication/index.mdx
@@ -6,7 +6,7 @@ sidebar:
tableOfContents: false
---
-With Cloudflare Zero Trust, users can connect to non-HTTP applications via a public hostname without installing the WARP client. This method requires you to onboard a domain to Cloudflare and install `cloudflared` on both the server and the user's device.
+With Cloudflare Zero Trust, users can connect to non-HTTP applications via a public hostname without installing the Cloudflare One Client. This method requires you to onboard a domain to Cloudflare and install `cloudflared` on both the server and the user's device.
Users log in to the application by running a `cloudflared access` command in their terminal. `cloudflared` will launch a browser window and prompt the user to authenticate with your identity provider.
diff --git a/src/content/docs/cloudflare-one/access-controls/applications/non-http/index.mdx b/src/content/docs/cloudflare-one/access-controls/applications/non-http/index.mdx
index 07938989f8c..28f3e799635 100644
--- a/src/content/docs/cloudflare-one/access-controls/applications/non-http/index.mdx
+++ b/src/content/docs/cloudflare-one/access-controls/applications/non-http/index.mdx
@@ -19,9 +19,9 @@ Non-HTTP applications require [connecting your private network](/cloudflare-one/
thumbnail="https://imagedelivery.net/xDOJvHcv1KwTQn6S-BGFIw/205bdeb4-3e37-4b04-f430-8b5c06a9b300/public"
/>
-## WARP client
+## Cloudflare One Client
-Users can connect by installing the Cloudflare WARP client on their device and enrolling in your Zero Trust organization. Remote devices connect to your applications as if they were on your private network. By default, all devices enrolled in your organization can access any private route unless they are protected by an Access policy or Gateway firewall rule. To secure the application, you can [create a self-hosted application](/cloudflare-one/access-controls/applications/non-http/self-hosted-private-app/) for a private IP range, port range, and/or hostname and build [Access policies](/cloudflare-one/access-controls/policies/) that allow or block specific users.
+Users can connect by installing the Cloudflare One Client on their device and enrolling in your Zero Trust organization. Remote devices connect to your applications as if they were on your private network. By default, all devices enrolled in your organization can access any private route unless they are protected by an Access policy or Gateway firewall rule. To secure the application, you can [create a self-hosted application](/cloudflare-one/access-controls/applications/non-http/self-hosted-private-app/) for a private IP range, port range, and/or hostname and build [Access policies](/cloudflare-one/access-controls/policies/) that allow or block specific users.
If you would like to define how users access specific infrastructure servers within your network, [create an infrastructure application](/cloudflare-one/access-controls/applications/non-http/infrastructure-apps/) in Access for Infrastructure. Access for Infrastructure provides an additional layer of control and visibility over how users access non-HTTP applications, including:
@@ -31,7 +31,7 @@ If you would like to define how users access specific infrastructure servers wit
## Clientless access
-Clientless access methods are suited for organizations that cannot deploy the WARP client or need to support third-party contractors where installing a client is not possible. Clientless access requires onboarding a domain to Cloudflare and configuring a public hostname in order to make the server reachable. Command logging is not supported.
+Clientless access methods are suited for organizations that cannot deploy the Cloudflare One Client or need to support third-party contractors where installing a client is not possible. Clientless access requires onboarding a domain to Cloudflare and configuring a public hostname in order to make the server reachable. Command logging is not supported.
### Browser-rendered terminal
diff --git a/src/content/docs/cloudflare-one/access-controls/applications/non-http/infrastructure-apps.mdx b/src/content/docs/cloudflare-one/access-controls/applications/non-http/infrastructure-apps.mdx
index 71468cc1481..5ea5cb226a0 100644
--- a/src/content/docs/cloudflare-one/access-controls/applications/non-http/infrastructure-apps.mdx
+++ b/src/content/docs/cloudflare-one/access-controls/applications/non-http/infrastructure-apps.mdx
@@ -9,7 +9,7 @@ import { Badge, Details, Tabs, TabItem, Render } from "~/components";
-| [WARP modes](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/) | [Zero Trust plans](https://www.cloudflare.com/teams-pricing/) |
+| [Client modes](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/) | [Zero Trust plans](https://www.cloudflare.com/teams-pricing/) |
| ---------------------------------------------------------------------------------------- | ------------------------------------------------------------- |
|
Traffic and DNS mode
Traffic only mode
| All plans |
@@ -33,7 +33,7 @@ Access for Infrastructure currently only supports [SSH](/cloudflare-one/networks
## Prerequisites
- [Connect your infrastructure](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/) to Cloudflare using `cloudflared` or WARP Connector.
-- [Deploy the WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/) on user devices in Traffic and DNS mode.
+- [Deploy the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/) on user devices in Traffic and DNS mode.
## 1. Add a target
@@ -63,11 +63,11 @@ Certain protocols require configuring the server to trust connections through Ac
## 5. Connect as a user
-Users connect to the target's IP address using their preferred client software. The user must be logged into WARP on their device, but no other system configuration is required. You can optionally configure a [private DNS resolver](/cloudflare-one/traffic-policies/resolver-policies/) to allow connections to the target's private hostname.
+Users connect to the target's IP address using their preferred client software. The user must be logged into the Cloudflare One Client on their device, but no other system configuration is required. You can optionally configure a [private DNS resolver](/cloudflare-one/traffic-policies/resolver-policies/) to allow connections to the target's private hostname.
### Connect to different VNET
-To connect to targets that are in different VNETS, users will need to [switch their connected virtual network](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/tunnel-virtual-networks/#connect-to-a-virtual-network) in the WARP client.
+To connect to targets that are in different VNETS, users will need to [switch their connected virtual network](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/tunnel-virtual-networks/#connect-to-a-virtual-network) in the Cloudflare One Client.
:::note
If a user is connected to a target in VNET-A and needs to connect to a target in VNET-B, switching their VNET will not break any existing connections to targets within VNET-A. At present, connections are maintained between VNETs.
@@ -77,7 +77,7 @@ If a user is connected to a target in VNET-A and needs to connect to a target in
-| System | Availability | Minimum WARP version |
+| System | Availability | Minimum client version |
| -------- | ------------ | -------------------- |
| Windows | ✅ | 2024.9.346.0 |
| macOS | ✅ | 2024.9.346.0 |
@@ -88,7 +88,7 @@ If a user is connected to a target in VNET-A and needs to connect to a target in
-Users can use `warp-cli` to display a list of targets they can access. On the WARP device, open a terminal and run the following command:
+Users can use `warp-cli` to display a list of targets they can access. On the device, open a terminal and run the following command:
diff --git a/src/content/docs/cloudflare-one/access-controls/applications/non-http/self-hosted-private-app.mdx b/src/content/docs/cloudflare-one/access-controls/applications/non-http/self-hosted-private-app.mdx
index 1b2354c737f..bf36757bf9d 100644
--- a/src/content/docs/cloudflare-one/access-controls/applications/non-http/self-hosted-private-app.mdx
+++ b/src/content/docs/cloudflare-one/access-controls/applications/non-http/self-hosted-private-app.mdx
@@ -18,7 +18,7 @@ This feature replaces the legacy [private network app type](/cloudflare-one/acce
## Prerequisites
-- Private IPs and hostnames are reachable over Cloudflare WARP, Cloudflare WAN (formerly Magic WAN) or Browser Isolation. For more details, refer to [Connect a private network](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/).
+- Private IPs and hostnames are reachable over the Cloudflare One Client, Cloudflare WAN (formerly Magic WAN) or Browser Isolation. For more details, refer to [Connect a private network](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/).
- Private hostnames route to your custom DNS resolver through [Local Domain Fallback](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/local-domains/) or [Gateway resolver policies](/cloudflare-one/traffic-policies/resolver-policies/).
- Public IPs and hostnames can be used to define a private application, however the IP or hostname must route through Cloudflare via [Cloudflare Tunnel](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/), [WARP Connector](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/), or [Cloudflare WAN](/cloudflare-wan/configuration/manually/how-to/configure-routes/).
- (Optional) Turn on [Gateway TLS decryption](/cloudflare-one/traffic-policies/http-policies/tls-decryption/) if you want to use Access JWTs to manage [HTTPS application sessions](#https-applications).
@@ -63,7 +63,7 @@ This feature replaces the legacy [private network app type](/cloudflare-one/acce
11. (Optional) Configure [App Launcher settings](/cloudflare-one/access-controls/access-settings/app-launcher/) for the application.
-12. (Optional) Turn on **Allow clientless access** to allow users to access this private hostname or IP without the WARP client. Users who pass your Access policies will see a tile in their App Launcher which points to a prefixed URL such as `https://.cloudflareaccess.com/browser/https://wiki.internal.local/`. The link will route traffic to the application through [Clientless Web Isolation](/cloudflare-one/remote-browser-isolation/setup/clientless-browser-isolation/). This setting is useful for users on unmanaged devices or contractors who cannot install a device client.
+12. (Optional) Turn on **Allow clientless access** to allow users to access this private hostname or IP without the Cloudflare One Client. Users who pass your Access policies will see a tile in their App Launcher which points to a prefixed URL such as `https://.cloudflareaccess.com/browser/https://wiki.internal.local/`. The link will route traffic to the application through [Clientless Web Isolation](/cloudflare-one/remote-browser-isolation/setup/clientless-browser-isolation/). This setting is useful for users on unmanaged devices or contractors who cannot install a device client.
:::note
Ensure your [remote browser permissions](/cloudflare-one/remote-browser-isolation/setup/clientless-browser-isolation/) allow users of this application to open Clientless Web Isolation links.
@@ -90,11 +90,11 @@ Users can now connect to your private application after authenticating with Clou
If [Gateway TLS decryption](/cloudflare-one/traffic-policies/http-policies/tls-decryption/) is turned on and a user is accessing an HTTPS application on port `443`, Cloudflare Access will present a login page in the browser and issue an [application token](/cloudflare-one/access-controls/applications/http-apps/authorization-cookie/application-token/) to your origin. This is the same cookie-based authentication flow used by [self-hosted public apps](/cloudflare-one/access-controls/applications/http-apps/self-hosted-public-app/).
-If [Gateway TLS decryption](/cloudflare-one/traffic-policies/http-policies/tls-decryption/) is turned off, session management is [handled in the WARP client](#non-https-applications) instead of in the browser.
+If [Gateway TLS decryption](/cloudflare-one/traffic-policies/http-policies/tls-decryption/) is turned off, session management is [handled in the Cloudflare One Client](#non-https-applications) instead of in the browser.
### Non-HTTPS applications
-The WARP client manages sessions for all non-HTTPS applications. Users will receive an `Authentication required` pop-up notification from the WARP client. When the user selects the notification, WARP will open a browser window with your Access login page.
+The Cloudflare One Client manages sessions for all non-HTTPS applications. Users will receive an `Authentication required` pop-up notification from the Cloudflare One Client. When the user selects the notification, the Cloudflare One Client will open a browser window with your Access login page.
diff --git a/src/content/docs/cloudflare-one/access-controls/policies/index.mdx b/src/content/docs/cloudflare-one/access-controls/policies/index.mdx
index a05eadc12b6..3504367f97d 100644
--- a/src/content/docs/cloudflare-one/access-controls/policies/index.mdx
+++ b/src/content/docs/cloudflare-one/access-controls/policies/index.mdx
@@ -72,7 +72,7 @@ For example, some applications have an endpoint under the `/admin` route that mu
| ------ | --------- | -------- | ---------- |
| Bypass | Include | Everyone | `Everyone` |
-As part of implementing a Zero Trust security model, Cloudflare does not recommend using Bypass to grant direct permanent access to your internal applications. To enable seamless and secure access for on-network employees, use Cloudflare Tunnel to [connect your private network](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/) and have users connect through WARP.
+As part of implementing a Zero Trust security model, Cloudflare does not recommend using Bypass to grant direct permanent access to your internal applications. To enable seamless and secure access for on-network employees, use Cloudflare Tunnel to [connect your private network](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/) and have users connect through the Cloudflare One Client.
:::note
@@ -82,7 +82,7 @@ When applying a Bypass action, security settings revert to the defaults configur
#### Product compatibility
-Bypass policies which contain [WARP device posture check](/cloudflare-one/reusable-components/posture-checks/) rules will not function when [Zaraz](/zaraz/) is enabled for the zone protected by Access, or if a [Worker](/workers/) intercepts the request. To work around this limitation and bypass Access, change the policy action to [Service Auth](#service-auth).
+Bypass policies which contain [device posture check](/cloudflare-one/reusable-components/posture-checks/) rules will not function when [Zaraz](/zaraz/) is enabled for the zone protected by Access, or if a [Worker](/workers/) intercepts the request. To work around this limitation and bypass Access, change the policy action to [Service Auth](#service-auth).
### Service Auth
@@ -159,9 +159,9 @@ Non-identity attributes are polled continuously, meaning they are-evaluated with
| Identity provider group | Checks the user groups configured with your identity provider (IdP). This selector only displays if you use Microsoft Entra ID, GitHub, Google, Okta, or an IdP that provisions groups with [SCIM](/cloudflare-one/team-and-resources/users/scim/). | ✅ | ❌ | ✅ |
| SAML Group | Checks a SAML attribute name / value pair. This selector only displays if you use a [generic SAML](/cloudflare-one/integrations/identity-providers/generic-saml/) identity provider. | ✅ | ❌ | ✅ |
| OIDC Claim | Checks an OIDC claim name / value pair. This selector only displays if you use a [generic OIDC](/cloudflare-one/integrations/identity-providers/generic-oidc/) identity provider. | ✅ | ❌ | ✅ |
-| Device posture | Checks device posture signals from the WARP client or a third-party service provider. This selector only displays after you create a [device posture check](/cloudflare-one/reusable-components/posture-checks/). | ✅ | ✅ | ❌ |
-| Warp | Checks that the device is connected to WARP, including the consumer version. This selector only displays after you enable the [WARP posture check](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-warp/). | ✅ | ✅ | ❌ |
-| Gateway | Checks that the device is connected to your Zero Trust instance through the WARP client. This selector only displays after you enable the [Gateway posture check](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-gateway/). | ✅ | ✅ | ❌ |
+| Device posture | Checks device posture signals from the Cloudflare One Client or a third-party service provider. This selector only displays after you create a [device posture check](/cloudflare-one/reusable-components/posture-checks/). | ✅ | ✅ | ❌ |
+| Warp | Checks that the device is connected to the Cloudflare One Client, including the consumer version. This selector only displays after you enable the [WARP posture check](/cloudflare-one/reusable-components/posture-checks/client-checks/require-warp/). | ✅ | ✅ | ❌ |
+| Gateway | Checks that the device is connected to your Zero Trust instance through the Cloudflare One Client. This selector only displays after you enable the [Gateway posture check](/cloudflare-one/reusable-components/posture-checks/client-checks/require-gateway/). | ✅ | ✅ | ❌ |
1 For SaaS applications, Access can only enforce policies at the time
of initial sign on and when reissuing the SaaS session. Once the user has
diff --git a/src/content/docs/cloudflare-one/access-controls/policies/isolate-application.mdx b/src/content/docs/cloudflare-one/access-controls/policies/isolate-application.mdx
index 7381ab78d7c..1fcc7e597e1 100644
--- a/src/content/docs/cloudflare-one/access-controls/policies/isolate-application.mdx
+++ b/src/content/docs/cloudflare-one/access-controls/policies/isolate-application.mdx
@@ -12,7 +12,7 @@ import { Render } from "~/components";
Requires [Cloudflare Browser Isolation](/cloudflare-one/remote-browser-isolation/).
:::
-With Access policies, you can require users to open self-hosted applications in a secure [remote browser](/cloudflare-one/remote-browser-isolation/). Because the remote browser is directly integrated into our Secure Web Gateway platform, [HTTP policies](/cloudflare-one/traffic-policies/http-policies/) can be applied to isolated applications without needing to install the WARP client. This allows you to distribute internal applications to unmanaged users while retaining control over sensitive data.
+With Access policies, you can require users to open self-hosted applications in a secure [remote browser](/cloudflare-one/remote-browser-isolation/). Because the remote browser is directly integrated into our Secure Web Gateway platform, [HTTP policies](/cloudflare-one/traffic-policies/http-policies/) can be applied to isolated applications without needing to install the Cloudflare One Client. This allows you to distribute internal applications to unmanaged users while retaining control over sensitive data.
## Prerequisites
diff --git a/src/content/docs/cloudflare-one/access-controls/service-credentials/mutual-tls-authentication.mdx b/src/content/docs/cloudflare-one/access-controls/service-credentials/mutual-tls-authentication.mdx
index a21d7b3dffe..652c546b0ef 100644
--- a/src/content/docs/cloudflare-one/access-controls/service-credentials/mutual-tls-authentication.mdx
+++ b/src/content/docs/cloudflare-one/access-controls/service-credentials/mutual-tls-authentication.mdx
@@ -96,7 +96,7 @@ When the authentication process completes successfully, a `CF_Authorization Set-
:::caution
-Cloudflare Gateway cannot inspect traffic to mTLS-protected domains. If a device has the WARP client turned on and passes HTTP requests through Gateway, access will be blocked unless you [bypass HTTP inspection](/cloudflare-one/traffic-policies/http-policies/#do-not-inspect) for the domain.
+Cloudflare Gateway cannot inspect traffic to mTLS-protected domains. If a device has the Cloudflare One Client turned on and passes HTTP requests through Gateway, access will be blocked unless you [bypass HTTP inspection](/cloudflare-one/traffic-policies/http-policies/#do-not-inspect) for the domain.
:::
### Test in a browser
diff --git a/src/content/docs/cloudflare-one/account-limits.mdx b/src/content/docs/cloudflare-one/account-limits.mdx
index 3429d510d03..4bdf9bdf2b5 100644
--- a/src/content/docs/cloudflare-one/account-limits.mdx
+++ b/src/content/docs/cloudflare-one/account-limits.mdx
@@ -96,8 +96,7 @@ This page lists the default account limits for rules, applications, fields, and
| Team domain | 63 |
| Gateway API policy expression | 140,000 |
-## WARP
-
+## Cloudflare One Client
| Feature | Limit |
| -------------------------------------------------------------------------- | ------ |
| Characters per device profile expression | 10,000 |
diff --git a/src/content/docs/cloudflare-one/data-loss-prevention/dlp-policies/common-policies.mdx b/src/content/docs/cloudflare-one/data-loss-prevention/dlp-policies/common-policies.mdx
index d86a3da3c41..9ca827f67e1 100644
--- a/src/content/docs/cloudflare-one/data-loss-prevention/dlp-policies/common-policies.mdx
+++ b/src/content/docs/cloudflare-one/data-loss-prevention/dlp-policies/common-policies.mdx
@@ -41,7 +41,7 @@ You can configure access on a per-user or group basis by adding [identity-based
Many Android applications (such as Google Drive) use certificate pinning, which is incompatible with Gateway inspection. If needed, you can create a [Do Not Inspect policy](/cloudflare-one/traffic-policies/http-policies/#do-not-inspect) so that the app can continue to function on Android:
-1. Set up an [OS version device posture check](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/os-version/) that checks for the Android operating system.
+1. Set up an [OS version device posture check](/cloudflare-one/reusable-components/posture-checks/client-checks/os-version/) that checks for the Android operating system.
2. Create the following HTTP policy in Gateway:
diff --git a/src/content/docs/cloudflare-one/data-loss-prevention/index.mdx b/src/content/docs/cloudflare-one/data-loss-prevention/index.mdx
index 1b0bf27da7a..6378f07d8dd 100644
--- a/src/content/docs/cloudflare-one/data-loss-prevention/index.mdx
+++ b/src/content/docs/cloudflare-one/data-loss-prevention/index.mdx
@@ -30,7 +30,7 @@ To get started, refer to [Scan HTTP traffic with DLP](/cloudflare-one/data-loss-
## Data at rest
-Data Loss Prevention complements [Cloudflare CASB](/cloudflare-one/integrations/cloud-and-saas/) to detect sensitive data stored in your SaaS applications. Unlike data in transit scans which read files sent through Cloudflare Gateway, CASB retrieves files directly via the API. Therefore, Gateway and WARP settings (such as [Do Not Inspect](/cloudflare-one/traffic-policies/http-policies/#do-not-inspect) policies and [Split Tunnel](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/) configurations) will not affect data at rest scans.
+Data Loss Prevention complements [Cloudflare CASB](/cloudflare-one/integrations/cloud-and-saas/) to detect sensitive data stored in your SaaS applications. Unlike data in transit scans which read files sent through Cloudflare Gateway, CASB retrieves files directly via the API. Therefore, Gateway and Cloudflare One Client settings (such as [Do Not Inspect](/cloudflare-one/traffic-policies/http-policies/#do-not-inspect) policies and [Split Tunnel](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/) configurations) will not affect data at rest scans.
To get started, refer to [Scan SaaS applications with DLP](/cloudflare-one/cloud-and-saas-findings/casb-dlp/).
diff --git a/src/content/docs/cloudflare-one/faq/devices-faq.mdx b/src/content/docs/cloudflare-one/faq/devices-faq.mdx
index e66dd7580e9..d4ade922fd9 100644
--- a/src/content/docs/cloudflare-one/faq/devices-faq.mdx
+++ b/src/content/docs/cloudflare-one/faq/devices-faq.mdx
@@ -10,9 +10,9 @@ description: Review frequently asked questions about devices in Cloudflare Zero
[❮ Back to FAQ](/cloudflare-one/faq/)
-## Why does my Windows device appear to switch from Wi-Fi to Ethernet when I enable WARP?
+## Why does my Windows device appear to switch from Wi-Fi to Ethernet when I enable the Cloudflare One Client?
-As the WARP client has replaced WinDivert with WinTun architecture, all Windows machines using WinTun will show as being connected using a virtual adapter. Windows, by default, shows virtual adapter connections with a wired Ethernet connection icon, even if the device is connected over wireless. This is by design and should have no impact on connectivity.
+As the Cloudflare One Client has replaced WinDivert with WinTun architecture, all Windows machines using WinTun will show as being connected using a virtual adapter. Windows, by default, shows virtual adapter connections with a wired Ethernet connection icon, even if the device is connected over wireless. This is by design and should have no impact on connectivity.
## Why is my device not connecting to a closer Cloudflare data center?
@@ -23,12 +23,12 @@ As our [Network Map](https://www.cloudflare.com/en-gb/network/) shows, we have l
## Why is my public IP address sometimes visible?
-Cloudflare WARP Client in WARP mode was meant to ensure all your traffic is kept private between you and the origin (the site you are connecting to), but not from the origin itself. In a number of cases, if the origin site you are communicating with can't determine who you are and where you're from, they can't serve locale relevant content to you.
+Cloudflare One Client in the Cloudflare One Client mode was meant to ensure all your traffic is kept private between you and the origin (the site you are connecting to), but not from the origin itself. In a number of cases, if the origin site you are communicating with can't determine who you are and where you're from, they can't serve locale relevant content to you.
Sites inside Cloudflare network are able to see this information. If a site is showing you your IP address, chances are they are in our network. Most sites outside our network (orange clouded sites) however are unable to see this information and instead see the nearest egress colo to their server. We are working to see if in the future we can't find a way to more easily share this information with a limited number of gray clouded sites where it is relevant to both parties.
-## Why has my throughput dropped while using WARP?
+## Why has my throughput dropped while using the Cloudflare One Client?
-Cloudflare WARP is in part powered by 1.1.1.1. When visiting sites or going to a new location on the Internet, you should see blazing fast DNS lookups. However, WARP is built to trade some throughput for enhanced privacy, because it encrypts all traffic both to and from your device. While this isn't noticeable at most mobile speeds, on desktop systems in countries where high speed broadband is available, you may notice a drop. We think the tradeoff is worth it though and continue to work on improving performance all over the system.
+the Cloudflare One Client is in part powered by 1.1.1.1. When visiting sites or going to a new location on the Internet, you should see blazing fast DNS lookups. However, the Cloudflare One Client is built to trade some throughput for enhanced privacy, because it encrypts all traffic both to and from your device. While this isn't noticeable at most mobile speeds, on desktop systems in countries where high speed broadband is available, you may notice a drop. We think the tradeoff is worth it though and continue to work on improving performance all over the system.
## Why is my device not connecting to a public Wi-Fi?
@@ -48,8 +48,8 @@ An [OS firewall rule](/cloudflare-one/team-and-resources/devices/cloudflare-one-
If your private network is [exposed via Cloudflare Tunnel](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/):
-* Verify that the WARP client is [properly configured](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/#device-configuration) on the device.
+* Verify that the Cloudflare One Client is [properly configured](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/#device-configuration) on the device.
* Verify that the user is allowed through by your Access and Gateway policies.
* Verify that the [local LAN settings](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/#router-configuration) for the device do not overlap with the CIDR range of your private network.
-When contacting Cloudflare support, ensure that you include [WARP debug logs](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/diagnostic-logs/) for your device. These logs will help Cloudflare support understand the overall architecture of your machine and networks.
+When contacting Cloudflare support, ensure that you include [Cloudflare One Client debug logs](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/diagnostic-logs/) for your device. These logs will help Cloudflare support understand the overall architecture of your machine and networks.
diff --git a/src/content/docs/cloudflare-one/faq/getting-started-faq.mdx b/src/content/docs/cloudflare-one/faq/getting-started-faq.mdx
index af9ed3f83e1..9ceadd06577 100644
--- a/src/content/docs/cloudflare-one/faq/getting-started-faq.mdx
+++ b/src/content/docs/cloudflare-one/faq/getting-started-faq.mdx
@@ -32,7 +32,7 @@ Once a team name has been used, even if the team domain is later deleted, the te
:::caution[Warning]
-If you change your team name, you need to update your organization's identity providers (IdPs) and the WARP client to reflect the new team name in order to avoid any mismatch errors.
+If you change your team name, you need to update your organization's identity providers (IdPs) and the Cloudflare One Client to reflect the new team name in order to avoid any mismatch errors.
:::
### Why is my old team name is still showing up on the Login page and App Launcher?
@@ -55,7 +55,7 @@ To make changes to your subscription, visit the Billing section under **Settings
## How are active seats measured?
-Cloudflare Zero Trust subscriptions consist of seats that users in your account consume. When users authenticate to an application or enroll their agent into WARP, they count against one of your active seats. Seats can be added, removed, or revoked at **Settings** > **Cloudflare One plan**. If all seats are currently consumed, you must first remove users before decreasing your purchased seat count.
+Cloudflare Zero Trust subscriptions consist of seats that users in your account consume. When users authenticate to an application or enroll their agent into the Cloudflare One Client, they count against one of your active seats. Seats can be added, removed, or revoked at **Settings** > **Cloudflare One plan**. If all seats are currently consumed, you must first remove users before decreasing your purchased seat count.
### Removing users
@@ -63,11 +63,11 @@ User seats can be removed for Access and Gateway at **Team & Resources** > **Use
- **Access**: All active sessions for that user will be invalidated. A user will be able to log back into an application unless you create an [Access policy](/cloudflare-one/access-controls/policies/) to block future logins from that user.
-- **Gateway**: All active devices for that user will be logged out of your Zero Trust organization, which stops all filtering and routing via the WARP client. A user will be able to re-enroll their device unless you create a [device enrollment policy](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/device-enrollment/) to block them.
+- **Gateway**: All active devices for that user will be logged out of your Zero Trust organization, which stops all filtering and routing via the Cloudflare One Client. A user will be able to re-enroll their device unless you create a [device enrollment policy](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/device-enrollment/) to block them.
:::caution
-The Remove action will remove a user's seat, but it will not permanently revoke their ability to authenticate. To permanently disable a user's ability to authenticate, you must modify the policies that allow them to reach a given application or enroll a device in WARP.
+The Remove action will remove a user's seat, but it will not permanently revoke their ability to authenticate. To permanently disable a user's ability to authenticate, you must modify the policies that allow them to reach a given application or enroll a device in the Cloudflare One Client.
:::
diff --git a/src/content/docs/cloudflare-one/faq/index.mdx b/src/content/docs/cloudflare-one/faq/index.mdx
index 5f413d9c3c0..e76c72b66d6 100644
--- a/src/content/docs/cloudflare-one/faq/index.mdx
+++ b/src/content/docs/cloudflare-one/faq/index.mdx
@@ -48,7 +48,7 @@ For questions on how policies work, and how to create and test them.
## Devices
-For questions on device connectivity and the WARP client.
+For questions on device connectivity and the Cloudflare One Client.
Devices ❯
diff --git a/src/content/docs/cloudflare-one/faq/troubleshooting.mdx b/src/content/docs/cloudflare-one/faq/troubleshooting.mdx
index 1dcee772105..4c319e71720 100644
--- a/src/content/docs/cloudflare-one/faq/troubleshooting.mdx
+++ b/src/content/docs/cloudflare-one/faq/troubleshooting.mdx
@@ -11,15 +11,15 @@ import { GlossaryTooltip, Render } from "~/components";
[❮ Back to FAQ](/cloudflare-one/faq/)
-## I tried to register the WARP client with my Zero Trust domain but received the following error messages: `Authentication Expired` and `Registration error. Please try again later`.
+## I tried to register the Cloudflare One Client with my Zero Trust domain but received the following error messages: `Authentication Expired` and `Registration error. Please try again later`.
-When a user logs into an organization, WARP will open a web page so the user can sign in via Cloudflare Access. Access then generates a JSON Web Token (JWT) that is passed from the web page to the WARP client to authenticate the device. This JWT has a timestamp indicating the exact time it was created, as well as a timestamp indicating it will expire 50 seconds into the future.
+When a user logs into an organization, the Cloudflare One Client will open a web page so the user can sign in via Cloudflare Access. Access then generates a JSON Web Token (JWT) that is passed from the web page to the Cloudflare One Client to authenticate the device. This JWT has a timestamp indicating the exact time it was created, as well as a timestamp indicating it will expire 50 seconds into the future.
-This error message means that when the JWT is finally passed to the WARP client, it has already expired. One of two things can be happening:
+This error message means that when the JWT is finally passed to the Cloudflare One Client, it has already expired. One of two things can be happening:
1. (Most likely): Your computer system clock is not properly synced using Network Time Protocol (NTP). Visit [https://time.is](https://time.is) on the affected machine to validate your clock is properly synchronized within 20 seconds of the actual time.
-2. You are waiting more than one minute to open Cloudflare WARP from the time Cloudflare Access prompts you. Open the WARP client as soon as you get the prompt.
+2. You are waiting more than one minute to open the Cloudflare One Client from the time Cloudflare Access prompts you. Open the Cloudflare One Client as soon as you get the prompt.
## I see a website is blocked, and it shouldn't be.
@@ -72,7 +72,7 @@ You may not see analytics on the Overview page for the following reasons:
## I see a "No Browsers Available" alert.
-If you encounter this error, [file feedback](/cloudflare-one/remote-browser-isolation/known-limitations/) via the WARP client and we will investigate.
+If you encounter this error, [file feedback](/cloudflare-one/remote-browser-isolation/known-limitations/) via the Cloudflare One Client and we will investigate.
## I see a "Maximum Sessions Reached" alert.
@@ -92,13 +92,13 @@ This error will appear if a certificate has not been generated for the Access ap
These mobile applications may use certificate pinning Cloudflare Gateway dynamically generates a certificate for all encrypted connections in order to inspect the content of HTTP traffic. This certificate will not match the expected certificate by applications that use certificate pinning.
To allow these applications to function normally, administrators can configure bypass rules to exempt traffic to hosts associated with the application from being intercepted and inspected.
-## Firefox shows a network protocol violation when I use the WARP client.
+## Firefox shows a network protocol violation when I use the Cloudflare One Client.
If you see this warning, you may have to disable DNS over HTTPS setting in Firefox. If you need help doing that, see [these instructions](https://support.mozilla.org/en-US/kb/firefox-dns-over-https#w_manually-enabling-and-disabling-dns-over-https).
-## Chrome shows `NET::ERR_CERT_AUTHORITY_INVALID` when I use the WARP client.
+## Chrome shows `NET::ERR_CERT_AUTHORITY_INVALID` when I use the Cloudflare One Client.
-Advanced security features including HTTPS traffic inspection require you to deploy a [root certificate](/cloudflare-one/team-and-resources/devices/user-side-certificates/) on the device. If [**Install CA to system certificate store**](/cloudflare-one/team-and-resources/devices/user-side-certificates/automated-deployment/) is enabled, the WARP client will automatically install a new root certificate whenever you install or update WARP.
+Advanced security features including HTTPS traffic inspection require you to deploy a [root certificate](/cloudflare-one/team-and-resources/devices/user-side-certificates/) on the device. If [**Install CA to system certificate store**](/cloudflare-one/team-and-resources/devices/user-side-certificates/automated-deployment/) is enabled, the Cloudflare One Client will automatically install a new root certificate whenever you install or update the Cloudflare One Client.
Certain web browsers (such as Chrome and Microsoft Edge) load and cache root certificates when they start. Therefore, if you install a root certificate while the browser is already running, the browser may not detect the new certificate. To resolve the error, restart the browser.
@@ -107,7 +107,7 @@ Certain web browsers (such as Chrome and Microsoft Edge) load and cache root cer
This error appears if you try to change your [team domain](/cloudflare-one/faq/getting-started-faq/#whats-a-team-domainteam-name) while the [Cloudflare dashboard SSO](/fundamentals/manage-members/dashboard-sso/) feature is enabled on your account.
Cloudflare dashboard SSO does not currently support team domain changes. Contact your account team for more details.
-## WARP on Linux shows `DNS connectivity check failed`.
+## the Cloudflare One Client on Linux shows `DNS connectivity check failed`.
This error means that the `systemd-resolved` service on Linux is not allowing WARP to resolve DNS requests. You can identify this issue in the [`daemon.log`](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/diagnostic-logs/#warp-diag-logs) file of the `warp diag` logs, where the error message appears as `ERROR main_loop: warp::warp::connectivity_check: DNS connectivity check failed to resolve host="warp-svc."`.
@@ -127,9 +127,9 @@ ResolveUnicastSingleLabel=yes
sudo systemctl restart systemd-resolved.service
```
-## Windows incorrectly shows `No Internet access` when WARP is enabled.
+## Windows incorrectly shows `No Internet access` when the Cloudflare One Client is enabled.
-[NCSI](https://learn.microsoft.com/en-us/windows-server/networking/ncsi/ncsi-overview) is a Windows feature for determining network quality and connectivity. When WARP is enabled, NCSI checks can sometimes fail and cause a cosmetic UI error where the user believes they have no Internet even though the device still has full connectivity. Some apps (Outlook, JumpCloud) may refuse to connect because Windows is reporting there is no Internet connectivity.
+[NCSI](https://learn.microsoft.com/en-us/windows-server/networking/ncsi/ncsi-overview) is a Windows feature for determining network quality and connectivity. When the Cloudflare One Client is enabled, NCSI checks can sometimes fail and cause a cosmetic UI error where the user believes they have no Internet even though the device still has full connectivity. Some apps (Outlook, JumpCloud) may refuse to connect because Windows is reporting there is no Internet connectivity.
To resolve the issue, you will need to edit two Windows registry keys:
@@ -142,7 +142,7 @@ To resolve the issue, you will need to edit two Windows registry keys:
Data: 1
```
-2. Configure NCSI to use active probing mode, as WARP may be obscuring the number of hops expected by the [passive probe](https://learn.microsoft.com/en-us/windows-server/networking/ncsi/ncsi-frequently-asked-questions#how-does-passive-probing-determine-connectivity).
+2. Configure NCSI to use active probing mode, as the Cloudflare One Client may be obscuring the number of hops expected by the [passive probe](https://learn.microsoft.com/en-us/windows-server/networking/ncsi/ncsi-frequently-asked-questions#how-does-passive-probing-determine-connectivity).
```txt
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NlaSvc\Parameters\Internet
@@ -169,7 +169,7 @@ To enable software rasterization:
## I cannot send emails on port `25`.
-By default, the WARP client blocks outgoing SMTP traffic on port `25` to prevent users from abusing our service to send spam. Modern email service providers use port `587` or `465` to encrypt emails over a TLS/SSL connection. For more information, refer to [What SMTP port should be used?](https://www.cloudflare.com/learning/email-security/smtp-port-25-587/).
+By default, the Cloudflare One Client blocks outgoing SMTP traffic on port `25` to prevent users from abusing our service to send spam. Modern email service providers use port `587` or `465` to encrypt emails over a TLS/SSL connection. For more information, refer to [What SMTP port should be used?](https://www.cloudflare.com/learning/email-security/smtp-port-25-587/).
If you need to unblock port `25`, contact your account team.
@@ -191,13 +191,13 @@ If you added a [multi-level subdomain](/cloudflare-one/networks/connectors/cloud
The default global Cloudflare root certificate expired on 2025-02-02 at 16:05 UTC. If you installed the default Cloudflare certificate before 2024-10-17, you must [generate a new certificate](/cloudflare-one/team-and-resources/devices/user-side-certificates/#generate-a-cloudflare-root-certificate) and activate it for your Zero Trust organization to avoid inspection errors. If you did not generate a new certificate before February 2, 2025, you will encounter browser warnings like `Your connection is not private`.
-Starting with WARP client version 2024.12.554.0 and later, the WARP client will automatically install Cloudflare certificates in an end-user device's certificate store as soon as the Cloudflare certificates appear as **Available** in the Cloudflare dashboard.
+Starting with Cloudflare One Client version 2024.12.554.0 and later, the Cloudflare One Client will automatically install Cloudflare certificates in an end-user device's certificate store as soon as the Cloudflare certificates appear as **Available** in the Cloudflare dashboard.
-For WARP client versions prior to 2024.12.554.0, certificates had to be marked as **In-Use** in the Cloudflare dashboard before the WARP client could push the Cloudflare certificates to an end-user device's certificate store.
+For Cloudflare One Client versions prior to 2024.12.554.0, certificates had to be marked as **In-Use** in the Cloudflare dashboard before the Cloudflare One Client could push the Cloudflare certificates to an end-user device's certificate store.
### What do I need to do?
-For WARP client versions before and after 2024.12.554.0, certificate propagation will only occur when the WARP client is responsible for automatically installing the certificate on the client device. To enable the WARP client to propogate certificates:
+For Cloudflare One Client versions before and after 2024.12.554.0, certificate propagation will only occur when the Cloudflare One Client is responsible for automatically installing the certificate on the client device. To enable the Cloudflare One Client to propogate certificates:
1. In [Cloudflare One](https://one.dash.cloudflare.com/), go to **Team & Resources** > **Devices**.
2. Select the **Management** tab.
@@ -212,7 +212,7 @@ After enabling certificate propagation, you must update your certificate:
3. Select the expiration date for this new certificate (five years is the default, but this can be adjusted) and select **Generate certificate**.
4. The new certificate will be marked **Inactive** at first. Select the **three dots** to the right of the certificate, then select **Activate** to activate the certificate.
-When you activate a certificate, WARP will download the new certificate to end-user devices.
+When you activate a certificate, the Cloudflare One Client will download the new certificate to end-user devices.
Certificate propagation to end-user devices can take up to 10 minutes, but can be expedited by resetting the encryption keys.
@@ -231,7 +231,7 @@ After confirming that the certificate is installed and trusted on the end-user d
It is recommended to have end users disconnect and reconnect WARP to expedite this change being reflected on their local machine. To verify the new certificate is being used correctly:
-1. Connect to WARP.
+1. Connect to the Cloudflare One Client.
2. Visit an HTTPS site.
3. Verify that no certificate error is enountered.
@@ -249,7 +249,7 @@ If the new certificate is not activating on the end-user device or you are getti
warp-cli tunnel rotate-keys
```
-2. [Upgrade](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/update/#how-to-update-warp) to WARP version 2024.12.554.0.
+2. [Upgrade](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/update/#how-to-update-warp) to the Cloudflare One Client version 2024.12.554.0.
Some customers who are on versions earlier than 2024.11.309.0 have experienced inconsistencies with certificate installation and may need to upgrade.
@@ -263,25 +263,25 @@ Turning off TLS decryption should be a temporary measure. TLS decryption should
-## I entered an override code for WARP that was supposed to be valid for 3 hours but the override code expired faster than I expected.
+## I entered an override code for the Cloudflare One Client that was supposed to be valid for 3 hours but the override code expired faster than I expected.
[Admin override codes](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/#allow-admin-override-codes) are time-sensitive and adhere to fixed-hour time blocks. Override codes can be reused until the end of their timeout. An override code's timeout begins in the hour the override code was generated in. Refer to the following scenarios.
### Scenario one: Admin generates an override code at 9:00 AM with a timeout of one hour.
-If admin generates an override code with a timeout of one hour at **9:00 AM** and the user inputs the override code in their device at **9:59 AM**, the user will be able to toggle WARP on and off until **10:59 AM** (a one hour duration.)
+If admin generates an override code with a timeout of one hour at **9:00 AM** and the user inputs the override code in their device at **9:59 AM**, the user will be able to toggle the Cloudflare One Client on and off until **10:59 AM** (a one hour duration.)
However, if the user attempts to enter the override code at **10:00 AM**, the override code will not work. The override code will not work because the override code was generated at **9:00 AM** and its one hour validity was counted as used in the 9:00 AM to 10:00 AM hour.
### Scenario two: Admin generates an override code at 9:30 AM with timeout of three hours.
-If admin generates an override code with a timeout of three hours at **9:30 AM** and the user inputs the override code in their device at **9:59 AM**, the user will be able to toggle WARP on and off until **12:59 PM** (a three hour duration.)
+If admin generates an override code with a timeout of three hours at **9:30 AM** and the user inputs the override code in their device at **9:59 AM**, the user will be able to toggle the Cloudflare One Client on and off until **12:59 PM** (a three hour duration.)
However, if the user attempts to enter the override code at **10:00 AM**, the override code will only be valid until **12:00 PM** (a two hour duration). The override code was generated at **9:30 AM** and one hour of its total three hour validity was counted as used in the 9:00 AM to 10:00 AM hour.
### Scenario three: Admin generates an override code at 12:30 PM with a timeout of 24 hours.
-If admin generates an override code with a timeout of 24 hours at **12:30 PM** and the user inputs the override code in their device at **12:59 PM** the same day, the user will be able to toggle WARP on and off until **12:59 PM** the next day (a 24 hour duration.)
+If admin generates an override code with a timeout of 24 hours at **12:30 PM** and the user inputs the override code in their device at **12:59 PM** the same day, the user will be able to toggle the Cloudflare One Client on and off until **12:59 PM** the next day (a 24 hour duration.)
However, if the user attempts to enter the override code at **1:00 PM** the same day, the override code will only be valid until **11:00 AM** the next day (a 23 hour duration). The override code was generated at **12:30 PM** and one hour of its total 24 hour validity was counted as used in the 12:00 PM to 1:00 PM hour.
@@ -289,7 +289,7 @@ If the user attempts to enter the override code at **11:59 AM** the next day, th
## I disabled WARP using an override code but WARP turned on by itself before my override code expired.
-If you are using an [admin override code](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/#allow-admin-override-codes) with [Auto connect](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/#auto-connect) also enabled, WARP will turn on automatically according to the Timeout set for **Auto connect**. Using an override code to override the WARP lock switch will not disable Auto connect. As best practice, review your Auto connect settings before sending the override code to the user.
+If you are using an [admin override code](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/#allow-admin-override-codes) with [Auto connect](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/#auto-connect) also enabled, the Cloudflare One Client will turn on automatically according to the Timeout set for **Auto connect**. Using an override code to override the WARP lock switch will not disable Auto connect. As best practice, review your Auto connect settings before sending the override code to the user.
To prevent WARP from auto connecting while using an admin override code, disable Auto connect or set a longer **Timeout** for **Auto connect**. Note the changes you make to Auto connect while the end user is using the admin override code if you need to revert these changes later.
@@ -301,9 +301,9 @@ For example, [Microsoft Entra](/cloudflare-one/integrations/identity-providers/e
You can also examine logs in your identity provider to identify any denied requests related to API access.
-## WSL2 is losing connectivity when using WARP.
+## WSL2 is losing connectivity when using the Cloudflare One Client.
-If your WSL2 environment is losing connectivity while using WARP, check your [split tunnel configuration](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/).
+If your WSL2 environment is losing connectivity while using the Cloudflare One Client, check your [split tunnel configuration](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/).
The issue may arise because the IP range that the WSL environment uses to communicate with the host device is included in the split tunnel configuration. Excluding the WSL environment's IP range should restore connectivity.
@@ -337,7 +337,7 @@ When you put your Google Workspace behind Access, users will not be able to log
This configuration creates an authentication loop. Cloudflare Access tries to authenticate the user via Google, but Google itself treats Cloudflare as its identity provider and requires authentication from Cloudflare. Since each system depends on the other to complete login first, the user is caught in an infinite redirect cycle and can never successfully authenticate.
-## When installing WARP on Windows, the Setup Wizard ends prematurely.
+## When installing the Cloudflare One Client on Windows, the Setup Wizard ends prematurely.
This error can occur for several reasons, including missing dependencies, like the appropriate .NET Framework version or other Dynamic Link Libraries (DLLs) such as `netstandard2.0`, required during installation.
@@ -349,7 +349,7 @@ msiexec /i /L*V
Check the logs to verify if there are any missing DLLs (for example, `netstandard2.0`), which may point to a missing or outdated version of the .NET Framework.
-One common cause is a missing or outdated version of the [.NET Framework Runtime](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/#windows:~:text=NET%20Framework%20version-,4.7.2%20or%20later,-HD%20space). Cloudflare WARP requires a .NET Framework version of `4.7.2` or later.
+One common cause is a missing or outdated version of the [.NET Framework Runtime](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/#windows:~:text=NET%20Framework%20version-,4.7.2%20or%20later,-HD%20space). the Cloudflare One Client requires a .NET Framework version of `4.7.2` or later.
Some legacy Windows systems (such as Windows 10 Enterprise 1607 LTSB, which is bundled with .NET `4.6`) do not include this runtime by default and may fail during installation with a `Setup Wizard ended prematurely` error. More recent Windows versions include .NET `4.7.2` or later by default and do not encounter this error.
diff --git a/src/content/docs/cloudflare-one/index.mdx b/src/content/docs/cloudflare-one/index.mdx
index 731d1a4716d..1550bb4be21 100644
--- a/src/content/docs/cloudflare-one/index.mdx
+++ b/src/content/docs/cloudflare-one/index.mdx
@@ -75,7 +75,7 @@ Inspect and filter DNS, network, HTTP, and egress traffic to enforce your compan
-
+
Protect corporate devices by privately sending traffic from those devices to Cloudflare's global network, build device posture rules, and enforce security policies anywhere.
diff --git a/src/content/docs/cloudflare-one/insights/dex/index.mdx b/src/content/docs/cloudflare-one/insights/dex/index.mdx
index 6d69d17c339..0ba6f119e7d 100644
--- a/src/content/docs/cloudflare-one/insights/dex/index.mdx
+++ b/src/content/docs/cloudflare-one/insights/dex/index.mdx
@@ -19,7 +19,7 @@ If a user notifies that “the connection is not working” or “performance is
- Use [device monitoring](/cloudflare-one/insights/dex/monitoring/) to check device health and endpoint connectivity.
- Test network health and application responsiveness with [synthetic tests](/cloudflare-one/insights/dex/tests/).
-- Identify whether problems originate from the device (such as [issues with the WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/troubleshooting-guide/)), the network, or Cloudflare.
+- Identify whether problems originate from the device (such as [issues with the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/troubleshooting-guide/)), the network, or Cloudflare.
## Troubleshooting other Cloudflare One features
@@ -34,7 +34,7 @@ Use DEX to troubleshoot other Cloudflare One features:
To start using DEX for device, network, and application monitoring:
1. [Create a Zero Trust organization](/cloudflare-one/setup/#create-a-zero-trust-organization).
-2. [Install the WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) and sign in to register your device to the organization.
+2. [Install the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) and sign in to register your device to the organization.
3. Create [tests](/cloudflare-one/insights/dex/tests/) to verify device connectivity to applications and networks.
4. [Monitor](/cloudflare-one/insights/dex/monitoring/) device and network health across your fleet using real-time and historical metrics.
5. Run [remote captures](/cloudflare-one/insights/dex/remote-captures/) to collect diagnostic logs and packet captures from user devices.
diff --git a/src/content/docs/cloudflare-one/insights/dex/ip-visibility.mdx b/src/content/docs/cloudflare-one/insights/dex/ip-visibility.mdx
index b83c02ec82f..4b43582fb8b 100644
--- a/src/content/docs/cloudflare-one/insights/dex/ip-visibility.mdx
+++ b/src/content/docs/cloudflare-one/insights/dex/ip-visibility.mdx
@@ -9,7 +9,7 @@ import { Render, Details } from "~/components";
-| System | Availability | Minimum WARP version |
+| System | Availability | Minimum client version |
| -------- | ------------ | -------------------- |
| Windows | ✅ | 2025.1.861.0 |
| macOS | ✅ | 2025.1.861.0 |
@@ -61,7 +61,7 @@ DEX's IP visibility allows you to review an event log of a device's IP history f
## Troubleshoot with IP visibility
-While IP visibility allows you to inspect a device's IP information, use [DEX's live analytics](/cloudflare-one/insights/dex/monitoring/#available-metrics) to review which Cloudflare data center the device is connected to. When traffic leaves a WARP-connected end-user device, it will hit a [Cloudflare data center](/support/troubleshooting/general-troubleshooting/gathering-information-for-troubleshooting-sites/#identify-the-cloudflare-data-center-serving-your-request).
+While IP visibility allows you to inspect a device's IP information, use [DEX's live analytics](/cloudflare-one/insights/dex/monitoring/#available-metrics) to review which Cloudflare data center the device is connected to. When traffic leaves a Cloudflare One Client-connected end-user device, it will hit a [Cloudflare data center](/support/troubleshooting/general-troubleshooting/gathering-information-for-troubleshooting-sites/#identify-the-cloudflare-data-center-serving-your-request).
To find which Cloudflare data center a device is connected to:
diff --git a/src/content/docs/cloudflare-one/insights/dex/monitoring.mdx b/src/content/docs/cloudflare-one/insights/dex/monitoring.mdx
index a71a87ba7c7..f0142e9dc95 100644
--- a/src/content/docs/cloudflare-one/insights/dex/monitoring.mdx
+++ b/src/content/docs/cloudflare-one/insights/dex/monitoring.mdx
@@ -13,7 +13,7 @@ Network and device performance data helps IT administrators troubleshoot perform
## Device overview
-A fleet is a collection of user devices. All devices in a fleet have WARP installed and are connected to a [Cloudflare Zero Trust organization](/cloudflare-one/setup/#create-a-zero-trust-organization).
+A fleet is a collection of user devices. All devices in a fleet have the Cloudflare One Client installed and are connected to a [Cloudflare Zero Trust organization](/cloudflare-one/setup/#create-a-zero-trust-organization).
To view fleet status:
@@ -30,26 +30,26 @@ To view analytics on a per-device level, go to [Device monitoring](/cloudflare-o
- **Devices connected by colo**: Number of devices connected to a given [Cloudflare data center](https://www.cloudflarestatus.com/).
-- **Connectivity status**: Percentage of devices in a given WARP client state.
+- **Connectivity status**: Percentage of devices in a given Cloudflare One Client state.
| Status | Description |
| ------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
- | Connected | WARP has successfully established a connection to the Cloudflare global network. |
- | Disconnected | WARP has been intentionally or unintentionally disconnected from the Cloudflare global network. |
+ | Connected | the Cloudflare One Client has successfully established a connection to the Cloudflare global network. |
+ | Disconnected | the Cloudflare One Client has been intentionally or unintentionally disconnected from the Cloudflare global network. |
| Paused | A user or administrator has taken an explicit action to temporarily turn off WARP, for example by entering an [admin override code](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/#allow-admin-override-codes). Paused clients will [auto-connect](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/#auto-connect) after a timeout period. |
- | Connecting | WARP is pending connection, but is actively trying to establish a connection to the Cloudflare global network. |
+ | Connecting | the Cloudflare One Client is pending connection, but is actively trying to establish a connection to the Cloudflare global network. |
-- **Mode**: [WARP mode](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/) deployed on the device.
+- **Mode**: [Client mode](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/) deployed on the device.
- **Colo**: Percentage of devices connected to a given Cloudflare data center.
- **Platform**: Operating system of the device.
-- **Major Version**: WARP client version installed on the device.
+- **Major Version**: Cloudflare One Client version installed on the device.
-- **Device Status Over Time**: WARP client connection status over the selected time period.
+- **Device Status Over Time**: Cloudflare One Client connection status over the selected time period.
-- **Connection Methods Over Time**: WARP mode used by the device over the selected time period.
+- **Connection Methods Over Time**: Client mode used by the device over the selected time period.
## Device monitoring
diff --git a/src/content/docs/cloudflare-one/insights/dex/tests/http.mdx b/src/content/docs/cloudflare-one/insights/dex/tests/http.mdx
index f6fec4a6d3b..a7910ac272c 100644
--- a/src/content/docs/cloudflare-one/insights/dex/tests/http.mdx
+++ b/src/content/docs/cloudflare-one/insights/dex/tests/http.mdx
@@ -8,11 +8,11 @@ sidebar:
import { Details, Render } from "~/components";
-| [WARP modes](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/) | [Zero Trust plans](https://www.cloudflare.com/teams-pricing/) |
+| [Client modes](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/) | [Zero Trust plans](https://www.cloudflare.com/teams-pricing/) |
| ------------------------------------------------------------------------------------------- | ------------------------------------------------------------- |
|
Traffic and DNS mode
Traffic only mode
| All plans |
-| System | Availability | Minimum WARP version |
+| System | Availability | Minimum client version |
| -------- | ------------ | -------------------- |
| Windows | ✅ | 2023.3.381 |
| macOS | ✅ | 2023.3.381 |
diff --git a/src/content/docs/cloudflare-one/insights/dex/tests/index.mdx b/src/content/docs/cloudflare-one/insights/dex/tests/index.mdx
index 7933b9036b4..16e33ac6db8 100644
--- a/src/content/docs/cloudflare-one/insights/dex/tests/index.mdx
+++ b/src/content/docs/cloudflare-one/insights/dex/tests/index.mdx
@@ -9,7 +9,7 @@ import { DirectoryListing, Render } from "~/components";
-DEX tests will only run when the WARP client is turned on, whereas [fleet status](/cloudflare-one/insights/dex/monitoring/#fleet-status) metrics are always available.
+DEX tests will only run when the Cloudflare One Client is turned on, whereas [fleet status](/cloudflare-one/insights/dex/monitoring/#fleet-status) metrics are always available.
To specify the target group of a test, use [DEX rules](/cloudflare-one/insights/dex/rules/).
diff --git a/src/content/docs/cloudflare-one/insights/dex/tests/traceroute.mdx b/src/content/docs/cloudflare-one/insights/dex/tests/traceroute.mdx
index fb955c1a677..49b828348c9 100644
--- a/src/content/docs/cloudflare-one/insights/dex/tests/traceroute.mdx
+++ b/src/content/docs/cloudflare-one/insights/dex/tests/traceroute.mdx
@@ -9,11 +9,11 @@ import { Details, Render } from "~/components";
-| [WARP modes](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/) | [Zero Trust plans](https://www.cloudflare.com/teams-pricing/) |
+| [Client modes](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/) | [Zero Trust plans](https://www.cloudflare.com/teams-pricing/) |
| ------------------------------------------------------------------------------------------- | ------------------------------------------------------------- |
|
Traffic and DNS mode
Traffic only mode
| All plans |
-| System | Availability | Minimum WARP version |
+| System | Availability | Minimum client version |
| -------- | ------------ | -------------------- |
| Windows | ✅ | 2023.5.587 |
| macOS | ✅ | 2023.5.589 |
@@ -36,7 +36,7 @@ To set up a traceroute test for an application:
4. Fill in the following fields:
- **Name**: Enter any name for the test.
- **Target**: Enter the IP address of the server you want to test (for example, `192.0.2.0`). You can test either a public-facing endpoint or a private endpoint you have connected to Cloudflare.
- - **Source device profiles**: (Optional) Select the [WARP device profiles](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-profiles/) that you want to run the test on. If no profiles are selected, the test will run on all supported devices connected to your Zero Trust organization.
+ - **Source device profiles**: (Optional) Select the [device profiles](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-profiles/) that you want to run the test on. If no profiles are selected, the test will run on all supported devices connected to your Zero Trust organization.
- **Test type**: Select _Traceroute_.
- **Test frequency**: Specify how often the test will run. Input a minute value between 5 and 60.
5. Select **Add test**.
diff --git a/src/content/docs/cloudflare-one/insights/logs/gateway-logs/index.mdx b/src/content/docs/cloudflare-one/insights/logs/gateway-logs/index.mdx
index ad55c84673c..855e48c5661 100644
--- a/src/content/docs/cloudflare-one/insights/logs/gateway-logs/index.mdx
+++ b/src/content/docs/cloudflare-one/insights/logs/gateway-logs/index.mdx
@@ -37,7 +37,7 @@ These settings will only apply to logs displayed in Cloudflare One. Logpush data
| --------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Query name** | Name of the domain that was queried. |
| **Query ID** | UUID of the query assigned by Cloudflare. |
-| **Email** | Email address of the user who registered the WARP client where traffic originated from. If a non-identity on-ramp (such as a [proxy endpoint](/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/)) or machine-level authentication (such as a [service token](/cloudflare-one/access-controls/service-credentials/service-tokens/)) was used, this value will be `non_identity@.cloudflareaccess.com`. |
+| **Email** | Email address of the user who registered the Cloudflare One Client where traffic originated from. If a non-identity on-ramp (such as a [proxy endpoint](/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/)) or machine-level authentication (such as a [service token](/cloudflare-one/access-controls/service-credentials/service-tokens/)) was used, this value will be `non_identity@.cloudflareaccess.com`. |
| **Action** | The [Action](/cloudflare-one/traffic-policies/dns-policies/#actions) Gateway applied to the query (such as Allow or Block). |
| **Time** | Date and time of the DNS query. |
| **Resolver decision** | The reason why Gateway applied a particular **Action** to the request. Refer to the [list of resolver decisions](#resolver-decisions). |
@@ -59,11 +59,11 @@ These settings will only apply to logs displayed in Cloudflare One. Logpush data
| Field | Description |
| ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
-| **Email** | Email address of the user who registered the WARP client where traffic originated from. |
+| **Email** | Email address of the user who registered the Cloudflare One Client where traffic originated from. |
| **User ID** | UUID of the user. Each unique email address in your organization will have a UUID associated with it. |
-| **Registration ID** | UUID of the user's WARP client registration. A unique registration ID is generated each time a device is registered for a particular email. The same physical device may have multiple registration IDs. |
+| **Registration ID** | UUID of the user's Cloudflare One Client registration. A unique registration ID is generated each time a device is registered for a particular email. The same physical device may have multiple registration IDs. |
| **Device name** | Display name of the device returned by the operating system to the WARP client. Typically this is the hostname of a device. Not all devices will have a device name. Device names are not guaranteed to be unique. |
-| **Device ID** | UUID of the device connected with the WARP client. Each physical device in your organization will have a UUID. |
+| **Device ID** | UUID of the device connected with the Cloudflare One Client. Each physical device in your organization will have a UUID. |
| **Last authenticated** | Date and time the user last authenticated their Zero Trust session. |
#### DNS query details
@@ -156,11 +156,11 @@ Gateway can log failed connections in [network session logs](/logs/logpush/logpu
| Field | Description |
| ---------------------- | ------------------------------------------------------------------------------------- |
-| **Email** | Email address of the user sending the packet. This is generated by the WARP client. |
-| **User ID** | ID of the user sending the packet. This is generated by the WARP client. |
-| **Registration ID** | ID of the user's device registration. This is generated by the WARP client. |
+| **Email** | Email address of the user sending the packet. This is generated by the Cloudflare One Client. |
+| **User ID** | ID of the user sending the packet. This is generated by the Cloudflare One Client. |
+| **Registration ID** | ID of the user's device registration. This is generated by the Cloudflare One Client. |
| **Device name** | Name of the device that sent the packet. |
-| **Device ID** | ID of the physical device that sent the packet. This is generated by the WARP client. |
+| **Device ID** | ID of the physical device that sent the packet. This is generated by the Cloudflare One Client. |
| **Last authenticated** | Date and time the user last authenticated with Zero Trust. |
#### Network query details
@@ -200,7 +200,7 @@ When an HTTP request results in an error, Gateway logs the first 512 bytes of th
| Field | Description |
| ---------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Host** | Hostname in the HTTP header for the HTTP request. Gateway will log the SNI in this field if it responded to the request with a Do Not Inspect action. If Gateway does not receive the SNI, this field will be empty. |
-| **Email** | Email address of the user who made the HTTP request. This is generated by the WARP client. |
+| **Email** | Email address of the user who made the HTTP request. This is generated by the Cloudflare One Client. |
| **Action** | The Gateway [Action](/cloudflare-one/traffic-policies/dns-policies/#actions) taken based on the first rule that matched (such as Allow or Block). |
| **Request ID** | Unique ID of the request. |
| **Time** | Date and time of the HTTP request. |
@@ -226,11 +226,11 @@ When an HTTP request results in an error, Gateway logs the first 512 bytes of th
| Field | Description |
| ---------------------- | ----------------------------------------------------------------------------------------------------------------------------- |
-| **Email** | Email address of the user who made the HTTP request. This is generated by the WARP client. |
-| **User ID** | ID of the user who made the request. This is generated by the WARP client. |
-| **Registration ID** | ID of the user's device registration. This is generated by the WARP client. |
+| **Email** | Email address of the user who made the HTTP request. This is generated by the Cloudflare One Client. |
+| **User ID** | ID of the user who made the request. This is generated by the Cloudflare One Client. |
+| **Registration ID** | ID of the user's device registration. This is generated by the Cloudflare One Client. |
| **Device name** | Name of the device that made the request. |
-| **Device ID** | ID of the physical device that made the request. This is generated by the WARP client on the device that created the request. |
+| **Device ID** | ID of the physical device that made the request. This is generated by the Cloudflare One Client on the device that created the request. |
| **Last authenticated** | Date and time the user last authenticated with Zero Trust. |
#### HTTP query details
diff --git a/src/content/docs/cloudflare-one/insights/logs/logpush.mdx b/src/content/docs/cloudflare-one/insights/logs/logpush.mdx
index 7f0a480e6ca..692855053bc 100644
--- a/src/content/docs/cloudflare-one/insights/logs/logpush.mdx
+++ b/src/content/docs/cloudflare-one/insights/logs/logpush.mdx
@@ -47,15 +47,15 @@ Refer to [Logpush datasets](/logs/logpush/logpush-job/datasets/) for a list of a
| [Audit Logs](/logs/logpush/logpush-job/datasets/account/audit_logs/) | Authentication events through Cloudflare Access |
| [Browser Isolation User Actions](/logs/logpush/logpush-job/datasets/account/biso_user_actions/) | Data transfer actions performed by a user in the remote browser |
| [CASB Findings](/logs/logpush/logpush-job/datasets/account/casb_findings/) | Security issues detected by Cloudflare CASB |
-| [Device Posture Results](/logs/logpush/logpush-job/datasets/account/device_posture_results/) | Device posture status from the WARP client |
-| [DEX Application Tests](/logs/logpush/logpush-job/datasets/account/dex_application_tests/) | Device application synthetic test results from the WARP client |
-| [DEX Device State Events](/logs/logpush/logpush-job/datasets/account/dex_device_state_events/) | Device event data like connectivity, CPU usage, and Disk I/O from the WARP client |
+| [Device Posture Results](/logs/logpush/logpush-job/datasets/account/device_posture_results/) | Device posture status from the Cloudflare One Client |
+| [DEX Application Tests](/logs/logpush/logpush-job/datasets/account/dex_application_tests/) | Device application synthetic test results from the Cloudflare One Client |
+| [DEX Device State Events](/logs/logpush/logpush-job/datasets/account/dex_device_state_events/) | Device event data like connectivity, CPU usage, and Disk I/O from the Cloudflare One Client |
| [Gateway DNS](/logs/logpush/logpush-job/datasets/account/gateway_dns/) | DNS queries inspected by Cloudflare Gateway |
| [Gateway HTTP](/logs/logpush/logpush-job/datasets/account/gateway_http/) | HTTP requests inspected by Cloudflare Gateway |
| [Gateway Network](/logs/logpush/logpush-job/datasets/account/gateway_network/) | Network packets inspected by Cloudflare Gateway |
| [SSH Logs](/logs/logpush/logpush-job/datasets/account/ssh_logs/) | SSH command logs for [Access for Infrastructure targets](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-infrastructure-access/) |
-| [WARP Config Changes](/logs/logpush/logpush-job/datasets/account/warp_config_changes/) | Event logs that Cloudflare generates whenever a WARP device changes [profiles](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-profiles/) |
-| [WARP Toggle Events](/logs/logpush/logpush-job/datasets/account/warp_toggle_changes/) | Event logs that Cloudflare generates whenever a WARP device toggles WARP on or off |
+| [WARP Config Changes](/logs/logpush/logpush-job/datasets/account/warp_config_changes/) | Event logs that Cloudflare generates whenever a device changes [profiles](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-profiles/) |
+| [WARP Toggle Events](/logs/logpush/logpush-job/datasets/account/warp_toggle_changes/) | Event logs that Cloudflare generates whenever a device toggles the Cloudflare One Client on or off |
| [Zero Trust Network Session Logs](/logs/logpush/logpush-job/datasets/account/zero_trust_network_sessions/) | Network session logs for traffic proxied by Cloudflare Gateway |
## Verify regional map application
diff --git a/src/content/docs/cloudflare-one/insights/logs/posture-logs.mdx b/src/content/docs/cloudflare-one/insights/logs/posture-logs.mdx
index ddcdbaa8a45..c4ebe602293 100644
--- a/src/content/docs/cloudflare-one/insights/logs/posture-logs.mdx
+++ b/src/content/docs/cloudflare-one/insights/logs/posture-logs.mdx
@@ -6,7 +6,7 @@ sidebar:
---
-Posture logs show the [device posture check](/cloudflare-one/reusable-components/posture-checks/) results reported by the WARP client.
+Posture logs show the [device posture check](/cloudflare-one/reusable-components/posture-checks/) results reported by the Cloudflare One Client.
To view device posture logs, log in to [Cloudflare One](https://one.dash.cloudflare.com/) and go to **Logs** > **Posture**. Logs will only display if you have configured [device posture checks](/cloudflare-one/reusable-components/posture-checks/) for your Zero Trust organization.
@@ -19,7 +19,7 @@ Enterprise users can generate more detailed logs with [Logpush](/cloudflare-one/
| Field | Description |
| ----------------- | ---------------------------- |
| **Name** | Name of the device. |
-| **ID** | Device ID generated by the WARP client. |
+| **ID** | Device ID generated by the Cloudflare One Client. |
| **Serial number** | Serial number of the device. |
| **Manufacturer** | Manufacturer of the device. |
| **Model** | Model of the device. |
@@ -30,15 +30,15 @@ Enterprise users can generate more detailed logs with [Logpush](/cloudflare-one/
| ----------- | -------------------------------------------------- |
| **Email** | Email used to register the device with Zero Trust. |
| **User ID** | UUID of the user who registered the device. |
-| **Registration ID** | UUID of the user's WARP client registration. |
+| **Registration ID** | UUID of the user's Cloudflare One Client registration. |
### Posture details
| Field | Description |
| ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Name** | Name of the [device posture check](/cloudflare-one/reusable-components/posture-checks/). |
-| **Type** | Type of [WARP client check](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/) or [service provider check](/cloudflare-one/integrations/service-providers/). |
+| **Type** | Type of [Cloudflare One Client check](/cloudflare-one/reusable-components/posture-checks/client-checks/) or [service provider check](/cloudflare-one/integrations/service-providers/). |
| **Rule ID** | UUID of the device posture check. |
| **Conditions met** | Whether the device passed or failed the posture check criteria. Evaluates to `true` if the **Received values** match the **Expected values**. |
| **Expected values** | Values required to pass the device posture check. |
-| **Received values** | Posture check values detected by the WARP client. |
+| **Received values** | Posture check values detected by the Cloudflare One Client. |
diff --git a/src/content/docs/cloudflare-one/integrations/identity-providers/okta-saml.mdx b/src/content/docs/cloudflare-one/integrations/identity-providers/okta-saml.mdx
index 81de0198531..6871fc77a8f 100644
--- a/src/content/docs/cloudflare-one/integrations/identity-providers/okta-saml.mdx
+++ b/src/content/docs/cloudflare-one/integrations/identity-providers/okta-saml.mdx
@@ -83,7 +83,7 @@ To test that your connection is working, go to **Integrations** > **Identity pro
:::caution
-SAML attributes are only refreshed during authentications with the Okta identity provider. This means the Okta group membership is not updated unless a user logs in and out of the WARP client, or logs in to an Access application.
+SAML attributes are only refreshed during authentications with the Okta identity provider. This means the Okta group membership is not updated unless a user logs in and out of the Cloudflare One Client, or logs in to an Access application.
:::
diff --git a/src/content/docs/cloudflare-one/integrations/service-providers/custom.mdx b/src/content/docs/cloudflare-one/integrations/service-providers/custom.mdx
index 09acb9348dd..f7be6052c18 100644
--- a/src/content/docs/cloudflare-one/integrations/service-providers/custom.mdx
+++ b/src/content/docs/cloudflare-one/integrations/service-providers/custom.mdx
@@ -29,7 +29,7 @@ The custom service provider integration works with any API service that meets th
### Authentication
-The WARP client authenticates to the external API through Cloudflare Access. The external API should [validate the application token](/cloudflare-one/access-controls/applications/http-apps/authorization-cookie/validating-json/) issued by Cloudflare Access to ensure that any requests which bypass Access (for example, due to a network misconfiguration) are rejected.
+The Cloudflare One Client authenticates to the external API through Cloudflare Access. The external API should [validate the application token](/cloudflare-one/access-controls/applications/http-apps/authorization-cookie/validating-json/) issued by Cloudflare Access to ensure that any requests which bypass Access (for example, due to a network misconfiguration) are rejected.
### Data passed to external API
@@ -37,8 +37,8 @@ Cloudflare will pass the following parameters to the configured API endpoint. Yo
| Field | Description |
| --------------- | -------------------------------------------------- |
-| `device_id` | Device UUID assigned by the WARP client |
-| `email` | Email address used to authenticate the WARP client |
+| `device_id` | Device UUID assigned by the Cloudflare One Client |
+| `email` | Email address used to authenticate the Cloudflare One Client |
| `serial_number` | Device serial number |
| `mac_address` | Device MAC address |
| `virtual_ipv4` | Device virtual IPv4 address |
@@ -103,7 +103,7 @@ WARP uses an Access Client ID and Access Client Secret to securely authenticate
### 2. Create an Access application
-Next, secure the external API behind Cloudflare Access so that WARP can authenticate with the service token. To add the API endpoint to Access:
+Next, secure the external API behind Cloudflare Access so that the Cloudflare One Client can authenticate with the service token. To add the API endpoint to Access:
1. [Create a self-hosted application](/cloudflare-one/access-controls/applications/http-apps/self-hosted-public-app/) for your API endpoint.
2. Add the following Access policy to the application. Make sure that **Action** is set to _Service Auth_ (not _Allow_).
diff --git a/src/content/docs/cloudflare-one/integrations/service-providers/index.mdx b/src/content/docs/cloudflare-one/integrations/service-providers/index.mdx
index 527963c5477..fccd50fcd7f 100644
--- a/src/content/docs/cloudflare-one/integrations/service-providers/index.mdx
+++ b/src/content/docs/cloudflare-one/integrations/service-providers/index.mdx
@@ -5,9 +5,9 @@ sidebar:
order: 3
---
-Service-to-service integrations allow the WARP client to get device posture data from a third-party API. To use this feature, you must [deploy the WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/) to your devices and enable the desired posture checks.
+Service-to-service integrations allow the Cloudflare One Client to get device posture data from a third-party API. To use this feature, you must [deploy the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/) to your devices and enable the desired posture checks.
-## Supported WARP modes
+## Supported Client modes
- Traffic and DNS mode
- Traffic only mode
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/configure-tunnels/tunnel-availability/index.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/configure-tunnels/tunnel-availability/index.mdx
index 7970e11ca14..bbc2e6c494b 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/configure-tunnels/tunnel-availability/index.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/configure-tunnels/tunnel-availability/index.mdx
@@ -70,7 +70,7 @@ For setup instructions, refer to [Public load balancers](/cloudflare-one/network
There are two types of load balancers that you can use with Cloudflare Tunnel endpoints:
- [Public load balancers](/cloudflare-one/networks/connectors/cloudflare-tunnel/routing-to-tunnel/public-load-balancers/) steer traffic from the Internet to applications published on a Cloudflare domain. Use this method if your service is served by Cloudflare Tunnel via a [published application route](/cloudflare-one/networks/connectors/cloudflare-tunnel/get-started/create-remote-tunnel/#2a-publish-an-application).
-- [Private load balancers](/load-balancing/private-network/) steer traffic from WARP clients, Cloudflare WAN, and other on-ramps to an internal IP on your private network. Use this method if your service is connected to Cloudflare Tunnel via a [CIDR route](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/connect-cidr/).
+- [Private load balancers](/load-balancing/private-network/) steer traffic from Cloudflare One Clients, Cloudflare WAN, and other on-ramps to an internal IP on your private network. Use this method if your service is connected to Cloudflare Tunnel via a [CIDR route](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/connect-cidr/).
:::note
[Private hostname routes](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/connect-private-hostname/) are not currently compatible with Load Balancing. If your service is connected via a hostname route, use `cloudflared` [replicas](#cloudflared-replicas) for high availability.
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/configure-tunnels/tunnel-availability/system-requirements.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/configure-tunnels/tunnel-availability/system-requirements.mdx
index 8ca0764a28d..d787a2afb78 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/configure-tunnels/tunnel-availability/system-requirements.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/configure-tunnels/tunnel-availability/system-requirements.mdx
@@ -17,11 +17,11 @@ For most use cases, we recommend the following baseline configuration:
- Size each host with minimum 4GB of RAM and 4 CPU cores.
- Allocate 50,000 [ports](#number-of-ports) to the `cloudflared` process on each host.
-This setup is usually sufficient to handle traffic from 8,000 WARP users (4,000 per host). The actual amount of resources used by `cloudflared` will depend on many variables, including the number of requests per second, bandwidth, network path and hardware. As additional users are onboarded, or if network traffic increases beyond your existing [tunnel capacity](#estimated-throughput), you can scale your tunnel by adding an additional `cloudflared` host in that location.
+This setup is usually sufficient to handle traffic from 8,000 Cloudflare One Client users (4,000 per host). The actual amount of resources used by `cloudflared` will depend on many variables, including the number of requests per second, bandwidth, network path and hardware. As additional users are onboarded, or if network traffic increases beyond your existing [tunnel capacity](#estimated-throughput), you can scale your tunnel by adding an additional `cloudflared` host in that location.
### Number of ports
-When `cloudflared` receives a request from a WARP device, it uses the ports on the host machine to evaluate and forward the request to your origin service. Every machine by system design is hardware-limited to a maximum 65,535 ports. Additionally, each service on the machine has a limited number of ports that it can consume. For this reason, we recommend the following deployment model:
+When `cloudflared` receives a request from a device, it uses the ports on the host machine to evaluate and forward the request to your origin service. Every machine by system design is hardware-limited to a maximum 65,535 ports. Additionally, each service on the machine has a limited number of ports that it can consume. For this reason, we recommend the following deployment model:
- `cloudflared` should be deployed on a dedicated host machine. This model is typically appropriate, but there may be serverless or clustered workflows where a dedicated host is not possible.
- The host machine should allocate 50,000 ports to be available for use by the `cloudflared` service. The remaining ports are reserved for system administrative processes.
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/deployment-guides/aws.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/deployment-guides/aws.mdx
index 85b60ed4891..8049ca824e6 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/deployment-guides/aws.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/deployment-guides/aws.mdx
@@ -26,7 +26,7 @@ We will deploy:
To complete the following procedure, you will need to:
- [Add a website to Cloudflare](/fundamentals/manage-domains/add-site/)
-- [Deploy the WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/manual-deployment/) on an end-user device
+- [Deploy the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/manual-deployment/) on an end-user device
## 1. Create a VM instance in AWS
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/deployment-guides/azure.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/deployment-guides/azure.mdx
index cf4595bb9ea..c0cf544bfe2 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/deployment-guides/azure.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/deployment-guides/azure.mdx
@@ -26,7 +26,7 @@ We will deploy:
To complete the following procedure, you will need to:
- [Add a website to Cloudflare](/fundamentals/manage-domains/add-site/)
-- [Deploy the WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/manual-deployment/) on an end-user device
+- [Deploy the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/manual-deployment/) on an end-user device
## 1. Create a VM instance in Azure
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/deployment-guides/google-cloud-platform.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/deployment-guides/google-cloud-platform.mdx
index f63156986a7..30ba9db5983 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/deployment-guides/google-cloud-platform.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/deployment-guides/google-cloud-platform.mdx
@@ -23,7 +23,7 @@ We will deploy:
To complete the following procedure, you will need to:
- [Add a website to Cloudflare](/fundamentals/manage-domains/add-site/)
-- [Deploy the WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/manual-deployment/) on an end-user device
+- [Deploy the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/manual-deployment/) on an end-user device
## 1. Create a VM instance in GCP
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/do-more-with-tunnels/local-management/tunnel-useful-commands.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/do-more-with-tunnels/local-management/tunnel-useful-commands.mdx
index 83ba2b7f879..916dde9b69b 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/do-more-with-tunnels/local-management/tunnel-useful-commands.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/do-more-with-tunnels/local-management/tunnel-useful-commands.mdx
@@ -30,9 +30,9 @@ import { Render } from "~/components";
| Command | Description |
| ---------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
-| `cloudflared tunnel route ip add ` | Adds any network route space (represented as a CIDR) to your routing table. That network space becomes reachable for requests egressing from a user's machine as long as it is using Cloudflare WARP and is enrolled in the same account that is running the tunnel chosen here. Further, those requests will be proxied to the specified tunnel, and reach an IP in the given CIDR, as long as that IP is reachable from the tunnel. To assign the IP route to a specific [Virtual Network](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/tunnel-virtual-networks/), use the `--vnet` option. |
+| `cloudflared tunnel route ip add ` | Adds any network route space (represented as a CIDR) to your routing table. That network space becomes reachable for requests egressing from a user's machine as long as it is using the Cloudflare One Client and is enrolled in the same account that is running the tunnel chosen here. Further, those requests will be proxied to the specified tunnel, and reach an IP in the given CIDR, as long as that IP is reachable from the tunnel. To assign the IP route to a specific [Virtual Network](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/tunnel-virtual-networks/), use the `--vnet` option. |
| `cloudflared tunnel route ip show` (or `list`) | Shows your organization's private routing table. You can use additional flags to filter the results. |
-| `cloudflared tunnel route ip delete` | Deletes the row for a given CIDR from your routing table. That portion of your network will no longer be reachable by the WARP client. |
+| `cloudflared tunnel route ip delete` | Deletes the row for a given CIDR from your routing table. That portion of your network will no longer be reachable by the Cloudflare One Client. |
| `cloudflared tunnel route ip get ` | Checks which row of the routing table will be used to proxy a given IP. This helps check and validate your configuration. |
| `cloudflared tunnel vnet add ` | Creates a Virtual Network to which IP routes can be assigned. To make this Virtual Network the default for your Zero Trust organization, use the `-d` flag. |
| `cloudflared tunnel vnet delete ` | Deletes the Virtual Network with the given name or UUID. Before you can delete a Virtual Network, you must first delete all IP routes assigned to the Virtual Network. |
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/get-started/tunnel-useful-terms.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/get-started/tunnel-useful-terms.mdx
index 5c8010efb68..0b9a244afab 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/get-started/tunnel-useful-terms.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/get-started/tunnel-useful-terms.mdx
@@ -41,4 +41,4 @@ Quick tunnels, when run, will generate a URL that consists of a random subdomain
## Virtual networks
-A [virtual network](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/tunnel-virtual-networks/) is a software abstraction that allows you to logically segregate resources on your private network. Virtual networks are especially useful for exposing resources which have overlapping IP routes. To connect to a resource, end users would select a virtual network in their WARP client settings before entering the destination IP.
+A [virtual network](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/tunnel-virtual-networks/) is a software abstraction that allows you to logically segregate resources on your private network. Virtual networks are especially useful for exposing resources which have overlapping IP routes. To connect to a resource, end users would select a virtual network in their Cloudflare One Client settings before entering the destination IP.
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/connect-cidr.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/connect-cidr.mdx
index 743d2165d2b..8084d7dedb6 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/connect-cidr.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/connect-cidr.mdx
@@ -29,7 +29,7 @@ To connect your infrastructure with Cloudflare Tunnel:
-## 3. Route private network IPs through WARP
+## 3. Route private network IPs through the Cloudflare One Client
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/connect-private-hostname.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/connect-private-hostname.mdx
index 01c06af968d..da4dea5c064 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/connect-private-hostname.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/connect-private-hostname.mdx
@@ -36,7 +36,7 @@ Private hostname routing only works for applications connected with `cloudflared
| Connector | Compatibility | Minimum version |
| ------------------------------------------------------------------------------------------ | ------------- | -- |
| [cloudflared](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/) | ✅ | 2025.7.0 |
-| [WARP-to-WARP](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp/) | ❌ | |
+| [Peer-to-peer](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp/) | ❌ | |
| [WARP Connector](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/) | ❌ | |
| [Cloudflare WAN](/cloudflare-wan/zero-trust/cloudflare-gateway/) | ❌ | |
@@ -54,7 +54,7 @@ To connect to private hostnames, your devices must forward the following traffic
Configuration steps vary depending on your [device on-ramp](#device-connectivity):
-
+
1.
2. In [Local Domain Fallback](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/local-domains/), delete the top-level domain for your private hostname. This configures WARP to send the DNS query to Cloudflare Gateway for resolution.
@@ -148,7 +148,7 @@ If you prefer to secure the application using a traditional firewall model, you
product="cloudflare-one"
/>
-Additionally, SNI selectors will only apply to WARP client traffic. If your users will be connecting from other [on-ramps](#device-connectivity), you can allow or block network traffic using the [Destination IP](/cloudflare-one/traffic-policies/network-policies/#destination-ip) selector instead of SNI.
+Additionally, SNI selectors will only apply to Cloudflare One Client traffic. If your users will be connecting from other [on-ramps](#device-connectivity), you can allow or block network traffic using the [Destination IP](/cloudflare-one/traffic-policies/network-policies/#destination-ip) selector instead of SNI.
:::
### 4. Test the connection
@@ -159,7 +159,7 @@ End users can now reach the application by going to its private hostname. For ex
If you cannot connect, verify the following:
-1. **Confirm DNS resolution** - From the WARP device, confirm that you can successfully resolve the private hostname:
+1. **Confirm DNS resolution** - From the device, confirm that you can successfully resolve the private hostname:
```sh
nslookup wiki.internal.local
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/index.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/index.mdx
index a22213ad62f..87b37b43ef2 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/index.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/index.mdx
@@ -10,7 +10,7 @@ sidebar:
`cloudflared` is a daemon service that can run on nearly any host machine in your private network and proxies local traffic once validated from the Cloudflare network. The Cloudflare Tunnel created by `cloudflared` is outbound-only, meaning that it will only proxy requests initiated from a user to your private network. Requests made by a service or application running behind the tunnel will use the server's default routing table.
-On the client side, end users connect to Cloudflare's global network using the Cloudflare WARP client. The WARP client can be rolled out to your entire organization in just a few minutes using your in-house MDM tooling. When users connect to an IP address or hostname made available through Cloudflare Tunnel, WARP sends their connection through Cloudflare's network and down the corresponding tunnel to the internal service. Traffic to services behind the tunnel will carry the local source IP address of the host machine running the `cloudflared` daemon.
+On the client side, end users connect to Cloudflare's global network using the Cloudflare One Client. The Cloudflare One Client can be rolled out to your entire organization in just a few minutes using your in-house MDM tooling. When users connect to an IP address or hostname made available through Cloudflare Tunnel, WARP sends their connection through Cloudflare's network and down the corresponding tunnel to the internal service. Traffic to services behind the tunnel will carry the local source IP address of the host machine running the `cloudflared` daemon.

diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/private-dns.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/private-dns.mdx
index a508eca5b9d..33c8a14e0d1 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/private-dns.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/private-dns.mdx
@@ -27,14 +27,14 @@ To resolve private DNS queries:
3. Route specific DNS queries to your internal DNS resolver using one of the following options:
- - [Create a Local Domain Fallback entry](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/local-domains/) that points to the internal DNS resolver. For example, you can instruct the WARP client to resolve all requests for `myorg.privatecorp` through an internal resolver at `10.0.0.25` rather than attempting to resolve this publicly.
+ - [Create a Local Domain Fallback entry](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/local-domains/) that points to the internal DNS resolver. For example, you can instruct the Cloudflare One Client to resolve all requests for `myorg.privatecorp` through an internal resolver at `10.0.0.25` rather than attempting to resolve this publicly.
- Alternatively, [create a resolver policy](/cloudflare-one/traffic-policies/resolver-policies/#create-a-resolver-policy) that points to the internal DNS resolver.
4. [Enable the Gateway proxy](/cloudflare-one/traffic-policies/proxy/#turn-on-the-gateway-proxy) for TCP and UDP.
5. Finally, ensure that your tunnel uses QUIC as the default [transport protocol](/cloudflare-one/networks/connectors/cloudflare-tunnel/configure-tunnels/run-parameters/#protocol). This will enable `cloudflared` to proxy UDP-based traffic which is required in most cases to resolve DNS queries.
-The WARP client will now send DNS queries to your internal DNS resolver for resolution. To learn more, refer to [How the WARP client handles DNS requests](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/#how-the-warp-client-handles-dns-requests).
+The Cloudflare One Client will now send DNS queries to your internal DNS resolver for resolution. To learn more, refer to [How the Cloudflare One Client handles DNS requests](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/#how-the-warp-client-handles-dns-requests).
## Test the setup
@@ -50,7 +50,7 @@ The `dig` command will work because `myorg.privatecorp` was configured above as
dig @10.0.0.25 AAAA www.myorg.privatecorp
```
-Both `dig` commands will fail if the WARP client is disabled on your end user's device.
+Both `dig` commands will fail if the Cloudflare One Client is disabled on your end user's device.
## Troubleshooting
@@ -62,7 +62,7 @@ Use the following troubleshooting strategies if you are running into issues whil
- Ensure that the machine where `cloudflared` is running is allowed to egress via UDP to port 7844 to talk out to Cloudflare.
-- Ensure that end-user devices are enrolled into WARP by visiting [https://help.teams.cloudflare.com](https://help.teams.cloudflare.com).
+- Ensure that end-user devices are enrolled into the Cloudflare One Client by visiting [https://help.teams.cloudflare.com](https://help.teams.cloudflare.com).
- Double-check the [order of precedence](/cloudflare-one/traffic-policies/order-of-enforcement/#order-of-precedence) for your [Gateway network policies](/cloudflare-one/traffic-policies/network-policies/). Ensure that a more global Block or Allow policy will not supersede application-specific policies.
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/tunnel-virtual-networks.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/tunnel-virtual-networks.mdx
index 3dd07fdde46..53e8d1f239a 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/tunnel-virtual-networks.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/tunnel-virtual-networks.mdx
@@ -11,7 +11,7 @@ import { Details, Render, Tabs, TabItem } from "~/components";
-| [WARP modes](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/) | [Zero Trust plans](https://www.cloudflare.com/teams-pricing/) |
+| [Client modes](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/) | [Zero Trust plans](https://www.cloudflare.com/teams-pricing/) |
| ---------------------------------------------------------------------------------------- | ------------------------------------------------------------- |
|
Traffic and DNS mode
Traffic only mode
| All plans |
@@ -41,7 +41,7 @@ Here are a few scenarios where virtual networks may prove useful:
## Prerequisites
- [Install `cloudflared`](/cloudflare-one/networks/connectors/cloudflare-tunnel/downloads/) on each private network.
-- [Deploy the WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/) on user devices.
+- [Deploy the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/) on user devices.
## Create a virtual network
@@ -69,7 +69,7 @@ In this example, "private network" refers to a distinct environment (such as sta
7. Save the tunnel.
8. Repeat Steps 2a-2g to create another tunnel called `Production tunnel`. Be sure to install the connector within your production environment and assign the route to *production-vnet*.
- We now have two overlapping IP addresses routed over `staging-vnet` and `production-vnet` respectively. You can use the Cloudflare WARP client to [switch between virtual networks](#connect-to-a-virtual-network).
+ We now have two overlapping IP addresses routed over `staging-vnet` and `production-vnet` respectively. You can use the Cloudflare One Client to [switch between virtual networks](#connect-to-a-virtual-network).
@@ -219,7 +219,7 @@ In this example, "private network" refers to a distinct environment (such as sta
8. Within your production environment, repeat Steps 6 and 7 for `production-tunnel`.
- You can use now the Cloudflare WARP client to [switch between virtual networks](#connect-to-a-virtual-network).
+ You can use now the Cloudflare One Client to [switch between virtual networks](#connect-to-a-virtual-network).
@@ -282,14 +282,14 @@ In this example, "private network" refers to a distinct environment (such as sta
-1. Open the WARP client.
+1. Open the Cloudflare One Client.
2. Go to **Settings** > **Traffic and DNS mode** > **Virtual Networks**.
3. Choose the virtual network you want to connect to, for example `staging-vnet`.
-When you visit `10.128.0.3/32`, WARP will route your request to the staging environment.
+When you visit `10.128.0.3/32`, the Cloudflare One Client will route your request to the staging environment.
### iOS, Android, and ChromeOS
@@ -297,4 +297,4 @@ When you visit `10.128.0.3/32`, WARP will route your request to the staging envi
2. Go to **Advanced** > **Connection options** > **Virtual networks**.
3. Choose the virtual network you want to connect to, for example `staging-vnet`.
-When you visit `10.128.0.3/32`, WARP will route your request to the staging environment.
+When you visit `10.128.0.3/32`, the Cloudflare One Client will route your request to the staging environment.
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/index.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/index.mdx
index 3745cf6a583..b335147d92c 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/index.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/index.mdx
@@ -9,7 +9,7 @@ sidebar:
With Cloudflare Zero Trust, you can connect private networks and the services running in those networks to Cloudflare's global network. This involves installing a [connector](#connectors) on the private network, and then [setting up routes](/cloudflare-one/networks/connectors/cloudflare-tunnel/get-started/create-remote-tunnel/#2b-connect-a-network) which define the IP addresses available in that environment. Unlike [published applications](/cloudflare-one/networks/connectors/cloudflare-tunnel/routing-to-tunnel/), private network routes can expose both HTTP and non-HTTP resources.
-To reach private network IPs, end users must connect their device to Cloudflare and enroll in your Zero Trust organization. The most common method is to install the [WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) on their device, or you can onboard their network traffic to Cloudflare using our [WARP Connector](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/) or [Cloudflare WAN](/cloudflare-wan/zero-trust/cloudflare-tunnel/).
+To reach private network IPs, end users must connect their device to Cloudflare and enroll in your Zero Trust organization. The most common method is to install the [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) on their device, or you can onboard their network traffic to Cloudflare using our [WARP Connector](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/) or [Cloudflare WAN](/cloudflare-wan/zero-trust/cloudflare-tunnel/).
Administrators can optionally set [Gateway network policies](/cloudflare-one/traffic-policies/network-policies/) to control access to services based on user identity and device posture.
@@ -18,6 +18,6 @@ Administrators can optionally set [Gateway network policies](/cloudflare-one/tra
Here are the different ways you can connect your private network to Cloudflare:
- [**cloudflared**](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/) installs on a server in your private network to create a secure, outbound tunnel to Cloudflare. Cloudflare Tunnel using `cloudflared` only proxies traffic initiated from a user to a server. Any service or application running behind the tunnel will use the server's default routing table for server-initiated connectivity.
-- [**WARP-to-WARP**](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp/) uses the [Cloudflare WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) to establish peer-to-peer connectivity between two or more devices. Each device running WARP can access services on any other device running WARP via an assigned virtual IP address.
+- [**Peer-to-peer**](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp/) uses the [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) to establish peer-to-peer connectivity between two or more devices. Each device running the Cloudflare One Client can access services on any other device running the Cloudflare One Client via an assigned virtual IP address.
- [**WARP Connector**](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/) installs on a Linux server in your private network to establish site-to-site, bidirectional, and mesh networking connectivity. The WARP Connector acts as a subnet router to relay client-initiated and server-initiated traffic between all devices on a private network and Cloudflare.
- [**Cloudflare WAN**](/cloudflare-one/networks/connectors/cloudflare-wan/) relies on configuring legacy networking equipment to establish anycast GRE or IPsec tunnels between an entire network location and Cloudflare.
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/index.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/index.mdx
index ef50c14bfff..622e169664c 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/index.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/index.mdx
@@ -15,7 +15,7 @@ import { Render, Details } from "~/components";
-| [WARP modes](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/) | [Zero Trust plans](https://www.cloudflare.com/teams-pricing/) |
+| [Client modes](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/) | [Zero Trust plans](https://www.cloudflare.com/teams-pricing/) |
| ---------------------------------------------------------------------------------------- | ------------------------------------------------------------- |
| Traffic and DNS mode | All plans |
@@ -34,7 +34,7 @@ import { Render, Details } from "~/components";
Accounts on Legacy routing mode do not support WARP Connector when [Cloudflare WAN](/cloudflare-wan/) (formerly Magic WAN) is enabled. Your account needs to be on Unified Routing (beta) for this to be supported. Contact your account team for more information.
:::
-Cloudflare WARP Connector (beta) is a software client[^1] that enables site-to-site, bidirectional, and mesh networking connectivity without requiring changes to underlying network routing infrastructure. WARP Connector establishes a secure Layer 3 proxy between a private network and Cloudflare, allowing you to:
+the Cloudflare One Client Connector (beta) is a software client[^1] that enables site-to-site, bidirectional, and mesh networking connectivity without requiring changes to underlying network routing infrastructure. WARP Connector establishes a secure Layer 3 proxy between a private network and Cloudflare, allowing you to:
- Connect two or more private networks to each other.
- Connect IoT devices that cannot run external software, such as printers and IP phones.
@@ -49,7 +49,7 @@ To set up WARP Connector, refer to the guide for your use case:
- **[Site-to-Internet](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/site-to-internet/)**: Send requests from your private network to the Internet.
- **[Site-to-site](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/site-to-site/)**: Send requests between two or more private networks.
-- **[User-to-site](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/user-to-site/)**: Allow WARP client devices to send requests to your private network.
+- **[User-to-site](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/user-to-site/)**: Allow Cloudflare One Client devices to send requests to your private network.
- **Internet-to-site**: Not supported by WARP Connector. To provide clientless access to applications on your private network, set up a [Cloudflare Tunnel with `cloudflared`](/cloudflare-one/networks/connectors/cloudflare-tunnel/get-started/create-remote-tunnel/) and configure a [published application](/cloudflare-one/networks/connectors/cloudflare-tunnel/routing-to-tunnel/).
-[^1]: WARP Connector is an extension of the [WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/).
+[^1]: WARP Connector is an extension of the [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/).
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/tips.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/tips.mdx
index eee30449fb3..3b3f29c09fa 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/tips.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/tips.mdx
@@ -52,7 +52,7 @@ Split Tunnels is the only supported method of running both connectors on one mac
To ensure reliable network performance, it is important to understand the requirements for [Maximum Transmission Unit (MTU)](https://www.cloudflare.com/learning/network-layer/what-is-mtu/) and [Maximum Segment Size (MSS)](https://www.cloudflare.com/learning/network-layer/what-is-mss/) when using WARP Connector. An incorrect configuration can lead to performance degradation or packet loss.
-WARP Connector uses encapsulation to route traffic, which adds extra headers and bytes to each [packet](https://www.cloudflare.com/learning/network-layer/what-is-a-packet/). This is especially critical for traffic from your private network (on-ramped via WARP Connector) to a remote WARP client. This traffic flow is encapsulated twice:
+WARP Connector uses encapsulation to route traffic, which adds extra headers and bytes to each [packet](https://www.cloudflare.com/learning/network-layer/what-is-a-packet/). This is especially critical for traffic from your private network (on-ramped via WARP Connector) to a remote Cloudflare One Client. This traffic flow is encapsulated twice:
1. By the WARP Connector on your Linux host.
2. Again by Cloudflare before being delivered to the off-ramp.
@@ -64,7 +64,7 @@ Generally, this does not cause issues for TCP traffic and modern applications th
However, this may cause issues for legacy applications (like some video streaming or monitoring tools) that may not perform [Path MTU Discovery (PMTUD)](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/path-mtu-discovery/). Instead, they send large packets (e.g., more than 1,280 bytes) with the `do not fragment` (DF) bit unset (`DF=0`).
In this situation, WARP Connector host receives this large packet (for example, 1,460 bytes), then fragments the packet to fit its [tunnel MTU](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/client-architecture/#virtual-interface). These fragments are then reassembled at a Cloudflare data center back into the original 1,460-byte packet.
-Cloudflare then tries to encapsulate this 1,460-byte packet to send to the WARP client, pushing it over 1,500 bytes and causing it to be dropped. Cloudflare does not currently support fragmenting these outgoing encapsulated packets.
+Cloudflare then tries to encapsulate this 1,460-byte packet to send to the Cloudflare One Client, pushing it over 1,500 bytes and causing it to be dropped. Cloudflare does not currently support fragmenting these outgoing encapsulated packets.
### Recommendations
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/user-to-site.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/user-to-site.mdx
index 91c318749c0..d066ac89301 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/user-to-site.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/user-to-site.mdx
@@ -1,6 +1,6 @@
---
pcx_content_type: how-to
-title: Connect private network to WARP clients
+title: Connect private network to Cloudflare One Clients
tags:
- Private networks
sidebar:
@@ -10,7 +10,7 @@ sidebar:
import { Render, Details, GlossaryTooltip, TabItem, Tabs } from "~/components";
-This guide covers how to connect WARP client user devices to a private network behind WARP Connector. In this example, we will create a WARP Connector for subnet `10.0.0.0/24` and install it on `10.0.0.1`.
+This guide covers how to connect Cloudflare One Client user devices to a private network behind WARP Connector. In this example, we will create a WARP Connector for subnet `10.0.0.0/24` and install it on `10.0.0.1`.
```mermaid
flowchart LR
@@ -28,7 +28,7 @@ This guide covers how to connect WARP client user devices to a private network b
- A Linux host [^1] on the subnet.
- For WARP Connector to connect to Cloudflare services, your firewall should allow inbound/outbound traffic for the [WARP IP addresses, ports, and domains](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/firewall/).
-- For WARP clients to connect to your subnet, your firewall should allow inbound traffic from your [device IPs](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-ips/).
+- For Cloudflare One Clients to connect to your subnet, your firewall should allow inbound traffic from your [device IPs](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-ips/).
## 1. Install a WARP Connector
@@ -40,13 +40,13 @@ This guide covers how to connect WARP client user devices to a private network b
## 3. Route device IPs through Cloudflare
-WARP clients and WARP Connectors are accessed using their [device IP](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-ips/). Therefore, traffic to your device IPs must route through Cloudflare on both the WARP Connector host and WARP client devices.
+Cloudflare One Clients and WARP Connectors are accessed using their [device IP](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-ips/). Therefore, traffic to your device IPs must route through Cloudflare on both the WARP Connector host and Cloudflare One Client devices.
1. In your WARP Connector device profile, go to [Split Tunnels](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/).
2.
-3. Repeat the previous steps for all WARP client device profiles.
+3. Repeat the previous steps for all Cloudflare One Client device profiles.
## 4. Route traffic from subnet to WARP Connector
@@ -65,7 +65,7 @@ Depending on where you installed the WARP Connector, you may need to configure o
#### Add IP route to router
-`100.96.0.0/12` is the default CIDR for all user devices running the [WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/). On your router, add a rule that routes the destination IP `100.96.0.0/12` to the WARP Connector host machine (`10.0.0.100`).
+`100.96.0.0/12` is the default CIDR for all user devices running the [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/). On your router, add a rule that routes the destination IP `100.96.0.0/12` to the WARP Connector host machine (`10.0.0.100`).
## 5. Test the WARP Connector
-You can now send a request from a WARP client user device to your subnet. To test connections to the WARP Connector host, on the WARP client device run `ping 10.0.0.1`. To connect to a device behind WARP connector, run `ping 10.0.0.2`.
+You can now send a request from a Cloudflare One Client user device to your subnet. To test connections to the WARP Connector host, on the Cloudflare One Client device run `ping 10.0.0.1`. To connect to a device behind WARP connector, run `ping 10.0.0.2`.
```mermaid
flowchart LR
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp.mdx
index f943c8c7430..838ec1cbbac 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp.mdx
@@ -7,40 +7,40 @@ sidebar:
order: 5
head:
- tag: title
- content: Create private networks with WARP-to-WARP
+ content: Create private networks with Peer-to-peer
---
import { Render, GlossaryTooltip, Tabs, TabItem } from "~/components";
-With Cloudflare Zero Trust, you can create a private network between any two or more devices running Cloudflare WARP. This means that you can have a private network between your phone and laptop without ever needing to be connected to the same physical network. If you already have an existing Zero Trust deployment, you can also enable this feature to add device-to-device connectivity to your private network with the press of a button. This will allow you to connect to any service that relies on TCP, UDP, or ICMP-based protocols through Cloudflare's network.
+With Cloudflare Zero Trust, you can create a private network between any two or more devices running the Cloudflare One Client. This means that you can have a private network between your phone and laptop without ever needing to be connected to the same physical network. If you already have an existing Zero Trust deployment, you can also enable this feature to add device-to-device connectivity to your private network with the press of a button. This will allow you to connect to any service that relies on TCP, UDP, or ICMP-based protocols through Cloudflare's network.
Users in your organization can reach these services by enrolling into your organization's Zero Trust account. Once enrolled, each device is assigned a [virtual IP address](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-ips/) which will allow users or systems to address these devices directly. Administrators will then be able to build Zero Trust policies to determine who within your organization can reach those virtual IPs.
This guide covers how to:
-- Enable WARP-to-WARP connectivity to establish a private network between your devices.
-- Manage Split Tunnel preferences for the WARP client to determine what traffic should be routed to the Cloudflare global network.
+- Enable Peer-to-peer connectivity to establish a private network between your devices.
+- Manage Split Tunnel preferences for the Cloudflare One Client to determine what traffic should be routed to the Cloudflare global network.
- Create Zero Trust security policies to restrict access.
-- Connect to virtual IP spaces from WARP devices without any client-side configuration changes.
+- Connect to virtual IP spaces from the Cloudflare One Client devices without any client-side configuration changes.
## Prerequisites
-- [Install the Cloudflare WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/) on your devices.
+- [Install the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/) on your devices.
- [Define device enrollment permissions](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/device-enrollment/).
- [Enroll your devices](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/manual-deployment/) in your Zero Trust organization.
-## Enable WARP-to-WARP
+## Enable Peer-to-peer
1. In [Cloudflare One](https://one.dash.cloudflare.com), go to **Team & Resources** > **Devices** > **Management**.
2. Select **Peer to peer connectivity**.
3. Turn on [**Allow all Cloudflare One traffic to reach enrolled devices**](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/#allow-all-cloudflare-one-traffic-to-reach-enrolled-devices).
-4. Go to **Team & Resources** > **Devices** > **Device profiles** > **General profiles** and select the device group that needs WARP-to-WARP connectivity.
+4. Go to **Team & Resources** > **Devices** > **Device profiles** > **General profiles** and select the device group that needs Peer-to-peer connectivity.
5.
This will instruct WARP to begin proxying any traffic destined for a `100.96.0.0/12` IP address to Cloudflare for routing and policy enforcement.
-## Connect via WARP
+## Connect via the Cloudflare One Client
Once enrolled, your users and services will be able to connect to the virtual IPs configured for TCP, UDP, or ICMP-based traffic. You can optionally create [Gateway network policies](/cloudflare-one/traffic-policies/network-policies/) to define the users and devices that can access the `100.96.0.0/12` IP space.
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/troubleshoot-tunnels/common-errors.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/troubleshoot-tunnels/common-errors.mdx
index e3b62a06ea3..74038504525 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/troubleshoot-tunnels/common-errors.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/troubleshoot-tunnels/common-errors.mdx
@@ -43,7 +43,7 @@ The tunnel status only reflects the connection between `cloudflared` and the Clo
## My tunnel randomly disconnects.
-Long-lived connections initiated through Cloudflare One, such as SSH sessions, can last up to eight hours. However, disruptions along the service path may result in more frequent disconnects. Often, these disconnects are caused by regularly scheduled maintenance events such as data center, server, or service updates and restarts. If you believe these events are not the cause of disconnects in your environment, collect the relevant [WARP logs](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/diagnostic-logs/) and [Tunnel logs](/cloudflare-one/networks/connectors/cloudflare-tunnel/monitor-tunnels/logs/) and contact Support.
+Long-lived connections initiated through Cloudflare One, such as SSH sessions, can last up to eight hours. However, disruptions along the service path may result in more frequent disconnects. Often, these disconnects are caused by regularly scheduled maintenance events such as data center, server, or service updates and restarts. If you believe these events are not the cause of disconnects in your environment, collect the relevant [client logs](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/diagnostic-logs/) and [Tunnel logs](/cloudflare-one/networks/connectors/cloudflare-tunnel/monitor-tunnels/logs/) and contact Support.
## `ping` and `traceroute` commands do not work.
@@ -51,7 +51,7 @@ To ping an IP address behind Cloudflare Tunnel, your system must allow ICMP traf
## I see `Error: This route's network is inside an existing subnet's network at "100.96.0.0/12"`.
-This error occurs when you try to add a CIDR route that falls within Cloudflare WARP's CGNAT IP range. The `100.96.0.0/12` range, which covers addresses from `100.96.0.1` to `100.111.255.254`, is reserved for internal WARP routing and cannot be added as a Cloudflare Tunnel route. To connect your private network, you will need to change its IP/CIDR so that it does not overlap with `100.96.0.0/12`.
+This error occurs when you try to add a CIDR route that falls within the Cloudflare One Client's CGNAT IP range. The `100.96.0.0/12` range, which covers addresses from `100.96.0.1` to `100.111.255.254`, is reserved for internal WARP routing and cannot be added as a Cloudflare Tunnel route. To connect your private network, you will need to change its IP/CIDR so that it does not overlap with `100.96.0.0/12`.
## Troubleshooting
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/grpc.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/grpc.mdx
index 8b53a301686..692c3c0886b 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/grpc.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/grpc.mdx
@@ -15,7 +15,7 @@ gRPC is a Remote Procedure Call (RPC) framework that allows client applications
In this example, we will connect a gRPC server to Cloudflare using the
`cloudflared` daemon, secure
the server with Gateway policies, and open a gRPC channel to the server using
-the Cloudflare WARP client.
+the Cloudflare One Client.
## 1. Set up a gRPC server
@@ -38,7 +38,7 @@ To establish a secure, outbound-only connection to Cloudflare:
3. In the **CIDR** tab for the tunnel, enter the private IP or CIDR address of your server.
-## 3. Route private network IPs through WARP
+## 3. Route private network IPs through the Cloudflare One Client
-## 5. Route private network IPs through WARP
+## 5. Route private network IPs through the Cloudflare One Client
-### 3. Route private network IPs through WARP
+### 3. Route private network IPs through the Cloudflare One Client
@@ -39,7 +39,7 @@ Cloudflare offers four ways to secure SSH:
**Setup time:** 45-60 minutes
-**Required products:** [Cloudflare Tunnel](/cloudflare-one/networks/connectors/cloudflare-tunnel/) (`cloudflared` on server), [WARP](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) or [Cloudflare WAN](/cloudflare-wan/) (client on-ramp), [Gateway](/cloudflare-one/traffic-policies/), [Access](/cloudflare-one/access-controls/)
+**Required products:** [Cloudflare Tunnel](/cloudflare-one/networks/connectors/cloudflare-tunnel/) (`cloudflared` on server), [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) or [Cloudflare WAN](/cloudflare-wan/) (client on-ramp), [Gateway](/cloudflare-one/traffic-policies/), [Access](/cloudflare-one/access-controls/)
**Best for:** Advanced SSH certificate-based authentication with short-lived credentials
@@ -55,7 +55,7 @@ Cloudflare offers four ways to secure SSH:
**Setup time:** 30-45 minutes
-**Required products:** [Cloudflare Tunnel](/cloudflare-one/networks/connectors/cloudflare-tunnel/) (`cloudflared` on server), [WARP](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) or [Cloudflare WAN](/cloudflare-wan/) (client on-ramp), [Gateway](/cloudflare-one/traffic-policies/)
+**Required products:** [Cloudflare Tunnel](/cloudflare-one/networks/connectors/cloudflare-tunnel/) (`cloudflared` on server), [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) or [Cloudflare WAN](/cloudflare-wan/) (client on-ramp), [Gateway](/cloudflare-one/traffic-policies/)
**Best for:** Traditional SSH key management with network-level policy enforcement
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-browser-rendering.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-browser-rendering.mdx
index ab33d72005e..3da5b53452f 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-browser-rendering.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-browser-rendering.mdx
@@ -10,7 +10,7 @@ sidebar:
import { Render } from "~/components";
-Cloudflare's browser-based terminal allows end users to connect to an SSH server without managing SSH keys or installing the WARP client.
+Cloudflare's browser-based terminal allows end users to connect to an SSH server without managing SSH keys or installing the Cloudflare One Client.
This method requires routing SSH access to the server through a public hostname. The traffic is proxied over this connection, and the user logs in to the server with their Cloudflare Access credentials.
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-cloudflared-authentication.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-cloudflared-authentication.mdx
index cb3dfba48f9..73ce842ef8f 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-cloudflared-authentication.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-cloudflared-authentication.mdx
@@ -10,7 +10,7 @@ sidebar:
import { Render } from "~/components";
-End users can connect to an SSH server without the WARP client by authenticating through `cloudflared` in their native terminal. This method requires having `cloudflared` installed on both the server machine and on the client machine, as well as an active zone on Cloudflare. The traffic is proxied over this connection, and the user logs in to the server with their Cloudflare Access credentials.
+End users can connect to an SSH server without the Cloudflare One Client by authenticating through `cloudflared` in their native terminal. This method requires having `cloudflared` installed on both the server machine and on the client machine, as well as an active zone on Cloudflare. The traffic is proxied over this connection, and the user logs in to the server with their Cloudflare Access credentials.
Client-side `cloudflared` can be used in conjunction with [routing over WARP](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-warp-to-tunnel/) and [Access for Infrastructure](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-infrastructure-access/) so that there are multiple ways to connect to the server. You can reuse the same Cloudflare Tunnel when configuring each connection method.
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-infrastructure-access.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-infrastructure-access.mdx
index fee24ecad0f..b1129a5ec1c 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-infrastructure-access.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-infrastructure-access.mdx
@@ -31,11 +31,11 @@ import { Tabs, TabItem, Badge, Render, APIRequest } from "~/components";
To connect your devices to Cloudflare:
-1. [Deploy the WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/) on your devices in Traffic and DNS mode.
+1. [Deploy the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/) on your devices in Traffic and DNS mode.
2. [Enable the Gateway proxy for TCP](/cloudflare-one/traffic-policies/proxy/#turn-on-the-gateway-proxy).
3. [Create device enrollment rules](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/device-enrollment/) to determine which devices can enroll to your Zero Trust organization.
-## 3. Route server IPs through WARP
+## 3. Route server IPs through the Cloudflare One Client
@
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-warp-to-tunnel.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-warp-to-tunnel.mdx
index 63a8937f6b9..e57224de9a9 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-warp-to-tunnel.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-warp-to-tunnel.mdx
@@ -10,7 +10,7 @@ sidebar:
import { Render, Details, GlossaryTooltip } from "~/components";
-If you want to manage your own SSH keys, you can use Cloudflare Tunnel to create a secure, outbound-only connection from your server to Cloudflare's global network. This requires running the `cloudflared` daemon on the server (or any other host machine within the private network). Users with SSH keys that are trusted by the SSH server can access the server by installing the [Cloudflare WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) on their device and enrolling in your Zero Trust organization. Users can SSH directly to the server's private hostname (for example, `ssh.internal.local`). You control access to the server using network-level Gateway policies instead of application-level Access policies.
+If you want to manage your own SSH keys, you can use Cloudflare Tunnel to create a secure, outbound-only connection from your server to Cloudflare's global network. This requires running the `cloudflared` daemon on the server (or any other host machine within the private network). Users with SSH keys that are trusted by the SSH server can access the server by installing the [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) on their device and enrolling in your Zero Trust organization. Users can SSH directly to the server's private hostname (for example, `ssh.internal.local`). You control access to the server using network-level Gateway policies instead of application-level Access policies.
:::note
@@ -20,7 +20,7 @@ If you want to create more granular policies, allow Cloudflare to manage SSH key
## Prerequisites
- A [Cloudflare Zero Trust organization](/cloudflare-one/setup/#create-a-zero-trust-organization)
-- [WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/) installed on user devices.
+- [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/) installed on user devices.
- Devices [enrolled](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/manual-deployment/) in your Zero Trust organization
## 1. Create an example SSH server
@@ -143,9 +143,9 @@ The output should contain the server's private IP address (the **Internal IP** o
params={{ hostname: "ssh.internal.local" }}
/>
-### 3.3 Configure WARP clients
+### 3.3 Configure Cloudflare One Clients
-To connect to private hostnames, WARP clients must be configured to forward the following traffic to Cloudflare:
+To connect to private hostnames, Cloudflare One Clients must be configured to forward the following traffic to Cloudflare:
- Initial resolved IPs (CGNAT range: `100.64.0.0/10`)
- DNS queries for your private hostname
@@ -166,7 +166,7 @@ For example, if your SSH hostname is `ssh.internal.local`, remove `internal.loca
To connect to the SSH server using its IP address (instead of a [hostname](#3-use-hostname-routes)), [add a CIDR route](/cloudflare-one/networks/routes/add-routes/#add-a-cidr-route) that includes the server's private IP address.
-### 4.2 Configure WARP clients
+### 4.2 Configure Cloudflare One Clients
-Additionally, SNI selectors will only apply to WARP client traffic.
+Additionally, SNI selectors will only apply to Cloudflare One Client traffic.
:::
## 6. Connect as a user
@@ -235,13 +235,13 @@ Once you have set up the tunnel route and the user device, the user can now SSH
ssh -i ~/.ssh/gcp_ssh @ssh.internal.local
```
-The WARP client must be connected to your Zero Trust organization. Users will be able to connect if they match the Gateway network policies you created.
+The Cloudflare One Client must be connected to your Zero Trust organization. Users will be able to connect if they match the Gateway network policies you created.
### Troubleshooting
If you cannot connect, verify the following:
-1. **Confirm DNS resolution** - From the WARP device, confirm that you can successfully resolve the private hostname:
+1. **Confirm DNS resolution** - From the device, confirm that you can successfully resolve the private hostname:
```sh
nslookup ssh.internal.local
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/cloudflare-gateway.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/cloudflare-gateway.mdx
index 406af50dba3..38504f7de91 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/cloudflare-gateway.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/cloudflare-gateway.mdx
@@ -18,8 +18,8 @@ import { Render } from "~/components";
cfManualCertificatesURL: "/cloudflare-one/team-and-resources/devices/user-side-certificates/manual-deployment/",
decryptTlsURL: "/cloudflare-one/traffic-policies/http-policies/tls-decryption/",
doNotInspectURL: "/cloudflare-one/traffic-policies/http-policies/#do-not-inspect",
- warpChecksURL: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
- osVersionChecks: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/os-version/",
+ warpChecksURL: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
+ osVersionChecks: "/cloudflare-one/reusable-components/posture-checks/client-checks/os-version/",
mwanOnrampsURL: "/cloudflare-one/networks/connectors/cloudflare-wan/on-ramps/",
gatewayResolverPoliciesURL: "/cloudflare-one/traffic-policies/resolver-policies/",
gatewayInternalDnsURL: "/cloudflare-one/traffic-policies/resolver-policies/#internal-dns",
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/index.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/index.mdx
index a82a7da957b..5367a413e14 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/index.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/index.mdx
@@ -6,7 +6,7 @@ sidebar:
head:
- tag: title
content: Cloudflare One integration tutorials
-description: Learn how to integrate Cloudflare WAN with other Cloudflare One products, such as Cloudflare Gateway and Cloudflare WARP.
+description: Learn how to integrate Cloudflare WAN with other Cloudflare One products, such as Cloudflare Gateway and the Cloudflare One Client.
---
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/warp.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/warp.mdx
index 7a4a1aaa97f..a77e4699085 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/warp.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/warp.mdx
@@ -3,9 +3,9 @@ title: WARP
pcx_content_type: how-to
head:
- tag: title
- content: Use WARP as an on-ramp
+ content: Use the Cloudflare One Client as an on-ramp
description: >-
- Use WARP as an on-ramp to Cloudflare WAN and route traffic from user devices with WARP installed to any network connected with Cloudflare Tunnel or IP-layer tunnels (anycast GRE, IPsec, or CNI).
+ Use the Cloudflare One Client as an on-ramp to Cloudflare WAN and route traffic from user devices with the Cloudflare One Client installed to any network connected with Cloudflare Tunnel or IP-layer tunnels (anycast GRE, IPsec, or CNI).
---
import { Render } from "~/components";
diff --git a/src/content/docs/cloudflare-one/networks/resolvers-and-proxies/dns/dns-over-https.mdx b/src/content/docs/cloudflare-one/networks/resolvers-and-proxies/dns/dns-over-https.mdx
index fe462203aaf..b50c61d2b91 100644
--- a/src/content/docs/cloudflare-one/networks/resolvers-and-proxies/dns/dns-over-https.mdx
+++ b/src/content/docs/cloudflare-one/networks/resolvers-and-proxies/dns/dns-over-https.mdx
@@ -9,7 +9,7 @@ sidebar:
import { Details, GlossaryTooltip, Render } from "~/components";
-With Cloudflare Gateway, you can filter DNS over HTTPS (DoH) requests by [DNS location](/cloudflare-one/networks/resolvers-and-proxies/dns/locations/) or by user without needing to install the WARP client on your devices.
+With Cloudflare Gateway, you can filter DNS over HTTPS (DoH) requests by [DNS location](/cloudflare-one/networks/resolvers-and-proxies/dns/locations/) or by user without needing to install the Cloudflare One Client on your devices.
Location-based policies require that you send DNS requests to a [location-specific DoH endpoint](#filter-doh-requests-by-location), while identity-based policies require that requests include a [user-specific DoH token](#filter-doh-requests-by-user).
diff --git a/src/content/docs/cloudflare-one/networks/resolvers-and-proxies/dns/locations/dns-resolver-ips.mdx b/src/content/docs/cloudflare-one/networks/resolvers-and-proxies/dns/locations/dns-resolver-ips.mdx
index 344ba641b98..9469f5390ea 100644
--- a/src/content/docs/cloudflare-one/networks/resolvers-and-proxies/dns/locations/dns-resolver-ips.mdx
+++ b/src/content/docs/cloudflare-one/networks/resolvers-and-proxies/dns/locations/dns-resolver-ips.mdx
@@ -77,7 +77,7 @@ Each DNS location is assigned a unique hostname for DNS over HTTPS (DoH). Gatewa
### DoH subdomain
-Each DNS location in Cloudflare Zero Trust has a unique DoH subdomain (previously known as unique ID). If your organization uses DNS policies, you can enter your location's DoH subdomain as part of the WARP client settings.
+Each DNS location in Cloudflare Zero Trust has a unique DoH subdomain (previously known as unique ID). If your organization uses DNS policies, you can enter your location's DoH subdomain as part of the Cloudflare One Client settings.
For example, for the DoH hostname `https://65y9p2vm1u.cloudflare-gateway.com/dns-query`, the DoH subdomain is `65y9p2vm1u`.
diff --git a/src/content/docs/cloudflare-one/networks/resolvers-and-proxies/dns/locations/index.mdx b/src/content/docs/cloudflare-one/networks/resolvers-and-proxies/dns/locations/index.mdx
index ae1cb3aee14..eaf7f514119 100644
--- a/src/content/docs/cloudflare-one/networks/resolvers-and-proxies/dns/locations/index.mdx
+++ b/src/content/docs/cloudflare-one/networks/resolvers-and-proxies/dns/locations/index.mdx
@@ -27,7 +27,7 @@ You do not need to configure the IPv4 DNS endpoint if:
- Your network only uses IPv6.
- Your users will send all DNS requests from this location using [DNS over HTTPS](#dns-over-https-doh) via a browser.
-- You will deploy the [WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/).
+- You will deploy the [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/).
:::note[Your IPv4 address is taken error]
When you try to configure a DNS location over IPv4, Gateway may display a **Your source IPv4 address is taken** error. This may mean someone else in the same network configured Gateway before you did. If your network supports IPv6, you can still use Gateway's DNS filtering by sending DNS queries over IPv6. You can also use the DNS over HTTPS hostname to send queries using a DNS over HTTPS client.
diff --git a/src/content/docs/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/index.mdx b/src/content/docs/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/index.mdx
index 77186f7e2d4..915be2628c8 100644
--- a/src/content/docs/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/index.mdx
+++ b/src/content/docs/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/index.mdx
@@ -23,12 +23,12 @@ import {
Proxy endpoints allow you to apply Gateway policies without installing a client on your devices. By configuring a [Proxy Auto-Configuration (PAC) file](#what-is-a-pac-file) at the browser level, you can route traffic through Gateway for filtering and policy enforcement. Cloudflare supports configuring two types of proxy endpoints: identity-based [authorization endpoints](#authorization-endpoint) and [source IP proxy endpoints](#source-ip-endpoint).
:::note
-For the best experience and deepest visibility, Cloudflare recommends using the [WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/). Use proxy endpoints when installing a device client is not feasible for your environment.
+For the best experience and deepest visibility, Cloudflare recommends using the [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/). Use proxy endpoints when installing a device client is not feasible for your environment.
:::
### When to use proxy endpoints
-Proxy endpoints are designed for environments where deploying the WARP client is not an option. Common use cases include:
+Proxy endpoints are designed for environments where deploying the Cloudflare One Client is not an option. Common use cases include:
- **Virtual desktops (VDI)**: Users log into a virtual machine and use a browser to reach the Internet.
- **Compliance-restricted endpoints**: Environments where you are legally or technically prohibited from installing software on the endpoint.
@@ -486,7 +486,7 @@ Proxy endpoint traffic is logged in the following locations:
## Billing
-Each user who authenticates through an authorization proxy endpoint occupies a [Gateway seat](/cloudflare-one/team-and-resources/users/seat-management/), the same as a user connected through the WARP client.
+Each user who authenticates through an authorization proxy endpoint occupies a [Gateway seat](/cloudflare-one/team-and-resources/users/seat-management/), the same as a user connected through the Cloudflare One Client.
## Limitations
diff --git a/src/content/docs/cloudflare-one/networks/routes/reserved-ips.mdx b/src/content/docs/cloudflare-one/networks/routes/reserved-ips.mdx
index 27f0e7ab110..1376d7deff6 100644
--- a/src/content/docs/cloudflare-one/networks/routes/reserved-ips.mdx
+++ b/src/content/docs/cloudflare-one/networks/routes/reserved-ips.mdx
@@ -17,14 +17,14 @@ When planning your private network addressing and configuring [Split Tunnel](/cl
| ------------------------------------------------------------- | ---------------- | ------------ |
| [Cloudflare source IPs](#cloudflare-source-ips) | `100.64.0.0/12` | Yes |
| [Gateway initial resolved IPs](#gateway-initial-resolved-ips) | `100.80.0.0/16` | No |
-| [WARP device IPs](#warp-device-ips) | `100.96.0.0/12` | Yes |
+| [device IPs](#warp-device-ips) | `100.96.0.0/12` | Yes |
| [Private Load Balancer IPs](#private-load-balancer-ips) | `100.112.0.0/16` | Yes |
## IPv6 ranges
| Name | Default CIDR | Configurable |
| ------------------------------------------------------------- | -------------------------- | ------------ |
-| [WARP device IPs](#warp-device-ips) | `2606:4700:0cf1:1000::/64` | No |
+| [device IPs](#warp-device-ips) | `2606:4700:0cf1:1000::/64` | No |
| [Gateway initial resolved IPs](#gateway-initial-resolved-ips) | `2606:4700:0cf1:4000::/64` | No |
| [Cloudflare source IPs](#cloudflare-source-ips) | `2606:4700:0cf1:5000::/64` | No |
@@ -51,13 +51,13 @@ The following features use this range:
Initial resolved IPs are assigned from the `100.80.0.0/16` (IPv4) or `2606:4700:0cf1:4000::/64` (IPv6) range. This range is not configurable.
-## WARP device IPs
+## device IPs
-WARP device IPs are virtual addresses assigned to each WARP device registration. These IPs identify and route traffic to specific devices for the following features:
+device IPs are virtual addresses assigned to each device registration. These IPs identify and route traffic to specific devices for the following features:
-- [Peer-to-peer connectivity (WARP-to-WARP)](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp/) — allows WARP devices to communicate directly with each other over Cloudflare's network.
+- [Peer-to-peer connectivity (Peer-to-peer)](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp/) — allows devices to communicate directly with each other over Cloudflare's network.
- [WARP Connector](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/) — routes traffic between your private network and WARP devices.
-- [Cloudflare WAN](/cloudflare-one/networks/connectors/cloudflare-wan/) — on-ramps traffic from WAN tunnels to WARP devices.
+- [Cloudflare WAN](/cloudflare-one/networks/connectors/cloudflare-wan/) — on-ramps traffic from WAN tunnels to the Cloudflare One Client devices.
The default IPv4 range is `100.96.0.0/12`. If this range conflicts with services on your private network, you can configure custom IPv4 subnets drawn from RFC 1918 or CGNAT address space. For configuration instructions, refer to [Device IPs](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-ips/).
@@ -67,15 +67,15 @@ Private Load Balancer IPs are virtual addresses allocated to [Private Network Lo
## WARP Split Tunnel configuration
-For deployments that use the [WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/), ensure that the [reserved IP ranges](#ipv4-ranges) required by your deployment route through [WARP Split Tunnels](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/) to Cloudflare. Configuration depends on whether your [Split Tunnels mode](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/#change-split-tunnels-mode) is set to **Exclude IPs and domains** or **Include IPs and domains**.
+For deployments that use the [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/), ensure that the [reserved IP ranges](#ipv4-ranges) required by your deployment route through [WARP Split Tunnels](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/) to Cloudflare. Configuration depends on whether your [Split Tunnels mode](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/#change-split-tunnels-mode) is set to **Exclude IPs and domains** or **Include IPs and domains**.
### Exclude mode (default)
-In **Exclude IPs and domains** mode, the CGNAT range (`100.64.0.0/10`) is excluded from WARP routing by default. You must delete the [reserved IP ranges](#ipv4-ranges) from your Split Tunnels exclude list, or the associated features will stop working.
+In **Exclude IPs and domains** mode, the CGNAT range (`100.64.0.0/10`) is excluded from the Cloudflare One Client routing by default. You must delete the [reserved IP ranges](#ipv4-ranges) from your Split Tunnels exclude list, or the associated features will stop working.
Cloudflare recommends adding back the IPs that are not explicitly used for Cloudflare One services. This reduces the risk of conflicts with existing private network configurations that may use CGNAT address space.
-You can use the calculator below to determine which IP ranges to add back based on the Cloudflare One features you use. For example, if your deployment requires [Gateway initial resolved IPs](#gateway-initial-resolved-ips) (`100.80.0.0/16`) and [WARP device IPs](#warp-device-ips) (`100.96.0.0/12`), delete `100.64.0.0/10` from Split Tunnels and add back `100.64.0.0/12`, `100.81.0.0/16`, `100.82.0.0/15`, `100.84.0.0/14`, `100.88.0.0/13`, and `100.112.0.0/12`.
+You can use the calculator below to determine which IP ranges to add back based on the Cloudflare One features you use. For example, if your deployment requires [Gateway initial resolved IPs](#gateway-initial-resolved-ips) (`100.80.0.0/16`) and [device IPs](#warp-device-ips) (`100.96.0.0/12`), delete `100.64.0.0/10` from Split Tunnels and add back `100.64.0.0/12`, `100.81.0.0/16`, `100.82.0.0/15`, `100.84.0.0/14`, `100.88.0.0/13`, and `100.112.0.0/12`.
` is not provided, users are presented with a Cloudflare Zero Trust lan
### Allow or block websites
-When users visit a website through the [Clientless Web Isolation URL](#use-the-remote-browser), the traffic passes through Cloudflare Gateway. This allows you to [apply HTTP policies](/cloudflare-one/traffic-policies/http-policies/) to control what websites the remote browser can connect to, even if the user's device does not have WARP installed.
+When users visit a website through the [Clientless Web Isolation URL](#use-the-remote-browser), the traffic passes through Cloudflare Gateway. This allows you to [apply HTTP policies](/cloudflare-one/traffic-policies/http-policies/) to control what websites the remote browser can connect to, even if the user's device does not have the Cloudflare One Client installed.
For example, if you use a third-party Secure Web Gateway to block `example.com`, users can still access the page in the remote browser by visiting `https://.cloudflareaccess.com/browser/https://www.example.com/`. To block `https://.cloudflareaccess.com/browser/https://www.example.com/`, create a Cloudflare Gateway HTTP policy to block `example.com`:
@@ -137,7 +137,7 @@ To turn on or off the address bar, users can right-click on any isolated page an
## Redirect traffic to the remote browser
-If you want to isolate a website without Cloudflare WARP installed, you will need to redirect traffic to the Clientless Web Isolation [prefixed URL](#use-the-remote-browser). One way to do this is through a third-party Secure Web Gateway. To redirect users to the remote browser, you can implement a custom block page similar to the example shown below.
+If you want to isolate a website without the Cloudflare One Client installed, you will need to redirect traffic to the Clientless Web Isolation [prefixed URL](#use-the-remote-browser). One way to do this is through a third-party Secure Web Gateway. To redirect users to the remote browser, you can implement a custom block page similar to the example shown below.
```html
diff --git a/src/content/docs/cloudflare-one/remote-browser-isolation/setup/index.mdx b/src/content/docs/cloudflare-one/remote-browser-isolation/setup/index.mdx
index a829f7ea816..8cb736fb338 100644
--- a/src/content/docs/cloudflare-one/remote-browser-isolation/setup/index.mdx
+++ b/src/content/docs/cloudflare-one/remote-browser-isolation/setup/index.mdx
@@ -14,7 +14,7 @@ Setup instructions vary depending on how you want to connect your devices to Clo
| Connection | Mode | Description |
| --------------------------------------------------------------------------------------------------------- | ------------ | -------------------------------------------------------------------------------------------------------------------- |
-| [Traffic and DNS mode](/cloudflare-one/traffic-policies/get-started/http/) | In-line | Apply identity-based HTTP policies to traffic proxied through the WARP client. |
+| [Traffic and DNS mode](/cloudflare-one/traffic-policies/get-started/http/) | In-line | Apply identity-based HTTP policies to traffic proxied through the Cloudflare One Client. |
| [Access](/cloudflare-one/access-controls/policies/isolate-application/) | In-line | Apply identity-based HTTP policies to Access applications that are rendered in a remote browser. |
| [Gateway proxy endpoint](/cloudflare-one/remote-browser-isolation/setup/non-identity/) | In-line | Apply non-identity HTTP policies to traffic forwarded to a proxy endpoint. |
| [Cloudflare WAN](/cloudflare-one/remote-browser-isolation/setup/non-identity/) | In-line | Apply non-identity HTTP policies to traffic connected through a GRE or IPsec tunnel. |
@@ -62,5 +62,5 @@ Users can see if a webpage is isolated by using one of the following methods:
#### Disconnect Browser Isolation
-WARP users can temporarily disable remote browsing by [disconnecting the WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/#lock-warp-switch).
-Once WARP is disconnected, a refresh will return the non-isolated page.
+Cloudflare One Client users can temporarily disable remote browsing by [disconnecting the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/#lock-warp-switch).
+Once the Cloudflare One Client is disconnected, a refresh will return the non-isolated page.
diff --git a/src/content/docs/cloudflare-one/remote-browser-isolation/setup/non-identity.mdx b/src/content/docs/cloudflare-one/remote-browser-isolation/setup/non-identity.mdx
index 8bab4c79577..28d7b6f6767 100644
--- a/src/content/docs/cloudflare-one/remote-browser-isolation/setup/non-identity.mdx
+++ b/src/content/docs/cloudflare-one/remote-browser-isolation/setup/non-identity.mdx
@@ -5,11 +5,11 @@ sidebar:
order: 5
---
-With Cloudflare One, you can isolate HTTP traffic from on-ramps such as [proxy endpoints](/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/) or [Cloudflare WAN](/cloudflare-wan/zero-trust/cloudflare-gateway/) (formerly Magic WAN). Since these on-ramps do not require users to log in to Cloudflare WARP, [identity-based policies](/cloudflare-one/traffic-policies/identity-selectors/) are not supported.
+With Cloudflare One, you can isolate HTTP traffic from on-ramps such as [proxy endpoints](/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/) or [Cloudflare WAN](/cloudflare-wan/zero-trust/cloudflare-gateway/) (formerly Magic WAN). Since these on-ramps do not require users to log in to the Cloudflare One Client, [identity-based policies](/cloudflare-one/traffic-policies/identity-selectors/) are not supported.
:::note
-If you want to apply Isolate policies based on user identity, you will need to either install the [WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) or manually redirect users to the [Clientless Web Isolation](/cloudflare-one/remote-browser-isolation/setup/clientless-browser-isolation/) URL.
+If you want to apply Isolate policies based on user identity, you will need to either install the [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) or manually redirect users to the [Clientless Web Isolation](/cloudflare-one/remote-browser-isolation/setup/clientless-browser-isolation/) URL.
:::
## Set up non-identity browser isolation
diff --git a/src/content/docs/cloudflare-one/reusable-components/custom-pages/gateway-block-page.mdx b/src/content/docs/cloudflare-one/reusable-components/custom-pages/gateway-block-page.mdx
index bca8ff841df..402d3b3d3d1 100644
--- a/src/content/docs/cloudflare-one/reusable-components/custom-pages/gateway-block-page.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/custom-pages/gateway-block-page.mdx
@@ -76,7 +76,7 @@ You can add a Mailto link to your custom block page, which allows users to direc
| Source IP | The public source IP of the user device. |
| Account ID | The Cloudflare account associated with the block policy. |
| User ID | The ID of the user who visited the page. Currently, User IDs are not surfaced in the dashboard and can only be viewed by calling the [API](/api/resources/zero_trust/subresources/access/subresources/users/methods/list/). |
-| Device ID | The ID of the device that visited the page. This is generated by the WARP client. |
+| Device ID | The ID of the device that visited the page. This is generated by the Cloudflare One Client. |
| Block Reason | Your policy-specific block message. |
## Configure policy block behavior
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/access-integrations.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/access-integrations.mdx
index 23b196eb162..942ec344581 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/access-integrations.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/access-integrations.mdx
@@ -5,7 +5,7 @@ sidebar:
order: 3
---
-The following device posture checks do not require the WARP client and can only be used in [Cloudflare Access policies](/cloudflare-one/access-controls/policies/). They cannot be used in Gateway network policies.
+The following device posture checks do not require the Cloudflare One Client and can only be used in [Cloudflare Access policies](/cloudflare-one/access-controls/policies/). They cannot be used in Gateway network policies.
## Supported operating systems
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/index.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/index.mdx
index bb4468ea99d..4c1a1de0d3b 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/index.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/index.mdx
@@ -7,13 +7,13 @@ sidebar:
import { Render } from "~/components";
-With Cloudflare Zero Trust, you can configure Zero Trust policies that rely on additional signals from the WARP client or from third-party endpoint security providers. When device posture checks are configured, users can only connect to a protected application or network resource if they have a managed or healthy device.
+With Cloudflare Zero Trust, you can configure Zero Trust policies that rely on additional signals from the Cloudflare One Client or from third-party endpoint security providers. When device posture checks are configured, users can only connect to a protected application or network resource if they have a managed or healthy device.
## 1. Enable device posture checks
Setup instructions and requirements vary depending on the device posture attribute. Refer to the links below to view the setup guide for your provider.
-- [WARP client checks](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/) are performed by the Cloudflare WARP client.
+- [Cloudflare One Client checks](/cloudflare-one/reusable-components/posture-checks/client-checks/) are performed by the Cloudflare One Client.
- [Service-to-service checks](/cloudflare-one/integrations/service-providers/) are performed by third-party device posture providers.
- [Access integration checks](/cloudflare-one/reusable-components/posture-checks/access-integrations/) are only configurable for Access applications. These attributes cannot be used in Gateway policies.
@@ -32,12 +32,12 @@ You can now use your device posture check in an [Access policy](/cloudflare-one/
:::caution[Gateway policy limitation]
-Gateway does not support device posture checks for the [Tanium Access integration](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/tanium/).
+Gateway does not support device posture checks for the [Tanium Access integration](/cloudflare-one/reusable-components/posture-checks/client-checks/tanium/).
:::
-## 4. Ensure traffic is going through WARP
+## 4. Ensure traffic is going through the Cloudflare One Client
-[WARP client](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/) and [service-to-service](/cloudflare-one/integrations/service-providers/) posture checks rely on traffic going through WARP to detect posture information for a device. In your [Split Tunnel configuration](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/), ensure that the following domains are included in WARP:
+[Cloudflare One Client](/cloudflare-one/reusable-components/posture-checks/client-checks/) and [service-to-service](/cloudflare-one/integrations/service-providers/) posture checks rely on traffic going through the Cloudflare One Client to detect posture information for a device. In your [Split Tunnel configuration](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/), ensure that the following domains are included in the Cloudflare One Client:
- The IdP used to authenticate to Cloudflare Zero Trust if posture check is part of an Access policy.
- `.cloudflareaccess.com` if posture check is part of an Access policy.
@@ -71,9 +71,9 @@ By default, the posture result on Cloudflare remains valid until it is overwritt
### Polling frequency
-#### WARP client checks
+#### Cloudflare One Client checks
-By default, the WARP client polls the device for status changes every five minutes. To modify the polling frequency, use the API to update the [`schedule`](/api/resources/zero_trust/subresources/devices/subresources/posture/methods/update/) parameter.
+By default, the Cloudflare One Client polls the device for status changes every five minutes. To modify the polling frequency, use the API to update the [`schedule`](/api/resources/zero_trust/subresources/devices/subresources/posture/methods/update/) parameter.
#### Service provider checks
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/antivirus.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/antivirus.mdx
index 6921c7a84b5..55d7cd7fa6d 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/antivirus.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/antivirus.mdx
@@ -10,7 +10,7 @@ head:
import { Render } from "~/components";
-The Antivirus device posture attribute checks if any antivirus software is installed and active on a device. The WARP client queries the [Windows Security Center API](https://learn.microsoft.com/en-us/windows/win32/api/iwscapi/ne-iwscapi-wsc_security_product_state) to determine the state of registered security products. For the posture check to pass, Windows Security Center must report that a security product is turned on and up to date.
+The Antivirus device posture attribute checks if any antivirus software is installed and active on a device. The Cloudflare One Client queries the [Windows Security Center API](https://learn.microsoft.com/en-us/windows/win32/api/iwscapi/ne-iwscapi-wsc_security_product_state) to determine the state of registered security products. For the posture check to pass, Windows Security Center must report that a security product is turned on and up to date.
## Prerequisites
@@ -18,15 +18,15 @@ The Antivirus device posture attribute checks if any antivirus software is insta
file="posture/prereqs-warp-is-deployed"
product="cloudflare-one"
params={{
- name: "WARP Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
+ name: "Cloudflare One Client Checks",
+ link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
}}
/>
## Enable the antivirus check
1. In [Cloudflare One](https://one.dash.cloudflare.com), go to **Reusable components** > **Posture checks**.
-2. Go to **WARP client checks** and select **Add a check**.
+2. Go to **Cloudflare One Client checks** and select **Add a check**.
3. Select **Antivirus**.
4. Enter a descriptive name for the check.
5. Select your operating system.
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/application-check.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/application-check.mdx
index f1837248eee..f4c1fbe2380 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/application-check.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/application-check.mdx
@@ -15,8 +15,8 @@ The Application Check device posture attribute checks that a specific applicatio
file="posture/prereqs-warp-is-deployed"
product="cloudflare-one"
params={{
- name: "WARP Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
+ name: "Cloudflare One Client Checks",
+ link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
}}
/>
@@ -24,7 +24,7 @@ The Application Check device posture attribute checks that a specific applicatio
1. In [Cloudflare One](https://one.dash.cloudflare.com), go to **Reusable components** > **Posture checks**.
-2. Go to **WARP client checks** and select **Add a check**.
+2. Go to **Cloudflare One Client checks** and select **Add a check**.
3. Select **Application Check**.
@@ -47,7 +47,7 @@ Next, go to **Insights** > **Logs** > **Posture logs** and verify that the appli
## Determine the signing thumbprint
-The process to determine the signing thumbprint of an application varies depending on the operating system. This is how you would look up the signing thumbprint of the Cloudflare WARP application on macOS and Windows.
+The process to determine the signing thumbprint of an application varies depending on the operating system. This is how you would look up the signing thumbprint of the Cloudflare One Client application on macOS and Windows.
:::note
@@ -65,7 +65,7 @@ When setting up new device posture checks, we recommend first testing them witho
~/Desktop $ cd tmp
```
-2. Run the following command to extract certificates for the WARP application:
+2. Run the following command to extract certificates for the Cloudflare One Client application:
```sh
~/Desktop/tmp $ codesign -d --extract-certificates "/Applications/Cloudflare WARP.app/Contents/Resources/CloudflareWARP"
@@ -112,7 +112,7 @@ The SHA-256 value almost always changes between versions of a file/application.
## How WARP checks for an application
-Learn how the WARP client determines if an application is running on various systems.
+Learn how the Cloudflare One Client determines if an application is running on various systems.
### macOS
@@ -126,7 +126,7 @@ The application path must appear in the output for the check to pass.
### Linux
-The WARP client gets the list of running binaries by following the soft links in `/proc//exe`. To view all active processes and their soft links:
+The Cloudflare One Client gets the list of running binaries by following the soft links in `/proc//exe`. To view all active processes and their soft links:
```sh
ps -eo pid | awk '{print "/proc/"$1"/exe"}' | xargs readlink -f | awk '{print $1}' | sort | uniq
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/carbon-black.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/carbon-black.mdx
index 7aff2998e80..e6688f964be 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/carbon-black.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/carbon-black.mdx
@@ -16,8 +16,8 @@ Cloudflare One can check if [Carbon Black](https://www.carbonblack.com/) is runn
file="posture/prereqs-warp-is-deployed"
product="cloudflare-one"
params={{
- name: "WARP Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
+ name: "Cloudflare One Client Checks",
+ link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
}}
/>
@@ -25,7 +25,7 @@ Cloudflare One can check if [Carbon Black](https://www.carbonblack.com/) is runn
1. In [Cloudflare One](https://one.dash.cloudflare.com), go to **Reusable components** > **Posture checks**.
-2. Go to **WARP client checks** and select **Add a check**.
+2. Go to **Cloudflare One Client checks** and select **Add a check**.
3. Select **Carbon Black**.
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/client-certificate.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/client-certificate.mdx
index 8b69ddd37dc..e1aef32ff62 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/client-certificate.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/client-certificate.mdx
@@ -11,11 +11,11 @@ The Client Certificate device posture attribute checks if the device has a valid
-| [WARP modes](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/) | [Zero Trust plans](https://www.cloudflare.com/teams-pricing/) |
+| [Client modes](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/) | [Zero Trust plans](https://www.cloudflare.com/teams-pricing/) |
| ----------------------------------------------------------------------------------------- | ------------------------------------------------------------- |
| All modes | All plans |
-| System | Availability | Minimum WARP version1 |
+| System | Availability | Minimum client version1 |
| -------- | ------------ | -------------------------------- |
| Windows | ✅ | 2024.6.415.0 |
| macOS | ✅ | 2024.6.416.0 |
@@ -24,12 +24,12 @@ The Client Certificate device posture attribute checks if the device has a valid
| Android | ❌ | |
| ChromeOS | ❌ | |
-1 Client certificate checks that ran on an earlier WARP version will continue to work. To configure a new certificate check, update WARP to the versions listed above.
+1 Client certificate checks that ran on an earlier Cloudflare One Client version will continue to work. To configure a new certificate check, update the Cloudflare One Client to the versions listed above.
## Prerequisites
-- A CA that issues client certificates for your devices. WARP does not evaluate the certificate trust chain; this needs to be the issuing certificate.
+- A CA that issues client certificates for your devices. the Cloudflare One Client does not evaluate the certificate trust chain; this needs to be the issuing certificate.
:::note[Upload the signing certificate that issued the client certificate]
@@ -39,7 +39,7 @@ The Client Certificate device posture attribute checks if the device has a valid
:::
-- Cloudflare WARP client is [deployed](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/) on the device.
+- Cloudflare One Client is [deployed](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/) on the device.
- A client certificate is [installed and trusted](#configure-the-client-certificate-check) on the device.
:::note
@@ -60,7 +60,7 @@ To generate a sample root CA for testing, refer to [Generate mTLS certificates](
2. In [Cloudflare One](https://one.dash.cloudflare.com), go to **Reusable components** > **Posture checks**.
-3. Go to **WARP client checks** and select **Add a check**.
+3. Go to **Cloudflare One Client checks** and select **Add a check**.
4. Select **Client certificate**.
@@ -86,10 +86,10 @@ To generate a sample root CA for testing, refer to [Generate mTLS certificates](
files or the same file.
4. **Certificate ID**: Enter the UUID of the signing certificate.
- 5. **Common name**: (Optional) To check for a Common Name (CN) on the client certificate, enter a string with optional `${serial_number}` and `${hostname}` variables (for example, `${serial_number}_mycompany`). WARP will search for an exact, case-insensitive match. If you do not specify a common name, WARP will ignore the common name field on the certificate.
+ 5. **Common name**: (Optional) To check for a Common Name (CN) on the client certificate, enter a string with optional `${serial_number}` and `${hostname}` variables (for example, `${serial_number}_mycompany`). the Cloudflare One Client will search for an exact, case-insensitive match. If you do not specify a common name, the Cloudflare One Client will ignore the common name field on the certificate.
6. **Check for Extended Key Usage**: (Optional) Check whether the client certificate has one or more attributes set. Supported values are **Client authentication** (`1.3.6.1.5.5.7.3.2`) and/or **Email** (`1.3.6.1.5.5.7.3.4`).
7. **Check for private key**: (Recommended) When enabled, WARP checks that the device has a private key associated with the client certificate.
- 8. **Subject Alternative Name**: (Optional) To check for a Subject Alternative Name (SAN) on the client certificate, enter a string with optional `${serial_number}` and `${hostname}` variables (for example, `${serial_number}_mycompany`). WARP will search for an exact, case-insensitive match. You can add multiple SANs to the posture check — a certificate only needs to match one SAN for the check to pass.
+ 8. **Subject Alternative Name**: (Optional) To check for a Subject Alternative Name (SAN) on the client certificate, enter a string with optional `${serial_number}` and `${hostname}` variables (for example, `${serial_number}_mycompany`). the Cloudflare One Client will search for an exact, case-insensitive match. You can add multiple SANs to the posture check — a certificate only needs to match one SAN for the check to pass.
6. Select **Save**.
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/corp-device.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/corp-device.mdx
index 5fbf9c588af..956f6bf1e19 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/corp-device.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/corp-device.mdx
@@ -15,8 +15,8 @@ Cloudflare One allows you to build Zero Trust rules based on device serial numbe
file="posture/prereqs-warp-is-deployed"
product="cloudflare-one"
params={{
- name: "WARP Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
+ name: "Cloudflare One Client Checks",
+ link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
}}
/>
@@ -71,4 +71,4 @@ You can use the following commands to check the serial number of your device. Th
### iOS, Android and ChromeOS
-Serial number checks are not supported on mobile devices. You can identify mobile devices by a [unique client ID](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/device-uuid) instead of by serial number.
+Serial number checks are not supported on mobile devices. You can identify mobile devices by a [unique client ID](/cloudflare-one/reusable-components/posture-checks/client-checks/device-uuid) instead of by serial number.
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/device-uuid.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/device-uuid.mdx
index 3ba7c2a0d7d..36b68f9806a 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/device-uuid.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/device-uuid.mdx
@@ -15,8 +15,8 @@ Cloudflare One allows you to build Zero Trust rules based on device UUIDs suppli
file="posture/prereqs-warp-is-deployed"
product="cloudflare-one"
params={{
- name: "WARP Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
+ name: "Cloudflare One Client Checks",
+ link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
}}
/>
@@ -53,7 +53,7 @@ Hyphens are automatically stripped from UUIDs. For example, the posture check wi
1. In [Cloudflare One](https://one.dash.cloudflare.com), go to **Reusable components** > **Posture checks**.
-2. Go to **WARP client checks** and select **Add a check**.
+2. Go to **Cloudflare One Client checks** and select **Add a check**.
3. Select **Unique Client ID**.
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/disk-encryption.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/disk-encryption.mdx
index 6b5de66fb21..63f5bffc4b8 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/disk-encryption.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/disk-encryption.mdx
@@ -18,15 +18,15 @@ The Disk Encryption device posture attribute ensures that disks are encrypted on
file="posture/prereqs-warp-is-deployed"
product="cloudflare-one"
params={{
- name: "WARP Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
+ name: "Cloudflare One Client Checks",
+ link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
}}
/>
## Enable the disk encryption check
1. In [Cloudflare One](https://one.dash.cloudflare.com), go to **Reusable components** > **Posture checks**.
-2. Go to **WARP client checks** and select **Add a check**.
+2. Go to **Cloudflare One Client checks** and select **Add a check**.
3. Select **Disk Encryption**.
4. Enter a descriptive name for the check.
5. Select your operating system.
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/domain-joined.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/domain-joined.mdx
index 759ecea8bc2..cbc11581562 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/domain-joined.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/domain-joined.mdx
@@ -18,15 +18,15 @@ The Domain Joined device posture attribute ensures that a user is a member of a
file="posture/prereqs-warp-is-deployed"
product="cloudflare-one"
params={{
- name: "WARP Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
+ name: "Cloudflare One Client Checks",
+ link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
}}
/>
## Enable the Domain Joined check
1. In [Cloudflare One](https://one.dash.cloudflare.com), go to **Reusable components** > **Posture checks**.
-2. Go to **WARP client checks** and select **Add a check**.
+2. Go to **Cloudflare One Client checks** and select **Add a check**.
3. Select **Domain Joined**.
4. Enter a descriptive name for the check.
5. Select your operating system.
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/file-check.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/file-check.mdx
index be62ab9b4e6..dedfd613808 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/file-check.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/file-check.mdx
@@ -15,8 +15,8 @@ The File Check device posture attribute checks for the presence of a file on a d
file="posture/prereqs-warp-is-deployed"
product="cloudflare-one"
params={{
- name: "WARP Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
+ name: "Cloudflare One Client Checks",
+ link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
}}
/>
@@ -24,7 +24,7 @@ The File Check device posture attribute checks for the presence of a file on a d
1. In [Cloudflare One](https://one.dash.cloudflare.com), go to **Reusable components** > **Posture checks**.
-2. Go to **WARP client checks** and select **Add a check**.
+2. Go to **Cloudflare One Client checks** and select **Add a check**.
3. Select **File Check**.
@@ -32,8 +32,8 @@ The File Check device posture attribute checks for the presence of a file on a d
1. **Name**: Enter a unique name for this device posture check.
2. **Operating system**: Select your operating system.
3. **File Path**: Enter a file path (for example, `c:\my folder\myfile.exe`).
- 4. **Signing certificate thumbprint (recommended)**: Enter the [thumbprint](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/application-check/#determine-the-signing-thumbprint) of the publishing certificate used to sign the file. Adding this information will enable the check to ensure that the file was signed by the expected software developer.
- 5. **SHA-256 (optional)**: Enter the [SHA-256 value](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/application-check/#determine-the-sha-256-value) of the file. This is used to ensure the integrity of the file on the device.
+ 4. **Signing certificate thumbprint (recommended)**: Enter the [thumbprint](/cloudflare-one/reusable-components/posture-checks/client-checks/application-check/#determine-the-signing-thumbprint) of the publishing certificate used to sign the file. Adding this information will enable the check to ensure that the file was signed by the expected software developer.
+ 5. **SHA-256 (optional)**: Enter the [SHA-256 value](/cloudflare-one/reusable-components/posture-checks/client-checks/application-check/#determine-the-sha-256-value) of the file. This is used to ensure the integrity of the file on the device.
5. Select **Save**.
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/firewall.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/firewall.mdx
index 70a7fbfdf0c..d1916644dc0 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/firewall.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/firewall.mdx
@@ -18,15 +18,15 @@ The Firewall device posture attribute ensures that a firewall is running on a de
file="posture/prereqs-warp-is-deployed"
product="cloudflare-one"
params={{
- name: "WARP Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
+ name: "Cloudflare One Client Checks",
+ link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
}}
/>
## Enable the firewall check
1. In [Cloudflare One](https://one.dash.cloudflare.com), go to **Reusable components** > **Posture checks**.
-2. Go to **WARP client checks** and select **Add a check**.
+2. Go to **Cloudflare One Client checks** and select **Add a check**.
3. Select **Firewall**.
4. Enter a descriptive name for the check.
5. Select your operating system.
@@ -35,7 +35,7 @@ The Firewall device posture attribute ensures that a firewall is running on a de
- **Disabled**: The posture check passes only if the firewall is turned off.
:::note
- The **Enable firewall check** toggle does not turn the posture check on or off; rather, the toggle determines whether the WARP client looks for an active or inactive firewall.
+ The **Enable firewall check** toggle does not turn the posture check on or off; rather, the toggle determines whether the Cloudflare One Client looks for an active or inactive firewall.
:::
7. Select **Save**.
@@ -43,11 +43,11 @@ Next, go to **Insights** > **Logs** > **Posture logs** and verify that the firew
## Validate firewall status
-Operating systems determine firewall configuration in various ways. Follow the steps below to understand how the WARP client determines if the firewall is enabled.
+Operating systems determine firewall configuration in various ways. Follow the steps below to understand how the Cloudflare One Client determines if the firewall is enabled.
### On macOS
-macOS has two firewalls: an application-based firewall and a port-based firewall. The WARP client will report a firewall is enabled if either firewall is running.
+macOS has two firewalls: an application-based firewall and a port-based firewall. The Cloudflare One Client will report a firewall is enabled if either firewall is running.
#### Application-based firewall
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/index.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/index.mdx
index d2f44d8e9f6..ae9fd69d4c6 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/index.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/index.mdx
@@ -1,14 +1,14 @@
---
pcx_content_type: navigation
-title: WARP client checks
+title: Cloudflare One Client checks
sidebar:
order: 1
---
-These device posture checks are performed by the [Cloudflare WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/). To use this feature, you must [deploy the WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/) to your devices and enable the desired posture checks.
+These device posture checks are performed by the [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/). To use this feature, you must [deploy the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/) to your devices and enable the desired posture checks.
-## Supported WARP modes
+## Supported Client modes
* Traffic and DNS mode
* Traffic only mode
@@ -18,18 +18,18 @@ These device posture checks are performed by the [Cloudflare WARP client](/cloud
| Device posture check | macOS | Windows | Linux | iOS | Android/ChromeOS |
| --------------------------------------------------------------------------------------------- | ----- | ------- | ----------- | --- | ---------------- |
-| [Antivirus](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/antivirus/) | ❌ | ✅ | ❌ | ❌ | ❌ |
-| [Application check](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/application-check/) | ✅ | ✅ | ✅ | ❌ | ❌ |
-| [Carbon Black](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/carbon-black/) | ✅ | ✅ | ✅ | ❌ | ❌ |
-| [Client certificate](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/client-certificate/) | ✅ | ✅ | ✅ | ❌ | ❌ |
-| [Device serial numbers](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/corp-device/) | ✅ | ✅ | ✅ | ❌ | ❌ |
-| [Device UUID](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/device-uuid/) | ❌ | ❌ | ❌ | ✅ | ✅ |
-| [Disk encryption](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/disk-encryption/) | ✅ | ✅ | ✅ | ❌ | ❌ |
-| [Domain joined](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/domain-joined/) | ❌ | ✅ | ❌ | ❌ | ❌ |
-| [File check](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/file-check/) | ✅ | ✅ | ✅ | ❌ | ❌ |
-| [Firewall](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/firewall/) | ✅ | ✅ | ❌ | ❌ | ❌ |
-| [OS version](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/os-version/) | ✅ | ✅ | ✅ | ✅ | ✅ |
-| [Require Gateway](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-gateway/) | ✅ | ✅ | ✅ | ✅ | ✅ |
-| [Require WARP](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-warp/) | ✅ | ✅ | ✅ | ✅ | ✅ |
-| [SentinelOne](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/sentinel-one/) | ✅ | ✅ | ✅ | ❌ | ❌ |
-| [Tanium (legacy)](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/tanium/) | ✅ | ✅ | ✅ | ❌ | ❌ |
+| [Antivirus](/cloudflare-one/reusable-components/posture-checks/client-checks/antivirus/) | ❌ | ✅ | ❌ | ❌ | ❌ |
+| [Application check](/cloudflare-one/reusable-components/posture-checks/client-checks/application-check/) | ✅ | ✅ | ✅ | ❌ | ❌ |
+| [Carbon Black](/cloudflare-one/reusable-components/posture-checks/client-checks/carbon-black/) | ✅ | ✅ | ✅ | ❌ | ❌ |
+| [Client certificate](/cloudflare-one/reusable-components/posture-checks/client-checks/client-certificate/) | ✅ | ✅ | ✅ | ❌ | ❌ |
+| [Device serial numbers](/cloudflare-one/reusable-components/posture-checks/client-checks/corp-device/) | ✅ | ✅ | ✅ | ❌ | ❌ |
+| [Device UUID](/cloudflare-one/reusable-components/posture-checks/client-checks/device-uuid/) | ❌ | ❌ | ❌ | ✅ | ✅ |
+| [Disk encryption](/cloudflare-one/reusable-components/posture-checks/client-checks/disk-encryption/) | ✅ | ✅ | ✅ | ❌ | ❌ |
+| [Domain joined](/cloudflare-one/reusable-components/posture-checks/client-checks/domain-joined/) | ❌ | ✅ | ❌ | ❌ | ❌ |
+| [File check](/cloudflare-one/reusable-components/posture-checks/client-checks/file-check/) | ✅ | ✅ | ✅ | ❌ | ❌ |
+| [Firewall](/cloudflare-one/reusable-components/posture-checks/client-checks/firewall/) | ✅ | ✅ | ❌ | ❌ | ❌ |
+| [OS version](/cloudflare-one/reusable-components/posture-checks/client-checks/os-version/) | ✅ | ✅ | ✅ | ✅ | ✅ |
+| [Require Gateway](/cloudflare-one/reusable-components/posture-checks/client-checks/require-gateway/) | ✅ | ✅ | ✅ | ✅ | ✅ |
+| [Require WARP](/cloudflare-one/reusable-components/posture-checks/client-checks/require-warp/) | ✅ | ✅ | ✅ | ✅ | ✅ |
+| [SentinelOne](/cloudflare-one/reusable-components/posture-checks/client-checks/sentinel-one/) | ✅ | ✅ | ✅ | ❌ | ❌ |
+| [Tanium (legacy)](/cloudflare-one/reusable-components/posture-checks/client-checks/tanium/) | ✅ | ✅ | ✅ | ❌ | ❌ |
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/os-version.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/os-version.mdx
index 9ea2df87529..c6f5a66910b 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/os-version.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/os-version.mdx
@@ -15,15 +15,15 @@ The OS Version device posture attribute checks whether the version of a device's
file="posture/prereqs-warp-is-deployed"
product="cloudflare-one"
params={{
- name: "WARP Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
+ name: "Cloudflare One Client Checks",
+ link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
}}
/>
## Enable the OS version check
1. In [Cloudflare One](https://one.dash.cloudflare.com), go to **Reusable components** > **Posture checks**.
-2. Go to **WARP client checks** and select **Add a check**.
+2. Go to **Cloudflare One Client checks** and select **Add a check**.
3. Select **OS version**.
4. Configure the **Operating system**, **Operator**, and **Version** fields to specify the [OS version](#determine-the-os-version) you want devices to match.
@@ -116,7 +116,7 @@ The Linux OS version check reads the system kernel version.
#### Distro version
-The WARP client reads **Distro name** and **Distro revision** from the `/etc/os-release` file. The name comes from the **ID** field, and the revision comes from the **VERSION_ID** field.
+The Cloudflare One Client reads **Distro name** and **Distro revision** from the `/etc/os-release` file. The name comes from the **ID** field, and the revision comes from the **VERSION_ID** field.
To determine the Linux distro version on your device:
@@ -128,7 +128,7 @@ To determine the Linux distro version on your device:
cat /etc/os-release | grep "ID"
```
-3. If the output of the above command contained `ID=ubuntu` and `VERSION_ID=22.04`, **Distro name** would be `ubuntu` and **Distro revision** would be `22.04`. The WARP client will check these strings for an exact match.
+3. If the output of the above command contained `ID=ubuntu` and `VERSION_ID=22.04`, **Distro name** would be `ubuntu` and **Distro revision** would be `22.04`. The Cloudflare One Client will check these strings for an exact match.
### ChromeOS
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-gateway.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-gateway.mdx
index 5a46268e880..27f11840753 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-gateway.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-gateway.mdx
@@ -10,7 +10,7 @@ head:
import { Render } from "~/components";
-With Require Gateway, you can allow access to your applications only to devices enrolled in your Zero Trust organization. Unlike [Require WARP](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-warp/), which will check for any WARP instance (including the consumer version), Require Gateway will only allow requests coming from devices whose traffic is filtered by your organization's Cloudflare Gateway configuration. This policy is best used when you want to protect company-owned assets by only allowing access to employees.
+With Require Gateway, you can allow access to your applications only to devices enrolled in your Zero Trust organization. Unlike [Require WARP](/cloudflare-one/reusable-components/posture-checks/client-checks/require-warp/), which will check for any WARP instance (including the consumer version), Require Gateway will only allow requests coming from devices whose traffic is filtered by your organization's Cloudflare Gateway configuration. This policy is best used when you want to protect company-owned assets by only allowing access to employees.
## Prerequisites
@@ -18,8 +18,8 @@ With Require Gateway, you can allow access to your applications only to devices
file="posture/prereqs-warp-is-deployed"
product="cloudflare-one"
params={{
- name: "WARP Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
+ name: "Cloudflare One Client Checks",
+ link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
}}
/>
@@ -27,7 +27,7 @@ With Require Gateway, you can allow access to your applications only to devices
1. In [Cloudflare One](https://one.dash.cloudflare.com), go to **Reusable components** > **Posture checks**.
-2. Go to **WARP client checks** and select **Add a check**.
+2. Go to **Cloudflare One Client checks** and select **Add a check**.
3. Select **Gateway**, then select **Save**.
@@ -43,4 +43,4 @@ With Require Gateway, you can allow access to your applications only to devices
5. Save the Access application.
-Before granting access to the application, the policy will check that the device is running the WARP client and enrolled in your Zero Trust organization.
+Before granting access to the application, the policy will check that the device is running the Cloudflare One Client and enrolled in your Zero Trust organization.
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-warp.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-warp.mdx
index accbaf0e2e4..d0f5e1aa76d 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-warp.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-warp.mdx
@@ -16,7 +16,7 @@ This device posture attribute will check for all versions of WARP, including the
:::
-Cloudflare One enables you to restrict access to your applications to devices running the Cloudflare WARP client. This allows you to flexibly ensure that a user's traffic is secure and encrypted before allowing access to a resource protected behind Cloudflare One.
+Cloudflare One enables you to restrict access to your applications to devices running the Cloudflare One Client. This allows you to flexibly ensure that a user's traffic is secure and encrypted before allowing access to a resource protected behind Cloudflare One.
## Prerequisites
@@ -24,8 +24,8 @@ Cloudflare One enables you to restrict access to your applications to devices ru
file="posture/prereqs-warp-is-deployed"
product="cloudflare-one"
params={{
- name: "WARP Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
+ name: "Cloudflare One Client Checks",
+ link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
}}
/>
@@ -34,7 +34,7 @@ Cloudflare One enables you to restrict access to your applications to devices ru
1. In [Cloudflare One](https://one.dash.cloudflare.com), go to **Traffic policies** > **Traffic settings**.
2. Ensure that *Allow Secure Web Gateway to proxy traffic** is enabled.
3. Go to **Reusable components** > **Posture checks**.
-4. In **WARP client checks**, select **Add a check**.
+4. In **Cloudflare One Client checks**, select **Add a check**.
5. Select **WARP**, then select **Save**.
## 2. Add the check to an Access policy
@@ -49,4 +49,4 @@ Cloudflare One enables you to restrict access to your applications to devices ru
5. Save the Access application.
-Before granting access to the application, the policy will check that the device is running the WARP client.
+Before granting access to the application, the policy will check that the device is running the Cloudflare One Client.
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/sentinel-one.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/sentinel-one.mdx
index b24e4d30ff4..513e4b6a9bf 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/sentinel-one.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/sentinel-one.mdx
@@ -5,7 +5,7 @@ sidebar:
order: 11
head:
- tag: title
- content: SentinelOne - WARP client checks
+ content: SentinelOne - Cloudflare One Client checks
---
import { Render } from "~/components";
@@ -19,8 +19,8 @@ Cloudflare One can check if [SentinelOne](https://www.sentinelone.com/) is runni
file="posture/prereqs-warp-is-deployed"
product="cloudflare-one"
params={{
- name: "WARP Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
+ name: "Cloudflare One Client Checks",
+ link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
}}
/>
@@ -28,7 +28,7 @@ Cloudflare One can check if [SentinelOne](https://www.sentinelone.com/) is runni
1. In [Cloudflare One](https://one.dash.cloudflare.com), go to **Reusable components** > **Posture checks**.
-2. Go to **WARP client checks** and select **Add a check**.
+2. Go to **Cloudflare One Client checks** and select **Add a check**.
3. Select **SentinelOne**.
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/tanium.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/tanium.mdx
index e473c77e3c3..2ef8b6572a6 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/tanium.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/tanium.mdx
@@ -44,7 +44,7 @@ The integration does not currently support Safari.
2. In [Cloudflare One](https://one.dash.cloudflare.com), go to **Reusable components** > **Posture checks**.
-3. Go to **WARP client checks** and select **Add a check**.
+3. Go to **Cloudflare One Client checks** and select **Add a check**.
4. Select **Tanium** from the list of providers.
diff --git a/src/content/docs/cloudflare-one/roles-permissions.mdx b/src/content/docs/cloudflare-one/roles-permissions.mdx
index c4e09c85190..fb1d1b32653 100644
--- a/src/content/docs/cloudflare-one/roles-permissions.mdx
+++ b/src/content/docs/cloudflare-one/roles-permissions.mdx
@@ -28,7 +28,7 @@ Only Super Administrators will be able to assign or remove the following roles f
| Cloudflare CASB Read | ❌ | ❌ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✅ | ❌ |
| Cloudflare CASB | ❌ | ❌ | ✅ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ❌ | ✅ | ✅ |
-[^1]: The **Cloudflare Zero Trust** role grants administrator access to all Zero Trust products including Access, Gateway, WARP, Tunnel, Browser Isolation, CASB, DLP, DEX, and Email security.
+[^1]: The **Cloudflare Zero Trust** role grants administrator access to all Zero Trust products including Access, Gateway, the Cloudflare One Client, Tunnel, Browser Isolation, CASB, DLP, DEX, and Email security.
[^2]: Users with the **Cloudflare Zero Trust DNS Locations Write** role can view all DNS locations for an organization but can only create and edit [secure DNS locations](/cloudflare-one/networks/resolvers-and-proxies/dns/locations/#secure-dns-locations).
@@ -46,7 +46,7 @@ The Cloudflare Zero Trust PII role does not apply to Access authentication logs.
For more information on Email security roles, refer to [Account-scoped roles](/fundamentals/manage-members/roles/#account-scoped-roles).
-- **Cloudflare Zero Trust**: Can edit Cloudflare [Zero Trust](/cloudflare-one/). Grants administrator access to all Zero Trust products including Access, Gateway, WARP, Tunnel, Browser Isolation, CASB, DLP, DEX, and Email security.
+- **Cloudflare Zero Trust**: Can edit Cloudflare [Zero Trust](/cloudflare-one/). Grants administrator access to all Zero Trust products including Access, Gateway, the Cloudflare One Client, Tunnel, Browser Isolation, CASB, DLP, DEX, and Email security.
- **Cloudflare Zero Trust PII**: Can read PII in Zero Trust. This includes Email security.
- **Email security Analyst** and **Email security Configuration Admin**: Has full access to all admin features in Email security.
- **Email security Integration Admin**: Can read and set up integrations only.
diff --git a/src/content/docs/cloudflare-one/setup/replace-vpn/device-to-device.mdx b/src/content/docs/cloudflare-one/setup/replace-vpn/device-to-device.mdx
index 98bc6c49729..0b71ae60dc7 100644
--- a/src/content/docs/cloudflare-one/setup/replace-vpn/device-to-device.mdx
+++ b/src/content/docs/cloudflare-one/setup/replace-vpn/device-to-device.mdx
@@ -4,7 +4,7 @@ title: "Device to device"
sidebar:
order: 2
label: Device to device
-description: Create a secure peer-to-peer connection between two devices using the WARP client and Cloudflare's network.
+description: Create a secure peer-to-peer connection between two devices using the Cloudflare One Client and Cloudflare's network.
products:
- cloudflare-one
tags:
@@ -21,7 +21,7 @@ This guide follows the same steps as the **Get Started** onboarding wizard in th
## How it works
-The [WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) is an app that you install on each device you want to connect. When you sign in to your Cloudflare account through WARP (called "enrolling"), each device is assigned a [virtual IP address](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp/).
+The [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) is an app that you install on each device you want to connect. When you sign in to your Cloudflare account through the Cloudflare One Client (called "enrolling"), each device is assigned a [virtual IP address](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp/).
Devices use these virtual IPs to communicate with each other through Cloudflare's network. This works for most common types of network traffic, including web requests, remote desktop, file sharing, and ping.
@@ -34,7 +34,7 @@ Only devices signed in to your Cloudflare account can reach these addresses, so
## Step 1: Enroll your first device
-Enrollment permissions control which users can connect devices to your account. In this step, you set an enrollment email and download the WARP client. The email you provide becomes the first allowed login for your organization, and anyone with that email address can enroll a device.
+Enrollment permissions control which users can connect devices to your account. In this step, you set an enrollment email and download the Cloudflare One Client. The email you provide becomes the first allowed login for your organization, and anyone with that email address can enroll a device.
1. In [Cloudflare One](https://one.dash.cloudflare.com), select the **Get Started** tab.
2. For **Replace my client-based or site-to-site VPN**, select **Get started**.
@@ -42,7 +42,7 @@ Enrollment permissions control which users can connect devices to your account.
4. On the **Create a device mesh on Cloudflare's network** screen, select **Continue**.
5. Enter the email you want to use to enroll your first device.
6. Select your device's operating system.
-7. Select **Download to continue** to download the WARP client, or copy the download link to send to a different device.
+7. Select **Download to continue** to download the Cloudflare One Client, or copy the download link to send to a different device.
8. Select **Continue**.
:::note
@@ -64,7 +64,7 @@ Both devices must be enrolled in your Cloudflare account for the connection to w
1. Select the operating system of your second device.
2. Copy the download link and send it to your second device (for example, by email or messaging app), or select **Download to continue** if you are on that device.
3. On the second device, follow the same WARP installation and login steps from [Step 2](#step-2-complete-warp-setup).
-4. The WARP client should show as **Connected** on the second device.
+4. The Cloudflare One Client should show as **Connected** on the second device.
5. Select **Continue** in the dashboard.
## Step 4: Verify your connection
@@ -92,5 +92,5 @@ For in-depth guidance on policy design and device posture checks, refer to the [
If you have issues connecting, try these steps:
- **Windows users**: Windows Firewall blocks device-to-device traffic by default. You may need to add a firewall rule that allows incoming traffic from `100.96.0.0/12`. For details, refer to [Peer-to-peer connectivity](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp/#troubleshooting).
-- [Troubleshoot WARP](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/): resolve WARP client connection and enrollment issues.
-- [Peer-to-peer connectivity](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp/): review WARP-to-WARP setup details and firewall requirements.
+- [Troubleshoot WARP](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/): resolve Cloudflare One Client connection and enrollment issues.
+- [Peer-to-peer connectivity](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp/): review Peer-to-peer setup details and firewall requirements.
diff --git a/src/content/docs/cloudflare-one/setup/replace-vpn/device-to-network.mdx b/src/content/docs/cloudflare-one/setup/replace-vpn/device-to-network.mdx
index 5d801904750..daa630b3843 100644
--- a/src/content/docs/cloudflare-one/setup/replace-vpn/device-to-network.mdx
+++ b/src/content/docs/cloudflare-one/setup/replace-vpn/device-to-network.mdx
@@ -4,7 +4,7 @@ title: "Device to network"
sidebar:
order: 1
label: Device to network
-description: Connect a remote device to a private network using Cloudflare Tunnel and the WARP client.
+description: Connect a remote device to a private network using Cloudflare Tunnel and the Cloudflare One Client.
products:
- cloudflare-one
tags:
@@ -23,13 +23,13 @@ This guide follows the same steps as the **Get Started** onboarding wizard in th
[Cloudflare Tunnel](/cloudflare-one/networks/connectors/cloudflare-tunnel/) is a network connector that creates an outbound-only connection between your private network and Cloudflare. No open inbound ports or firewall changes are required.
-The [WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) is an app that you install on each user's device. It routes traffic through Cloudflare and into the tunnel, so users can reach internal resources from anywhere.
+The [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) is an app that you install on each user's device. It routes traffic through Cloudflare and into the tunnel, so users can reach internal resources from anywhere.
## Prerequisites
- A Cloudflare account with a Zero Trust organization. If you have not set this up, refer to [Get started](/cloudflare-one/setup/).
- A Linux, Windows, or macOS device on your private network to run the tunnel.
-- A Linux, Windows, or macOS device to install the WARP client on.
+- A Linux, Windows, or macOS device to install the Cloudflare One Client on.
## Step 1: Assign a Tunnel
@@ -73,11 +73,11 @@ Install the `cloudflared` connector on a device in your private network and run
## Step 4: Enroll your devices
-Device enrollment controls which users can connect their devices to your private network through Cloudflare. In this step, you register your first device by providing an email address and installing the WARP client.
+Device enrollment controls which users can connect their devices to your private network through Cloudflare. In this step, you register your first device by providing an email address and installing the Cloudflare One Client.
1. Enter the email you want to use to enroll your first device.
2. Select your device's operating system.
-3. Select **Download to continue** to download the WARP client, or copy the download link to send to a different device.
+3. Select **Download to continue** to download the Cloudflare One Client, or copy the download link to send to a different device.
4. Select **Continue**.
:::note
@@ -112,5 +112,5 @@ For in-depth guidance on policy design and device posture checks, refer to the [
If you have issues connecting, refer to these resources:
-- [Troubleshoot WARP](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/): resolve WARP client connection and enrollment issues.
+- [Troubleshoot WARP](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/): resolve Cloudflare One Client connection and enrollment issues.
- [Troubleshoot tunnels](/cloudflare-one/networks/connectors/cloudflare-tunnel/troubleshoot-tunnels/): diagnose tunnel connectivity and routing problems.
diff --git a/src/content/docs/cloudflare-one/team-and-resources/devices/device-registration.mdx b/src/content/docs/cloudflare-one/team-and-resources/devices/device-registration.mdx
index 000799396c0..f7296f97737 100644
--- a/src/content/docs/cloudflare-one/team-and-resources/devices/device-registration.mdx
+++ b/src/content/docs/cloudflare-one/team-and-resources/devices/device-registration.mdx
@@ -7,9 +7,9 @@ sidebar:
import { Render, TabItem, Tabs, APIRequest } from "~/components";
-A device registration represents an individual session of the [WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) on a physical device, linking a user (or service token) and the device to your [Zero Trust organization](/cloudflare-one/setup/#create-a-zero-trust-organization). A device registration is created when the WARP client first authenticates. Each device registration has associated configuration, which includes a unique public key, device profile, and virtual IP addresses (one IPv4 and one IPv6).
+A device registration represents an individual session of the [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) on a physical device, linking a user (or service token) and the device to your [Zero Trust organization](/cloudflare-one/setup/#create-a-zero-trust-organization). A device registration is created when the Cloudflare One Client first authenticates. Each device registration has associated configuration, which includes a unique public key, device profile, and virtual IP addresses (one IPv4 and one IPv6).
-A single physical device can have [multiple device registrations](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/windows-multiuser/), for example, if multiple users share a single laptop and each enrolls the WARP client with their own credentials.
+A single physical device can have [multiple device registrations](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/windows-multiuser/), for example, if multiple users share a single laptop and each enrolls the Cloudflare One Client with their own credentials.
## Key concepts
@@ -18,7 +18,7 @@ A single physical device can have [multiple device registrations](/cloudflare-on
| [User](/cloudflare-one/team-and-resources/users/seat-management/#manage-users) | An identity provider (IdP)-backed human identity that can connect new devices to your Zero Trust organization. |
| [Seat](/cloudflare-one/team-and-resources/users/seat-management/) | A unique, billable user within your Zero Trust organization who has performed [an authentication event](/cloudflare-one/team-and-resources/users/seat-management/#authentication-events). Service tokens do not consume seats. |
| [Service token](/cloudflare-one/access-controls/service-credentials/service-tokens/) | A token used by automated systems (a non-human identity) to authenticate against your Cloudflare One policies. |
-| Device registration | An individual session of the WARP client on a physical device, with associated configuration including a unique public key, device profile, and [virtual IP addresses](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-ips/) (one IPv4 and one IPv6). |
+| Device registration | An individual session of the Cloudflare One Client on a physical device, with associated configuration including a unique public key, device profile, and [virtual IP addresses](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-ips/) (one IPv4 and one IPv6). |
| [Session](/cloudflare-one/access-controls/access-settings/session-management/) | JSON Web Tokens (JWTs) that are generated when Access validates user identity against your Access policies and determines how long a user can access an Access application without re-authenticating. Unlike these session-based tokens, device registration is a persistent state that does not expire and will exist until permanently deleted. |
## Review device registration status
@@ -97,7 +97,7 @@ Registrations can have the following statuses:
| Status | Description |
| --- | --- |
-| **Active** | Registered and able to connect via WARP. This is the expected operational state. |
+| **Active** | Registered and able to connect via the Cloudflare One Client. This is the expected operational state. |
| **Revoked** | The registration's public key is invalidated. Revocation does not release the assigned virtual IP addresses. |
@@ -139,7 +139,7 @@ The device registration is now permanently deleted, and its virtual IP address i
:::caution[Automatic device re-registration]
-If you delete a device registration, but the WARP client remains installed and is successfully able to re-authenticate, a new device registration will be created for the user or service token. For long-term, permanent denial of access, you should [remove the user from your device enrollment policies or your IdP](/cloudflare-one/team-and-resources/devices/device-registration/#remove-user-access) or [remove service token access](/cloudflare-one/team-and-resources/devices/device-registration/#remove-service-token-access).
+If you delete a device registration, but the Cloudflare One Client remains installed and is successfully able to re-authenticate, a new device registration will be created for the user or service token. For long-term, permanent denial of access, you should [remove the user from your device enrollment policies or your IdP](/cloudflare-one/team-and-resources/devices/device-registration/#remove-user-access) or [remove service token access](/cloudflare-one/team-and-resources/devices/device-registration/#remove-service-token-access).
:::
@@ -166,7 +166,7 @@ Devices that have zero active registrations (because all registrations were dele
:::caution[Automatic device re-creation]
-If you delete a device record, but the WARP client remains installed and a user or service token is successfully able to re-authenticate, a device record will be automatically created in your dashboard with a new device registration. For permanent deletion, you should [remove service token access](/cloudflare-one/team-and-resources/devices/device-registration/#remove-service-token-access).
+If you delete a device record, but the Cloudflare One Client remains installed and a user or service token is successfully able to re-authenticate, a device record will be automatically created in your dashboard with a new device registration. For permanent deletion, you should [remove service token access](/cloudflare-one/team-and-resources/devices/device-registration/#remove-service-token-access).
:::
diff --git a/src/content/docs/cloudflare-one/team-and-resources/devices/user-side-certificates/automated-deployment.mdx b/src/content/docs/cloudflare-one/team-and-resources/devices/user-side-certificates/automated-deployment.mdx
index 95ad4fadf66..3b84cad7834 100644
--- a/src/content/docs/cloudflare-one/team-and-resources/devices/user-side-certificates/automated-deployment.mdx
+++ b/src/content/docs/cloudflare-one/team-and-resources/devices/user-side-certificates/automated-deployment.mdx
@@ -1,6 +1,6 @@
---
pcx_content_type: how-to
-title: Install certificate using WARP
+title: Install certificate using the Cloudflare One Client
sidebar:
order: 1
head: []
@@ -11,11 +11,11 @@ import { Details, Render } from "~/components";
-| [WARP modes](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/) | [Zero Trust plans](https://www.cloudflare.com/teams-pricing/) |
+| [Client modes](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/) | [Zero Trust plans](https://www.cloudflare.com/teams-pricing/) |
| ---------------------------------------------------------------------------------------- | ------------------------------------------------------------- |
| All modes | All plans |
-| System | Availability | Minimum WARP version |
+| System | Availability | Minimum client version |
| ------------------- | ------------ | -------------------- |
| Windows | ✅ | 2024.12.554.0 |
| macOS | ✅ | 2024.12.554.0 |
@@ -27,33 +27,33 @@ import { Details, Render } from "~/components";
* Only supported on Debian-based systems.
-The [WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) can automatically install a Cloudflare certificate or [custom root certificate](/cloudflare-one/team-and-resources/devices/user-side-certificates/custom-certificate/) on Windows, macOS, and Debian/Ubuntu Linux devices. On mobile devices and Red Hat-based systems, you will need to [install the certificate manually](/cloudflare-one/team-and-resources/devices/user-side-certificates/manual-deployment/).
+The [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) can automatically install a Cloudflare certificate or [custom root certificate](/cloudflare-one/team-and-resources/devices/user-side-certificates/custom-certificate/) on Windows, macOS, and Debian/Ubuntu Linux devices. On mobile devices and Red Hat-based systems, you will need to [install the certificate manually](/cloudflare-one/team-and-resources/devices/user-side-certificates/manual-deployment/).
The certificate is required if you want to [apply HTTP policies to encrypted websites](/cloudflare-one/traffic-policies/http-policies/tls-decryption/), display custom [block pages](/cloudflare-one/reusable-components/custom-pages/gateway-block-page/), and more.
-## Install a certificate using WARP
+## Install a certificate using the Cloudflare One Client
-To configure WARP to install a root certificate on your organization's devices:
+To configure the Cloudflare One Client to install a root certificate on your organization's devices:
1. (Optional) [Upload](/cloudflare-one/team-and-resources/devices/user-side-certificates/custom-certificate/) a custom root certificate to Cloudflare.
2. In [Cloudflare One](https://one.dash.cloudflare.com/), go to **Team & Resources** > **Devices** > **Management**.
-3. Under **Global WARP settings**, turn on [**Install CA to system certificate store**](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/#install-ca-to-system-certificate-store).
-4. [Install](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/) the WARP client on the device.
+3. Under **Global Cloudflare One Client settings**, turn on [**Install CA to system certificate store**](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/#install-ca-to-system-certificate-store).
+4. [Install](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/) the Cloudflare One Client on the device.
5. [Enroll the device](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/manual-deployment/) in your Zero Trust organization.
6. (Optional) If the device is running macOS Big Sur or newer, [manually trust the certificate](#manually-trust-the-certificate).
-WARP will now download any [certificates set to **Available**](/cloudflare-one/team-and-resources/devices/user-side-certificates/#activate-a-root-certificate). After download, WARP will add the certificates to the device's system certificate store in `installed_certs/.pem` and append the contents to the `installed_cert.pem` file. If you have any scripts using `installed_cert.pem`, Cloudflare recommends you set them to use the individual files in the `installed_certs/` directory instead. `installed_certs.pem` will be deprecated by 2025-06-31.
+the Cloudflare One Client will now download any [certificates set to **Available**](/cloudflare-one/team-and-resources/devices/user-side-certificates/#activate-a-root-certificate). After download, the Cloudflare One Client will add the certificates to the device's system certificate store in `installed_certs/.pem` and append the contents to the `installed_cert.pem` file. If you have any scripts using `installed_cert.pem`, Cloudflare recommends you set them to use the individual files in the `installed_certs/` directory instead. `installed_certs.pem` will be deprecated by 2025-06-31.
:::note
:::
-WARP does not install certificates to individual applications. You will need to [manually add certificates](/cloudflare-one/team-and-resources/devices/user-side-certificates/manual-deployment/#add-the-certificate-to-applications) to applications that rely on their own certificate store instead of the system certificate store.
+the Cloudflare One Client does not install certificates to individual applications. You will need to [manually add certificates](/cloudflare-one/team-and-resources/devices/user-side-certificates/manual-deployment/#add-the-certificate-to-applications) to applications that rely on their own certificate store instead of the system certificate store.
## Access the installed certificate
-After installing the certificate using WARP, you can verify successful installation by accessing the device's system certificate store.
+After installing the certificate using the Cloudflare One Client, you can verify successful installation by accessing the device's system certificate store.
### macOS
@@ -64,7 +64,7 @@ To access the installed certificate in macOS:
3. Open your certificate. The default Cloudflare certificate name is **Gateway CA - Cloudflare Managed G1**.
4. If the certificate is trusted by all users, Keychain Access will display **This certificate is marked as trusted for all users**.
-The WARP client will also place the certificate in `/Library/Application Support/Cloudflare/installed_cert.pem` for reference by scripts or tools.
+The Cloudflare One Client will also place the certificate in `/Library/Application Support/Cloudflare/installed_cert.pem` for reference by scripts or tools.
#### Manually trust the certificate
@@ -85,11 +85,11 @@ To access the installed certificate in Windows:
2. Enter `certlm.msc`.
3. Go to **Trusted Root Certification Authority** > **Certificates**. The default Cloudflare certificate name is **Gateway CA - Cloudflare Managed G1**.
-The WARP client will also place the certificate in `%PROGRAMDATA%\Cloudflare\installed_cert.pem` for reference by scripts or tools.
+The Cloudflare One Client will also place the certificate in `%PROGRAMDATA%\Cloudflare\installed_cert.pem` for reference by scripts or tools.
### Debian-based Linux distributions
-On Debian-based Linux distributions, the certificate is stored in `/usr/local/share/ca-certificates`. The default installed Cloudflare certificate name is `managed-warp.pem`. The WARP client will create a symbolic link named `managed-warp.crt` to use as its root certificate. If your system is not using `managed-warp.crt`, run the following commands to update the system store:
+On Debian-based Linux distributions, the certificate is stored in `/usr/local/share/ca-certificates`. The default installed Cloudflare certificate name is `managed-warp.pem`. The Cloudflare One Client will create a symbolic link named `managed-warp.crt` to use as its root certificate. If your system is not using `managed-warp.crt`, run the following commands to update the system store:
1. Update your list of custom CA certificates.
@@ -114,10 +114,10 @@ On Debian-based Linux distributions, the certificate is stored in `/usr/local/sh
-rw-r--r-- 1 root root 1139 Jan 3 21:46 managed-warp.pem
```
-The WARP client will also place the certificate in `/var/lib/cloudflare-warp/installed_cert.pem` for reference by scripts or tools.
+The Cloudflare One Client will also place the certificate in `/var/lib/cloudflare-warp/installed_cert.pem` for reference by scripts or tools.
## Uninstall the certificate
-If the certificate was installed by the WARP client, it is automatically removed when you turn on another certificate for inspection in Cloudflare One, turn off **Install CA to system certificate store**, or [uninstall WARP](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/uninstall/). WARP does not remove certificates that were installed manually (for example, certificates added to third-party applications).
+If the certificate was installed by the Cloudflare One Client, it is automatically removed when you turn on another certificate for inspection in Cloudflare One, turn off **Install CA to system certificate store**, or [uninstall the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/uninstall/). the Cloudflare One Client does not remove certificates that were installed manually (for example, certificates added to third-party applications).
To manually remove the certificate, refer to the instructions supplied by your operating system or the third-party application.
diff --git a/src/content/docs/cloudflare-one/team-and-resources/devices/user-side-certificates/custom-certificate.mdx b/src/content/docs/cloudflare-one/team-and-resources/devices/user-side-certificates/custom-certificate.mdx
index 145880e0145..cba15291218 100644
--- a/src/content/docs/cloudflare-one/team-and-resources/devices/user-side-certificates/custom-certificate.mdx
+++ b/src/content/docs/cloudflare-one/team-and-resources/devices/user-side-certificates/custom-certificate.mdx
@@ -149,7 +149,7 @@ You can upload a single root certificate or a full certificate chain. When uploa
}
```
-4. (Optional) Verify the certificate is installed on your user's devices either [with WARP](/cloudflare-one/team-and-resources/devices/user-side-certificates/automated-deployment/) or [manually](/cloudflare-one/team-and-resources/devices/user-side-certificates/manual-deployment/).
+4. (Optional) Verify the certificate is installed on your user's devices either [with the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/user-side-certificates/automated-deployment/) or [manually](/cloudflare-one/team-and-resources/devices/user-side-certificates/manual-deployment/).
5. Use the [Patch Zero Trust account configuration endpoint](/api/resources/zero_trust/subresources/gateway/subresources/configurations/methods/edit/) to turn on the certificate for use in inspection. For example:
diff --git a/src/content/docs/cloudflare-one/team-and-resources/devices/user-side-certificates/index.mdx b/src/content/docs/cloudflare-one/team-and-resources/devices/user-side-certificates/index.mdx
index af7b63e48f3..d4cfa381efb 100644
--- a/src/content/docs/cloudflare-one/team-and-resources/devices/user-side-certificates/index.mdx
+++ b/src/content/docs/cloudflare-one/team-and-resources/devices/user-side-certificates/index.mdx
@@ -25,7 +25,7 @@ Zero Trust will indicate if a certificate is ready for use in inspection based o
| -------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Inactive | The certificate has been generated by or uploaded to Cloudflare but is not deployed across the global network. |
| Pending | The certificate is being activated or deactivated for use. |
-| Available | The certificate is deployed across the Cloudflare global network and ready to be turned on. The WARP client will install the certificate on your users' devices. |
+| Available | The certificate is deployed across the Cloudflare global network and ready to be turned on. The Cloudflare One Client will install the certificate on your users' devices. |
| Available and In-Use | The certificate is turned on. Gateway will use the certificate for inspection. |
## Generate a Cloudflare root certificate
@@ -86,7 +86,7 @@ Send a `POST` request to the [Activate a Zero Trust certificate](/api/resources/
-The status of the certificate will change to **Pending** while it deploys. Once the status of your certificate is **Available**, you can install it on your user's devices either [with WARP](/cloudflare-one/team-and-resources/devices/user-side-certificates/automated-deployment/) or [manually](/cloudflare-one/team-and-resources/devices/user-side-certificates/manual-deployment/).
+The status of the certificate will change to **Pending** while it deploys. Once the status of your certificate is **Available**, you can install it on your user's devices either [with the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/user-side-certificates/automated-deployment/) or [manually](/cloudflare-one/team-and-resources/devices/user-side-certificates/manual-deployment/).
Once you deploy and install your certificate, you can turn it on for use in inspection:
diff --git a/src/content/docs/cloudflare-one/team-and-resources/devices/user-side-certificates/manual-deployment.mdx b/src/content/docs/cloudflare-one/team-and-resources/devices/user-side-certificates/manual-deployment.mdx
index 11c33f13f4f..442baece9f4 100644
--- a/src/content/docs/cloudflare-one/team-and-resources/devices/user-side-certificates/manual-deployment.mdx
+++ b/src/content/docs/cloudflare-one/team-and-resources/devices/user-side-certificates/manual-deployment.mdx
@@ -11,10 +11,10 @@ description: Manually add a Cloudflare certificate to mobile devices and
import { Details, Render, TabItem, Tabs } from "~/components";
:::note
-This procedure is only required to enable specific Cloudflare Zero Trust features, and should only be done at the direction of your IT department. This procedure is not required to enable the WARP client for consumers.
+This procedure is only required to enable specific Cloudflare Zero Trust features, and should only be done at the direction of your IT department. This procedure is not required to enable the Cloudflare One Client for consumers.
:::
-If your device does not support [certificate installation via WARP](/cloudflare-one/team-and-resources/devices/user-side-certificates/automated-deployment/), you can manually install a Cloudflare certificate. You must add the certificate to both the [system keychain](#add-the-certificate-to-operating-systems) and to [individual application stores](#add-the-certificate-to-applications). These steps must be performed on each new device that is to be subject to HTTP filtering.
+If your device does not support [certificate installation via the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/user-side-certificates/automated-deployment/), you can manually install a Cloudflare certificate. You must add the certificate to both the [system keychain](#add-the-certificate-to-operating-systems) and to [individual application stores](#add-the-certificate-to-applications). These steps must be performed on each new device that is to be subject to HTTP filtering.
Zero Trust will only inspect traffic using installed certificates set to [**Available** and **In-Use**](/cloudflare-one/team-and-resources/devices/user-side-certificates/#activate-a-root-certificate).
@@ -27,7 +27,7 @@ To install a certificate manually, you must:
## 1. Download a Cloudflare root certificate
:::note[Download limitation]
-You can only download Cloudflare-generated certificates from the Cloudflare One dashboard or with WARP.
+You can only download Cloudflare-generated certificates from the Cloudflare One dashboard or with the Cloudflare One Client.
:::
First, [generate](/cloudflare-one/team-and-resources/devices/user-side-certificates/#generate-a-cloudflare-root-certificate) and download a Cloudflare certificate. The certificate is available in both `.pem` and `.crt` file format. Certain applications require the certificate to be in a specific file type, so ensure you download the most appropriate file for your use case.
@@ -38,7 +38,7 @@ First, [generate](/cloudflare-one/team-and-resources/devices/user-side-certifica
4. Select **More actions**.
5. Depending on which format you want, choose **Download .pem** and/or **Download .crt**.
-Alternatively, you can download and install a certificate [using WARP](/cloudflare-one/team-and-resources/devices/user-side-certificates/automated-deployment/#install-a-certificate-using-warp). WARP will add the certificates to the device's system certificate store in `installed_certs/.pem`.
+Alternatively, you can download and install a certificate [using the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/user-side-certificates/automated-deployment/#install-a-certificate-using-warp). the Cloudflare One Client will add the certificates to the device's system certificate store in `installed_certs/.pem`.
## 2. Verify the downloaded certificate
@@ -110,7 +110,7 @@ Some applications require a certificate formatted in the `.cer` file type. You c
## 4. Add the certificate to operating systems
-If you are deploying the Cloudflare certificate to desktop devices, use the [Install certificate using WARP](/cloudflare-one/team-and-resources/devices/user-side-certificates/automated-deployment/) method.
+If you are deploying the Cloudflare certificate to desktop devices, use the [Install certificate using the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/user-side-certificates/automated-deployment/) method.
Mobile devices require manual installations detailed in the instructions below.
@@ -188,7 +188,7 @@ Windows offers two locations to install the certificate, each impacting which us
The root certificate is now installed and ready to be used.
:::caution
-If your certificate is installed in the **Local Machine Store**, the [device posture check](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/) looking for a certificate will fail. Install the certificate in the **Current User Store** to ensure a successful posture device check.
+If your certificate is installed in the **Local Machine Store**, the [device posture check](/cloudflare-one/reusable-components/posture-checks/client-checks/) looking for a certificate will fail. Install the certificate in the **Current User Store** to ensure a successful posture device check.
:::
### Linux
@@ -326,7 +326,7 @@ Some applications require the use of a publicly trusted certificate — they do
:::
:::caution
-Even if you deployed WARP through the [Install certificate using WARP](/cloudflare-one/team-and-resources/devices/user-side-certificates/automated-deployment/) method, you may still need to add the Cloudflare certificate to certain applications. The Install certificate using WARP method only installs the Cloudflare certificate to the operating system certificate store.
+Even if you deployed WARP through the [Install certificate using the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/user-side-certificates/automated-deployment/) method, you may still need to add the Cloudflare certificate to certain applications. The Install certificate using the Cloudflare One Client method only installs the Cloudflare certificate to the operating system certificate store.
:::
### Browsers
@@ -365,7 +365,7 @@ For information on installing a Cloudflare certificate for organizations, refer
### Mobile device management (MDM) software
-Zero Trust integrates with several [mobile device management (MDM) software partners](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/partners/) to deploy WARP across devices.
+Zero Trust integrates with several [mobile device management (MDM) software partners](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/partners/) to deploy the Cloudflare One Client across devices.
#### Microsoft Intune
diff --git a/src/content/docs/cloudflare-one/team-and-resources/users/scim.mdx b/src/content/docs/cloudflare-one/team-and-resources/users/scim.mdx
index 2ab57ac3d64..42d60886593 100644
--- a/src/content/docs/cloudflare-one/team-and-resources/users/scim.mdx
+++ b/src/content/docs/cloudflare-one/team-and-resources/users/scim.mdx
@@ -24,7 +24,7 @@ Cloudflare Access supports SCIM provisioning for all SAML and OIDC identity prov
## Sync users and groups in Zero Trust policies
-Cloudflare Access can automatically deprovision users from Zero Trust after they are deactivated in the identity provider and display synchronized group names in the Access and Gateway policy builders. Cloudflare does not provision new users in Zero Trust when they are added to the identity provider -- users must first register a device with the WARP client or authenticate to an Access application.
+Cloudflare Access can automatically deprovision users from Zero Trust after they are deactivated in the identity provider and display synchronized group names in the Access and Gateway policy builders. Cloudflare does not provision new users in Zero Trust when they are added to the identity provider -- users must first register a device with the Cloudflare One Client or authenticate to an Access application.
To set up SCIM for Zero Trust, refer to our [SSO integration](/cloudflare-one/integrations/identity-providers/) guides.
diff --git a/src/content/docs/cloudflare-one/team-and-resources/users/users.mdx b/src/content/docs/cloudflare-one/team-and-resources/users/users.mdx
index 114438c3af4..e7181a77e36 100644
--- a/src/content/docs/cloudflare-one/team-and-resources/users/users.mdx
+++ b/src/content/docs/cloudflare-one/team-and-resources/users/users.mdx
@@ -13,11 +13,11 @@ User logs show a list of all users who have authenticated to Cloudflare One. For
In [Cloudflare One](https://one.dash.cloudflare.com/), go to **Teams & Resources** > **Users**.
-This page lists all users who have registered the WARP client or authenticated to a Cloudflare Access application. You can select a user's name to view detailed logs, [revoke their session](/cloudflare-one/access-controls/access-settings/session-management/#revoke-user-sessions), or [remove their seat](/cloudflare-one/team-and-resources/users/seat-management/).
+This page lists all users who have registered the Cloudflare One Client or authenticated to a Cloudflare Access application. You can select a user's name to view detailed logs, [revoke their session](/cloudflare-one/access-controls/access-settings/session-management/#revoke-user-sessions), or [remove their seat](/cloudflare-one/team-and-resources/users/seat-management/).
### Available logs
* **User Registry identity**: Select the user's name to view their last seen identity. This identity is used to evaluate Gateway policies and WARP [device profiles](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-profiles/). A refresh occurs when the user re-authenticates WARP, logs into an Access application, or has their IdP group membership updated via SCIM provisioning. To track how the user's identity has changed over time, go to the **Audit logs** tab.
* **Session identities**: The user's active sessions, the identity used to authenticate each session, and when each session will [expire](/cloudflare-one/access-controls/access-settings/session-management/).
-* **Devices**: Devices registered to the user via WARP.
+* **Devices**: Devices registered to the user via the Cloudflare One Client.
* **Recent activities**: The user's five most recent Access login attempts. For more details, refer to your [authentication audit logs](/cloudflare-one/insights/logs/audit-logs/#authentication-audit-logs).
diff --git a/src/content/docs/cloudflare-one/traffic-policies/dns-policies/index.mdx b/src/content/docs/cloudflare-one/traffic-policies/dns-policies/index.mdx
index db2aed7d3b1..e72ecd40b03 100644
--- a/src/content/docs/cloudflare-one/traffic-policies/dns-policies/index.mdx
+++ b/src/content/docs/cloudflare-one/traffic-policies/dns-policies/index.mdx
@@ -149,7 +149,7 @@ If the block page is turned off for a policy, Gateway will respond to queries bl
-#### WARP client block notifications
+#### Cloudflare One Client block notifications
@@ -107,7 +107,7 @@ Gateway does not currently support hostname-based filtering for traffic on non-`
## 5. Test the connection
-From a WARP device, open a browser and go to `app.bank.com`.
+From a device, open a browser and go to `app.bank.com`.
You can search for `app.bank.com` in your [Gateway DNS logs](/cloudflare-one/insights/logs/gateway-logs/); the **DNS response details** section should show the public resolved IPs as well as an initial resolved IP. You can also check your [Cloudflare Tunnel logs](/cloudflare-one/networks/connectors/cloudflare-tunnel/monitor-tunnels/logs/) to confirm that requests are routing through the tunnel to the public resolved IPs.
diff --git a/src/content/docs/cloudflare-one/traffic-policies/egress-policies/host-selectors.mdx b/src/content/docs/cloudflare-one/traffic-policies/egress-policies/host-selectors.mdx
index d38d77e777c..94789f1fbb9 100644
--- a/src/content/docs/cloudflare-one/traffic-policies/egress-policies/host-selectors.mdx
+++ b/src/content/docs/cloudflare-one/traffic-policies/egress-policies/host-selectors.mdx
@@ -9,11 +9,11 @@ import { Tabs, TabItem, Details, APIRequest, Render } from "~/components";
-| [WARP modes](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/) | [Zero Trust plans](https://www.cloudflare.com/teams-pricing/) |
+| [Client modes](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/) | [Zero Trust plans](https://www.cloudflare.com/teams-pricing/) |
| ---------------------------------------------------------------------------------------- | ------------------------------------------------------------- |
| Traffic and DNS mode | Enterprise |
-| System | Availability | Minimum WARP version |
+| System | Availability | Minimum client version |
| -------- | ------------ | -------------------- |
| Windows | ✅ | 2025.4.929.0 |
| macOS | ✅ | 2025.4.929.0 |
@@ -63,7 +63,7 @@ Traffic must be on-ramped to Gateway with the following methods:
| On-ramp method | Compatibility |
| --------------------------------------------------------------------------------------------------- | ------------- |
-| [WARP](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) | ✅ |
+| [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) | ✅ |
| [PAC files](/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/) | ✅ |
| [Browser Isolation](/cloudflare-one/remote-browser-isolation/) | ✅ |
| [WARP Connector](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/) | ❌ |
@@ -75,10 +75,10 @@ Unsupported traffic will be resolved with your default Gateway settings. If you
To configure your Zero Trust organization to use Host selectors with Egress policies:
-1. Make sure you deploy the following version of WARP on your users' devices:
- - **Desktop**: [WARP version 2025.4.929.0](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/) or later
- - **iOS**: [WARP version 1.11](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/#ios) or later
- - **Android and Chrome OS**: [WARP version 2.4.2](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/#android) or later.
+1. Make sure you deploy the following version of the Cloudflare One Client on your users' devices:
+ - **Desktop**: [Cloudflare One Client version 2025.4.929.0](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/) or later
+ - **iOS**: [Cloudflare One Client version 1.11](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/#ios) or later
+ - **Android and Chrome OS**: [Cloudflare One Client version 2.4.2](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/#android) or later.
If you need to support devices running prior versions of WARP, add and deploy the following key-value pair to your devices' [WARP configuration file](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/) (`mdm.xml` on Windows and Linux or `com.cloudflare.warp.plist` on macOS):
@@ -95,7 +95,7 @@ To configure your Zero Trust organization to use Host selectors with Egress poli
2.
-The WARP client must be set to _Traffic and DNS mode_ mode for traffic affected by these selectors to route correctly.
+The Cloudflare One Client must be set to _Traffic and DNS mode_ mode for traffic affected by these selectors to route correctly.
{/* prettier-ignore-end */}
diff --git a/src/content/docs/cloudflare-one/traffic-policies/egress-policies/index.mdx b/src/content/docs/cloudflare-one/traffic-policies/egress-policies/index.mdx
index 0014dd770a9..8031a32aa88 100644
--- a/src/content/docs/cloudflare-one/traffic-policies/egress-policies/index.mdx
+++ b/src/content/docs/cloudflare-one/traffic-policies/egress-policies/index.mdx
@@ -19,11 +19,11 @@ import {
Only available on Enterprise plans.
:::
-When your users connect to the Internet through Cloudflare Gateway, by default their traffic is assigned a source IP address that is shared across all Cloudflare WARP users. Enterprise users can purchase [dedicated egress IPs](/cloudflare-one/traffic-policies/egress-policies/dedicated-egress-ips/) to ensure that egress traffic from your organization is assigned a unique, static IP. These source IPs are dedicated to your account and can be used within allowlists on upstream services.
+When your users connect to the Internet through Cloudflare Gateway, by default their traffic is assigned a source IP address that is shared across all the Cloudflare One Client users. Enterprise users can purchase [dedicated egress IPs](/cloudflare-one/traffic-policies/egress-policies/dedicated-egress-ips/) to ensure that egress traffic from your organization is assigned a unique, static IP. These source IPs are dedicated to your account and can be used within allowlists on upstream services.
Egress policies allow you to control which dedicated egress IP is used and when, based on attributes such as identity, IP address, and geolocation. Traffic that does not match an egress policy will default to using the most performant dedicated egress IP.
-Cloudflare does not publish WARP egress IP ranges. WARP egress IPs are not documented at [Cloudflare's IP Ranges](https://cloudflare.com/ips). To obtain a dedicated WARP egress IP, contact your account team.
+Cloudflare does not publish Cloudflare One Client egress IP ranges. Cloudflare One Client egress IPs are not documented at [Cloudflare's IP Ranges](https://cloudflare.com/ips). To obtain a dedicated Cloudflare One Client egress IP, contact your account team.
diff --git a/src/content/docs/cloudflare-one/traffic-policies/get-started/dns.mdx b/src/content/docs/cloudflare-one/traffic-policies/get-started/dns.mdx
index 7bb1078e029..90dffcc4935 100644
--- a/src/content/docs/cloudflare-one/traffic-policies/get-started/dns.mdx
+++ b/src/content/docs/cloudflare-one/traffic-policies/get-started/dns.mdx
@@ -35,8 +35,8 @@ You can filter DNS queries from individual devices (for example, employee laptop
To filter DNS requests from an individual device such as a laptop or phone:
-1. [Install the WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/) on your device. WARP is a lightweight agent that routes the device's DNS queries through Cloudflare so Gateway can inspect and filter them.
-2. [Enroll the WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/manual-deployment/) in your organization's Zero Trust instance [^1]. This tells WARP which Gateway policies to enforce.
+1. [Install the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/) on your device. the Cloudflare One Client is a lightweight agent that routes the device's DNS queries through Cloudflare so Gateway can inspect and filter them.
+2. [Enroll the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/manual-deployment/) in your organization's Zero Trust instance [^1]. This tells WARP which Gateway policies to enforce.
3. (Optional) If you want to display a [custom block page](/cloudflare-one/reusable-components/custom-pages/gateway-block-page/) instead of a generic browser error when a request is blocked, [install a Cloudflare root certificate](/cloudflare-one/team-and-resources/devices/user-side-certificates/) on your device.
### Connect DNS locations
diff --git a/src/content/docs/cloudflare-one/traffic-policies/get-started/http.mdx b/src/content/docs/cloudflare-one/traffic-policies/get-started/http.mdx
index a342a0e991c..166d579a09f 100644
--- a/src/content/docs/cloudflare-one/traffic-policies/get-started/http.mdx
+++ b/src/content/docs/cloudflare-one/traffic-policies/get-started/http.mdx
@@ -21,13 +21,13 @@ For a more detailed guide to filtering HTTP requests and other traffic for your
## 1. Connect to Gateway
-HTTP filtering requires three components working together: the WARP client routes device traffic through Cloudflare, a root certificate lets Gateway decrypt HTTPS traffic so it can inspect URLs and content, and the Gateway proxy enables Gateway to intercept and evaluate HTTP requests. Without the certificate, Gateway can only see the domain name — not the full URL or request body.
+HTTP filtering requires three components working together: the Cloudflare One Client routes device traffic through Cloudflare, a root certificate lets Gateway decrypt HTTPS traffic so it can inspect URLs and content, and the Gateway proxy enables Gateway to intercept and evaluate HTTP requests. Without the certificate, Gateway can only see the domain name — not the full URL or request body.
To filter HTTP requests from a device:
1. [Install the Cloudflare root certificate](/cloudflare-one/team-and-resources/devices/user-side-certificates/) on your device.
-2. [Install the WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/) on your device.
-3. In the WARP client Settings, log in to your organization's Cloudflare One instance.
+2. [Install the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/) on your device.
+3. In the Cloudflare One Client Settings, log in to your organization's Cloudflare One instance.
4. [Enable the Gateway proxy](/cloudflare-one/traffic-policies/proxy/#turn-on-the-gateway-proxy) for TCP. Optionally, enable the UDP proxy to also inspect QUIC traffic on port 443 — this covers HTTP/3, a newer protocol some browsers use by default.
5. To inspect HTTPS traffic, [enable TLS decryption](/cloudflare-one/traffic-policies/http-policies/tls-decryption/#turn-on-tls-decryption). TLS decryption allows Gateway to read encrypted requests. Without it, Gateway can see that a user visited `example.com` but not which specific page or what they uploaded.
6. (Optional) To scan file uploads and downloads for malware, [enable anti-virus scanning](/cloudflare-one/traffic-policies/http-policies/antivirus-scanning/).
diff --git a/src/content/docs/cloudflare-one/traffic-policies/get-started/network.mdx b/src/content/docs/cloudflare-one/traffic-policies/get-started/network.mdx
index 97f3a5e03c9..321fc50d5e6 100644
--- a/src/content/docs/cloudflare-one/traffic-policies/get-started/network.mdx
+++ b/src/content/docs/cloudflare-one/traffic-policies/get-started/network.mdx
@@ -24,8 +24,8 @@ For a more detailed guide to filtering network traffic and more for your organiz
To filter network traffic from a device such as a laptop or phone:
-1. [Install the WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/) on your device.
-2. In the WARP client Settings, log in to your organization's Cloudflare One instance.
+1. [Install the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/) on your device.
+2. In the Cloudflare One Client Settings, log in to your organization's Cloudflare One instance.
3. (Optional) If you want to display a [custom block page](/cloudflare-one/reusable-components/custom-pages/gateway-block-page/) when users are blocked, [install the Cloudflare root certificate](/cloudflare-one/team-and-resources/devices/user-side-certificates/) on your device. Without the certificate, blocked users will see a generic browser connection error instead of an informative page.
4. [Enable the Gateway proxy](/cloudflare-one/traffic-policies/proxy/#turn-on-the-gateway-proxy) for TCP. The Gateway proxy is what routes your device's traffic through Cloudflare so network policies can inspect it — without it enabled, your policies will have no effect. Optionally, enable the UDP proxy to also inspect QUIC traffic (a newer protocol used by HTTP/3 connections) on port 443.
@@ -41,7 +41,7 @@ To verify your device is connected to Cloudflare One:
1. In [Cloudflare One](https://one.dash.cloudflare.com), go to **Traffic policies** > **Traffic settings**.
2. Under **Log traffic activity**, enable activity logging for all Network logs. This tells Cloudflare to record network-level traffic so you can confirm your device appears in the logs.
-3. On your WARP-enabled device, open a browser and visit any website. This generates traffic that should appear in the logs.
+3. On your Cloudflare One Client-enabled device, open a browser and visit any website. This generates traffic that should appear in the logs.
4. Determine the **Source IP** for your device (the public-facing address Cloudflare sees for your connection):
@@ -52,7 +52,7 @@ To verify your device is connected to Cloudflare One:
3. Note the **Client Interface IP**. This is the same address that will appear as the Source IP in your network logs.
- 1. Open the WARP client.
+ 1. Open the Cloudflare One Client.
2. Go to **Settings** (gear icon) **Preferences** > **General**.
3. Note the **Public IP**. This is the same address that will appear as the Source IP in your network logs.
@@ -61,7 +61,7 @@ To verify your device is connected to Cloudflare One:
5. In Cloudflare One, go to **Insights** > **Logs** > **Network logs**. Before building network policies, make sure you see network logs from the Source IP assigned to your device.
-If no logs appear after a few minutes, check two things: first, verify that the [Gateway proxy is turned on](/cloudflare-one/traffic-policies/proxy/#turn-on-the-gateway-proxy). Second, confirm that the device is enrolled in your Zero Trust organization by checking the WARP client connection status.
+If no logs appear after a few minutes, check two things: first, verify that the [Gateway proxy is turned on](/cloudflare-one/traffic-policies/proxy/#turn-on-the-gateway-proxy). Second, confirm that the device is enrolled in your Zero Trust organization by checking the Cloudflare One Client connection status.
## 3. Create your first network policy
diff --git a/src/content/docs/cloudflare-one/traffic-policies/global-policies.mdx b/src/content/docs/cloudflare-one/traffic-policies/global-policies.mdx
index 1c7d45cabd8..8570afc2686 100644
--- a/src/content/docs/cloudflare-one/traffic-policies/global-policies.mdx
+++ b/src/content/docs/cloudflare-one/traffic-policies/global-policies.mdx
@@ -56,7 +56,7 @@ Gateway enforces global DNS and resolver policies before any other policies. Thi
| Name | ID | Criteria | Value | Action | Description |
| --------------------------------------------------- | -------------------------------------- | -------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------- |
-| Allow CF Network Error Logging L4 | `00000001-e4af-4b82-8f8c-c79c1d5d212e` | Hostname | `*.nel.cloudflare.com` | allow | Allows SNI domains for WARP registration. |
+| Allow CF Network Error Logging L4 | `00000001-e4af-4b82-8f8c-c79c1d5d212e` | Hostname | `*.nel.cloudflare.com` | allow | Allows SNI domains for Cloudflare One Client registration. |
| Allow CF Client | `00000001-8c3d-4e27-a01b-af8418000077` | Hostname | `*.cloudflareclient.com` and `*.fed.cloudflareclient.com` | allow | Allows Zero Trust client. |
| Allow Gateway Proxy PAC | `00000001-776e-438d-9856-987d7053762b` | Hostname | `*.cloudflare-gateway.com` and `*.fed.cloudflare-gateway.com` | allow | Allows Gateway proxy with [PAC files](/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/). |
| Allow Zero Trust Services | `00000001-e1e8-421b-a0fe-895397489f28` | Hostname | `dash.teams.cloudflare.com`, `help.teams.cloudflare.com`, `blocked.teams.cloudflare.com`, `blocked.teams.fed.cloudflare.com`, `api.cloudflare.com`, `api.fed.cloudflare.com`, `cloudflarestatus.com`, `www.cloudflarestatus.com`, `one.dash.cloudflare.com`, `one.dash.fed.cloudflare.com`, `help.one.cloudflare.com`, `dash.cloudflare.com`, `dash.fed.cloudflare.com`, and `developers.cloudflare.com` | allow | Allows Cloudflare Zero Trust services. |
@@ -70,7 +70,7 @@ Gateway enforces global DNS and resolver policies before any other policies. Thi
| Prevent Account Change Block | `00000001-d1f2-461a-8253-501c8d882a15` | Hostname | `*.cloudflareclient.com` and `*.fed.cloudflareclient.com`; not `notifications.cloudflareclient.com` or `notifications.fed.cloudflareclient.com` | bypass | Ensures users cannot accidentally block themselves from making account changes. |
| Bypass RBI Assets | `00000001-df61-4068-aa6c-0f684c3cd4e6` | Hostname | `*.content.browser.run` | bypass | Required for [Browser Isolation](/cloudflare-one/remote-browser-isolation/). |
| Inspect RBI Urls | `00000001-3faa-4f59-98d4-0f6d6af4b6d0` | Hostname | `*.edge.browser.run` and `*.cloudflarebrowser.com` | bypass | Required for Browser Isolation. |
-| Allow Gateway Help Page | `00000001-8e9a-4429-b3c2-d267d0ce6114` | Hostname | `help.teams.cloudflare.com` and `help.one.cloudflare.com` | allow | Used by the WARP client to check if Gateway is on by inspecting the certificate and checking if it is properly installed on the client device. |
+| Allow Gateway Help Page | `00000001-8e9a-4429-b3c2-d267d0ce6114` | Hostname | `help.teams.cloudflare.com` and `help.one.cloudflare.com` | allow | Used by the Cloudflare One Client to check if Gateway is on by inspecting the certificate and checking if it is properly installed on the client device. |
| Bypass Gateway DNS | `00000001-d9c0-46b0-8704-2ea5b9d7bdfc` | Hostname | `*.cloudflare-gateway.com` and `*.fed.cloudflare-gateway.com` | bypass | Ensures requests to the `cloudflare-gateway.com` DNS endpoint will not be inspected. |
| Bypass CF Status | `00000001-5399-4b71-a9fc-d4d90ccf0758` | Hostname | `*.cloudflarestatus.com` | bypass | Bypasses `cloudflarestatus.com` so users can reach the status page in case of a Gateway outage. |
| Bypass CF Network Error Logging | `00000001-dfe0-4737-8d1e-8191e8f637df` | Hostname | `*.nel.cloudflare.com` | bypass | Bypasses `*.nel.cloudflarestatus.com` for Cloudflare's network error logging feature. |
diff --git a/src/content/docs/cloudflare-one/traffic-policies/http-policies/antivirus-scanning.mdx b/src/content/docs/cloudflare-one/traffic-policies/http-policies/antivirus-scanning.mdx
index dab9cf6db6e..6ed47f8b1ba 100644
--- a/src/content/docs/cloudflare-one/traffic-policies/http-policies/antivirus-scanning.mdx
+++ b/src/content/docs/cloudflare-one/traffic-policies/http-policies/antivirus-scanning.mdx
@@ -22,7 +22,7 @@ To turn on AV scanning:
When a request is blocked due to the presence of malware, Gateway will log the match as a Block decision in your [HTTP logs](/cloudflare-one/insights/logs/gateway-logs/#http-logs).
-### WARP client block notifications
+### Cloudflare One Client block notifications
**Account information** > **Re-authenticate** [^1]. This will open a browser window and prompt the user to log in.
+- In the Cloudflare One Client, re-authenticate the session by going to **Profile** > **Account information** > **Re-authenticate** [^1]. This will open a browser window and prompt the user to log in.
-[^1]: In WARP version 2026.1 and earlier, select **Preferences** > **Account** > **Re-Authenticate Session**.
+[^1]: In Cloudflare One Client version 2026.1 and earlier, select **Preferences** > **Account** > **Re-Authenticate Session**.
To view the identity that Gateway will use when evaluating policies, check the [user registry](/cloudflare-one/team-and-resources/users/users/).
diff --git a/src/content/docs/cloudflare-one/traffic-policies/index.mdx b/src/content/docs/cloudflare-one/traffic-policies/index.mdx
index 40c3d933973..ba9752a4c4f 100644
--- a/src/content/docs/cloudflare-one/traffic-policies/index.mdx
+++ b/src/content/docs/cloudflare-one/traffic-policies/index.mdx
@@ -82,7 +82,7 @@ For each policy type, follow this workflow:
3. Set up recommended security policies — for example, block all [security threat categories](/cloudflare-one/traffic-policies/domain-categories/#security-categories) with a DNS policy.
4. Add policies specific to your organization's needs.
-For example, if your goal is to prevent employees from accessing known malware domains, you would start by enrolling devices with the WARP client (step 1), confirm DNS queries appear in your Gateway logs (step 2), then create a DNS policy that blocks all security-risk categories (step 3).
+For example, if your goal is to prevent employees from accessing known malware domains, you would start by enrolling devices with the Cloudflare One Client (step 1), confirm DNS queries appear in your Gateway logs (step 2), then create a DNS policy that blocks all security-risk categories (step 3).
For step-by-step setup guides, refer to [DNS](/cloudflare-one/traffic-policies/get-started/dns/), [Network](/cloudflare-one/traffic-policies/get-started/network/), and [HTTP](/cloudflare-one/traffic-policies/get-started/http/) policies.
diff --git a/src/content/docs/cloudflare-one/traffic-policies/network-policies/common-policies.mdx b/src/content/docs/cloudflare-one/traffic-policies/network-policies/common-policies.mdx
index 50ad8120a09..7082542a101 100644
--- a/src/content/docs/cloudflare-one/traffic-policies/network-policies/common-policies.mdx
+++ b/src/content/docs/cloudflare-one/traffic-policies/network-policies/common-policies.mdx
@@ -84,7 +84,7 @@ In the following API examples, `filters: ["l4"]` indicates that this is a networ
## Enforce device posture
-Require devices to have certain software installed or other configuration attributes. For instructions on enabling a device posture check, refer to the [device posture section](/cloudflare-one/reusable-components/posture-checks/). For example, you can use a list of [device serial numbers](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/corp-device/) to ensure users can only access an application if they connect with the WARP client from a company device:
+Require devices to have certain software installed or other configuration attributes. For instructions on enabling a device posture check, refer to the [device posture section](/cloudflare-one/reusable-components/posture-checks/). For example, you can use a list of [device serial numbers](/cloudflare-one/reusable-components/posture-checks/client-checks/corp-device/) to ensure users can only access an application if they connect with the Cloudflare One Client from a company device:
-The ICMP proxy allows ICMP traffic to reach your private network through Gateway. For example, this would allow a WARP user to run diagnostic commands such as `ping` and `traceroute` to an internal server IP.
+The ICMP proxy allows ICMP traffic to reach your private network through Gateway. For example, this would allow a Cloudflare One Client user to run diagnostic commands such as `ping` and `traceroute` to an internal server IP.
:::caution[Limitation]
Gateway cannot log or filter ICMP traffic.
@@ -113,7 +113,7 @@ By default the [`cloudflared` Docker container](https://github.com/cloudflare/cl
## Turn on the Gateway proxy
-The Gateway proxy toggle only applies to traffic from WARP devices. Gateway will always proxy traffic sent with [PAC files](/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/) or [Browser Isolation](/cloudflare-one/remote-browser-isolation/) regardless of this setting.
+The Gateway proxy toggle only applies to traffic from the Cloudflare One Client devices. Gateway will always proxy traffic sent with [PAC files](/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/) or [Browser Isolation](/cloudflare-one/remote-browser-isolation/) regardless of this setting.
1. In [Cloudflare One](https://one.dash.cloudflare.com), go to **Traffic policies** > **Traffic settings**.
2. In **Proxy and inspection settings**, turn on **Allow Secure Web Gateway to proxy traffic**.
diff --git a/src/content/docs/cloudflare-one/traffic-policies/resolver-policies.mdx b/src/content/docs/cloudflare-one/traffic-policies/resolver-policies.mdx
index ed4b9b8563a..0ba00a377f0 100644
--- a/src/content/docs/cloudflare-one/traffic-policies/resolver-policies.mdx
+++ b/src/content/docs/cloudflare-one/traffic-policies/resolver-policies.mdx
@@ -50,7 +50,7 @@ To get started with resolving internal DNS queries with resolver policies, refer
### Local Domain Fallback
-If your resolver is only reachable by a client device and not by Gateway via a Cloudflare Tunnel, IPsec/GRE tunnel, or other public Internet connections, you should configure [Local Domain Fallback](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/local-domains/) for your device. If both Local Domain Fallback and resolver policies are configured for the same device, Cloudflare will apply your client-side Local Domain Fallback rules first. If you onboard DNS queries to Gateway with the WARP client and route them with resolver policies, the source IP of the queries will be the IP address assigned by the WARP client.
+If your resolver is only reachable by a client device and not by Gateway via a Cloudflare Tunnel, IPsec/GRE tunnel, or other public Internet connections, you should configure [Local Domain Fallback](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/local-domains/) for your device. If both Local Domain Fallback and resolver policies are configured for the same device, Cloudflare will apply your client-side Local Domain Fallback rules first. If you onboard DNS queries to Gateway with the Cloudflare One Client and route them with resolver policies, the source IP of the queries will be the IP address assigned by the Cloudflare One Client.
diff --git a/src/content/docs/cloudflare-one/traffic-policies/troubleshoot-gateway.mdx b/src/content/docs/cloudflare-one/traffic-policies/troubleshoot-gateway.mdx
index 31615fd3218..e7b7f620ea3 100644
--- a/src/content/docs/cloudflare-one/traffic-policies/troubleshoot-gateway.mdx
+++ b/src/content/docs/cloudflare-one/traffic-policies/troubleshoot-gateway.mdx
@@ -105,10 +105,10 @@ To resolve this issue:
## Private DNS and internal resources are not working
-You have configured Gateway to resolve internal hostnames, but users are unable to access them. For example, a user connected to WARP tries to access an internal service like `jira.mycompany.local`, but the DNS query fails.
+You have configured Gateway to resolve internal hostnames, but users are unable to access them. For example, a user connected to the Cloudflare One Client tries to access an internal service like `jira.mycompany.local`, but the DNS query fails.
| Common causes | Solution |
| ------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Missing or incorrect resolver policy | Go to **Traffic policies** > **Resolver policies**. Create a policy that matches your internal domain suffix and forwards queries to your internal DNS servers' IP addresses. |
-| Split Tunnel excludes the private IP range | If your internal resources are in a private IP range (such as `10.0.0.0/8`), that range must be included in the tunnel. If it is in the Exclude list of your Split Tunnel configuration, WARP will not proxy the traffic. |
+| Split Tunnel excludes the private IP range | If your internal resources are in a private IP range (such as `10.0.0.0/8`), that range must be included in the tunnel. If it is in the Exclude list of your Split Tunnel configuration, the Cloudflare One Client will not proxy the traffic. |
| Local Domain Fallback misconfiguration | Use resolver policies for corporate DNS. Only use Local Domain Fallback for domains specific to a user's immediate physical network. |
diff --git a/src/content/docs/cloudflare-one/tutorials/clientless-access-private-dns.mdx b/src/content/docs/cloudflare-one/tutorials/clientless-access-private-dns.mdx
index 88fb787577a..b45a04bf9d1 100644
--- a/src/content/docs/cloudflare-one/tutorials/clientless-access-private-dns.mdx
+++ b/src/content/docs/cloudflare-one/tutorials/clientless-access-private-dns.mdx
@@ -13,7 +13,7 @@ tags:
import { Render } from "~/components";
-With Cloudflare Browser Isolation and resolver policies, users can connect to private web-based applications via their private hostnames without needing to install the WARP client. By the end of this tutorial, users who pass your Gateway DNS and network policies will be able to access your private application at `https://.cloudflareaccess.com/browser/https://internalrecord.com`.
+With Cloudflare Browser Isolation and resolver policies, users can connect to private web-based applications via their private hostnames without needing to install the Cloudflare One Client. By the end of this tutorial, users who pass your Gateway DNS and network policies will be able to access your private application at `https://.cloudflareaccess.com/browser/https://internalrecord.com`.
## Before you begin
@@ -93,7 +93,7 @@ To test, open a browser and go to `https://.cloudflareaccess.com/brow
:::note
-Device posture checks are not supported because they require the WARP client.
+Device posture checks are not supported because they require the Cloudflare One Client.
:::
diff --git a/src/content/docs/cloudflare-one/tutorials/m365-dedicated-egress-ips.mdx b/src/content/docs/cloudflare-one/tutorials/m365-dedicated-egress-ips.mdx
index 64af3b40db3..5870cd5c9f1 100644
--- a/src/content/docs/cloudflare-one/tutorials/m365-dedicated-egress-ips.mdx
+++ b/src/content/docs/cloudflare-one/tutorials/m365-dedicated-egress-ips.mdx
@@ -78,6 +78,6 @@ Your policy will block access for your selected users from any location except t
## Test your policies
-1. Using [WARP](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/), sign in to your Zero Trust organization with a user's account.
+1. Using [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/), sign in to your Zero Trust organization with a user's account.
2. Go to any Microsoft 365 app within your organization. Entra ID should allow access.
3. Disconnect WARP from your Zero Trust organization. Entra ID should block access to any Microsoft 365 applications.
diff --git a/src/content/docs/cloudflare-one/tutorials/mysql-network-policy.mdx b/src/content/docs/cloudflare-one/tutorials/mysql-network-policy.mdx
index 60e8819e047..9ee1826299b 100644
--- a/src/content/docs/cloudflare-one/tutorials/mysql-network-policy.mdx
+++ b/src/content/docs/cloudflare-one/tutorials/mysql-network-policy.mdx
@@ -5,7 +5,7 @@ difficulty: Intermediate
pcx_content_type: tutorial
title: Access and secure a MySQL database using Cloudflare Tunnel and network policies
description: >-
- Using Cloudflare Tunnel's private networks, users can connect to arbitrary non-browser based TCP/UDP applications, like databases. You can set up network policies that implement zero trust controls to define who and what can access those applications using the WARP client.
+ Using Cloudflare Tunnel's private networks, users can connect to arbitrary non-browser based TCP/UDP applications, like databases. You can set up network policies that implement zero trust controls to define who and what can access those applications using the Cloudflare One Client.
tags:
- MySQL
- Private networks
@@ -13,7 +13,7 @@ tags:
import { Render } from "~/components";
-Using Cloudflare Tunnel's private networks, users can connect to arbitrary non-browser based TCP/UDP applications, like databases. You can set up network policies that implement zero trust controls to define who and what can access those applications using the WARP client.
+Using Cloudflare Tunnel's private networks, users can connect to arbitrary non-browser based TCP/UDP applications, like databases. You can set up network policies that implement zero trust controls to define who and what can access those applications using the Cloudflare One Client.
By the end of this tutorial, users that pass network policies will be able to access a remote MySQL database available through a Cloudflare Tunnel on TCP port 3306.
@@ -44,7 +44,7 @@ The application and (optional) DNS server are now connected to Cloudflare.
## Create a Gateway network policy
1. Go to **Traffic policies** > **Network policies**.
-2. Add a [network policy](/cloudflare-one/traffic-policies/network-policies/) that targets the private IP address and the port of the MySQL database (port 3306 by default). The following example allows access to the database to the users that enrolled into WARP using an `@example.com` email address. The network policies can also take into consideration [device posture checks](/cloudflare-one/reusable-components/posture-checks/).
+2. Add a [network policy](/cloudflare-one/traffic-policies/network-policies/) that targets the private IP address and the port of the MySQL database (port 3306 by default). The following example allows access to the database to the users that enrolled into the Cloudflare One Client using an `@example.com` email address. The network policies can also take into consideration [device posture checks](/cloudflare-one/reusable-components/posture-checks/).
| Selector | Operator | Value | Logic | Action |
| ---------------- | ------------- | --------------- | ----- | ------ |
@@ -54,7 +54,7 @@ The application and (optional) DNS server are now connected to Cloudflare.
In addition to the Allow rule above, Cloudflare recommends adding a [catch-all block policy](/learning-paths/replace-vpn/build-policies/) to the bottom of your network policy list to enforce a default-deny model.
-Allowed WARP users can now connect to the MySQL server at `10.128.0.175` using the MySQL client of their choice.
+Allowed Cloudflare One Client users can now connect to the MySQL server at `10.128.0.175` using the MySQL client of their choice.
## (Optional) Create a Gateway resolver policy
@@ -84,4 +84,4 @@ If your internal DNS server has an `A` record for the MySQL database, users can
`mysql IN A 10.128.0.175`
-Allowed WARP users can connect to the MySQL database at `mysql.internalrecord.com` using the MySQL client of their choice.
+Allowed Cloudflare One Client users can connect to the MySQL database at `mysql.internalrecord.com` using the MySQL client of their choice.
diff --git a/src/content/docs/cloudflare-one/tutorials/regional-private-dns-resolver-policies.mdx b/src/content/docs/cloudflare-one/tutorials/regional-private-dns-resolver-policies.mdx
index 4f1aa229d1f..74a649fc799 100644
--- a/src/content/docs/cloudflare-one/tutorials/regional-private-dns-resolver-policies.mdx
+++ b/src/content/docs/cloudflare-one/tutorials/regional-private-dns-resolver-policies.mdx
@@ -100,9 +100,9 @@ Gateway will apply the first matching policy. If no policies match your traffic,
### Test from different regions
-To test your configuration, deploy WARP on a device in each region where you have a private DNS server and run a DNS query to an internal domain. For example, to test the US region:
+To test your configuration, deploy the Cloudflare One Client on a device in each region where you have a private DNS server and run a DNS query to an internal domain. For example, to test the US region:
-1. [Deploy WARP](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/manual-deployment/) on a device in the US region.
+1. [Deploy the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/manual-deployment/) on a device in the US region.
2. From the device, open a terminal and run:
```sh
diff --git a/src/content/docs/cloudflare-one/tutorials/user-selectable-egress-ips.mdx b/src/content/docs/cloudflare-one/tutorials/user-selectable-egress-ips.mdx
index c05c839b484..554b00d2b6d 100644
--- a/src/content/docs/cloudflare-one/tutorials/user-selectable-egress-ips.mdx
+++ b/src/content/docs/cloudflare-one/tutorials/user-selectable-egress-ips.mdx
@@ -20,7 +20,7 @@ Only available on Enterprise plans.
:::
-This tutorial gives administrators an easy way to allow their users to change their egress IP address between any of your assigned dedicated egress IP addresses. Your users can choose which egress IP to use by switching virtual networks directly from in the WARP client.
+This tutorial gives administrators an easy way to allow their users to change their egress IP address between any of your assigned dedicated egress IP addresses. Your users can choose which egress IP to use by switching virtual networks directly from in the Cloudflare One Client.
Changing egress IPs can be useful in quality assurance (QA) and other similar scenarios in which users both use their local egress location and either switch to or simulate other remote locations.
@@ -28,7 +28,7 @@ Changing egress IPs can be useful in quality assurance (QA) and other similar sc
Make sure you have:
-- [Deployed the WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/) on your users' devices.
+- [Deployed the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/) on your users' devices.
- [Configured tunnels](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/) to connect your private network to Cloudflare. This tutorial assumes you have:
- Created two tunnels [through the dashboard](/cloudflare-one/networks/connectors/cloudflare-tunnel/get-started/create-remote-tunnel/).
- Routed `10.0.0.0/8` through one tunnel.
@@ -194,7 +194,7 @@ Each policy you create should correspond to a different primary dedicated egress
-1. On your user's device, log in to your Zero Trust organization in the WARP client.
+1. On your user's device, log in to your Zero Trust organization in the Cloudflare One Client.
2. In a terminal, run the following command to check the default egress IP address.
@@ -207,7 +207,7 @@ Each policy you create should correspond to a different primary dedicated egress
3. In the client GUI, use the **VNET** dropdown to switch to a virtual network you created.
- In the WARP client, select the gear icon > **Virtual Networks**.
+ In the Cloudflare One Client, select the gear icon > **Virtual Networks**.
diff --git a/src/content/docs/cloudflare-one/tutorials/warp-on-headless-linux.mdx b/src/content/docs/cloudflare-one/tutorials/warp-on-headless-linux.mdx
index e11667a6e74..aab9ed408d0 100644
--- a/src/content/docs/cloudflare-one/tutorials/warp-on-headless-linux.mdx
+++ b/src/content/docs/cloudflare-one/tutorials/warp-on-headless-linux.mdx
@@ -3,19 +3,19 @@ reviewed: 2025-09-26
category: Zero Trust
difficulty: Beginner
pcx_content_type: tutorial
-title: Deploy WARP on headless Linux machines
+title: Deploy the Cloudflare One Client on headless Linux machines
description: >-
- This tutorial explains how to deploy the Cloudflare WARP client on headless Linux devices using a service token and an installation script.
+ This tutorial explains how to deploy the Cloudflare One Client on headless Linux devices using a service token and an installation script.
tags:
- Linux
---
import { Render, GlossaryTooltip } from "~/components";
-This tutorial explains how to deploy the [Cloudflare WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) on Linux devices using a service token and an installation script. This deployment workflow is designed for headless servers - that is, servers which do not have access to a browser for identity provider logins - and for situations where you want to fully automate the onboarding process. Because devices will not register through an identity provider, [identity-based policies](/cloudflare-one/traffic-policies/identity-selectors/) and logging will be unavailable.
+This tutorial explains how to deploy the [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) on Linux devices using a service token and an installation script. This deployment workflow is designed for headless servers - that is, servers which do not have access to a browser for identity provider logins - and for situations where you want to fully automate the onboarding process. Because devices will not register through an identity provider, [identity-based policies](/cloudflare-one/traffic-policies/identity-selectors/) and logging will be unavailable.
:::note
-This tutorial focuses on deploying WARP as an endpoint device agent. If you are looking to deploy WARP as a gateway to a private network, refer to the [WARP Connector documentation](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/).
+This tutorial focuses on deploying the Cloudflare One Client as an endpoint device agent. If you are looking to deploy the Cloudflare One Client as a gateway to a private network, refer to the [WARP Connector documentation](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/).
:::
## Prerequisites
@@ -24,7 +24,7 @@ This tutorial focuses on deploying WARP as an endpoint device agent. If you are
## 1. Create a service token
-Fully automated deployments rely on a service token to enroll the WARP client in your Zero Trust organization. You can use the same token to enroll multiple devices, or generate a unique token per device if they require different [device profile settings](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-profiles/).
+Fully automated deployments rely on a service token to enroll the Cloudflare One Client in your Zero Trust organization. You can use the same token to enroll multiple devices, or generate a unique token per device if they require different [device profile settings](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-profiles/).
To create a service token:
@@ -52,7 +52,7 @@ To allow devices to enroll using a service token:
## 3. Create an installation script
-You can use a shell script to automate WARP installation and registration. The following example shows how to deploy WARP on Ubuntu 24.04.
+You can use a shell script to automate WARP installation and registration. The following example shows how to deploy the Cloudflare One Client on Ubuntu 24.04.
1. In a terminal, create a new `.sh` file using a text editor. For example:
```sh
@@ -64,7 +64,7 @@ You can use a shell script to automate WARP installation and registration. The f
#!/bin/bash
set -e
- # Download and install the WARP client
+ # Download and install the Cloudflare One Client
function warp() {
curl -fsSL https://pkg.cloudflareclient.com/pubkey.gpg | sudo gpg --yes --dearmor --output /usr/share/keyrings/cloudflare-warp-archive-keyring.gpg
echo "deb [signed-by=/usr/share/keyrings/cloudflare-warp-archive-keyring.gpg] https://pkg.cloudflareclient.com/ $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/cloudflare-client.list
@@ -72,7 +72,7 @@ You can use a shell script to automate WARP installation and registration. The f
sudo apt-get install --assume-yes cloudflare-warp
}
- # Create an MDM file with your WARP deployment parameters
+ # Create an MDM file with your Cloudflare One Client deployment parameters
function mdm() {
sudo touch /var/lib/cloudflare-warp/mdm.xml
cat > /var/lib/cloudflare-warp/mdm.xml << "EOF"
@@ -103,13 +103,13 @@ You can use a shell script to automate WARP installation and registration. The f
4. Modify the values in the `mdm()` function:
1. For `auth_client_id` and `auth_client_secret`, replace the string values with the Client ID and Client Secret of your [service token](/cloudflare-one/tutorials/warp-on-headless-linux/#1-create-a-service-token).
2. For `organization`, replace `your-team-name` with your Zero Trust team name.
- 3. (Optional) Add or modify other [WARP deployment parameters](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/parameters/) according to your preferences.
+ 3. (Optional) Add or modify other [Cloudflare One Client deployment parameters](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/parameters/) according to your preferences.
5. Press `esc`, then type `:x` and press `Enter` to save and exit.
## 4. Install WARP
-To install WARP using the example script:
+To install the Cloudflare One Client using the example script:
1. Make the script executable:
@@ -122,4 +122,4 @@ To install WARP using the example script:
sudo ./install_warp.sh
```
-WARP is now deployed with the configuration parameters stored in `/var/lib/cloudflare-warp/mdm.xml`. Assuming [`auto_connect`](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/parameters/#auto_connect) is configured, WARP will automatically connect to your Zero Trust organization. Once connected, the device will appear in [Cloudflare One](https://one.dash.cloudflare.com) under **Team & Resources** > **Devices** with the email `non_identity@.cloudflareaccess.com`.
+the Cloudflare One Client is now deployed with the configuration parameters stored in `/var/lib/cloudflare-warp/mdm.xml`. Assuming [`auto_connect`](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/parameters/#auto_connect) is configured, the Cloudflare One Client will automatically connect to your Zero Trust organization. Once connected, the device will appear in [Cloudflare One](https://one.dash.cloudflare.com) under **Team & Resources** > **Devices** with the email `non_identity@.cloudflareaccess.com`.
diff --git a/src/content/docs/cloudflare-wan/changelog.mdx b/src/content/docs/cloudflare-wan/changelog.mdx
index 45ce7368e02..18a44800e3b 100644
--- a/src/content/docs/cloudflare-wan/changelog.mdx
+++ b/src/content/docs/cloudflare-wan/changelog.mdx
@@ -44,9 +44,9 @@ Customers can exchange routes dynamically with their Magic virtual network overl
## 2024-09-27
-**Magic WAN Connector sends WARP client traffic to Internet**
+**Magic WAN Connector sends Cloudflare One Client traffic to Internet**
-All Magic WAN Connectors now route WARP client traffic directly to the Internet, bypassing IPsec tunneling, to prevent double encapsulation of WARP traffic.
+All Magic WAN Connectors now route Cloudflare One Client traffic directly to the Internet, bypassing IPsec tunneling, to prevent double encapsulation of Cloudflare One Client traffic.
## 2024-07-17
@@ -68,9 +68,9 @@ The Magic WAN Connector can now prioritize traffic on a per-application basis.
## 2024-05-31
-**WARP virtual IP addresses**
+**virtual IP addresses**
-Customers using Gateway to filter traffic to Magic WAN destinations will now see traffic from Cloudflare egressing with WARP virtual IP addresses (CGNAT range), rather than public Cloudflare IP addresses. This simplifies configuration and improves visibility for customers.
+Customers using Gateway to filter traffic to Magic WAN destinations will now see traffic from Cloudflare egressing with the Cloudflare One Client virtual IP addresses (CGNAT range), rather than public Cloudflare IP addresses. This simplifies configuration and improves visibility for customers.
## 2024-01-23
diff --git a/src/content/docs/cloudflare-wan/zero-trust/index.mdx b/src/content/docs/cloudflare-wan/zero-trust/index.mdx
index 19cdb5ef306..4353a764dca 100644
--- a/src/content/docs/cloudflare-wan/zero-trust/index.mdx
+++ b/src/content/docs/cloudflare-wan/zero-trust/index.mdx
@@ -7,7 +7,7 @@ head:
- tag: title
content: Cloudflare One integration tutorials
description: Learn how to integrate Cloudflare WAN (formerly Magic WAN) with other Cloudflare
- Cloudflare One products, such as Cloudflare Gateway and Cloudflare WARP.
+ Cloudflare One products, such as Cloudflare Gateway and the Cloudflare One Client.
---
diff --git a/src/content/docs/cloudflare-wan/zero-trust/warp.mdx b/src/content/docs/cloudflare-wan/zero-trust/warp.mdx
index a62eabad613..078ec39b808 100644
--- a/src/content/docs/cloudflare-wan/zero-trust/warp.mdx
+++ b/src/content/docs/cloudflare-wan/zero-trust/warp.mdx
@@ -3,9 +3,9 @@ title: WARP
pcx_content_type: tutorial
head:
- tag: title
- content: Use WARP as an on-ramp
+ content: Use the Cloudflare One Client as an on-ramp
description: >-
- Use WARP as an on-ramp to Cloudflare WAN and route traffic from user devices with WARP installed to any network connected with Cloudflare Tunnel or Magic IP-layer tunnels (anycast GRE, IPsec, or CNI).
+ Use the Cloudflare One Client as an on-ramp to Cloudflare WAN and route traffic from user devices with the Cloudflare One Client installed to any network connected with Cloudflare Tunnel or Magic IP-layer tunnels (anycast GRE, IPsec, or CNI).
---
import { Render } from "~/components";
diff --git a/src/content/docs/containers/local-dev.mdx b/src/content/docs/containers/local-dev.mdx
index 8cf3eeb0fea..54d2d9306bd 100644
--- a/src/content/docs/containers/local-dev.mdx
+++ b/src/content/docs/containers/local-dev.mdx
@@ -76,14 +76,14 @@ This retry logic should be handled for you if you are using the [containers pack
If you see an opaque `internal error` when attempting to connect to your container, you may need to set the `DOCKER_HOST` environment variable to the socket path your container engine is listening on. Wrangler or Vite will attempt to automatically find the correct socket to use to communicate with your container engine, but if that does not work, you may have to set this environment variable to the appropriate socket path.
-### SSL errors with Cloudflare WARP or a VPN
+### SSL errors with the Cloudflare One Client or a VPN
-If you are running Cloudflare WARP or a VPN that performs TLS inspection, HTTPS requests made during the Docker build process may fail with SSL or certificate errors. This happens because the VPN intercepts HTTPS traffic and re-signs it with its own certificate authority, which Docker does not trust by default.
+If you are running the Cloudflare One Client or a VPN that performs TLS inspection, HTTPS requests made during the Docker build process may fail with SSL or certificate errors. This happens because the VPN intercepts HTTPS traffic and re-signs it with its own certificate authority, which Docker does not trust by default.
To resolve this, you can either:
-- Disable WARP or your VPN while running `wrangler dev` or `wrangler deploy`, then re-enable it afterwards.
-- Add the certificate to your Docker build context. Cloudflare WARP exposes its certificate via the `NODE_EXTRA_CA_CERTS` and `SSL_CERT_FILE` environment variables on your host machine. You can pass the certificate into your Docker build as an environment variable, so that it is available during the build without being baked into the final image.
+- Disable the Cloudflare One Client or your VPN while running `wrangler dev` or `wrangler deploy`, then re-enable it afterwards.
+- Add the certificate to your Docker build context. the Cloudflare One Client exposes its certificate via the `NODE_EXTRA_CA_CERTS` and `SSL_CERT_FILE` environment variables on your host machine. You can pass the certificate into your Docker build as an environment variable, so that it is available during the build without being baked into the final image.
```dockerfile
RUN if [ -n "$SSL_CERT_FILE" ]; then \
diff --git a/src/content/docs/data-localization/compatibility.mdx b/src/content/docs/data-localization/compatibility.mdx
index f3010e0c981..9a25bbba0b7 100644
--- a/src/content/docs/data-localization/compatibility.mdx
+++ b/src/content/docs/data-localization/compatibility.mdx
@@ -156,7 +156,7 @@ The table below provides a summary of the Data Localization Suite product's beha
[^20]: You can [bring your own certificate](https://blog.cloudflare.com/bring-your-certificates-cloudflare-gateway/) to Gateway but these cannot yet be restricted to a specific region.
-[^21]: Gateway HTTP supports Regional Services. Gateway DNS does not yet support regionalization. ICMP proxy and WARP-to-WARP proxy are not available to Regional Services users. [File Sandboxing](/cloudflare-one/traffic-policies/http-policies/file-sandboxing/) (add-on) is incompatible with DLS.
+[^21]: Gateway HTTP supports Regional Services. Gateway DNS does not yet support regionalization. ICMP proxy and Peer-to-peer proxy are not available to Regional Services users. [File Sandboxing](/cloudflare-one/traffic-policies/http-policies/file-sandboxing/) (add-on) is incompatible with DLS.
[^22]: Dashboard Analytics and Logs are empty when using CMB outside the US region. Use Logpush instead.
diff --git a/src/content/docs/data-localization/how-to/zero-trust.mdx b/src/content/docs/data-localization/how-to/zero-trust.mdx
index 8a39e0435e7..fb21c16c74e 100644
--- a/src/content/docs/data-localization/how-to/zero-trust.mdx
+++ b/src/content/docs/data-localization/how-to/zero-trust.mdx
@@ -11,7 +11,7 @@ In the following sections, we will give you some details about how different Zer
## Gateway
-Regional Services can be used with Gateway in all [supported regions](/data-localization/region-support/). Be aware that Regional Services only apply when using the WARP client in Traffic and DNS mode.
+Regional Services can be used with Gateway in all [supported regions](/data-localization/region-support/). Be aware that Regional Services only apply when using the Cloudflare One Client in Traffic and DNS mode.
### Egress policies
@@ -20,7 +20,7 @@ This allows your egress traffic to geolocate to the city selected in your [egres
### HTTP policies
-As part of Regional Services, Cloudflare Gateway will only perform [TLS decryption](/cloudflare-one/traffic-policies/http-policies/tls-decryption/) when using the [WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) (in default [Traffic and DNS mode](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/)).
+As part of Regional Services, Cloudflare Gateway will only perform [TLS decryption](/cloudflare-one/traffic-policies/http-policies/tls-decryption/) when using the [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) (in default [Traffic and DNS mode](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/)).
{/* TODO: Reintroduce */}
{/* */}
@@ -39,7 +39,7 @@ You are able to [configure SSH proxy and command logs](/cloudflare-one/traffic-p
Regional Services controls where Cloudflare decrypts traffic; because most DNS traffic is not encrypted, Gateway DNS cannot be regionalized using Regional Services.
-Refer to the [WARP Settings](/data-localization/how-to/zero-trust/#warp-settings) section below for more information.
+Refer to the [Cloudflare One Client settings](/data-localization/how-to/zero-trust/#warp-settings) section below for more information.
### Custom certificates
@@ -66,7 +66,7 @@ To ensure that all reverse proxy requests for applications protected by Cloudfla
You can [configure Cloudflare Tunnel](/cloudflare-one/networks/connectors/cloudflare-tunnel/configure-tunnels/run-parameters/#region) to only connect to data centers within the United States, regardless of where the software was deployed.
-## WARP settings
+## Cloudflare One Client settings
### Local Domain Fallback
diff --git a/src/content/docs/email-security/migrate-to-email-security.mdx b/src/content/docs/email-security/migrate-to-email-security.mdx
index 835931117e9..a273943eecd 100644
--- a/src/content/docs/email-security/migrate-to-email-security.mdx
+++ b/src/content/docs/email-security/migrate-to-email-security.mdx
@@ -44,7 +44,7 @@ Once you have added new account members, you will have to assign each member an
| Area 1 | Email security | Description |
| ------------------- | ------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
-| N/A | Cloudflare Zero Trust | Can edit Cloudflare [Zero Trust](/cloudflare-one/). Has administrator access to all Zero Trust products including Access, Gateway, WARP, Tunnel, Browser Isolation, CASB, DLP, DEX, and Email security. |
+| N/A | Cloudflare Zero Trust | Can edit Cloudflare [Zero Trust](/cloudflare-one/). Has administrator access to all Zero Trust products including Access, Gateway, the Cloudflare One Client, Tunnel, Browser Isolation, CASB, DLP, DEX, and Email security. |
| Super Admin | Email security Analyst + Email security Configuration Admin = Super Admin | Has full access to all admin features in Email security |
| Configuration Admin | Email security Configuration Admin | Has administrator access. Cannot take actions on emails, or read emails |
| SOC Analyst | Email security Analyst | Has analyst access. Can take action on emails and read emails. |
diff --git a/src/content/docs/fundamentals/concepts/traffic-flow-cloudflare.mdx b/src/content/docs/fundamentals/concepts/traffic-flow-cloudflare.mdx
index b4d3ff7987d..50c51e7da3d 100644
--- a/src/content/docs/fundamentals/concepts/traffic-flow-cloudflare.mdx
+++ b/src/content/docs/fundamentals/concepts/traffic-flow-cloudflare.mdx
@@ -44,7 +44,7 @@ Refer to the list below for products you can use to on-ramp traffic to Cloudflar
* [DNS-based](/fundamentals/concepts/how-cloudflare-works/#cloudflare-as-a-dns-provider) traffic resolves domains onboarded to [Cloudflare's CDN](/fundamentals/concepts/how-cloudflare-works/). Cloudflare's DNS directs traffic to Cloudflare's global network of servers instead of a website's origin server.
* [Cloudflare Tunnel](/cloudflare-one/networks/connectors/cloudflare-tunnel/) connects your resources to Cloudflare without a publicly routable IP address so that your origins can serve traffic through Cloudflare without being vulnerable to attacks that bypass Cloudflare.
* [Magic Transit](/magic-transit/about/) offers DDoS protection, traffic acceleration, and more for on-premise, cloud-hosted, and hybrid networks by accepting IP packets destined for your network, processing them, and outputting the packets to your origin infrastructure.
-* The [Cloudflare WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) securely and privately sends traffic from corporate devices to Cloudflare's global network while also applying advanced Zero Trust policies that check for a device's health before it connects to corporate applications.
+* The [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) securely and privately sends traffic from corporate devices to Cloudflare's global network while also applying advanced Zero Trust policies that check for a device's health before it connects to corporate applications.
### Off-ramp traffic from Cloudflare
diff --git a/src/content/docs/fundamentals/manage-members/roles.mdx b/src/content/docs/fundamentals/manage-members/roles.mdx
index db76afe29e1..0ea20a8169c 100644
--- a/src/content/docs/fundamentals/manage-members/roles.mdx
+++ b/src/content/docs/fundamentals/manage-members/roles.mdx
@@ -35,7 +35,7 @@ Account-scoped roles apply across an entire Cloudflare account, and through all
| Cloudflare R2 Admin | Can edit Cloudflare [R2](/r2/) buckets, objects, and associated configurations. |
| Cloudflare R2 Read | Can read Cloudflare [R2](/r2/) buckets, objects, and associated configurations. |
| Cloudflare Stream | Can edit [Cloudflare Stream](/stream/) media. |
-| Cloudflare Zero Trust | Can edit [Cloudflare Zero Trust](/cloudflare-one/). Grants administrator access to all Zero Trust products including Access, Gateway, WARP, Tunnel, Browser Isolation, CASB, DLP, DEX, and Email security. |
+| Cloudflare Zero Trust | Can edit [Cloudflare Zero Trust](/cloudflare-one/). Grants administrator access to all Zero Trust products including Access, Gateway, the Cloudflare One Client, Tunnel, Browser Isolation, CASB, DLP, DEX, and Email security. |
| Cloudflare Zero Trust DNS Locations Write | Can view [Gateway DNS locations](/cloudflare-one/networks/resolvers-and-proxies/dns/locations/#secure-dns-locations) and create and edit [secure DNS locations](/cloudflare-one/networks/resolvers-and-proxies/dns/locations/#secure-dns-locations). |
| Cloudflare Zero Trust PII | Can access [Cloudflare Zero Trust](/cloudflare-one/) PII. |
| Cloudflare Zero Trust Read Only | Can access [Cloudflare Zero Trust](/cloudflare-one/) read only mode. |
diff --git a/src/content/docs/fundamentals/reference/partners.mdx b/src/content/docs/fundamentals/reference/partners.mdx
index 1bcc5bf9c92..8b194f505d8 100644
--- a/src/content/docs/fundamentals/reference/partners.mdx
+++ b/src/content/docs/fundamentals/reference/partners.mdx
@@ -23,7 +23,7 @@ Connect your network infrastructure with Cloudflare [network connectivity partne
## Cloudflare Zero Trust Technology Partners
-Our third-party integrations allow you to deploy the WARP client application and configure devices remotely.
+Our third-party integrations allow you to deploy the Cloudflare One Client application and configure devices remotely.
diff --git a/src/content/docs/learning-paths/china-network-overview/series/china-express-overview-2.mdx b/src/content/docs/learning-paths/china-network-overview/series/china-express-overview-2.mdx
index ad3268e3610..febbd207083 100644
--- a/src/content/docs/learning-paths/china-network-overview/series/china-express-overview-2.mdx
+++ b/src/content/docs/learning-paths/china-network-overview/series/china-express-overview-2.mdx
@@ -11,7 +11,7 @@ import { Render, Tabs, TabItem, Stream, Card } from "~/components";
-In this video, Jess Liu discusses Cloudflare's CDN Global Acceleration (formerly China Express), including solutions for high latency on dynamic content, accelerating API calls, accessing Cloudflare One services like WARP and Cloudflare WAN from within mainland China, and securely connecting private enterprise networks.
+In this video, Jess Liu discusses Cloudflare's CDN Global Acceleration (formerly China Express), including solutions for high latency on dynamic content, accelerating API calls, accessing Cloudflare One services like the Cloudflare One Client and Cloudflare WAN from within mainland China, and securely connecting private enterprise networks.
.cloudflareaccess.com/browser/`
@@ -24,5 +24,5 @@ To configure Clientless Web Isolation to augment clientless access, refer to [th
## Best practices
* For guidance on building Gateway policies for private network applications, refer to [Secure your first application](/learning-paths/replace-vpn/build-policies/create-policy/).
-* If you already deployed the WARP client to some devices as part of a mixed-access methodology, ensure that your Gateway firewall policies do not rely on device posture checks. Because Clientless Web Isolation is not a machine in your fleet, it will not return any values for device posture checks.
+* If you already deployed the Cloudflare One Client to some devices as part of a mixed-access methodology, ensure that your Gateway firewall policies do not rely on device posture checks. Because Clientless Web Isolation is not a machine in your fleet, it will not return any values for device posture checks.
* You can standardize the user experience by making specific applications available in your App Launcher as [bookmarks](/learning-paths/clientless-access/customize-ux/bookmarks/). In this case, you would create a new bookmark for `https://.cloudflareaccess.com/browser/https://internalresource.com`, which would take users directly to an isolated session with your application.
diff --git a/src/content/docs/learning-paths/replace-vpn/build-policies/block-page.mdx b/src/content/docs/learning-paths/replace-vpn/build-policies/block-page.mdx
index 80e12515cd3..a8faa2516d7 100644
--- a/src/content/docs/learning-paths/replace-vpn/build-policies/block-page.mdx
+++ b/src/content/docs/learning-paths/replace-vpn/build-policies/block-page.mdx
@@ -12,7 +12,7 @@ With Cloudflare Zero Trust, you can deliver actionable feedback to users when th
There are two different ways to surface block messages:
- [Custom block page](#custom-block-page)
-- [WARP client block notifications](#warp-client-block-notifications)
+- [Cloudflare One Client block notifications](#warp-client-block-notifications)
## Custom block page
@@ -24,7 +24,7 @@ The custom block page has a few drawbacks:
- The block page does not appear when users are blocked by a Gateway network policy.
- The custom block page only displays when the user loads a site in a browser. If, for instance, the user is allowed to visit a site but not allowed to upload a file, the file upload would fail silently and the user would not get a block page.
-To work around these limitations, we recommend using [WARP client block notifications](#warp-client-block-notifications).
+To work around these limitations, we recommend using [Cloudflare One Client block notifications](#warp-client-block-notifications).
:::note
@@ -93,14 +93,14 @@ For DNS policies, you will need to enable the block page on a per-policy basis.
-## WARP client block notifications
+## Cloudflare One Client block notifications
:::note
Only available on Enterprise plans.
:::
-For more granular user feedback, you can enable WARP client block notifications on any Gateway DNS or Network _Block_ policy. Blocked users will receive an operating system notification from the WARP client with a custom message you set.
+For more granular user feedback, you can enable Cloudflare One Client block notifications on any Gateway DNS or Network _Block_ policy. Blocked users will receive an operating system notification from the Cloudflare One Client with a custom message you set.
Client notifications provide additional functionality over the [custom block page](#custom-block-page):
diff --git a/src/content/docs/learning-paths/replace-vpn/build-policies/session-timeouts.mdx b/src/content/docs/learning-paths/replace-vpn/build-policies/session-timeouts.mdx
index e24564cb10e..6c7f0dd90e6 100644
--- a/src/content/docs/learning-paths/replace-vpn/build-policies/session-timeouts.mdx
+++ b/src/content/docs/learning-paths/replace-vpn/build-policies/session-timeouts.mdx
@@ -10,7 +10,7 @@ import { Render } from "~/components"
Most legacy VPNs have a global timeout setting that requires end users to log in every X hours or resets VPN profiles at a certain frequency. By doing continuous identity evaluation, a Zero Trust security model eliminates the need for most of the user-interrupting workflows triggered by session timeouts. However, there can still be valid reasons to want users to reauthenticate, either on a recurring basis or to access specific, highly-sensitive or regulated internal services.
-To enforce WARP client reauthentication, you can configure WARP session timeouts on a per-application basis in your Gateway network policies.
+To enforce Cloudflare One Client reauthentication, you can configure the Cloudflare One Client session timeouts on a per-application basis in your Gateway network policies.
## Configure WARP session timeout
@@ -29,4 +29,4 @@ A global timeout does not necessarily fit all customer needs. With the increased
### Common mistake
-When configuring a global WARP session duration, a common mistake is to build a single policy that covers your entire private network range. An example would be an Allow policy that requires reauthentication every 7 days for all users with traffic to a destination IP in `10.0.0.0/8`. This type of global policy may result in a suboptimal user experience because an expired session blocks the user from the entire internal network (including private DNS functionality) instead of specific applications. If a user misses the one-time reauth notification, they may not know that they need to manually go into their WARP client settings to reauthenticate.
+When configuring a global WARP session duration, a common mistake is to build a single policy that covers your entire private network range. An example would be an Allow policy that requires reauthentication every 7 days for all users with traffic to a destination IP in `10.0.0.0/8`. This type of global policy may result in a suboptimal user experience because an expired session blocks the user from the entire internal network (including private DNS functionality) instead of specific applications. If a user misses the one-time reauth notification, they may not know that they need to manually go into their Cloudflare One Client settings to reauthenticate.
diff --git a/src/content/docs/learning-paths/replace-vpn/build-policies/test-your-first-application.mdx b/src/content/docs/learning-paths/replace-vpn/build-policies/test-your-first-application.mdx
index d33a74349f7..add8e4b21bf 100644
--- a/src/content/docs/learning-paths/replace-vpn/build-policies/test-your-first-application.mdx
+++ b/src/content/docs/learning-paths/replace-vpn/build-policies/test-your-first-application.mdx
@@ -7,22 +7,22 @@ sidebar:
import { DashButton, Render } from "~/components";
-You have now set up your [Zero Trust organization](/learning-paths/replace-vpn/get-started/), [configured the WARP client](/learning-paths/replace-vpn/configure-device-agent/), [installed it on devices](/learning-paths/replace-vpn/connect-devices/), and created your [Access and Gateway policies](/learning-paths/replace-vpn/build-policies/). The next step is to test those policies.
+You have now set up your [Zero Trust organization](/learning-paths/replace-vpn/get-started/), [configured the Cloudflare One Client](/learning-paths/replace-vpn/configure-device-agent/), [installed it on devices](/learning-paths/replace-vpn/connect-devices/), and created your [Access and Gateway policies](/learning-paths/replace-vpn/build-policies/). The next step is to test those policies.
## 1. Manually test your policies
-Test if the Access or Gateway policy that you configured is working by using a device with the WARP client installed to reach an internal application or external website.
+Test if the Access or Gateway policy that you configured is working by using a device with the Cloudflare One Client installed to reach an internal application or external website.
If you cannot reach an application protected by Access or an external application through Gateway as expected, Cloudflare recommends starting with reviewing your WARP configuration.
### 1.1. Troubleshoot WARP
-If your manual test fails, troubleshoot the WARP client. Cloudflare recommends starting with reviewing your WARP configuration because misconfiguration is the most common cause of connectivity issues.
+If your manual test fails, troubleshoot the Cloudflare One Client. Cloudflare recommends starting with reviewing your WARP configuration because misconfiguration is the most common cause of connectivity issues.
-- [WARP troubleshooting guide](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/troubleshooting-guide/): Step-by-step instructions to debug WARP client issues.
-- [WARP client errors](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/client-errors/): If you are receiving an error, review the associated solutions.
-- [WARP connectivity status](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/connectivity-status/): Review the connectivity stage of the WARP daemon as it establishes a connection from the device to Cloudflare.
-- [WARP with Firewall](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/firewall/): Ensure you have exempted the correct IP addresses and domains to allow the WARP client to connect.
+- [WARP troubleshooting guide](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/troubleshooting-guide/): Step-by-step instructions to debug Cloudflare One Client issues.
+- [Cloudflare One Client errors](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/client-errors/): If you are receiving an error, review the associated solutions.
+- [Cloudflare One Client connectivity status](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/connectivity-status/): Review the connectivity stage of the WARP daemon as it establishes a connection from the device to Cloudflare.
+- [WARP with Firewall](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/firewall/): Ensure you have exempted the correct IP addresses and domains to allow the Cloudflare One Client to connect.
### 1.2. Review analytics
@@ -57,12 +57,12 @@ Refer to [Digital Experience Monitoring (DEX)](/cloudflare-one/insights/dex/) fo
### Example use case
-- Imagine that you have three devices, with the WARP client installed, set up in your testing environment.
+- Imagine that you have three devices, with the Cloudflare One Client installed, set up in your testing environment.
- You have set up a [Cloudflare Tunnel](/cloudflare-one/networks/connectors/cloudflare-tunnel/) and an [Access policy](/cloudflare-one/access-controls/policies/) for your internal wiki that is available at `wiki.acme.org`.
-- You [manually tested](/learning-paths/replace-vpn/build-policies/test-your-first-application/#manually-test-your-policies) the three WARP client devices, and you confirmed they can all reach `wiki.acme.org`.
-- You want to set up automated connectivity and performance testing to `wiki.acme.org` for each of these WARP client devices so you can monitor them over time.
-- You set up a DEX test, and it sends an HTTP GET request to `wiki.acme.org` from all three WARP devices on a five minute interval.
-- If WARP device connectivity drops, or if there are performance problems, you can see the DEX test results to troubleshoot the problem.
+- You [manually tested](/learning-paths/replace-vpn/build-policies/test-your-first-application/#manually-test-your-policies) the three Cloudflare One Client devices, and you confirmed they can all reach `wiki.acme.org`.
+- You want to set up automated connectivity and performance testing to `wiki.acme.org` for each of these Cloudflare One Client devices so you can monitor them over time.
+- You set up a DEX test, and it sends an HTTP GET request to `wiki.acme.org` from all three devices on a five minute interval.
+- If device connectivity drops, or if there are performance problems, you can see the DEX test results to troubleshoot the problem.
### 2.1. Create a DEX test
@@ -86,7 +86,7 @@ Refer to [DEX Notifications](/cloudflare-one/insights/dex/notifications/) for mo
#### Device anomaly notification setup
-Customers who want to be notified when Cloudflare detects a spike or drop in the number of devices connected to the WARP client can create a [Device connectivity anomaly](/cloudflare-one/insights/dex/notifications/#available-notifications) notification.
+Customers who want to be notified when Cloudflare detects a spike or drop in the number of devices connected to the Cloudflare One Client can create a [Device connectivity anomaly](/cloudflare-one/insights/dex/notifications/#available-notifications) notification.
To create a device connectivity anomaly notification:
diff --git a/src/content/docs/learning-paths/replace-vpn/configure-device-agent/enable-tls-decryption.mdx b/src/content/docs/learning-paths/replace-vpn/configure-device-agent/enable-tls-decryption.mdx
index 399d71830dd..8583d18dad8 100644
--- a/src/content/docs/learning-paths/replace-vpn/configure-device-agent/enable-tls-decryption.mdx
+++ b/src/content/docs/learning-paths/replace-vpn/configure-device-agent/enable-tls-decryption.mdx
@@ -42,5 +42,5 @@ If you already have a certificate that you use for other inspection or trust pur
- If you are using WARP Connector to connect devices to Cloudflare, those devices will not be able to leverage HTTP policies that require decrypting TLS unless they have a certificate that matches either your uploaded certificate or the Cloudflare root certificate. It is more likely that your network infrastructure already has your own device certificates deployed, so using the existing PKI infrastructure for inspection will reduce the number of steps needed to deploy Zero Trust.
:::note[MDM deployments]
-Many customers [deploy WARP](/learning-paths/replace-vpn/connect-devices/) onto devices in production using an MDM tool like JAMF or Intune. Cloudflare has the ability to deploy a root certificate along with the device, but this could be more consistently and holistically configured within the MDM, where other certificates are presumably managed, trusted, and stored.
+Many customers [deploy the Cloudflare One Client](/learning-paths/replace-vpn/connect-devices/) onto devices in production using an MDM tool like JAMF or Intune. Cloudflare has the ability to deploy a root certificate along with the device, but this could be more consistently and holistically configured within the MDM, where other certificates are presumably managed, trusted, and stored.
:::
diff --git a/src/content/docs/learning-paths/replace-vpn/connect-devices/index.mdx b/src/content/docs/learning-paths/replace-vpn/connect-devices/index.mdx
index 6d6264c4fd0..d0e7f3f85d7 100644
--- a/src/content/docs/learning-paths/replace-vpn/connect-devices/index.mdx
+++ b/src/content/docs/learning-paths/replace-vpn/connect-devices/index.mdx
@@ -7,7 +7,7 @@ sidebar:
import { Render } from "~/components";
-Now that your device enrollment policies and WARP profiles are configured, you can begin deploying the WARP client to user devices for testing.
+Now that your device enrollment policies and Cloudflare One Client profiles are configured, you can begin deploying the Cloudflare One Client to user devices for testing.
:::note
The following steps are identical to [Device on-ramps](/learning-paths/secure-internet-traffic/connect-devices-networks/choose-on-ramp/#device-on-ramps) in the Secure your Internet traffic and SaaS apps implementation guide. If you have already completed Secure your Internet traffic and SaaS apps, you can skip ahead to [Build secure access policies](/learning-paths/replace-vpn/build-policies/).
diff --git a/src/content/docs/learning-paths/replace-vpn/connect-devices/install-agent.mdx b/src/content/docs/learning-paths/replace-vpn/connect-devices/install-agent.mdx
index fc645cc381f..23ce8ce9160 100644
--- a/src/content/docs/learning-paths/replace-vpn/connect-devices/install-agent.mdx
+++ b/src/content/docs/learning-paths/replace-vpn/connect-devices/install-agent.mdx
@@ -1,5 +1,5 @@
---
-title: Download and install WARP
+title: Download and install the Cloudflare One Client
pcx_content_type: overview
sidebar:
order: 1
diff --git a/src/content/docs/learning-paths/replace-vpn/connect-private-network/cloudflared.mdx b/src/content/docs/learning-paths/replace-vpn/connect-private-network/cloudflared.mdx
index 102c57be3fb..6d9a3342451 100644
--- a/src/content/docs/learning-paths/replace-vpn/connect-private-network/cloudflared.mdx
+++ b/src/content/docs/learning-paths/replace-vpn/connect-private-network/cloudflared.mdx
@@ -8,7 +8,7 @@ sidebar:
import { Render, Tabs, TabItem } from "~/components"
-Cloudflare Tunnel is an outbound-only daemon service that can run on nearly any host machine and proxies local traffic once validated from the Cloudflare network. User traffic initiated from the WARP endpoint client onramps to Cloudflare, passes down your Cloudflare Tunnel connections, and terminates automatically in your local network. Traffic reaching your internal applications or services will carry the local source IP address of the host machine running the `cloudflared` daemon.
+Cloudflare Tunnel is an outbound-only daemon service that can run on nearly any host machine and proxies local traffic once validated from the Cloudflare network. User traffic initiated from the Cloudflare One Client onramps to Cloudflare, passes down your Cloudflare Tunnel connections, and terminates automatically in your local network. Traffic reaching your internal applications or services will carry the local source IP address of the host machine running the `cloudflared` daemon.
## Create a tunnel
diff --git a/src/content/docs/learning-paths/replace-vpn/connect-private-network/connection-methods.mdx b/src/content/docs/learning-paths/replace-vpn/connect-private-network/connection-methods.mdx
index 401a43c71a8..a64373e1ee2 100644
--- a/src/content/docs/learning-paths/replace-vpn/connect-private-network/connection-methods.mdx
+++ b/src/content/docs/learning-paths/replace-vpn/connect-private-network/connection-methods.mdx
@@ -6,7 +6,7 @@ sidebar:
---
-There are [multiple ways](/reference-architecture/architectures/sase/#connecting-networks) to onramp traffic from your private networks to Cloudflare. This page will focus on the two software-based methods that are commonly used for a VPN replacement use case: Cloudflare Tunnel via cloudflared and Cloudflare Tunnel via WARP Connector. Both of these methods involve installing lightweight software — either `cloudflared` or Cloudflare WARP — on a host machine in your network. The software creates a secure tunnel, called a Cloudflare Tunnel, to connect services and applications to Cloudflare’s global network.
+There are [multiple ways](/reference-architecture/architectures/sase/#connecting-networks) to onramp traffic from your private networks to Cloudflare. This page will focus on the two software-based methods that are commonly used for a VPN replacement use case: Cloudflare Tunnel via cloudflared and Cloudflare Tunnel via WARP Connector. Both of these methods involve installing lightweight software — either `cloudflared` or the Cloudflare One Client — on a host machine in your network. The software creates a secure tunnel, called a Cloudflare Tunnel, to connect services and applications to Cloudflare’s global network.
## Cloudflare Tunnel via cloudflared
diff --git a/src/content/docs/learning-paths/replace-vpn/connect-private-network/overlapping-ips.mdx b/src/content/docs/learning-paths/replace-vpn/connect-private-network/overlapping-ips.mdx
index 4f33fd80f8c..58b85292eb2 100644
--- a/src/content/docs/learning-paths/replace-vpn/connect-private-network/overlapping-ips.mdx
+++ b/src/content/docs/learning-paths/replace-vpn/connect-private-network/overlapping-ips.mdx
@@ -36,7 +36,7 @@ To solve this problem, add a `10.0.1.0/24` route to Tunnel-A and assign it the `
| ------------------ | --------------- |
| `10.0.1.0/24` | staging |
-The user can now [toggle between the two virtual networks](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/tunnel-virtual-networks/#connect-to-a-virtual-network) in their WARP client, similar to the concept of switching VPN profiles in a VPN client. When a user selects `production`, they can connect to the entire `10.0.0.0/8` range served by Tunnel-A. When they select `staging`, they can connect to all of `10.0.0.0/8` in Tunnel-A except for `10.0.1.0/24`, which will be served by Tunnel-B.
+The user can now [toggle between the two virtual networks](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/tunnel-virtual-networks/#connect-to-a-virtual-network) in their Cloudflare One Client, similar to the concept of switching VPN profiles in a VPN client. When a user selects `production`, they can connect to the entire `10.0.0.0/8` range served by Tunnel-A. When they select `staging`, they can connect to all of `10.0.0.0/8` in Tunnel-A except for `10.0.1.0/24`, which will be served by Tunnel-B.
## Set up virtual networks
diff --git a/src/content/docs/learning-paths/replace-vpn/connect-private-network/warp-connector.mdx b/src/content/docs/learning-paths/replace-vpn/connect-private-network/warp-connector.mdx
index 023852ab5b2..f0557fe2523 100644
--- a/src/content/docs/learning-paths/replace-vpn/connect-private-network/warp-connector.mdx
+++ b/src/content/docs/learning-paths/replace-vpn/connect-private-network/warp-connector.mdx
@@ -6,7 +6,7 @@ sidebar:
---
-WARP Connector uses the same underlying technology as our WARP endpoint client. The software is installed on a Linux server or virtual machine in your private network and requires you to make routing updates to machines or networks behind WARP Connector. WARP Connector supports bidirectional proxy of traffic: it can proxy traffic initiated from a user running WARP into a private network (same as `cloudflared`), but it can also enable traffic from a network to be on-ramped to Cloudflare for either public or private destinations. You can also use WARP Connector to create mesh network connectivity so that any device either running the WARP client, or behind a WARP Connector, can communicate using the CGNat virtual IP addresses assigned to each device.
+WARP Connector uses the same underlying technology as the Cloudflare One Client. The software is installed on a Linux server or virtual machine in your private network and requires you to make routing updates to machines or networks behind WARP Connector. WARP Connector supports bidirectional proxy of traffic: it can proxy traffic initiated from a user running WARP into a private network (same as `cloudflared`), but it can also enable traffic from a network to be on-ramped to Cloudflare for either public or private destinations. You can also use WARP Connector to create mesh network connectivity so that any device either running the Cloudflare One Client, or behind a WARP Connector, can communicate using the CGNat virtual IP addresses assigned to each device.
For most customers, [`cloudflared`](/learning-paths/replace-vpn/connect-private-network/cloudflared/) should be the primary connectivity method for end-users to connect to services in your private network. WARP Connector is the preferred method for mesh or other software-defined networking — most of which require bidirectional connectivity — or when organizations do not want to make changes to their underlying network routing infrastructure.
diff --git a/src/content/docs/learning-paths/replace-vpn/get-started/index.mdx b/src/content/docs/learning-paths/replace-vpn/get-started/index.mdx
index bcc47b5b28e..9c382f6c127 100644
--- a/src/content/docs/learning-paths/replace-vpn/get-started/index.mdx
+++ b/src/content/docs/learning-paths/replace-vpn/get-started/index.mdx
@@ -7,7 +7,7 @@ sidebar:
import { Render } from "~/components";
-In this learning path, you will learn how to replace your existing VPN provider with Cloudflare's ZTNA solution. Your users will run the WARP endpoint client on their devices, and you will run either Cloudflare Tunnel or Cloudflare WARP Connector in your network or on your application servers. After deploying Zero Trust, users will be able to connect to private resources (not exposed to the Internet) via TCP/UDP/ICMP, and administrators will be able to control access to these resources based on user identity, device posture, and other factors.
+In this learning path, you will learn how to replace your existing VPN provider with Cloudflare's ZTNA solution. Your users will run the Cloudflare One Client on their devices, and you will run either Cloudflare Tunnel or the Cloudflare One Client Connector in your network or on your application servers. After deploying Zero Trust, users will be able to connect to private resources (not exposed to the Internet) via TCP/UDP/ICMP, and administrators will be able to control access to these resources based on user identity, device posture, and other factors.

diff --git a/src/content/docs/learning-paths/replace-vpn/get-started/prerequisites.mdx b/src/content/docs/learning-paths/replace-vpn/get-started/prerequisites.mdx
index e369a7cae8e..4cc6df66ffc 100644
--- a/src/content/docs/learning-paths/replace-vpn/get-started/prerequisites.mdx
+++ b/src/content/docs/learning-paths/replace-vpn/get-started/prerequisites.mdx
@@ -8,7 +8,7 @@ sidebar:
To make the most of this learning path, make sure that you have the following:
-* A device that can run [WARP](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/), Cloudflare's endpoint agent.
+* A device that can run [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/), Cloudflare's endpoint agent.
* A private network with applications or services that are available locally or via a VPN.
* A [host server](/cloudflare-one/networks/connectors/cloudflare-tunnel/configure-tunnels/tunnel-availability/system-requirements/#recommendations) on the private network that can run the lightweight Cloudflare Tunnel daemon process.
-* (Optional) A [Linux host server](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/#linux) on the private network that can run the Cloudflare WARP Connector. This is only needed for server-initiated traffic flows such as Microsoft SCCM, Active Directory (AD) updates, and DevOps workflows that require server-initiated connections.
+* (Optional) A [Linux host server](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/#linux) on the private network that can run the Cloudflare One Client Connector. This is only needed for server-initiated traffic flows such as Microsoft SCCM, Active Directory (AD) updates, and DevOps workflows that require server-initiated connections.
diff --git a/src/content/docs/learning-paths/secure-internet-traffic/build-dns-policies/create-policy.mdx b/src/content/docs/learning-paths/secure-internet-traffic/build-dns-policies/create-policy.mdx
index a4e422acf51..1e66d036609 100644
--- a/src/content/docs/learning-paths/secure-internet-traffic/build-dns-policies/create-policy.mdx
+++ b/src/content/docs/learning-paths/secure-internet-traffic/build-dns-policies/create-policy.mdx
@@ -9,7 +9,7 @@ import { Render, Tabs, TabItem, APIRequest } from "~/components";
DNS policies determine how Gateway should handle a DNS request. When a user sends a DNS request, Gateway matches the request against your filters and either allows the query to resolve, blocks the query, or responds to the query with a different IP.
-You can filter DNS traffic based on query or response parameters (such as domain, source IP, or geolocation). You can also filter by user identity if you connect your devices to Gateway with the [WARP client or Cloudflare One Agent](/learning-paths/secure-internet-traffic/connect-devices-networks/install-agent/).
+You can filter DNS traffic based on query or response parameters (such as domain, source IP, or geolocation). You can also filter by user identity if you connect your devices to Gateway with the [Cloudflare One Client or Cloudflare One Agent](/learning-paths/secure-internet-traffic/connect-devices-networks/install-agent/).
To create a new DNS policy:
diff --git a/src/content/docs/learning-paths/secure-internet-traffic/build-dns-policies/index.mdx b/src/content/docs/learning-paths/secure-internet-traffic/build-dns-policies/index.mdx
index 4f99a92f9d6..b75ecd42696 100644
--- a/src/content/docs/learning-paths/secure-internet-traffic/build-dns-policies/index.mdx
+++ b/src/content/docs/learning-paths/secure-internet-traffic/build-dns-policies/index.mdx
@@ -6,7 +6,7 @@ sidebar:
---
-DNS security is an important, wide-reaching, and early action in the lifecycle of a request. Cloudflare operates one of the world's largest and fastest public DNS resolvers. Your users' public DNS requests will be resolved by that same resolution engine -- whether they are connecting from a network pointing its resolvers to Cloudflare or an endpoint running the WARP client.
+DNS security is an important, wide-reaching, and early action in the lifecycle of a request. Cloudflare operates one of the world's largest and fastest public DNS resolvers. Your users' public DNS requests will be resolved by that same resolution engine -- whether they are connecting from a network pointing its resolvers to Cloudflare or an endpoint running the Cloudflare One Client.
## Objectives
diff --git a/src/content/docs/learning-paths/secure-internet-traffic/build-dns-policies/test-policy.mdx b/src/content/docs/learning-paths/secure-internet-traffic/build-dns-policies/test-policy.mdx
index 65a72e839d7..30f91fb6545 100644
--- a/src/content/docs/learning-paths/secure-internet-traffic/build-dns-policies/test-policy.mdx
+++ b/src/content/docs/learning-paths/secure-internet-traffic/build-dns-policies/test-policy.mdx
@@ -16,7 +16,7 @@ It is common for a misconfigured Gateway policy to accidentally block traffic to
3. Turn on any existing security policies or create a policy to block all security categories:
4. Ensure that your browser is not configured to use an alternate DNS resolver. For example, Chrome has a **Use secure DNS** setting that will cause the browser to send requests to 1.1.1.1 and bypass your DNS policies.
5. In the browser, go to `malware.testcategory.com`. Your browser will display:
- - The Gateway block page, if your device is connected through the WARP client in Traffic and DNS mode.
+ - The Gateway block page, if your device is connected through the Cloudflare One Client in Traffic and DNS mode.
- A generic error page, if your device is connected through another method, such as DNS only mode.
:::note
diff --git a/src/content/docs/learning-paths/secure-internet-traffic/build-egress-policies/deploy-egress-ips.mdx b/src/content/docs/learning-paths/secure-internet-traffic/build-egress-policies/deploy-egress-ips.mdx
index 6d384e472a0..72d8a527467 100644
--- a/src/content/docs/learning-paths/secure-internet-traffic/build-egress-policies/deploy-egress-ips.mdx
+++ b/src/content/docs/learning-paths/secure-internet-traffic/build-egress-policies/deploy-egress-ips.mdx
@@ -68,6 +68,6 @@ We recommend building baseline egress policies that can cover a majority of your
You may have use cases in which specific groups of your users may need to change the location from which they egress. Cloudflare observes this frequently with quality assurance (QA) teams for applications or sites that need to test resources as if they are accessing from different, predetermined locales. You can manage this when necessary via an egress policy, but most Cloudflare users prefer to manage this without ongoing changes to the administrative panel and existing policies. To accommodate this, you can build virtual networks for use as selectors in egress policies. This will allow your users to change their attached virtual network and subsequently change their egress IP as they choose.
-
+
For more information, refer to our [tutorial for user selectable egress IPs](/cloudflare-one/tutorials/user-selectable-egress-ips/).
diff --git a/src/content/docs/learning-paths/secure-internet-traffic/build-network-policies/recommended-network-policies.mdx b/src/content/docs/learning-paths/secure-internet-traffic/build-network-policies/recommended-network-policies.mdx
index 328b1b46973..f1b7d3b653e 100644
--- a/src/content/docs/learning-paths/secure-internet-traffic/build-network-policies/recommended-network-policies.mdx
+++ b/src/content/docs/learning-paths/secure-internet-traffic/build-network-policies/recommended-network-policies.mdx
@@ -134,7 +134,7 @@ resource "cloudflare_zero_trust_gateway_policy" "posture_fail_net_restricted_acc
-You can add a number of WARP client device posture checks as needed, such as [Disk encryption](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/disk-encryption/) and [Domain joined](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/domain-joined/). For more information on device posture checks, refer to [Enforce device posture](/cloudflare-one/reusable-components/posture-checks/).
+You can add a number of Cloudflare One Client device posture checks as needed, such as [Disk encryption](/cloudflare-one/reusable-components/posture-checks/client-checks/disk-encryption/) and [Domain joined](/cloudflare-one/reusable-components/posture-checks/client-checks/domain-joined/). For more information on device posture checks, refer to [Enforce device posture](/cloudflare-one/reusable-components/posture-checks/).
## FinanceUsers-NET-HTTPS-FinanceServers (example)
diff --git a/src/content/docs/learning-paths/secure-internet-traffic/configure-device-agent/pac-files.mdx b/src/content/docs/learning-paths/secure-internet-traffic/configure-device-agent/pac-files.mdx
index 55d1d23c48a..6d43d47229d 100644
--- a/src/content/docs/learning-paths/secure-internet-traffic/configure-device-agent/pac-files.mdx
+++ b/src/content/docs/learning-paths/secure-internet-traffic/configure-device-agent/pac-files.mdx
@@ -32,8 +32,8 @@ Think of PAC files like a GPS: you are driving to a friend's house, but there is
Some use cases for PAC files include:
-- **Versions of Windows before Windows 8/Windows Server 2012**: The WARP client does not support older versions of Windows, so PAC files provide a clientless solution to route traffic through Cloudflare to add security and filtering benefits.
-- **Non-persistent virtual desktop infrastructure (VDI) environments**: PAC files can be especially valuable in non-persistent VDI environments where installing and saving user details for the WARP client is challenging. In these instances, PAC files ensure consistent access and security regardless of individual user sessions.
+- **Versions of Windows before Windows 8/Windows Server 2012**: The Cloudflare One Client does not support older versions of Windows, so PAC files provide a clientless solution to route traffic through Cloudflare to add security and filtering benefits.
+- **Non-persistent virtual desktop infrastructure (VDI) environments**: PAC files can be especially valuable in non-persistent VDI environments where installing and saving user details for the Cloudflare One Client is challenging. In these instances, PAC files ensure consistent access and security regardless of individual user sessions.
- **Backup in case of agent outage**: In case of an agent outage, PAC files can act as a backup that can be deployed quickly to minimize downtime and security risk.
## Where are PAC files hosted?
diff --git a/src/content/docs/learning-paths/secure-internet-traffic/connect-devices-networks/choose-on-ramp.mdx b/src/content/docs/learning-paths/secure-internet-traffic/connect-devices-networks/choose-on-ramp.mdx
index 7bc5f0031e7..6d28d26cd5f 100644
--- a/src/content/docs/learning-paths/secure-internet-traffic/connect-devices-networks/choose-on-ramp.mdx
+++ b/src/content/docs/learning-paths/secure-internet-traffic/connect-devices-networks/choose-on-ramp.mdx
@@ -19,7 +19,7 @@ The most common way to protect and filter your end-user traffic is by using a de
### Zero Trust Client
-Cloudflare WARP is the most common onramp to send user traffic to Gateway. It is a lightweight device client, which builds proxy tunnels using either Wireguard or MASQUE, and builds a DNS proxy using DNS-over-HTTPS. It supports all major operating systems, supports all common forms of endpoint management tooling, and has a robust series of management parameters and profiles to accurately scope the needs of a diverse user base. It has flexible operating modes and can control device traffic as a proxy, control device DNS traffic as a DNS proxy, or both. It is the most common method to send traffic from user devices to be filtered and decrypted by Cloudflare Gateway.
+the Cloudflare One Client is the most common onramp to send user traffic to Gateway. It is a lightweight device client, which builds proxy tunnels using either Wireguard or MASQUE, and builds a DNS proxy using DNS-over-HTTPS. It supports all major operating systems, supports all common forms of endpoint management tooling, and has a robust series of management parameters and profiles to accurately scope the needs of a diverse user base. It has flexible operating modes and can control device traffic as a proxy, control device DNS traffic as a DNS proxy, or both. It is the most common method to send traffic from user devices to be filtered and decrypted by Cloudflare Gateway.
### PAC files (Enterprise only)
@@ -56,7 +56,7 @@ For more information on how Cloudflare WAN integrates with Zero Trust, refer to
[WARP Connector](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/), a software agent similar to our device client, functions as a virtual device to establish a connection between your network and the Cloudflare global network. You can install WARP Connector on a dedicated Linux server or virtual machine.
-WARP Connector supports egressing traffic from your private network to the Internet as a gateway. This means it can allow traffic initiated from a network to be on-ramped to Cloudflare for either public or private destinations. You can use WARP Connector to establish a secure egress path for servers or users on a network which may not each be able to run the WARP client and still apply Gateway network and HTTP inspection policies. This connection is most analogous to proxy server connectivity or site-to-site VPN.
+WARP Connector supports egressing traffic from your private network to the Internet as a gateway. This means it can allow traffic initiated from a network to be on-ramped to Cloudflare for either public or private destinations. You can use WARP Connector to establish a secure egress path for servers or users on a network which may not each be able to run the Cloudflare One Client and still apply Gateway network and HTTP inspection policies. This connection is most analogous to proxy server connectivity or site-to-site VPN.
For more information on setting up Cloudflare Tunnel via WARP Connector, refer to [Set up WARP Connector](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/).
diff --git a/src/content/docs/learning-paths/secure-internet-traffic/connect-devices-networks/install-agent.mdx b/src/content/docs/learning-paths/secure-internet-traffic/connect-devices-networks/install-agent.mdx
index 79e3b2f6634..100910ecc26 100644
--- a/src/content/docs/learning-paths/secure-internet-traffic/connect-devices-networks/install-agent.mdx
+++ b/src/content/docs/learning-paths/secure-internet-traffic/connect-devices-networks/install-agent.mdx
@@ -1,5 +1,5 @@
---
-title: Download and install WARP
+title: Download and install the Cloudflare One Client
pcx_content_type: learning-unit
sidebar:
order: 2
diff --git a/src/content/docs/learning-paths/secure-internet-traffic/initial-setup/prerequisites.mdx b/src/content/docs/learning-paths/secure-internet-traffic/initial-setup/prerequisites.mdx
index e5e59ea09d6..5354603607f 100644
--- a/src/content/docs/learning-paths/secure-internet-traffic/initial-setup/prerequisites.mdx
+++ b/src/content/docs/learning-paths/secure-internet-traffic/initial-setup/prerequisites.mdx
@@ -8,5 +8,5 @@ sidebar:
To make the most of securing your Internet traffic and SaaS apps, make sure that you have the following:
-* A device that can run [WARP](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/), Cloudflare's endpoint agent.
-* (Optional) A [Linux host server](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/#linux) on the private network that can run the Cloudflare WARP Connector.
+* A device that can run [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/), Cloudflare's endpoint agent.
+* (Optional) A [Linux host server](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/#linux) on the private network that can run the Cloudflare One Client Connector.
diff --git a/src/content/docs/learning-paths/secure-internet-traffic/secure-saas-applications/layer-security.mdx b/src/content/docs/learning-paths/secure-internet-traffic/secure-saas-applications/layer-security.mdx
index 9a059fab2e0..1383c6d4176 100644
--- a/src/content/docs/learning-paths/secure-internet-traffic/secure-saas-applications/layer-security.mdx
+++ b/src/content/docs/learning-paths/secure-internet-traffic/secure-saas-applications/layer-security.mdx
@@ -21,11 +21,11 @@ You can deliver inline security through Browser Isolation, but it requires a [fr
## Browser Isolation
-Cloudflare can deliver isolate SaaS apps in via either the WARP client or static links with Clientless Web Isolation.
+Cloudflare can deliver isolate SaaS apps in via either the Cloudflare One Client or static links with Clientless Web Isolation.
-### WARP client
+### Cloudflare One Client
-When your users' devices are enrolled with the WARP client, Cloudflare will transparently isolate browser sessions. In other words, a user's browser will display `example.com`, but Cloudflare will isolate the traffic by rendering it in an isolated browser.
+When your users' devices are enrolled with the Cloudflare One Client, Cloudflare will transparently isolate browser sessions. In other words, a user's browser will display `example.com`, but Cloudflare will isolate the traffic by rendering it in an isolated browser.
### Clientless Web Isolation
diff --git a/src/content/docs/learning-paths/secure-internet-traffic/secure-saas-applications/sso-front-door.mdx b/src/content/docs/learning-paths/secure-internet-traffic/secure-saas-applications/sso-front-door.mdx
index 16d05d749f4..bf187c53062 100644
--- a/src/content/docs/learning-paths/secure-internet-traffic/secure-saas-applications/sso-front-door.mdx
+++ b/src/content/docs/learning-paths/secure-internet-traffic/secure-saas-applications/sso-front-door.mdx
@@ -35,7 +35,7 @@ If you cannot use Access for SaaS for some or all of your SaaS apps, you can acc
### Policies based on dedicated egress IPs
-With [dedicated egress IPs](/cloudflare-one/traffic-policies/egress-policies/dedicated-egress-ips/), you can set explicit egress locations globally and share these IPs with your SSO provider. With this Zero Trust security approach, your users must meet all of your Cloudflare requirements (such as being enrolled in WARP or Browser Isolation) when they authenticate to your SSO provider. Using your dedicated egress IPs as a control mechanism within your SSO means you can set policies on the basis of which users are subject to security policy and inspection because they are guaranteed to be proxied through Cloudflare.
+With [dedicated egress IPs](/cloudflare-one/traffic-policies/egress-policies/dedicated-egress-ips/), you can set explicit egress locations globally and share these IPs with your SSO provider. With this Zero Trust security approach, your users must meet all of your Cloudflare requirements (such as being enrolled in the Cloudflare One Client or Browser Isolation) when they authenticate to your SSO provider. Using your dedicated egress IPs as a control mechanism within your SSO means you can set policies on the basis of which users are subject to security policy and inspection because they are guaranteed to be proxied through Cloudflare.
### Generic IdP multi-factor authentication
diff --git a/src/content/docs/load-balancing/load-balancers/index.mdx b/src/content/docs/load-balancing/load-balancers/index.mdx
index babf9ec1575..14bc343596d 100644
--- a/src/content/docs/load-balancing/load-balancers/index.mdx
+++ b/src/content/docs/load-balancing/load-balancers/index.mdx
@@ -25,7 +25,7 @@ For suggestions, refer to [Common load balancer configurations](/load-balancing/
Public Load Balancers are designed to handle traffic from the public Internet. When deployed, they automatically receive a hostname, making them immediately accessible. These load balancers can direct traffic to a range of destinations, including public hostnames, public IP addresses, and private IP addresses.
-Private Load Balancers, in contrast, are meant for internal use within private networks. They do not automatically receive a hostname, but one can be assigned via Gateway Firewall Policies or through an internal DNS system. Private Load Balancers only accept traffic over a private network on-ramp, such as [Cloudflare WARP](/warp-client/) or [Cloudflare WAN](/cloudflare-wan/). They are capable of forwarding traffic exclusively to private IP addresses.
+Private Load Balancers, in contrast, are meant for internal use within private networks. They do not automatically receive a hostname, but one can be assigned via Gateway Firewall Policies or through an internal DNS system. Private Load Balancers only accept traffic over a private network on-ramp, such as [the Cloudflare One Client](/warp-client/) or [Cloudflare WAN](/cloudflare-wan/). They are capable of forwarding traffic exclusively to private IP addresses.
## Load balancing and existing DNS records
diff --git a/src/content/docs/load-balancing/private-network/index.mdx b/src/content/docs/load-balancing/private-network/index.mdx
index 6369efcd04e..1f9b57d133d 100644
--- a/src/content/docs/load-balancing/private-network/index.mdx
+++ b/src/content/docs/load-balancing/private-network/index.mdx
@@ -43,7 +43,7 @@ Private Network Load Balancing supports off-ramping traffic for Cloudflare WAN (
## On-ramps
-Private Network Load Balancing on-ramps, on the other hand, refer to secure paths between the end-user request and the Cloudflare network. Cloudflare Load Balancing supports traffic from [CDN](/cache/), [Spectrum](/spectrum/), [WARP](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) and [Cloudflare WAN](/cloudflare-wan/) and forward that traffic to a load balancer, and then egress to an endpoint behind any off-ramp (CDN/CNI/IPSec/GRE/Tunnel). Your traffic can ingress and egress by any on-ramp/off-ramp combination.
+Private Network Load Balancing on-ramps, on the other hand, refer to secure paths between the end-user request and the Cloudflare network. Cloudflare Load Balancing supports traffic from [CDN](/cache/), [Spectrum](/spectrum/), [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) and [Cloudflare WAN](/cloudflare-wan/) and forward that traffic to a load balancer, and then egress to an endpoint behind any off-ramp (CDN/CNI/IPSec/GRE/Tunnel). Your traffic can ingress and egress by any on-ramp/off-ramp combination.
:::note
When using [Spectrum](/spectrum/) as an on-ramp and [Cloudflare WAN](/load-balancing/private-network/#cloudflare-wan) as an off-ramp the [proxy protocol](/spectrum/how-to/enable-proxy-protocol/) setting in Spectrum is not supported.
@@ -59,4 +59,4 @@ When using [Spectrum](/spectrum/) as an on-ramp and [Cloudflare WAN](/load-balan
- **Host applications on non-standard ports**: Easily specify and route traffic to applications hosted on private IP addresses using non-standard ports, allowing greater flexibility in service configuration without requiring changes to existing infrastructure.
-- **Public and Private Load Balancers**: Public LBs can direct Internet traffic to private IP addresses, supporting all L7 products like WAF and API Shield. Private LBs direct traffic originating from private networks to private IP addresses and require an on-ramp like WARP or Cloudflare WAN.
+- **Public and Private Load Balancers**: Public LBs can direct Internet traffic to private IP addresses, supporting all L7 products like WAF and API Shield. Private LBs direct traffic originating from private networks to private IP addresses and require an on-ramp like the Cloudflare One Client or Cloudflare WAN.
diff --git a/src/content/docs/load-balancing/private-network/warp-to-tunnel.mdx b/src/content/docs/load-balancing/private-network/warp-to-tunnel.mdx
index cbe54b86883..2c8aa9b3859 100644
--- a/src/content/docs/load-balancing/private-network/warp-to-tunnel.mdx
+++ b/src/content/docs/load-balancing/private-network/warp-to-tunnel.mdx
@@ -1,6 +1,6 @@
---
pcx_content_type: how-to
-title: Set up Private Network Load Balancing with WARP-to-Tunnel
+title: Set up Private Network Load Balancing with Client-to-Tunnel
sidebar:
order: 4
---
@@ -14,9 +14,9 @@ import {
GlossaryTooltip,
} from "~/components";
-You can use Private Network Load Balancing to distribute WARP client traffic to private hostnames and IPs connected via [Cloudflare Tunnel](/cloudflare-one/networks/connectors/cloudflare-tunnel/).
+You can use Private Network Load Balancing to distribute Cloudflare One Client traffic to private hostnames and IPs connected via [Cloudflare Tunnel](/cloudflare-one/networks/connectors/cloudflare-tunnel/).
-For example, assume you have an internal application running in two data centers, and you want WARP users to access the application from the data center closest to their geographic location. A typical load balancing configuration is shown in the following diagram:
+For example, assume you have an internal application running in two data centers, and you want Cloudflare One Client users to access the application from the data center closest to their geographic location. A typical load balancing configuration is shown in the following diagram:
```mermaid
graph LR
@@ -124,9 +124,9 @@ The following example adds a Cloudflare Tunnel endpoint to an existing Load Bala
After completing the setup, you will be redirected to the Load Balancing dashboard. You can locate your load balancer using the search bar or by filtering for **Private** load balancers. Be sure to note the load balancer IP as it will be required in the following steps.
-## 3. Route the load balancer IP through WARP
+## 3. Route the load balancer IP through the Cloudflare One Client
-In order for WARP clients to connect to your load balancer, the load balancer's IP address must route through the WARP tunnel in your [Split Tunnel settings](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/).
+In order for Cloudflare One Clients to connect to your load balancer, the load balancer's IP address must route through the WARP tunnel in your [Split Tunnel settings](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/).
1. In [Cloudflare One](https://one.dash.cloudflare.com), go to **Team & Resources** > **Device profiles**.
2. Find the [device profile](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-profiles/) you would like to modify and select **Edit**.
@@ -138,7 +138,7 @@ In order for WARP clients to connect to your load balancer, the load balancer's
:::
- **Include mode**: Add your load balancer IP.
-WARP traffic can now reach your private load balancer. For example, if your load balancer points to a web application, you can test by running `curl ` from the WARP device. This traffic will be distributed over Cloudflare Tunnel to your private endpoints according to your configured steering method.
+Cloudflare One Client traffic can now reach your private load balancer. For example, if your load balancer points to a web application, you can test by running `curl ` from the device. This traffic will be distributed over Cloudflare Tunnel to your private endpoints according to your configured steering method.
## 4. (Optional) Assign a hostname to the load balancer
diff --git a/src/content/docs/network-flow/tutorials/encrypt-network-flow-data.mdx b/src/content/docs/network-flow/tutorials/encrypt-network-flow-data.mdx
index 644aa20effc..315f3edeba0 100644
--- a/src/content/docs/network-flow/tutorials/encrypt-network-flow-data.mdx
+++ b/src/content/docs/network-flow/tutorials/encrypt-network-flow-data.mdx
@@ -8,7 +8,7 @@ head:
- tag: title
content: Network Flow encrypt network flow data
description: >-
- Encrypt the network flowData sent from your router to Cloudflare by routing your network traffic through a device running the WARP client.
+ Encrypt the network flowData sent from your router to Cloudflare by routing your network traffic through a device running the Cloudflare One Client.
---
import { Render } from "~/components";
diff --git a/src/content/docs/reference-architecture/architectures/cloudflare-sase-with-crowdstrike.mdx b/src/content/docs/reference-architecture/architectures/cloudflare-sase-with-crowdstrike.mdx
index fc16e9796a3..b422d24a5b2 100644
--- a/src/content/docs/reference-architecture/architectures/cloudflare-sase-with-crowdstrike.mdx
+++ b/src/content/docs/reference-architecture/architectures/cloudflare-sase-with-crowdstrike.mdx
@@ -45,7 +45,7 @@ The integration between Cloudflare and CrowdStrike establishes a comprehensive s
The architecture is defined by the following key flows:
- **Zero trust access control:**
- - The user's endpoint runs both the Cloudflare WARP client and the CrowdStrike Falcon agent.
+ - The user's endpoint runs both the Cloudflare One Client and the CrowdStrike Falcon agent.
- CrowdStrike Falcon Device Posture and ZTA scores are shared with Cloudflare via a service-to-service API.
- Cloudflare uses this real-time device health information as a critical factor in its Cloudflare Access decisions, enforcing zero trust policies for both public and private applications.
- **Unified security telemetry:**
diff --git a/src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx b/src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
index e893d763b91..b57fbb2d5c8 100644
--- a/src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
+++ b/src/content/docs/reference-architecture/architectures/cloudflare-sase-with-sentinelone.mdx
@@ -48,7 +48,7 @@ The SentinelOne Management Console provides centralized control and visibility,
Cloudflare's Zero Trust infrastructure provides the policy enforcement layer:
-The WARP client must be deployed alongside the SentinelOne agent on managed devices. This client creates the secure connection to Cloudflare's network and enables device posture checking.
+The Cloudflare One Client must be deployed alongside the SentinelOne agent on managed devices. This client creates the secure connection to Cloudflare's network and enables device posture checking.
The Cloudflare dashboard provides the configuration interface for:
@@ -64,7 +64,7 @@ The Cloudflare dashboard provides the configuration interface for:
When a user attempts to access a protected resource, the following sequence occurs:
-1. The user's device connects to Cloudflare's network through the WARP client.
+1. The user's device connects to Cloudflare's network through the Cloudflare One Client.
2. Cloudflare queries the SentinelOne API to check the device's security posture.
3. The SentinelOne platform returns current device status including infection state, threats, and agent health.
4. Cloudflare evaluates this information against configured policies.
@@ -100,9 +100,9 @@ SentinelOne provides [endpoint detection and response (EDR)](https://www.sentine

-The integration architecture begins at the managed endpoint device level, where two critical components coexist. The SentinelOne agent serves as the primary security enforcer, continuously monitoring the device for threats, assessing device health, and providing real-time security status updates. Alongside it, the Cloudflare WARP client establishes secure connectivity and manages the device's interaction with Cloudflare's Zero Trust infrastructure. These components work in tandem to ensure both endpoint security and secure network access.
+The integration architecture begins at the managed endpoint device level, where two critical components coexist. The SentinelOne agent serves as the primary security enforcer, continuously monitoring the device for threats, assessing device health, and providing real-time security status updates. Alongside it, the Cloudflare One Client establishes secure connectivity and manages the device's interaction with Cloudflare's Zero Trust infrastructure. These components work in tandem to ensure both endpoint security and secure network access.
-When a user attempts to access protected resources, the architecture initiates a sophisticated verification process. The WARP client first establishes a secure tunnel to Cloudflare's global network, creating an encrypted channel for all communications. This connection ensures that all traffic between the device and protected resources remains secure and can be properly evaluated against security policies.
+When a user attempts to access protected resources, the architecture initiates a sophisticated verification process. The Cloudflare One Client first establishes a secure tunnel to Cloudflare's global network, creating an encrypted channel for all communications. This connection ensures that all traffic between the device and protected resources remains secure and can be properly evaluated against security policies.
### Cloudflare Zero Trust platform operations
@@ -122,11 +122,11 @@ The **Security Analytics** component continuously processes security telemetry f
When a user requires access to protected resources, the architecture follows a specific flow:
-First, the device's security status is evaluated through the **SentinelOne agent**, which reports detailed health and security information to the SentinelOne platform. Simultaneously, the **Cloudflare WARP client** initiates the access request to Cloudflare's Zero Trust platform.
+First, the device's security status is evaluated through the **SentinelOne agent**, which reports detailed health and security information to the SentinelOne platform. Simultaneously, the **Cloudflare One Client** initiates the access request to Cloudflare's Zero Trust platform.
Next, Cloudflare's **Device Posture Engine** queries the SentinelOne platform through its **API Services** to verify the device's security status. This check includes all current security metrics, threat status, and compliance information. The **Access Policy Engine** then evaluates this information against defined security policies.
-If all security requirements are met, access is granted through the secure tunnel established by the WARP client. Throughout the session, continuous monitoring ensures that any change in device security status can trigger immediate reevaluation of access permissions.
+If all security requirements are met, access is granted through the secure tunnel established by the Cloudflare One Client. Throughout the session, continuous monitoring ensures that any change in device security status can trigger immediate reevaluation of access permissions.
### Security and monitoring capabilities
@@ -150,7 +150,7 @@ Organizations should consider their network architecture when implementing this
- Bandwidth and latency requirements for posture checks
- Integration with existing security tools and workflows
-The integration between Cloudflare One and SentinelOne requires thoughtful planning to ensure successful implementation. At its foundation, organizations need to prepare their environment by having the SentinelOne agent and Cloudflare WARP client deployed on all devices that will be subject to posture checks. This foundational step ensures that both security monitoring and secure network connectivity are in place before building additional security controls.
+The integration between Cloudflare One and SentinelOne requires thoughtful planning to ensure successful implementation. At its foundation, organizations need to prepare their environment by having the SentinelOne agent and Cloudflare One Client deployed on all devices that will be subject to posture checks. This foundational step ensures that both security monitoring and secure network connectivity are in place before building additional security controls.
When implementing the integration, organizations should approach it as a service provider relationship where SentinelOne acts as a trusted source of device security information. This relationship is established through secure API communications, with careful attention paid to proper credential management and regular verification of the connection between the platforms. The integration relies on SentinelOne's ability to provide real-time device security status, which Cloudflare then uses to make access decisions.
diff --git a/src/content/docs/reference-architecture/architectures/sase.mdx b/src/content/docs/reference-architecture/architectures/sase.mdx
index 15286fb8c5f..8581626febc 100644
--- a/src/content/docs/reference-architecture/architectures/sase.mdx
+++ b/src/content/docs/reference-architecture/architectures/sase.mdx
@@ -497,16 +497,16 @@ Not only does the user identity need to be verified, but the security posture of
The following built-in posture checks are available:
-- [Application check](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/application-check/): Checks that a specific application process is running
-- [File check](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/file-check/): Checks for the presence of a file
-- [Firewall](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/firewall/): Checks if a firewall is running
-- [Disk encryption](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/disk-encryption/): Checks if/how many disks are encrypted
-- [Domain joined](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/domain-joined/): Checks if the device is joined to a Microsoft Active Directory domain
-- [OS version](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/os-version/): Checks what version of the OS is running
-- [Unique Client ID](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/device-uuid/): When using an MDM too, organizations can assign a verifiable UUID to a mobile, desktop, or laptop device
-- [Device serial number](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/corp-device/): Checks to see if the device serial matches a list of company desktop/laptop computers
-
-Cloudflare One can also integrate with any deployed endpoint security solution, such as [Microsoft Endpoint Manager](/cloudflare-one/integrations/service-providers/microsoft/), [Tanium](/cloudflare-one/integrations/service-providers/taniums2s/), [Carbon Black](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/carbon-black/), [CrowdStrike](/cloudflare-one/integrations/service-providers/crowdstrike/), [SentinelOne](/cloudflare-one/integrations/service-providers/sentinelone/), and more. Any data from those products can be passed to Cloudflare for use in access decisions.
+- [Application check](/cloudflare-one/reusable-components/posture-checks/client-checks/application-check/): Checks that a specific application process is running
+- [File check](/cloudflare-one/reusable-components/posture-checks/client-checks/file-check/): Checks for the presence of a file
+- [Firewall](/cloudflare-one/reusable-components/posture-checks/client-checks/firewall/): Checks if a firewall is running
+- [Disk encryption](/cloudflare-one/reusable-components/posture-checks/client-checks/disk-encryption/): Checks if/how many disks are encrypted
+- [Domain joined](/cloudflare-one/reusable-components/posture-checks/client-checks/domain-joined/): Checks if the device is joined to a Microsoft Active Directory domain
+- [OS version](/cloudflare-one/reusable-components/posture-checks/client-checks/os-version/): Checks what version of the OS is running
+- [Unique Client ID](/cloudflare-one/reusable-components/posture-checks/client-checks/device-uuid/): When using an MDM too, organizations can assign a verifiable UUID to a mobile, desktop, or laptop device
+- [Device serial number](/cloudflare-one/reusable-components/posture-checks/client-checks/corp-device/): Checks to see if the device serial matches a list of company desktop/laptop computers
+
+Cloudflare One can also integrate with any deployed endpoint security solution, such as [Microsoft Endpoint Manager](/cloudflare-one/integrations/service-providers/microsoft/), [Tanium](/cloudflare-one/integrations/service-providers/taniums2s/), [Carbon Black](/cloudflare-one/reusable-components/posture-checks/client-checks/carbon-black/), [CrowdStrike](/cloudflare-one/integrations/service-providers/crowdstrike/), [SentinelOne](/cloudflare-one/integrations/service-providers/sentinelone/), and more. Any data from those products can be passed to Cloudflare for use in access decisions.
All of the above device information, combined with data on the user identity and also the network the device is on, is available in Cloudflare to be used as part of the company policy. For example, organizations could choose to only allow administrators to SSH into servers when all of the following conditions are met: their device is free from threats, running the latest operating system, and joined to the company domain.
diff --git a/src/content/docs/reference-architecture/architectures/security.mdx b/src/content/docs/reference-architecture/architectures/security.mdx
index d75ee5eacf7..39a3c1e8bdb 100644
--- a/src/content/docs/reference-architecture/architectures/security.mdx
+++ b/src/content/docs/reference-architecture/architectures/security.mdx
@@ -467,7 +467,7 @@ All network assets, whether on-premises or in private or public-hosted cloud env
##### Cloudflare WAN
-With [Cloudflare WAN](/cloudflare-wan/), customers can securely connect any traffic source — data centers, offices, devices, cloud properties — to Cloudflare’s network and configure routing policies to get the bits where they need to go. Cloudflare WAN supports a variety of on-ramps, including anycast GRE and IPsec tunnels, Cloudflare Network Interconnect, Cloudflare Tunnel, WARP, and a variety of network on-ramp partners. Cloudflare WAN can help end reliance on traditional SD-WAN appliances and securely connect users, offices, data centers, and hybrid cloud over the Cloudflare global network without relying on vendor-specific hardware or software.
+With [Cloudflare WAN](/cloudflare-wan/), customers can securely connect any traffic source — data centers, offices, devices, cloud properties — to Cloudflare’s network and configure routing policies to get the bits where they need to go. Cloudflare WAN supports a variety of on-ramps, including anycast GRE and IPsec tunnels, Cloudflare Network Interconnect, Cloudflare Tunnel, the Cloudflare One Client, and a variety of network on-ramp partners. Cloudflare WAN can help end reliance on traditional SD-WAN appliances and securely connect users, offices, data centers, and hybrid cloud over the Cloudflare global network without relying on vendor-specific hardware or software.
##### Cloudflare Network Firewall
diff --git a/src/content/docs/reference-architecture/design-guides/designing-ztna-access-policies.mdx b/src/content/docs/reference-architecture/design-guides/designing-ztna-access-policies.mdx
index b1bba0fbd3c..39e4ddd37ad 100644
--- a/src/content/docs/reference-architecture/design-guides/designing-ztna-access-policies.mdx
+++ b/src/content/docs/reference-architecture/design-guides/designing-ztna-access-policies.mdx
@@ -62,7 +62,7 @@ For SaaS and other Internet-facing applications, access from Cloudflare is simpl
- Our recommended approach is to use [software agents](/cloudflare-one/networks/connectors/cloudflare-tunnel/) such as [cloudflared](/cloudflare-one/networks/connectors/cloudflare-tunnel/get-started/) or [WARP connector](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/). (Note, only cloudflared currently supports proxying of public hostnames to private applications.)
- For network-based connectivity, [Cloudflare WAN](/cloudflare-wan/) (formerly Magic WAN) uses IPsec or GRE tunnels connecting Cloudflare to existing network appliances that are connected to the private networks, and [Network Interconnect](/network-interconnect/) creates direct connectivity if your applications run on servers in a data center Cloudflare operates in. (For migrating from existing legacy VPN solutions to network-based tunnels, you may find [this guide](/reference-architecture/design-guides/network-vpn-migration/) useful.)
-Once we have established connectivity to your applications, it is time to facilitate user access. Depending on your policy requirements (more on this later) users can access the application directly over an Internet connection to a public hostname, or — for greater security — we recommend using our [device agent](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/), Cloudflare WARP, which creates a tunnel directly to Cloudflare and also provides information about their device for use in access policies.
+Once we have established connectivity to your applications, it is time to facilitate user access. Depending on your policy requirements (more on this later) users can access the application directly over an Internet connection to a public hostname, or — for greater security — we recommend using our [device agent](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/), the Cloudflare One Client, which creates a tunnel directly to Cloudflare and also provides information about their device for use in access policies.
### Identity
@@ -70,7 +70,7 @@ A critical part of application access is authenticating a user. Cloudflare has a
### Device posture
-The final prerequisite for building really effective access policies is to configure [device posture](/cloudflare-one/reusable-components/posture-checks/). When using the [device agent](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/), Cloudflare has access to a [variety of information](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/) about the device which can then be used in an access policy. When using an [agentless method](/reference-architecture/diagrams/sase/sase-clientless-access-private-dns/) to access applications, only the user identity information is available. We also support using device posture information from [other vendors](/cloudflare-one/integrations/service-providers/), such as Microsoft, Crowdstrike and Sentinel One.
+The final prerequisite for building really effective access policies is to configure [device posture](/cloudflare-one/reusable-components/posture-checks/). When using the [device agent](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/), Cloudflare has access to a [variety of information](/cloudflare-one/reusable-components/posture-checks/client-checks/) about the device which can then be used in an access policy. When using an [agentless method](/reference-architecture/diagrams/sase/sase-clientless-access-private-dns/) to access applications, only the user identity information is available. We also support using device posture information from [other vendors](/cloudflare-one/integrations/service-providers/), such as Microsoft, Crowdstrike and Sentinel One.

@@ -282,7 +282,7 @@ This is a very simple Access Group, with just two group selectors. Note that bec
As you can see, it defines that "all employees" are those in the Azure AD group "Full Time Employees", who are also in the group "Completed security training." The first selector defines the initial scope of the Access Group, and the second selector requires that they must also be in that specific group.
-This Access Group requires that three [device posture checks](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/) have been created for the [OS version](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/os-version/). For example, the posture check "Latest version of macOS" is defined as "macOS version is greater than or equal to 15.1" and reflects the latest version the company considers stable and secure (vs. the very latest OS version). Once included in the Access policy, this will enforce the logic we’ve established here - if any user wants to sign in as a 'Secure Employee', they'll need to meet these requirements.
+This Access Group requires that three [device posture checks](/cloudflare-one/reusable-components/posture-checks/client-checks/) have been created for the [OS version](/cloudflare-one/reusable-components/posture-checks/client-checks/os-version/). For example, the posture check "Latest version of macOS" is defined as "macOS version is greater than or equal to 15.1" and reflects the latest version the company considers stable and secure (vs. the very latest OS version). Once included in the Access policy, this will enforce the logic we’ve established here - if any user wants to sign in as a 'Secure Employee', they'll need to meet these requirements.
#### Employees on trusted devices
@@ -341,7 +341,7 @@ But notice we now enable "Isolate Application." What does this mean? This forces
In the example above, the SWG policy is matching any traffic heading to your company wiki, then enforcing RBI (to match the ZTNA application policy) and then disabling all interaction with the wiki.
-It also adds the device posture check "WARP Check (Mac OS)" to scan the user's device for the presence of our device agent. If the user's device does not have the agent installed and enabled, then the device posture check cannot occur and they will automatically fail to meet the policy requirements. If the user does have the device agent enabled, then they will pass the posture check and be granted full wiki access. Note that WARP is the name used for our device agent.
+It also adds the device posture check "WARP Check (Mac OS)" to scan the user's device for the presence of our device agent. If the user's device does not have the agent installed and enabled, then the device posture check cannot occur and they will automatically fail to meet the policy requirements. If the user does have the device agent enabled, then they will pass the posture check and be granted full wiki access. Note that the Cloudflare One Client is the name used for our device agent.
Essentially, the employee on an insecure device is permitted to view the wiki in a "read-only" mode, but is restricted from further interactions like uploading/downloading or copying/pasting confidential information.
@@ -349,7 +349,7 @@ This policy approach accomplishes several objectives:
1. It enforces the use of trusted devices for full access to the wiki, aligning with your Zero Trust security goals.
2. It provides a fallback option for employees using personal devices, allowing them to access the wiki in a limited, secure manner through browser isolation.
-3. It incentivizes employees to use their company devices and/or keep WARP enabled, which is a net positive for an organization's security posture.
+3. It incentivizes employees to use their company devices and/or keep the Cloudflare One Client enabled, which is a net positive for an organization's security posture.
4. It demonstrates the power and flexibility of more granular security controls achieved by combining Cloudflare Access policies with Cloudflare Gateway HTTP policies.
This approach both secures your wiki and establishes a model for protecting other applications — allowing your organization to maintain strong cyber hygiene while adapting to the realities of hybrid work scenarios.
@@ -468,7 +468,7 @@ Define the policy:
| Device Posture \- Serial Number List | Company Managed Device Serial Numbers |
| External Evaluation | \[Time Evaluator URL\] |
-Inside the policy, we have made this application available to our new access group for IT Admins. Under "Require," we are enforcing the use of Cloudflare WARP specifically (as opposed to only Cloudflare Gateway). The user must be on a company-managed device, with an active device client that is authenticated to the company's instance of Cloudflare, MFA must be used during login, and there is an additional option below for external evaluation.
+Inside the policy, we have made this application available to our new access group for IT Admins. Under "Require," we are enforcing the use of the Cloudflare One Client specifically (as opposed to only Cloudflare Gateway). The user must be on a company-managed device, with an active device client that is authenticated to the company's instance of Cloudflare, MFA must be used during login, and there is an additional option below for external evaluation.
[External evaluation](/cloudflare-one/access-controls/policies/external-evaluation/) means we have an API endpoint containing some sort of [access logic](https://github.com/cloudflare/workers-access-external-auth-example) — in this case, time of day access. We are making an API call to this endpoint, and defining the key that Cloudflare is using to verify that the response came from the API. This is useful for several reasons:
@@ -483,7 +483,7 @@ Now, you will learn how to secure RDP access as a private IP application:
| Application Name | RDP |
| Destination IP | 169.254.255.254 |
-As mentioned before, private IP applications work because Cloudflare proxies the IP range across its network. The nature of this application necessitates the use of the device client, as unless the user is connected to Cloudflare (and more specifically, unless they can take advantage of the WARP-to-Tunnel connectivity), they will not be able to reach non-local RFC 1918 addresses.
+As mentioned before, private IP applications work because Cloudflare proxies the IP range across its network. The nature of this application necessitates the use of the device client, as unless the user is connected to Cloudflare (and more specifically, unless they can take advantage of the Client-to-Tunnel connectivity), they will not be able to reach non-local RFC 1918 addresses.
| Traffic | |
| :--------------------------------------- | :-------------------------------------------------------------- |
diff --git a/src/content/docs/reference-architecture/design-guides/zero-trust-for-startups.mdx b/src/content/docs/reference-architecture/design-guides/zero-trust-for-startups.mdx
index 5b4e4064e70..1cb86d9722a 100644
--- a/src/content/docs/reference-architecture/design-guides/zero-trust-for-startups.mdx
+++ b/src/content/docs/reference-architecture/design-guides/zero-trust-for-startups.mdx
@@ -226,7 +226,7 @@ If both operating models sound complicated and imperfect, it's because they are.
If your organization is experimenting with mesh connectivity, Cloudflare can help support discrete connectivity models while layering in unique identity concepts and supporting your security and scalability needs as you construct a networking framework to support your future growth.
-The Cloudflare products that are typically most relevant for startups are a combination of our WARP client (via `cloudflared`) and Cloudflare Tunnel (via WARP Connector). This allows you to manage remote access, mesh connectivity, and traditional networking connectivity from a single dashboard. On a more granular level, this means you can configure device posture information, identity information, client certificates, and common L4 indicators (like port, IP, and source/destination protocols) from a single point of policy enforcement — enabling you to build robust security policies for both human and autonomous network interaction.
+The Cloudflare products that are typically most relevant for startups are a combination of the Cloudflare One Client (via `cloudflared`) and Cloudflare Tunnel (via WARP Connector). This allows you to manage remote access, mesh connectivity, and traditional networking connectivity from a single dashboard. On a more granular level, this means you can configure device posture information, identity information, client certificates, and common L4 indicators (like port, IP, and source/destination protocols) from a single point of policy enforcement — enabling you to build robust security policies for both human and autonomous network interaction.

@@ -320,7 +320,7 @@ Cloudflare can help provide scoped secure access for both web and network connec
- **Cloudflare Access can integrate and use [multiple identity providers simultaneously](/cloudflare-one/integrations/identity-providers/).** This can be scoped to a single application and a singular policy, and can have granular capabilities to 'force' some user access to authenticate in specific ways. There are also many third-party specific workflows — like [purpose justification](/cloudflare-one/access-controls/policies/require-purpose-justification/) — that can ensure that user access is both easy for third parties, and documented and controllable for administrators.
- **Cloudflare Zero Trust can be deployed with flexible endpoint agent parameters and [logical groupings](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-profiles/) for contractor and third-party users.** If you have external users with internal access needs, they can be both tightly-scoped and limit potential conflict with other external systems.
- **[Cloudflare Tunnel](/cloudflare-one/networks/connectors/cloudflare-tunnel/) can act as a unidirectional access model to provide corporate users access to scoped customer resources.** It is lightweight, easy to deploy, and can even be built into your deployment packages and deployed alongside the services you manage in customer environments.
-- **Cloudflare WARP Connector can help you build secure, extensible networks relevant for each of your client controls.** This is particularly helpful when bidirectional (site-to-site) traffic flows are a necessity for the way that you engage with your customers, interact with their applications, or address other management concerns. WARP Connector has all of the same inline security policy application and auditability controls as the rest of your deployment, so you can maintain a Zero Trust security posture while achieving customer connectivity.
+- **the Cloudflare One Client Connector can help you build secure, extensible networks relevant for each of your client controls.** This is particularly helpful when bidirectional (site-to-site) traffic flows are a necessity for the way that you engage with your customers, interact with their applications, or address other management concerns. WARP Connector has all of the same inline security policy application and auditability controls as the rest of your deployment, so you can maintain a Zero Trust security posture while achieving customer connectivity.

@@ -398,7 +398,7 @@ This framework can also give your IT organization direction on which tools to co
### Where does Cloudflare fit in?
-Cloudflare can help set a foundation for visibility and management of your [shadow IT](/cloudflare-one/insights/analytics/shadow-it-discovery/) environment and subsequent discoveries. User traffic to the Internet can be audited and organized from the WARP client and our [Secure Web Gateway (SWG)](/cloudflare-one/traffic-policies/), and can you understand where your sensitive data moves outside of your corporate-accepted SaaS tenants.
+Cloudflare can help set a foundation for visibility and management of your [shadow IT](/cloudflare-one/insights/analytics/shadow-it-discovery/) environment and subsequent discoveries. User traffic to the Internet can be audited and organized from the Cloudflare One Client and our [Secure Web Gateway (SWG)](/cloudflare-one/traffic-policies/), and can you understand where your sensitive data moves outside of your corporate-accepted SaaS tenants.
This can then be an opportunity to further expand your Zero Trust strategy by ensuring those newly-discovered tools are either explicitly blocked or explicitly allowed, setting specific data security controls on them, or integrating them with your Zero Trust vendor (using something like [Access for SaaS](/cloudflare-one/access-controls/applications/http-apps/saas-apps/aws-sso-saas/) to apply security policies).
diff --git a/src/content/docs/reference-architecture/diagrams/sase/augment-access-with-serverless.mdx b/src/content/docs/reference-architecture/diagrams/sase/augment-access-with-serverless.mdx
index c22a2f12be0..0795ae99518 100644
--- a/src/content/docs/reference-architecture/diagrams/sase/augment-access-with-serverless.mdx
+++ b/src/content/docs/reference-architecture/diagrams/sase/augment-access-with-serverless.mdx
@@ -102,7 +102,7 @@ Cloudflare's Workers are a great candidate for interacting with incoming JSON We
In some situations, it is beneficial to elaborate on this JWT in order to execute additional processing on the protected destination application (for example, adding device [posture details](/cloudflare-one/reusable-components/posture-checks/) as part of an incoming request).
-In the following example, we want to make sure the exposed application is aware of the status of the device's firewall and disk encryption (Note that the WARP client needs to be installed on the client machine for these signals to be collected).
+In the following example, we want to make sure the exposed application is aware of the status of the device's firewall and disk encryption (Note that the Cloudflare One Client needs to be installed on the client machine for these signals to be collected).

diff --git a/src/content/docs/reference-architecture/diagrams/sase/deploying-self-hosted-VoIP-services-for-hybrid-users.mdx b/src/content/docs/reference-architecture/diagrams/sase/deploying-self-hosted-VoIP-services-for-hybrid-users.mdx
index 56da67a7e37..dc9bfcd2a28 100644
--- a/src/content/docs/reference-architecture/diagrams/sase/deploying-self-hosted-VoIP-services-for-hybrid-users.mdx
+++ b/src/content/docs/reference-architecture/diagrams/sase/deploying-self-hosted-VoIP-services-for-hybrid-users.mdx
@@ -83,5 +83,5 @@ With Cloudflare's WARP Connector, remote users communicating with other remote u
## Related resources
- [Set up WARP Connector](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/)
-- [Enable WARP-to-WARP connectivity](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp/#enable-warp-to-warp)
-- [About Cloudflare WARP](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/)
+- [Enable Peer-to-peer connectivity](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp/#enable-warp-to-warp)
+- [About the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/)
diff --git a/src/content/docs/style-guide/api-content-strategy/api-content-types/parameters.mdx b/src/content/docs/style-guide/api-content-strategy/api-content-types/parameters.mdx
index 4733cd723aa..7c5edca09f3 100644
--- a/src/content/docs/style-guide/api-content-strategy/api-content-types/parameters.mdx
+++ b/src/content/docs/style-guide/api-content-strategy/api-content-types/parameters.mdx
@@ -42,7 +42,7 @@ Below are some examples of parameter descriptions for reference:
**deviceName**: The device name.
-**version**: The WARP client version.
+**version**: The Cloudflare One Client version.
**per\_page**: Sets the maximum number of requested results.
diff --git a/src/content/docs/tunnel/deployment-guides/aws.mdx b/src/content/docs/tunnel/deployment-guides/aws.mdx
index c4942d8fa93..1c47369107f 100644
--- a/src/content/docs/tunnel/deployment-guides/aws.mdx
+++ b/src/content/docs/tunnel/deployment-guides/aws.mdx
@@ -42,7 +42,7 @@ This guide covers how to connect an Amazon Web Services (AWS) EC2 instance to Cl
To test, open a browser and go to the hostname you configured. You should see your web server's page.
:::note[Looking for private network access?]
-To connect to your EC2 instance via private IP using the WARP client, refer to the [Cloudflare One Tunnel documentation](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/).
+To connect to your EC2 instance via private IP using the Cloudflare One Client, refer to the [Cloudflare One Tunnel documentation](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/).
:::
## Firewall configuration
diff --git a/src/content/docs/tunnel/deployment-guides/azure.mdx b/src/content/docs/tunnel/deployment-guides/azure.mdx
index 49660e879df..1ae715f0344 100644
--- a/src/content/docs/tunnel/deployment-guides/azure.mdx
+++ b/src/content/docs/tunnel/deployment-guides/azure.mdx
@@ -43,7 +43,7 @@ This guide covers how to connect an Azure Virtual Machine to Cloudflare using `c
To test, open a browser and go to the hostname you configured. You should see the **Hello Cloudflare!** test page.
:::note[Looking for private network access?]
-To connect to your Azure VM via private IP using the WARP client, refer to the [Cloudflare One Tunnel documentation](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/).
+To connect to your Azure VM via private IP using the Cloudflare One Client, refer to the [Cloudflare One Tunnel documentation](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/).
:::
## Firewall configuration
diff --git a/src/content/docs/tunnel/deployment-guides/google-cloud-platform.mdx b/src/content/docs/tunnel/deployment-guides/google-cloud-platform.mdx
index f8350ee4622..ff7b018172e 100644
--- a/src/content/docs/tunnel/deployment-guides/google-cloud-platform.mdx
+++ b/src/content/docs/tunnel/deployment-guides/google-cloud-platform.mdx
@@ -42,7 +42,7 @@ To test, open a browser and go to the hostname you configured.
You can optionally add [Cloudflare Access](/tunnel/integrations/#cloudflare-access) to control who can reach the service.
:::note[Looking for private network access?]
-To connect to your VM via private IP using the WARP client, refer to the [Cloudflare One Tunnel documentation](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/).
+To connect to your VM via private IP using the Cloudflare One Client, refer to the [Cloudflare One Tunnel documentation](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/).
:::
## Firewall configuration
diff --git a/src/content/docs/tunnel/integrations.mdx b/src/content/docs/tunnel/integrations.mdx
index 06a9979814b..2f15a2d8cb7 100644
--- a/src/content/docs/tunnel/integrations.mdx
+++ b/src/content/docs/tunnel/integrations.mdx
@@ -12,10 +12,10 @@ Cloudflare Tunnel integrates with other Cloudflare products to extend connectivi
## Cloudflare One (private networking)
-Beyond publishing public applications, Cloudflare Tunnel is the connectivity layer for [Cloudflare One](/cloudflare-one/) — Cloudflare's SASE platform. The same post-quantum encrypted tunnels that serve your public applications can also serve private traffic when combined with the [WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/):
+Beyond publishing public applications, Cloudflare Tunnel is the connectivity layer for [Cloudflare One](/cloudflare-one/) — Cloudflare's SASE platform. The same post-quantum encrypted tunnels that serve your public applications can also serve private traffic when combined with the [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/):
- **Private applications** — Expose internal web apps, SSH servers, RDP hosts, and other services to authenticated users without making them publicly reachable.
-- **Private networks** — Route entire IP ranges (RFC 1918, custom CIDRs) through a tunnel, replacing site-to-site VPNs. Users on WARP-enrolled devices reach private IPs as if they were on your private network.
+- **Private networks** — Route entire IP ranges (RFC 1918, custom CIDRs) through a tunnel, replacing site-to-site VPNs. Users on Cloudflare One Client-enrolled devices reach private IPs as if they were on your private network.
- **Network traffic filtering** — Apply DNS, HTTP, and network-level policies through [Cloudflare Gateway](/cloudflare-one/traffic-policies/) to all traffic flowing through the tunnel.
If you are using Cloudflare Tunnel for Zero Trust network access, VPN replacement, or private network connectivity, refer to the [Cloudflare One Tunnel documentation](/cloudflare-one/networks/connectors/cloudflare-tunnel/) for setup and configuration.
diff --git a/src/content/partials/cloudflare-one/access/bookmarks.mdx b/src/content/partials/cloudflare-one/access/bookmarks.mdx
index 26bb9cc3546..e600a0cf925 100644
--- a/src/content/partials/cloudflare-one/access/bookmarks.mdx
+++ b/src/content/partials/cloudflare-one/access/bookmarks.mdx
@@ -44,7 +44,7 @@ Bookmark policies support all [Access policy selectors](/cloudflare-one/access-c
- Identity-based selectors (such as emails, email domains, or identity provider groups)
- Location-based selectors (such as country or IP ranges)
-- Device posture checks (requires installing the WARP client)
+- Device posture checks (requires installing the Cloudflare One Client)
The following policy features are not supported for bookmark applications:
@@ -55,5 +55,5 @@ The following policy features are not supported for bookmark applications:
If you attempt to assign a policy that uses an unsupported feature, the dashboard will display an error.
:::tip[Device posture policies]
-To show bookmarks only to users on managed devices, assign a policy that requires device posture checks (such as [Require Gateway](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-gateway/)). The bookmark will only appear in the App Launcher for users whose devices satisfy the posture requirements.
+To show bookmarks only to users on managed devices, assign a policy that requires device posture checks (such as [Require Gateway](/cloudflare-one/reusable-components/posture-checks/client-checks/require-gateway/)). The bookmark will only appear in the App Launcher for users whose devices satisfy the posture requirements.
:::
\ No newline at end of file
diff --git a/src/content/partials/cloudflare-one/access/one-time-pin-warning.mdx b/src/content/partials/cloudflare-one/access/one-time-pin-warning.mdx
index 4c2923b52eb..a3a422c4b0b 100644
--- a/src/content/partials/cloudflare-one/access/one-time-pin-warning.mdx
+++ b/src/content/partials/cloudflare-one/access/one-time-pin-warning.mdx
@@ -6,6 +6,6 @@ import { Tabs, TabItem, Render } from "~/components";
:::note
-Access and WARP will evaluate identity based on a user's last-known state. If a user authenticates via your Identity Provider, but later authenticates with a different method (such as One-Time PIN), Access will no longer evaluate the user's Identity Provider group memberships. Identity Provider group memberships are created and managed by the IdP and group membership data can only persist in an IdP-based authentication.
+Access and the Cloudflare One Client will evaluate identity based on a user's last-known state. If a user authenticates via your Identity Provider, but later authenticates with a different method (such as One-Time PIN), Access will no longer evaluate the user's Identity Provider group memberships. Identity Provider group memberships are created and managed by the IdP and group membership data can only persist in an IdP-based authentication.
:::
diff --git a/src/content/partials/cloudflare-one/access/scim-requires-login.mdx b/src/content/partials/cloudflare-one/access/scim-requires-login.mdx
index b88a20fbf39..0aaa9e7f0ec 100644
--- a/src/content/partials/cloudflare-one/access/scim-requires-login.mdx
+++ b/src/content/partials/cloudflare-one/access/scim-requires-login.mdx
@@ -3,5 +3,5 @@
---
:::note
-New users must first [register the WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/manual-deployment/) or authenticate to an Access application before SCIM provisioning can begin.
+New users must first [register the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/manual-deployment/) or authenticate to an Access application before SCIM provisioning can begin.
:::
\ No newline at end of file
diff --git a/src/content/partials/cloudflare-one/access/self-hosted-app/create-app.mdx b/src/content/partials/cloudflare-one/access/self-hosted-app/create-app.mdx
index 4f6a9b6ca97..031d341c3f3 100644
--- a/src/content/partials/cloudflare-one/access/self-hosted-app/create-app.mdx
+++ b/src/content/partials/cloudflare-one/access/self-hosted-app/create-app.mdx
@@ -20,5 +20,5 @@ import { Render } from "~/components"
{
props.private && (
-
If the application is non-HTTPS or you do not have TLS decryption turned on, the session is tracked by the WARP client per application.
)
+
If the application is non-HTTPS or you do not have TLS decryption turned on, the session is tracked by the Cloudflare One Client per application.
)
}
\ No newline at end of file
diff --git a/src/content/partials/cloudflare-one/dex/http-test-create-steps.mdx b/src/content/partials/cloudflare-one/dex/http-test-create-steps.mdx
index 0274f10d025..708d43bafc7 100644
--- a/src/content/partials/cloudflare-one/dex/http-test-create-steps.mdx
+++ b/src/content/partials/cloudflare-one/dex/http-test-create-steps.mdx
@@ -6,7 +6,7 @@ To set up an HTTP test for an application:
4. Fill in the following fields:
- **Name**: Enter any name for the test.
- **Target**: Enter the URL of the website or application that you want to test (for example, `https://jira.site.com`). Both public and private hostnames are supported. If testing a private hostname, ensure that the domain is on your [local domain fallback](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/local-domains/) list.
- - **Source device profiles**: (Optional) Select the [WARP device profiles](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-profiles/) that you want to run the test on. If no profiles are selected, the test will run on all supported devices connected to your Zero Trust organization.
+ - **Source device profiles**: (Optional) Select the [device profiles](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-profiles/) that you want to run the test on. If no profiles are selected, the test will run on all supported devices connected to your Zero Trust organization.
- **Test type**: Select _HTTP Get_.
- **Test frequency**: Specify how often the test will run. Input a minute value between 5 and 60.
5. Select **Add test**.
diff --git a/src/content/partials/cloudflare-one/dex/intro.mdx b/src/content/partials/cloudflare-one/dex/intro.mdx
index 96eac7dbe6c..c971f7911ab 100644
--- a/src/content/partials/cloudflare-one/dex/intro.mdx
+++ b/src/content/partials/cloudflare-one/dex/intro.mdx
@@ -1,3 +1,3 @@
Digital Experience Monitoring (DEX) provides visibility into device, network, and application performance across your Zero Trust organization.
-With DEX, you can monitor the state of your [WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) deployment and resolve issues impacting end-user productivity. DEX is designed for IT and security teams who need to proactively monitor and troubleshoot device and network health across distributed environments. DEX is available on all Cloudflare Zero Trust and SASE plans.
+With DEX, you can monitor the state of your [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) deployment and resolve issues impacting end-user productivity. DEX is designed for IT and security teams who need to proactively monitor and troubleshoot device and network health across distributed environments. DEX is available on all Cloudflare Zero Trust and SASE plans.
diff --git a/src/content/partials/cloudflare-one/dex/notifications-intro.mdx b/src/content/partials/cloudflare-one/dex/notifications-intro.mdx
index 87283d2fc6b..7323f05d091 100644
--- a/src/content/partials/cloudflare-one/dex/notifications-intro.mdx
+++ b/src/content/partials/cloudflare-one/dex/notifications-intro.mdx
@@ -1 +1 @@
-Administrators can receive alerts when Cloudflare detects connectivity issues with the WARP client or degraded application performance. Notifications can be delivered via email, webhook, and third-party services.
\ No newline at end of file
+Administrators can receive alerts when Cloudflare detects connectivity issues with the Cloudflare One Client or degraded application performance. Notifications can be delivered via email, webhook, and third-party services.
\ No newline at end of file
diff --git a/src/content/partials/cloudflare-one/dex/pcaps-check.mdx b/src/content/partials/cloudflare-one/dex/pcaps-check.mdx
index 4496256b9e0..3fdd8cbf075 100644
--- a/src/content/partials/cloudflare-one/dex/pcaps-check.mdx
+++ b/src/content/partials/cloudflare-one/dex/pcaps-check.mdx
@@ -7,4 +7,4 @@ To view a list of captures, go to **DEX** > **Remote captures**. The **Status**
- **Success**: The capture is complete and ready for download. Any partially successful captures will still upload to Cloudflare. For example, there could be a scenario where the PCAP succeeds on the primary network interface but fails on the WARP tunnel interface. You can [review PCAP results](/cloudflare-one/insights/dex/remote-captures/#download-remote-captures) to determine which PCAPs succeeded or failed.
- **Running**: The capture is in progress on the device.
- **Pending Upload**: The capture is complete but not yet ready for download.
-- **Failed**: The capture has either timed out or encountered an error. To retry the capture, check the WARP client version and [connectivity status](/cloudflare-one/insights/dex/monitoring/#fleet-status), then start a [new capture](/cloudflare-one/insights/dex/remote-captures/#start-a-remote-capture).
+- **Failed**: The capture has either timed out or encountered an error. To retry the capture, check the Cloudflare One Client version and [connectivity status](/cloudflare-one/insights/dex/monitoring/#fleet-status), then start a [new capture](/cloudflare-one/insights/dex/remote-captures/#start-a-remote-capture).
diff --git a/src/content/partials/cloudflare-one/dex/pcaps-run-availability.mdx b/src/content/partials/cloudflare-one/dex/pcaps-run-availability.mdx
index 232d86386fb..c7492dd4f28 100644
--- a/src/content/partials/cloudflare-one/dex/pcaps-run-availability.mdx
+++ b/src/content/partials/cloudflare-one/dex/pcaps-run-availability.mdx
@@ -6,11 +6,11 @@ import { Details } from "~/components";
-| [WARP modes](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/) | [Zero Trust plans](https://www.cloudflare.com/teams-pricing/) |
+| [Client modes](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/) | [Zero Trust plans](https://www.cloudflare.com/teams-pricing/) |
| ------------------------------------------------------------------------------------------- | ------------------------------------------------------------- |
|
Traffic and DNS mode
Traffic only mode
| All plans |
-| System | Availability | Minimum WARP version |
+| System | Availability | Minimum client version |
| -------- | ------------ | -------------------- |
| Windows | ✅ | 2024.12.492.0 |
| macOS | ✅ | 2024.12.492.0 |
diff --git a/src/content/partials/cloudflare-one/dex/pcaps-run.mdx b/src/content/partials/cloudflare-one/dex/pcaps-run.mdx
index 0440040dad6..48882c1fa30 100644
--- a/src/content/partials/cloudflare-one/dex/pcaps-run.mdx
+++ b/src/content/partials/cloudflare-one/dex/pcaps-run.mdx
@@ -19,4 +19,4 @@ To capture data from a remote device:
{props.bestPractice}
4. Select **Run diagnostics**.
-DEX will now send capture requests to the configured devices. If the WARP client is disconnected, the capture will time out after 10 minutes.
+DEX will now send capture requests to the configured devices. If the Cloudflare One Client is disconnected, the capture will time out after 10 minutes.
diff --git a/src/content/partials/cloudflare-one/dex/pcaps-view-warp-diag.mdx b/src/content/partials/cloudflare-one/dex/pcaps-view-warp-diag.mdx
index 0eac91b9f3e..2db495310f4 100644
--- a/src/content/partials/cloudflare-one/dex/pcaps-view-warp-diag.mdx
+++ b/src/content/partials/cloudflare-one/dex/pcaps-view-warp-diag.mdx
@@ -19,13 +19,13 @@ To access the WARP diagnostic analyzer:
| ----- | ----------- |
| Detection type | A common WARP issue that can appear in the diagnostic logs. |
| Occurences | Number of times an issue was detected in the logs. |
- | Severity level | Indicates the impact of the issue on WARP client functionality. The severity levels are:
**Critical**: Issue causes complete loss of functionality.
**Warning**: Issue causes degraded functionality but core features should still work.
**No detection**: Issue was not detected in the logs.
|
+ | Severity level | Indicates the impact of the issue on Cloudflare One Client functionality. The severity levels are:
**Critical**: Issue causes complete loss of functionality.
**Warning**: Issue causes degraded functionality but core features should still work.
**No detection**: Issue was not detected in the logs.
|
| Operating system | OS and OS version of the device. |
- | WARP version | [WARP release version](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/) |
- | Profile ID | [WARP device profile](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-profiles/) UUID|
- | Service mode | [WARP mode](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/) |
- | Configuration name | Name of the [Zero Trust organization](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/switch-organizations/) that WARP is connected to. |
- | Device ID | ID generated by the WARP client. |
+ | Cloudflare One Client version | [WARP release version](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/) |
+ | Profile ID | [device profile](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-profiles/) UUID|
+ | Service mode | [Client mode](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/) |
+ | Configuration name | Name of the [Zero Trust organization](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/switch-organizations/) that the Cloudflare One Client is connected to. |
+ | Device ID | ID generated by the Cloudflare One Client. |
4. Select a detection type for more information about the event and recommended next steps.
diff --git a/src/content/partials/cloudflare-one/dex/tests-intro.mdx b/src/content/partials/cloudflare-one/dex/tests-intro.mdx
index d60c721630e..880cdc6716d 100644
--- a/src/content/partials/cloudflare-one/dex/tests-intro.mdx
+++ b/src/content/partials/cloudflare-one/dex/tests-intro.mdx
@@ -1 +1 @@
-With Digital Experience Monitoring (DEX), you can test if your devices can connect to a private or public endpoint through the WARP client. Tests allow you to monitor availability for a given application and investigate performance issues reported by your end users.
+With Digital Experience Monitoring (DEX), you can test if your devices can connect to a private or public endpoint through the Cloudflare One Client. Tests allow you to monitor availability for a given application and investigate performance issues reported by your end users.
diff --git a/src/content/partials/cloudflare-one/gateway/add-locations-static-ip-warning.mdx b/src/content/partials/cloudflare-one/gateway/add-locations-static-ip-warning.mdx
index 6a765e90624..79866c96c6a 100644
--- a/src/content/partials/cloudflare-one/gateway/add-locations-static-ip-warning.mdx
+++ b/src/content/partials/cloudflare-one/gateway/add-locations-static-ip-warning.mdx
@@ -8,4 +8,4 @@ Deploying Gateway DNS filtering using static IP addresses may prevent users from
2. Connect to the Wi-Fi network.
3. Once the connection has been established, add the static IP addresses back.
-To avoid this issue, use the [WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) to connect your devices to Cloudflare One.
+To avoid this issue, use the [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) to connect your devices to Cloudflare One.
diff --git a/src/content/partials/cloudflare-one/gateway/client-notifications.mdx b/src/content/partials/cloudflare-one/gateway/client-notifications.mdx
index 81813636749..e98203d6e51 100644
--- a/src/content/partials/cloudflare-one/gateway/client-notifications.mdx
+++ b/src/content/partials/cloudflare-one/gateway/client-notifications.mdx
@@ -7,11 +7,11 @@ import { Details, Render, Markdown } from "~/components";
-| [WARP modes](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/) | [Zero Trust plans](https://www.cloudflare.com/plans/zero-trust-services/) |
+| [Client modes](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/) | [Zero Trust plans](https://www.cloudflare.com/plans/zero-trust-services/) |
| ----------------------------------------------------------------------------------------- | ------------------------------------------------------------------------- |
|
Traffic and DNS mode
Traffic only mode
| Enterprise |
-| System | Availability | Minimum WARP version |
+| System | Availability | Minimum client version |
| -------- | ------------ | -------------------- |
| Windows | ✅ | 2024.1.159.0 |
| macOS | ✅ | 2024.1.160.0 |
@@ -22,9 +22,9 @@ import { Details, Render, Markdown } from "~/components";
-Turn on to display notifications for Gateway block events. Blocked users will receive an operating system notification from the WARP client with a custom message you set. If you do not set a custom message, the WARP client will display a default message. Custom messages must be 100 characters or less. WARP will only display one notification per minute.
+Turn on to display notifications for Gateway block events. Blocked users will receive an operating system notification from the Cloudflare One Client with a custom message you set. If you do not set a custom message, the Cloudflare One Client will display a default message. Custom messages must be 100 characters or less. the Cloudflare One Client will only display one notification per minute.
-Upon selecting the notification, WARP will direct your users to the [Gateway block page](/cloudflare-one/reusable-components/custom-pages/gateway-block-page/) you have configured. Optionally, you can direct users to a custom URL, such as an internal support form.
+Upon selecting the notification, the Cloudflare One Client will direct your users to the [Gateway block page](/cloudflare-one/reusable-components/custom-pages/gateway-block-page/) you have configured. Optionally, you can direct users to a custom URL, such as an internal support form.
diff --git a/src/content/partials/cloudflare-one/gateway/doh-instructions.mdx b/src/content/partials/cloudflare-one/gateway/doh-instructions.mdx
index f5da3418efa..f658acf745f 100644
--- a/src/content/partials/cloudflare-one/gateway/doh-instructions.mdx
+++ b/src/content/partials/cloudflare-one/gateway/doh-instructions.mdx
@@ -18,7 +18,7 @@ Firefox is now configured to use your DoH endpoint. For more information on conf
:::note
-If you want to enforce DNS policies through WARP instead of over DoH, you can disable DoH for your organization by blocking the [Firefox DoH canary domain](https://support.mozilla.org/kb/canary-domain-use-application-dnsnet).
+If you want to enforce DNS policies through the Cloudflare One Client instead of over DoH, you can disable DoH for your organization by blocking the [Firefox DoH canary domain](https://support.mozilla.org/kb/canary-domain-use-application-dnsnet).
:::
diff --git a/src/content/partials/cloudflare-one/gateway/egress-selector-onramps.mdx b/src/content/partials/cloudflare-one/gateway/egress-selector-onramps.mdx
index 856d11653cf..d94e5fbdb76 100644
--- a/src/content/partials/cloudflare-one/gateway/egress-selector-onramps.mdx
+++ b/src/content/partials/cloudflare-one/gateway/egress-selector-onramps.mdx
@@ -6,7 +6,7 @@ import { Render, Details, GlossaryTooltip } from "~/components";
| On-ramp method | Compatibility |
| --------------------------------------------------------------------------------------------------- | ------------- |
-| [WARP](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) | ✅ |
+| [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) | ✅ |
| [PAC files](/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/) | ✅ |
| [Browser Isolation](/cloudflare-one/remote-browser-isolation/) | ✅ |
| [WARP Connector](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/) | ✅ |
diff --git a/src/content/partials/cloudflare-one/gateway/egress-selector-warp-version.mdx b/src/content/partials/cloudflare-one/gateway/egress-selector-warp-version.mdx
index ea62c9bf1cf..6c95a9b5c96 100644
--- a/src/content/partials/cloudflare-one/gateway/egress-selector-warp-version.mdx
+++ b/src/content/partials/cloudflare-one/gateway/egress-selector-warp-version.mdx
@@ -6,11 +6,11 @@ import { Details } from "~/components"
-| [WARP modes](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/) |
+| [Client modes](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/) |
| ----------------------------------------------------------------------------------------- |
| Traffic and DNS mode |
-| System | Availability | Minimum WARP version |
+| System | Availability | Minimum client version |
| -------- | ------------ | -------------------- |
| Windows | ✅ | 2025.4.929.0 |
| macOS | ✅ | 2025.4.929.0 |
diff --git a/src/content/partials/cloudflare-one/gateway/get-started/create-network-policy.mdx b/src/content/partials/cloudflare-one/gateway/get-started/create-network-policy.mdx
index d9ed57b5c27..ab196f1a0a9 100644
--- a/src/content/partials/cloudflare-one/gateway/get-started/create-network-policy.mdx
+++ b/src/content/partials/cloudflare-one/gateway/get-started/create-network-policy.mdx
@@ -12,7 +12,7 @@ To create a new network policy:
2. In the **Network** tab, select **Add a network policy**.
3. Name the policy.
4. Under **Traffic**, build a logical expression that defines the traffic you want to allow or block.
-5. Choose an **Action** to take when traffic matches the logical expression. For example, you can use a list of [device serial numbers](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/corp-device/) to ensure users can only access an application if they connect with the WARP client from a company device:
+5. Choose an **Action** to take when traffic matches the logical expression. For example, you can use a list of [device serial numbers](/cloudflare-one/reusable-components/posture-checks/client-checks/corp-device/) to ensure users can only access an application if they connect with the Cloudflare One Client from a company device:
diff --git a/src/content/partials/cloudflare-one/gateway/selectors/users.mdx b/src/content/partials/cloudflare-one/gateway/selectors/users.mdx
index 0ba95b98288..ce7d5d89de6 100644
--- a/src/content/partials/cloudflare-one/gateway/selectors/users.mdx
+++ b/src/content/partials/cloudflare-one/gateway/selectors/users.mdx
@@ -12,4 +12,4 @@ Identity-based selectors include:
* **User Group Names**
* **User Name**
-To use identity-based selectors, enable **Traffic and DNS mode** in the Zero Trust WARP client and enroll your user in your organization. For more information, refer to [Identity-based policies](/cloudflare-one/traffic-policies/identity-selectors/).
+To use identity-based selectors, enable **Traffic and DNS mode** in the Cloudflare One Client and enroll your user in your organization. For more information, refer to [Identity-based policies](/cloudflare-one/traffic-policies/identity-selectors/).
diff --git a/src/content/partials/cloudflare-one/gateway/selectors/virtual-network.mdx b/src/content/partials/cloudflare-one/gateway/selectors/virtual-network.mdx
index 1170c36ff4b..8b569c7bffa 100644
--- a/src/content/partials/cloudflare-one/gateway/selectors/virtual-network.mdx
+++ b/src/content/partials/cloudflare-one/gateway/selectors/virtual-network.mdx
@@ -5,7 +5,7 @@ inputParameters: param1
import { Markdown } from "~/components"
-Use this selector to match all traffic routed through a specific [Tunnel Virtual Network](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/tunnel-virtual-networks/) via the WARP client.
+Use this selector to match all traffic routed through a specific [Tunnel Virtual Network](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/tunnel-virtual-networks/) via the Cloudflare One Client.
| UI name | API example |
| --------------- | ---------------------------------------------- |
diff --git a/src/content/partials/cloudflare-one/posture/prereqs-warp-is-deployed.mdx b/src/content/partials/cloudflare-one/posture/prereqs-warp-is-deployed.mdx
index fe047c72076..38dd06ceea2 100644
--- a/src/content/partials/cloudflare-one/posture/prereqs-warp-is-deployed.mdx
+++ b/src/content/partials/cloudflare-one/posture/prereqs-warp-is-deployed.mdx
@@ -3,4 +3,4 @@ inputParameters: param1
---
-Cloudflare WARP client is [deployed](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/) on the device. For a list of supported modes and operating systems, refer to {props.name}.
+Cloudflare One Client is [deployed](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/) on the device. For a list of supported modes and operating systems, refer to {props.name}.
diff --git a/src/content/partials/cloudflare-one/posture/service-provider-intro.mdx b/src/content/partials/cloudflare-one/posture/service-provider-intro.mdx
index a2aadf32ff9..4a1fff93936 100644
--- a/src/content/partials/cloudflare-one/posture/service-provider-intro.mdx
+++ b/src/content/partials/cloudflare-one/posture/service-provider-intro.mdx
@@ -4,4 +4,4 @@ inputParameters: param1
import { Markdown } from "~/components";
-Cloudflare One can integrate with {props.one} to require that users connect to certain applications from managed devices. This service-to-service posture check uses the WARP client to read endpoint data from {props.one}. Devices are identified by their serial numbers. If multiple devices have the same serial number, Cloudflare cannot accurately match a WARP device with a third-party provider device. You must ensure that each of your devices has a unique serial number.
+Cloudflare One can integrate with {props.one} to require that users connect to certain applications from managed devices. This service-to-service posture check uses the Cloudflare One Client to read endpoint data from {props.one}. Devices are identified by their serial numbers. If multiple devices have the same serial number, Cloudflare cannot accurately match a device with a third-party provider device. You must ensure that each of your devices has a unique serial number.
diff --git a/src/content/partials/cloudflare-one/tunnel/catch-all-policy.mdx b/src/content/partials/cloudflare-one/tunnel/catch-all-policy.mdx
index f53752e0471..c4aa95aa270 100644
--- a/src/content/partials/cloudflare-one/tunnel/catch-all-policy.mdx
+++ b/src/content/partials/cloudflare-one/tunnel/catch-all-policy.mdx
@@ -2,5 +2,5 @@
{}
---
-To prevent WARP users from accessing your entire private network, we recommend creating a [catch-all Gateway block policy](/learning-paths/replace-vpn/build-policies/create-policy/#catch-all-policy) for your private IP space. You can then layer on higher priority Allow policies (in either Access or Gateway) which grant users access to specific applications or IPs.
+To prevent Cloudflare One Client users from accessing your entire private network, we recommend creating a [catch-all Gateway block policy](/learning-paths/replace-vpn/build-policies/create-policy/#catch-all-policy) for your private IP space. You can then layer on higher priority Allow policies (in either Access or Gateway) which grant users access to specific applications or IPs.
diff --git a/src/content/partials/cloudflare-one/tunnel/deployment-guides/cloud-private-ip.mdx b/src/content/partials/cloudflare-one/tunnel/deployment-guides/cloud-private-ip.mdx
index 28f92881794..8f4320caa8d 100644
--- a/src/content/partials/cloudflare-one/tunnel/deployment-guides/cloud-private-ip.mdx
+++ b/src/content/partials/cloudflare-one/tunnel/deployment-guides/cloud-private-ip.mdx
@@ -5,11 +5,11 @@ inputParameters: networkName;;resourceName;;exampleIp;;splitTunnelCidr;;calcExcl
import { Code } from "~/components";
import SubtractIPCalculator from "~/components/SubtractIPCalculator.tsx";
-[Private network routes](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/) allow users to connect to your {props.networkName} using the WARP client. To add a private network route for your Cloudflare Tunnel:
+[Private network routes](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/) allow users to connect to your {props.networkName} using the Cloudflare One Client. To add a private network route for your Cloudflare Tunnel:
1. In [Cloudflare One](https://one.dash.cloudflare.com), go to **Networks** > **Routes**.
2. In the **CIDR** tab, enter the **Private IP address** of your {props.resourceName} (for example, {props.exampleIp}). You can expand the IP range later if necessary.
-3. In your [Split Tunnel configuration](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/#add-a-route), make sure the private IP is routing through WARP. For example, if you are using Split Tunnels in **Exclude** mode, delete {props.splitTunnelCidr}. We recommend re-adding the IPs that are not explicitly used by your {props.resourceName}.
+3. In your [Split Tunnel configuration](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/#add-a-route), make sure the private IP is routing through the Cloudflare One Client. For example, if you are using Split Tunnels in **Exclude** mode, delete {props.splitTunnelCidr}. We recommend re-adding the IPs that are not explicitly used by your {props.resourceName}.
To determine which IP addresses to re-add, subtract your {props.resourceName} IPs from {props.splitTunnelCidr}:
@@ -24,7 +24,7 @@ import SubtractIPCalculator from "~/components/SubtractIPCalculator.tsx";
Add the results back to your Split Tunnel Exclude mode list.
4. To test on a user device:
- 1. [Log in to the WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/manual-deployment/).
+ 1. [Log in to the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/manual-deployment/).
2. Open a terminal window and connect to the service using its private IP:
diff --git a/src/content/partials/cloudflare-one/tunnel/deployment-guides/deploy-kubernetes.mdx b/src/content/partials/cloudflare-one/tunnel/deployment-guides/deploy-kubernetes.mdx
index 69872c2f5b3..08311a438ca 100644
--- a/src/content/partials/cloudflare-one/tunnel/deployment-guides/deploy-kubernetes.mdx
+++ b/src/content/partials/cloudflare-one/tunnel/deployment-guides/deploy-kubernetes.mdx
@@ -27,7 +27,7 @@ As shown in the diagram, we recommend setting up `cloudflared` as an adjacent [d
We do not recommend using `cloudflared` in autoscaling setups because downscaling (removing replicas) will break existing user connections to that replica. Additionally, `cloudflared` does not load balance across replicas; replicas are strictly for high availability. To load balance traffic to your nodes, you can use [Cloudflare Load Balancer](/load-balancing/private-network/) or a third-party load balancer.
:::
-Once the cluster is connected to Cloudflare, you can configure Cloudflare Tunnel routes to control how `cloudflared` will proxy traffic to services within the cluster. For example, you may wish to publish certain Kubernetes applications to the Internet and restrict other applications to internal WARP client users.
+Once the cluster is connected to Cloudflare, you can configure Cloudflare Tunnel routes to control how `cloudflared` will proxy traffic to services within the cluster. For example, you may wish to publish certain Kubernetes applications to the Internet and restrict other applications to internal Cloudflare One Client users.
## Prerequisites
diff --git a/src/content/partials/cloudflare-one/tunnel/filter-network-traffic.mdx b/src/content/partials/cloudflare-one/tunnel/filter-network-traffic.mdx
index 33b8915c0eb..ee6cdc2dac1 100644
--- a/src/content/partials/cloudflare-one/tunnel/filter-network-traffic.mdx
+++ b/src/content/partials/cloudflare-one/tunnel/filter-network-traffic.mdx
@@ -2,4 +2,4 @@
{}
---
-By default, all WARP devices enrolled in your Zero Trust organization can connect to your private network through Cloudflare Tunnel. You can configure Gateway to inspect your network traffic and either block or allow access based on user identity and device posture. To learn more about policy design, refer to [Secure your first application](/learning-paths/replace-vpn/build-policies/create-policy/).
+By default, all devices enrolled in your Zero Trust organization can connect to your private network through Cloudflare Tunnel. You can configure Gateway to inspect your network traffic and either block or allow access based on user identity and device posture. To learn more about policy design, refer to [Secure your first application](/learning-paths/replace-vpn/build-policies/create-policy/).
diff --git a/src/content/partials/cloudflare-one/tunnel/locally-managed/configuration-file.mdx b/src/content/partials/cloudflare-one/tunnel/locally-managed/configuration-file.mdx
index 1ae5fd07904..ea5c0232694 100644
--- a/src/content/partials/cloudflare-one/tunnel/locally-managed/configuration-file.mdx
+++ b/src/content/partials/cloudflare-one/tunnel/locally-managed/configuration-file.mdx
@@ -33,7 +33,7 @@ In the absence of a configuration file, `cloudflared` will proxy outbound traffi
exposing a private network
{" "}
- to end users running WARP, you need to add the warp-routing key
+ to end users running the Cloudflare One Client, you need to add the warp-routing key
and set it to true:
disable TLS verification for self-signed certificates. | `https://localhost:8000` |
| UNIX | Same as HTTP, but uses a Unix socket. | `unix:/home/production/echo.sock` |
| UNIX + TLS | Same as HTTPS, but uses a Unix socket. | `unix+tls:/home/production/echo.sock` |
-| TCP | Streams TCP over a WebSocket connection. End users run `cloudflared access tcp` to [connect](/cloudflare-one/access-controls/applications/non-http/cloudflared-authentication/arbitrary-tcp/). For long-lived connections, use [WARP-to-Tunnel](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/) instead. | `tcp://localhost:2222` |
-| SSH | Streams SSH over a WebSocket connection. End users run `cloudflared access ssh` to [connect](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-cloudflared-authentication/). For long-lived connections, use [WARP-to-Tunnel](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-infrastructure-access/) instead. | `ssh://localhost:22` |
+| TCP | Streams TCP over a WebSocket connection. End users run `cloudflared access tcp` to [connect](/cloudflare-one/access-controls/applications/non-http/cloudflared-authentication/arbitrary-tcp/). For long-lived connections, use [Client-to-Tunnel](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/) instead. | `tcp://localhost:2222` |
+| SSH | Streams SSH over a WebSocket connection. End users run `cloudflared access ssh` to [connect](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-cloudflared-authentication/). For long-lived connections, use [Client-to-Tunnel](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-infrastructure-access/) instead. | `ssh://localhost:22` |
| RDP | Streams RDP over a WebSocket connection. For more information, refer to [Connect to RDP with client-side cloudflared](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-cloudflared-authentication/). | `rdp://localhost:3389` |
| SMB | Streams SMB over a WebSocket connection. For more information, refer to [Connect to SMB with client-side cloudflared](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/smb/#connect-to-smb-server-with-cloudflared-access). | `smb://localhost:445` |
| HTTP_STATUS | Responds to all requests with a fixed HTTP status code. | `http_status:404` |
diff --git a/src/content/partials/cloudflare-one/tunnel/troubleshoot-private-networks.mdx b/src/content/partials/cloudflare-one/tunnel/troubleshoot-private-networks.mdx
index 8d83290cb93..44fbec6ba49 100644
--- a/src/content/partials/cloudflare-one/tunnel/troubleshoot-private-networks.mdx
+++ b/src/content/partials/cloudflare-one/tunnel/troubleshoot-private-networks.mdx
@@ -4,11 +4,11 @@
import { GlossaryTooltip, TabItem, Tabs } from "~/components";
-Follow this troubleshooting procedure when end users running Cloudflare WARP have issues connecting to a private network behind Cloudflare Tunnel.
+Follow this troubleshooting procedure when end users running the Cloudflare One Client have issues connecting to a private network behind Cloudflare Tunnel.
-## 1. Is the WARP client connected to a Cloudflare data center?
+## 1. Is the Cloudflare One Client connected to a Cloudflare data center?
-The WARP client GUI should display `Connected` and `Your Internet is protected`.
+The Cloudflare One Client GUI should display `Connected` and `Your Internet is protected`.
@@ -16,9 +16,9 @@ The WARP client GUI should display `Connected` and `Your Internet is protected`.
-If WARP is stuck in the `Disconnected` state or frequently changes between `Connected` and `Disconnected`, refer to [Unable to connect WARP](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/common-issues/#unable-to-connect-warp).
+If the Cloudflare One Client is stuck in the `Disconnected` state or frequently changes between `Connected` and `Disconnected`, refer to [Unable to connect WARP](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/common-issues/#unable-to-connect-warp).
-## 2. Is the WARP client connecting to your private DNS server?
+## 2. Is the Cloudflare One Client connecting to your private DNS server?
This step is only needed if users access your application via a private hostname (for example, `wiki.internal.local`).
@@ -28,11 +28,11 @@ This step is only needed if users access your application via a private hostname
If there are no relevant Gateway logs, it means that WARP was unable to forward the query to your private DNS server. Check your resolver policies or Local Domain Fallback configuration and refer to [How WARP handles DNS requests](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/#how-the-warp-client-handles-dns-requests).
-## 3. Is network traffic to the application going through WARP?
+## 3. Is network traffic to the application going through the Cloudflare One Client?
Next, check if your Gateway Network logs (**Insights** > **Logs** > **Network logs**) show any traffic to the destination IP.
-If WARP is connected but there are no network logs, it means that your private network IPs are not routing through WARP. You can confirm this by [searching the routing table](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/client-architecture/#routing-table) on the device for the IP address of your application. Traffic to your application should route through the Cloudflare WARP interface. If another interface is used, [check your Split Tunnel configuration](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/#3-route-private-network-ips-through-warp).
+If the Cloudflare One Client is connected but there are no network logs, it means that your private network IPs are not routing through the Cloudflare One Client. You can confirm this by [searching the routing table](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/client-architecture/#routing-table) on the device for the IP address of your application. Traffic to your application should route through the Cloudflare One Client interface. If another interface is used, [check your Split Tunnel configuration](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/#3-route-private-network-ips-through-warp).
## 4. Is the user blocked by a Gateway policy?
@@ -57,9 +57,9 @@ Determine whether the user is matching any policy, or if they are matching a pol
4. In the results, select a log and note its **Policy Name** value.
2. Go to **Traffic policies** > **Firewall policies** and compare the [order of enforcement](/cloudflare-one/traffic-policies/order-of-enforcement/) of the matched policy versus the expected policy.
3. Compare the Gateway log values with the expected policy criteria.
- - If the mismatched value is related to identity, [check the user registry](/cloudflare-one/team-and-resources/users/users/) and verify the values that are passed to Gateway from your IdP. Cloudflare updates the registry when the user enrolls in the WARP client. If the user's identity is outdated, ask the user to re-authenticate the client (**Profile** > **Account information** > **Re-authenticate**)[^1].
+ - If the mismatched value is related to identity, [check the user registry](/cloudflare-one/team-and-resources/users/users/) and verify the values that are passed to Gateway from your IdP. Cloudflare updates the registry when the user enrolls in the Cloudflare One Client. If the user's identity is outdated, ask the user to re-authenticate the client (**Profile** > **Account information** > **Re-authenticate**)[^1].
-[^1]: In WARP version 2026.1 and earlier, select **Preferences** > **Account** > **Re-Authenticate Session**.
+[^1]: In Cloudflare One Client version 2026.1 and earlier, select **Preferences** > **Account** > **Re-Authenticate Session**.
- If the mismatched value is related to device posture, [view posture check results](/cloudflare-one/reusable-components/posture-checks/#2-verify-device-posture-checks) for the user's device. Verify that the device passes the posture checks configured in the policy.
diff --git a/src/content/partials/cloudflare-one/tunnel/virtual-networks-intro.mdx b/src/content/partials/cloudflare-one/tunnel/virtual-networks-intro.mdx
index 3773d6eed28..76a1bb2ab42 100644
--- a/src/content/partials/cloudflare-one/tunnel/virtual-networks-intro.mdx
+++ b/src/content/partials/cloudflare-one/tunnel/virtual-networks-intro.mdx
@@ -2,4 +2,4 @@
{}
---
-Virtual networks allow you to connect private networks that have overlapping IP ranges without creating conflicts for users or services. For example, an organization may want to expose two distinct virtual private cloud (VPC) networks which they consider to be "production" and "staging". However, if the two private networks happened to receive the same RFC 1918 IP assignment, there may be two different resources with the same IP address. By creating two separate virtual networks, you can deterministically route traffic to duplicative private addresses like `10.128.0.1/32` staging and `10.128.0.1/32` production. These virtual networks will appear as user-selectable options within the WARP client GUI.
+Virtual networks allow you to connect private networks that have overlapping IP ranges without creating conflicts for users or services. For example, an organization may want to expose two distinct virtual private cloud (VPC) networks which they consider to be "production" and "staging". However, if the two private networks happened to receive the same RFC 1918 IP assignment, there may be two different resources with the same IP address. By creating two separate virtual networks, you can deterministically route traffic to duplicative private addresses like `10.128.0.1/32` staging and `10.128.0.1/32` production. These virtual networks will appear as user-selectable options within the Cloudflare One Client GUI.
diff --git a/src/content/partials/cloudflare-one/tunnel/warp-connector-install.mdx b/src/content/partials/cloudflare-one/tunnel/warp-connector-install.mdx
index 8be40835b48..2b02c80439a 100644
--- a/src/content/partials/cloudflare-one/tunnel/warp-connector-install.mdx
+++ b/src/content/partials/cloudflare-one/tunnel/warp-connector-install.mdx
@@ -9,7 +9,7 @@ To install WARP Connector on a host machine:
1. In [Cloudflare One](https://one.dash.cloudflare.com), go to **Networks** > **Connectors** > **Cloudflare Tunnels**.
2. Select **Create a tunnel**.
3. For the tunnel type, select **WARP Connector**.
-4. You will be prompted to turn on [**Allow all Cloudflare One traffic to reach enrolled devices**](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/#allow-all-cloudflare-one-traffic-to-reach-enrolled-devices) and [**Assign a unique IP address to each device**](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/#assign-a-unique-ip-address-to-each-device) if they are currently turned off. These settings allow Cloudflare to assign a unique CGNAT IP to each WARP device and route traffic between them.
+4. You will be prompted to turn on [**Allow all Cloudflare One traffic to reach enrolled devices**](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/#allow-all-cloudflare-one-traffic-to-reach-enrolled-devices) and [**Assign a unique IP address to each device**](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/#assign-a-unique-ip-address-to-each-device) if they are currently turned off. These settings allow Cloudflare to assign a unique CGNAT IP to each device and route traffic between them.
5. Give the tunnel any name (for example, `Subnet-10.0.0.0/24`) and select **Create tunnel**.
6. Select the operating system of your host machine.
7. On your host machine, open a terminal window and run the commands shown in Cloudflare One. Those commands will install the WARP Connector, enable IP forwarding on the host, and connect WARP Connector to your Zero Trust organization.
@@ -19,7 +19,7 @@ To install WARP Connector on a host machine:
If you are managing the deployment remotely over SSH, your connection may drop when you install the WARP Connector. Because the WARP connector immediately starts forwarding traffic to Cloudflare, the remote SSH server's traffic will now route via Cloudflare instead of via the server's public IP. To work around the issue:
- **Option 1**: In your WARP Connector [device profile](#2-recommended-create-a-device-profile), temporarily add the public IP of your local machine to the [Split Tunnel Exclude list](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/).
- - **Option 2**: Connect your local machine to Zero Trust (for example, via the WARP client) and SSH directly to the remote server's private IP. Traffic to this IP must route through the WARP tunnel.
+ - **Option 2**: Connect your local machine to Zero Trust (for example, via the Cloudflare One Client) and SSH directly to the remote server's private IP. Traffic to this IP must route through the WARP tunnel.
:::
8. (Optional) Configure IP forwarding:
@@ -48,7 +48,7 @@ To install WARP Connector on a host machine:
- If WARP is disconnected, try the following troubleshooting strategies:
+ If the Cloudflare One Client is disconnected, try the following troubleshooting strategies:
- Run `warp-cli connect`.
diff --git a/src/content/partials/cloudflare-one/tunnel/warp-to-tunnel-client.mdx b/src/content/partials/cloudflare-one/tunnel/warp-to-tunnel-client.mdx
index 0ffedfff86f..abd4a31bc8a 100644
--- a/src/content/partials/cloudflare-one/tunnel/warp-to-tunnel-client.mdx
+++ b/src/content/partials/cloudflare-one/tunnel/warp-to-tunnel-client.mdx
@@ -4,5 +4,5 @@
To connect your devices to Cloudflare:
-1. [Deploy the WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/) on your devices in Traffic and DNS mode or [generate a proxy endpoint](/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/) and deploy a PAC file.
+1. [Deploy the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/) on your devices in Traffic and DNS mode or [generate a proxy endpoint](/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/) and deploy a PAC file.
2. [Create device enrollment rules](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/device-enrollment/) to determine which devices can enroll to your Zero Trust organization.
diff --git a/src/content/partials/cloudflare-one/tunnel/warp-to-tunnel-route-ips.mdx b/src/content/partials/cloudflare-one/tunnel/warp-to-tunnel-route-ips.mdx
index 9d18b29d377..612d5ce5118 100644
--- a/src/content/partials/cloudflare-one/tunnel/warp-to-tunnel-route-ips.mdx
+++ b/src/content/partials/cloudflare-one/tunnel/warp-to-tunnel-route-ips.mdx
@@ -6,7 +6,7 @@ params:
import { Markdown, Details, Tabs, TabItem} from "~/components";
import SubtractIPCalculator from "~/components/SubtractIPCalculator.tsx";
-By default, WARP excludes traffic bound for [RFC 1918 space](https://datatracker.ietf.org/doc/html/rfc1918), which are IP addresses typically used in private networks and not reachable from the Internet. In order for WARP to send traffic to your , you must configure [Split Tunnels](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/) so that the IP/CIDR of your routes through WARP.
+By default, WARP excludes traffic bound for [RFC 1918 space](https://datatracker.ietf.org/doc/html/rfc1918), which are IP addresses typically used in private networks and not reachable from the Internet. In order for the Cloudflare One Client to send traffic to your , you must configure [Split Tunnels](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/) so that the IP/CIDR of your routes through the Cloudflare One Client.
1. First, check whether your [Split Tunnels mode](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/#change-split-tunnels-mode) is set to **Exclude** or **Include** mode.
2. Edit your Split Tunnel routes depending on the mode:
@@ -16,7 +16,7 @@ By default, WARP excludes traffic bound for [RFC 1918 space](https://datatracker
a. [Delete the route](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/#remove-a-route) containing your 's IP/CIDR range. For example, if your network uses the default AWS range of `172.31.0.0/16`, delete `172.16.0.0/12`.
- b. [Re-add IP/CIDR ranges](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/#add-a-route) that are not explicitly used by your . For the AWS example above, you would add new entries for `172.16.0.0/13`, `172.24.0.0/14`, `172.28.0.0/15`, and `172.30.0.0/16`. This ensures that only traffic to `172.31.0.0/16` routes through WARP.
+ b. [Re-add IP/CIDR ranges](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/#add-a-route) that are not explicitly used by your . For the AWS example above, you would add new entries for `172.16.0.0/13`, `172.24.0.0/14`, `172.28.0.0/15`, and `172.30.0.0/16`. This ensures that only traffic to `172.31.0.0/16` routes through the Cloudflare One Client.
You can use the following calculator to determine which IP addresses to re-add:
@@ -33,7 +33,7 @@ By default, WARP excludes traffic bound for [RFC 1918 space](https://datatracker
3. Re-add the calculator results to your Split Tunnel Exclude mode list.
- By tightening the private IP range included in WARP, you reduce the risk of breaking a user's [access to local resources](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/#allow-users-to-enable-local-network-exclusion).
+ By tightening the private IP range included in the Cloudflare One Client, you reduce the risk of breaking a user's [access to local resources](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/#allow-users-to-enable-local-network-exclusion).
diff --git a/src/content/partials/cloudflare-one/warp/device-enrollment-mtls.mdx b/src/content/partials/cloudflare-one/warp/device-enrollment-mtls.mdx
index a126ca0226f..0f9cabfed41 100644
--- a/src/content/partials/cloudflare-one/warp/device-enrollment-mtls.mdx
+++ b/src/content/partials/cloudflare-one/warp/device-enrollment-mtls.mdx
@@ -77,7 +77,7 @@ To check for an mTLS certificate:
}
```
-4. Add the policy to your [`cloudflared_zero_trust_access_application` for WARP](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/device-enrollment/#set-device-enrollment-permissions).
+4. Add the policy to your [`cloudflared_zero_trust_access_application` for the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/device-enrollment/#set-device-enrollment-permissions).
5. On your device, add the client certificate to the [system keychain](/cloudflare-one/access-controls/service-credentials/mutual-tls-authentication/#test-in-the-browser).
diff --git a/src/content/partials/cloudflare-one/warp/enroll-desktop.mdx b/src/content/partials/cloudflare-one/warp/enroll-desktop.mdx
index 8b3cba5c757..ca090aae3e6 100644
--- a/src/content/partials/cloudflare-one/warp/enroll-desktop.mdx
+++ b/src/content/partials/cloudflare-one/warp/enroll-desktop.mdx
@@ -11,13 +11,13 @@ To enroll your device using the client GUI:
1. [Download](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/) and install the Cloudflare One client.
2. Launch the Cloudflare One client.
-3. On the **What would you like to use WARP for?** screen, select **Zero Trust security**.
+3. On the **What would you like to use the Cloudflare One Client for?** screen, select **Zero Trust security**.
4. Enter your team name.
5. Complete the authentication steps required by your organization.
- Once authenticated, you will see a Success page and a dialog prompting you to open Cloudflare WARP.
+ Once authenticated, you will see a Success page and a dialog prompting you to open the Cloudflare One Client.
-6. Select **Open Cloudflare WARP** to complete the registration.
+6. Select **Open the Cloudflare One Client** to complete the registration.
@@ -31,7 +31,7 @@ To enroll your device using the client GUI:
13. Enter your team name.
14. Complete the authentication steps required by your organization.
- Once authenticated, you will see a Success page and a dialog prompting you to open WARP.
+ Once authenticated, you will see a Success page and a dialog prompting you to open the Cloudflare One Client.
15. Select **Open Cloudflare WARP.app** to complete the registration.
diff --git a/src/content/partials/cloudflare-one/warp/service-token-enrollment.mdx b/src/content/partials/cloudflare-one/warp/service-token-enrollment.mdx
index eb32010a8b1..d40657517f3 100644
--- a/src/content/partials/cloudflare-one/warp/service-token-enrollment.mdx
+++ b/src/content/partials/cloudflare-one/warp/service-token-enrollment.mdx
@@ -48,7 +48,7 @@ import { Tabs, TabItem } from "~/components";
}
```
-4. Add the policy to your [`cloudflared_zero_trust_access_application` for WARP](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/device-enrollment/#set-device-enrollment-permissions).
+4. Add the policy to your [`cloudflared_zero_trust_access_application` for the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/device-enrollment/#set-device-enrollment-permissions).
5. In your MDM [deployment parameters](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/parameters/), add the following fields:
- `auth_client_id`: The **Client ID** of your service token.
diff --git a/src/content/partials/learning-paths/china-network-overview-navigation.mdx b/src/content/partials/learning-paths/china-network-overview-navigation.mdx
index 98c78effcc0..5e5f0c65160 100644
--- a/src/content/partials/learning-paths/china-network-overview-navigation.mdx
+++ b/src/content/partials/learning-paths/china-network-overview-navigation.mdx
@@ -14,7 +14,7 @@ import { CardGrid, LinkCard, Card } from "~/components";
diff --git a/src/content/partials/learning-paths/zero-trust/configure-device-agent-description.mdx b/src/content/partials/learning-paths/zero-trust/configure-device-agent-description.mdx
index ec502269c46..e08c1e8aa24 100644
--- a/src/content/partials/learning-paths/zero-trust/configure-device-agent-description.mdx
+++ b/src/content/partials/learning-paths/zero-trust/configure-device-agent-description.mdx
@@ -3,4 +3,4 @@
---
-The Cloudflare WARP client (known as the Cloudflare One Agent in mobile app stores) encrypts designated traffic from a user's device to Cloudflare's global network. In this learning path, we will first define all of your parameters and deployment rules, and then we will install and connect the client. If you prefer to start the client download now, refer to [Download WARP](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/).
+The Cloudflare One Client (known as the Cloudflare One Agent in mobile app stores) encrypts designated traffic from a user's device to Cloudflare's global network. In this learning path, we will first define all of your parameters and deployment rules, and then we will install and connect the client. If you prefer to start the client download now, refer to [Download WARP](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/).
diff --git a/src/content/partials/learning-paths/zero-trust/configure-device-agent-objectives.mdx b/src/content/partials/learning-paths/zero-trust/configure-device-agent-objectives.mdx
index 166ccd7201a..08795498883 100644
--- a/src/content/partials/learning-paths/zero-trust/configure-device-agent-objectives.mdx
+++ b/src/content/partials/learning-paths/zero-trust/configure-device-agent-objectives.mdx
@@ -4,6 +4,6 @@
---
* Define which users can connect devices to your Zero Trust instance.
-* Configure global and device-specific settings for the WARP client.
+* Configure global and device-specific settings for the Cloudflare One Client.
* Route user traffic through Cloudflare Gateway.
* Route domains to a private DNS server, if required.
diff --git a/src/content/partials/learning-paths/zero-trust/connect-devices-objectives.mdx b/src/content/partials/learning-paths/zero-trust/connect-devices-objectives.mdx
index ef99e126c10..6af7493ea8d 100644
--- a/src/content/partials/learning-paths/zero-trust/connect-devices-objectives.mdx
+++ b/src/content/partials/learning-paths/zero-trust/connect-devices-objectives.mdx
@@ -3,6 +3,6 @@
---
-* Manually deploy WARP on a test device.
+* Manually deploy the Cloudflare One Client on a test device.
* Create an automated script to use with your organization's managed deployment tool.
* View user traffic in Zero Trust.
diff --git a/src/content/partials/learning-paths/zero-trust/device-enrollment-permissions.mdx b/src/content/partials/learning-paths/zero-trust/device-enrollment-permissions.mdx
index 70b2a742d49..5f2f956a234 100644
--- a/src/content/partials/learning-paths/zero-trust/device-enrollment-permissions.mdx
+++ b/src/content/partials/learning-paths/zero-trust/device-enrollment-permissions.mdx
@@ -5,7 +5,7 @@
import { Render } from "~/components"
-Device enrollment permissions determine which users can connect new devices to your organization's Cloudflare Zero Trust instance. Once the user registers their device, the WARP client will store their identity token and use it to authenticate to services in your private network.
+Device enrollment permissions determine which users can connect new devices to your organization's Cloudflare Zero Trust instance. Once the user registers their device, the Cloudflare One Client will store their identity token and use it to authenticate to services in your private network.
## Set device enrollment permissions
diff --git a/src/content/partials/learning-paths/zero-trust/device-profiles.mdx b/src/content/partials/learning-paths/zero-trust/device-profiles.mdx
index 650c7ca892d..43c2191137f 100644
--- a/src/content/partials/learning-paths/zero-trust/device-profiles.mdx
+++ b/src/content/partials/learning-paths/zero-trust/device-profiles.mdx
@@ -18,7 +18,7 @@ To customize the default settings:
2. Select the **Default** profile and select **Edit*.
-3. Many users running Cloudflare Zero Trust {props.one} have a default profile that resembles the following. Refer to [WARP client settings](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/) for a description of each setting.
+3. Many users running Cloudflare Zero Trust {props.one} have a default profile that resembles the following. Refer to [Cloudflare One Client settings](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/) for a description of each setting.
| Setting | State | Notes |
| ------------------------------------ | ----------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
@@ -26,7 +26,7 @@ To customize the default settings:
| Mode switch | Disabled | If enabled, users have the option to switch to a DNS-only security mode and lose access to your private network. {props.two} |
| Lock WARP switch | Enabled | Should be enabled unless users have an explicit reason to disable WARP, such as a conflicting VPN client on the device or other extenuating circumstances. If disabled for concerns about user experience, **Auto Connect** should be enabled and set on a short interval, like 10-15 minutes. |
| Allow device to leave organization | Disabled | |
- | Allow updates | Disabled | Usually disabled on managed devices. If enabled, users who are local administrators on their device can update the WARP client on their own — this can introduce version consistency control issues if WARP versions are centrally managed by IT. |
+ | Allow updates | Disabled | Usually disabled on managed devices. If enabled, users who are local administrators on their device can update the Cloudflare One Client on their own — this can introduce version consistency control issues if WARP versions are centrally managed by IT. |
| Auto connect | Enabled | Timeout is usually set between 10min - 30min. |
| Support URL | Enabled | |
| Service mode | Traffic and DNS mode | Proxies device traffic to Cloudflare according to your Split Tunnel rules. |
diff --git a/src/content/partials/learning-paths/zero-trust/enable-proxy-intro.mdx b/src/content/partials/learning-paths/zero-trust/enable-proxy-intro.mdx
index 362a138f844..e6800e57f7a 100644
--- a/src/content/partials/learning-paths/zero-trust/enable-proxy-intro.mdx
+++ b/src/content/partials/learning-paths/zero-trust/enable-proxy-intro.mdx
@@ -3,4 +3,4 @@
---
-With Cloudflare Gateway, you can log and filter DNS, network, and HTTP traffic from devices running the WARP client. This includes traffic to the public Internet and traffic directed to your private network. DNS filtering is enabled by default since the WARP client sends DNS queries to Cloudflare's public DNS resolver, [1.1.1.1](/1.1.1.1/). To enable network and HTTP filtering, you will need to allow Cloudflare Gateway to proxy that traffic.
+With Cloudflare Gateway, you can log and filter DNS, network, and HTTP traffic from devices running the Cloudflare One Client. This includes traffic to the public Internet and traffic directed to your private network. DNS filtering is enabled by default since the Cloudflare One Client sends DNS queries to Cloudflare's public DNS resolver, [1.1.1.1](/1.1.1.1/). To enable network and HTTP filtering, you will need to allow Cloudflare Gateway to proxy that traffic.
diff --git a/src/content/partials/learning-paths/zero-trust/install-agent.mdx b/src/content/partials/learning-paths/zero-trust/install-agent.mdx
index 3e84ed9d2ea..ebf3b261e8f 100644
--- a/src/content/partials/learning-paths/zero-trust/install-agent.mdx
+++ b/src/content/partials/learning-paths/zero-trust/install-agent.mdx
@@ -5,17 +5,17 @@ inputParameters: WARPsuccess
import { Details, Markdown, Render } from "~/components"
-Most admins test by manually downloading the WARP client and enrolling in your organization's Cloudflare Zero Trust instance.
+Most admins test by manually downloading the Cloudflare One Client and enrolling in your organization's Cloudflare Zero Trust instance.
## Install WARP
-1. First, uninstall any existing third-party VPN software if possible. Sometimes products placed in a disconnected or disabled state will still interfere with the WARP client.
+1. First, uninstall any existing third-party VPN software if possible. Sometimes products placed in a disconnected or disabled state will still interfere with the Cloudflare One Client.
2. If you are running third-party firewall or TLS decryption software, verify that it does not inspect or block traffic to the following destinations:
For more information, refer to [WARP with firewall](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/firewall/).
-3. Manually install WARP on the device.
+3. Manually install the Cloudflare One Client on the device.
@@ -29,4 +29,4 @@ Most admins test by manually downloading the WARP client and enrolling in your o
-The WARP client should show as **Connected**. {props.one}
+The Cloudflare One Client should show as **Connected**. {props.one}
diff --git a/src/content/partials/learning-paths/zero-trust/private-dns.mdx b/src/content/partials/learning-paths/zero-trust/private-dns.mdx
index c690b0ec61d..e80f23cb070 100644
--- a/src/content/partials/learning-paths/zero-trust/private-dns.mdx
+++ b/src/content/partials/learning-paths/zero-trust/private-dns.mdx
@@ -11,9 +11,9 @@ By default, all DNS requests on the user device are resolved by Cloudflare's [pu
## Local Domain Fallback
-Local Domain Fallback tells the WARP client to send specific DNS requests to your private DNS resolver instead of to Cloudflare's public DNS resolver. This method was the primary delivery mechanism for private DNS for a long time, and is the simplest option, but it has two shortcomings: you cannot deterministically route private DNS queries to different resolvers based on specific attributes, and you cannot apply Gateway DNS policies to this traffic because Cloudflare is not resolving it.
+Local Domain Fallback tells the Cloudflare One Client to send specific DNS requests to your private DNS resolver instead of to Cloudflare's public DNS resolver. This method was the primary delivery mechanism for private DNS for a long time, and is the simplest option, but it has two shortcomings: you cannot deterministically route private DNS queries to different resolvers based on specific attributes, and you cannot apply Gateway DNS policies to this traffic because Cloudflare is not resolving it.
-To learn more about how Local Domain Fallback works, refer to [How the WARP client handles DNS requests](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/#how-the-warp-client-handles-dns-requests).
+To learn more about how Local Domain Fallback works, refer to [How the Cloudflare One Client handles DNS requests](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/#how-the-warp-client-handles-dns-requests).
### Add a domain
diff --git a/src/content/partials/learning-paths/zero-trust/split-tunnel-settings.mdx b/src/content/partials/learning-paths/zero-trust/split-tunnel-settings.mdx
index e115e5a0c04..cb62ee20417 100644
--- a/src/content/partials/learning-paths/zero-trust/split-tunnel-settings.mdx
+++ b/src/content/partials/learning-paths/zero-trust/split-tunnel-settings.mdx
@@ -5,12 +5,12 @@
import { Render} from "~/components"
-Split tunnel settings determine which traffic WARP does and does not proxy.
+Split tunnel settings determine which traffic the Cloudflare One Client does and does not proxy.
WARP offers two different split tunnel modes:
* If you intend to send all internal and external destination traffic through Cloudflare's global network, opt for **Exclude IPs and domains** mode. This mode will proxy everything through the WARP tunnel with the exception of IPs and hosts defined explicitly within the Split Tunnel list.
-* If you intend to only use WARP to proxy private destination traffic, you can operate in **Include IPs and domains** mode, in which you explicitly define which IP ranges and domains should be included in the WARP routing table.
+* If you intend to only use the Cloudflare One Client to proxy private destination traffic, you can operate in **Include IPs and domains** mode, in which you explicitly define which IP ranges and domains should be included in the WARP routing table.
## Update Split Tunnels mode
diff --git a/src/content/partials/networking-services/analytics/network-analytics.mdx b/src/content/partials/networking-services/analytics/network-analytics.mdx
index a653dd7afef..fcc92aedff3 100644
--- a/src/content/partials/networking-services/analytics/network-analytics.mdx
+++ b/src/content/partials/networking-services/analytics/network-analytics.mdx
@@ -47,8 +47,8 @@ For details, refer to the [Network Analytics](/analytics/network-analytics/) doc
text={`
With Cloudflare WAN, you have increased insight into traffic flows across Cloudflare One products, including:
- - Traffic entering Cloudflare's network via WARP
- - Traffic leaving Cloudflare's network via WARP
+ - Traffic entering Cloudflare's network via the Cloudflare One Client
+ - Traffic leaving Cloudflare's network via the Cloudflare One Client
- Traffic leaving Cloudflare's network via Cloudflare Tunnel (\`cloudflared\`)
`}
@@ -102,7 +102,7 @@ For instructions, refer to [Access tunnel traffic analytics](#access-tunnel-traf
Cloudflare One Unified Routing for both to work together.
@@ -96,7 +96,7 @@ For detailed configuration, refer to the [WARP Connector documentation](/cloudfl
## DNS locations
-DNS locations allow you to filter DNS traffic from networks without deploying the WARP client. By configuring your network's DNS resolver to point to Cloudflare Gateway, Gateway applies DNS policies to all queries from that location.
+DNS locations allow you to filter DNS traffic from networks without deploying the Cloudflare One Client. By configuring your network's DNS resolver to point to Cloudflare Gateway, Gateway applies DNS policies to all queries from that location.
DNS locations support multiple endpoint types:
@@ -107,9 +107,9 @@ DNS locations support multiple endpoint types:
Use DNS locations when you need to filter DNS traffic for an entire office or network, per device without installing agents on devices, or integrate with existing network infrastructure.
:::note[Important to know]
-DNS locations filter DNS traffic only. To filter HTTP traffic, use the WARP client or proxy endpoints.
+DNS locations filter DNS traffic only. To filter HTTP traffic, use the Cloudflare One Client or proxy endpoints.
-For identity-based DNS policies without the WARP client, configure [DNS over HTTPS with user tokens](/cloudflare-one/networks/resolvers-and-proxies/dns/dns-over-https/#filter-doh-requests-by-user). To resolve internal domain names or route queries to private DNS servers, use [resolver policies](/cloudflare-one/traffic-policies/resolver-policies/) (Enterprise only).
+For identity-based DNS policies without the Cloudflare One Client, configure [DNS over HTTPS with user tokens](/cloudflare-one/networks/resolvers-and-proxies/dns/dns-over-https/#filter-doh-requests-by-user). To resolve internal domain names or route queries to private DNS servers, use [resolver policies](/cloudflare-one/traffic-policies/resolver-policies/) (Enterprise only).
:::
For detailed configuration, refer to the [DNS locations documentation](/cloudflare-one/networks/resolvers-and-proxies/dns/locations/).
@@ -137,9 +137,9 @@ For detailed configuration, refer to the [Proxy endpoints documentation](/cloudf
## Clientless Web Isolation
-Clientless Web Isolation allows users to securely access web applications through a remote browser without installing the WARP client. Users navigate to a prefixed URL (`https://.cloudflareaccess.com/browser/`), authenticate through Cloudflare Access, and Cloudflare renders the web content in an isolated browser, streaming only [safe draw commands](https://blog.cloudflare.com/cloudflare-and-remote-browser-isolation/) to the user's device while enforcing isolation policies.
+Clientless Web Isolation allows users to securely access web applications through a remote browser without installing the Cloudflare One Client. Users navigate to a prefixed URL (`https://.cloudflareaccess.com/browser/`), authenticate through Cloudflare Access, and Cloudflare renders the web content in an isolated browser, streaming only [safe draw commands](https://blog.cloudflare.com/cloudflare-and-remote-browser-isolation/) to the user's device while enforcing isolation policies.
-Use Clientless Web Isolation when you need to provide secure web access for unmanaged devices (contractors, BYOD), enable access to sensitive applications without requiring endpoint software, or on-ramp users who cannot install the WARP client.
+Use Clientless Web Isolation when you need to provide secure web access for unmanaged devices (contractors, BYOD), enable access to sensitive applications without requiring endpoint software, or on-ramp users who cannot install the Cloudflare One Client.
:::note[Important to know]
Clientless Web Isolation requires the Browser Isolation add-on and user authentication through Cloudflare Access. Gateway HTTP and DNS policies apply to isolated traffic.
@@ -272,7 +272,7 @@ Use the following guidance to select the appropriate connectivity option for you
| Requirement | Recommended option |
| ---- | ---- |
| Expose a private web application without a public IP | [Cloudflare Tunnel](#cloudflare-tunnel) |
-| Secure end-user devices | [WARP client](#warp-client) |
+| Secure end-user devices | [Cloudflare One Client](#warp-client) |
| Replace traditional VPN for remote access | [Cloudflare Tunnel](#cloudflare-tunnel) (primary) + [WARP Connector](#warp-connector) (for bidirectional needs) |
| Connect a site with IoT devices or VoIP systems | [WARP Connector](#warp-connector) |
| Connect a branch office using existing routers | [GRE](#gre-tunnels) or [IPsec tunnels](#ipsec-tunnels) |
@@ -288,7 +288,7 @@ The team driving your connectivity project influences which option provides the
| Primary team | Recommended starting point | Rationale |
| ---- | ---- | ---- |
-| Security / InfoSec | [Cloudflare Tunnel](#cloudflare-tunnel) + [WARP client](#warp-client) | Minimal network infrastructure changes required. Security controls are managed within the Cloudflare One dashboard. |
+| Security / InfoSec | [Cloudflare Tunnel](#cloudflare-tunnel) + [Cloudflare One Client](#warp-client) | Minimal network infrastructure changes required. Security controls are managed within the Cloudflare One dashboard. |
| Network Operations | [Cloudflare WAN](#ipsec-tunnels) (IPsec/GRE) or [Cloudflare One Appliance](#cloudflare-one-appliance) | Familiar routing and tunnel configuration. Integrates with existing network equipment and workflows. |
| DevOps / Platform Engineering | [WARP Connector](#warp-connector) or [Cloudflare Tunnel](#cloudflare-tunnel) | Software-defined deployment. Scriptable via API. No hardware dependencies. |
| Facilities / Branch IT | [Cloudflare One Appliance](#cloudflare-one-appliance) | Zero-touch deployment with centralized management. No on-site networking expertise required. |
@@ -304,7 +304,7 @@ WARP Connector and Cloudflare One Appliance both provide site-level connectivity
| **Best for** | Cloud VPCs, development environments, sites without dedicated network hardware, smaller deployments | Enterprise branch offices, data centers, sites requiring high throughput (1 Gbps+) |
| **Platform support** | Linux only (x86_64). Currently in beta. | Hardware appliance (Dell VEP1460) or virtual (VMware ESXi, Proxmox) |
| **High availability** | Not currently supported | Supported through multiple connectors per site |
-| **Management** | Configured as a device in the WARP client settings | Centralized through the Cloudflare WAN dashboard with zero-touch provisioning |
+| **Management** | Configured as a device in the Cloudflare One Client settings | Centralized through the Cloudflare WAN dashboard with zero-touch provisioning |
Use WARP Connector when you need lightweight, software-only connectivity for cloud workloads or sites without dedicated network hardware. Use Cloudflare One Appliance when you need enterprise-grade throughput, high availability, or integration with existing network infrastructure.
@@ -321,11 +321,11 @@ Not all connectivity options work together in the same account. Review the follo
| Combination | Compatible | Notes |
| ---- | ---- | ---- |
| WARP Connector + Cloudflare WAN | Conditional | Requires Cloudflare One Unified Routing. Accounts on Legacy routing mode cannot use both. |
-| WARP client + Cloudflare WAN | Yes | WARP users can access Cloudflare WAN-connected sites. Cloudflare WAN sites can also initiate connections to WARP devices using their virtual IP addresses. |
+| Cloudflare One Client + Cloudflare WAN | Yes | Cloudflare One Client users can access Cloudflare WAN-connected sites. Cloudflare WAN sites can also initiate connections to the Cloudflare One Client devices using their virtual IP addresses. |
| Cloudflare Tunnel + Cloudflare WAN | Yes | Avoid overlapping IP routes. Cloudflare Tunnel takes priority if the same CIDR is configured for both. |
| GRE + IPsec | Yes | Use for redundancy or migration scenarios. |
| CNI + GRE or IPsec | Yes | Use Internet-based GRE or IPsec tunnels as backup connectivity alongside CNI. |
-| WARP client + Cloudflare Tunnel + WARP Connector | Yes | Common pattern for remote access to private applications. All three work together. |
+| Cloudflare One Client + Cloudflare Tunnel + WARP Connector | Yes | Common pattern for remote access to private applications. All three work together. |
| CNI + Cloudflare Tunnel | Conditional | `cloudflared` connects to multiple Cloudflare regions for redundancy. If CNI only advertises one region, the tunnel operates with reduced redundancy. Evaluate whether Cloudflare Tunnel is necessary if CNI already provides private connectivity. |
### Routing considerations
@@ -345,7 +345,7 @@ When layering tunnels or using multiple encapsulation methods, account for overh
| GRE tunnel | 1,476 bytes | 1,436 bytes or lower |
| IPsec tunnel | 1,400-1,436 bytes (varies by encryption) | 1,360-1,396 bytes |
| WARP behind Cloudflare WAN (double encapsulation) | ~1,300 bytes | Configure based on testing |
-| WARP Connector to WARP client | ~1,280 bytes | Configure based on testing. Traffic is encapsulated twice: by WARP Connector and again by Cloudflare before delivery to the WARP client. |
+| WARP Connector to Cloudflare One Client | ~1,280 bytes | Configure based on testing. Traffic is encapsulated twice: by WARP Connector and again by Cloudflare before delivery to the Cloudflare One Client. |
Configure MSS clamping on your edge devices to ensure TCP traffic does not require fragmentation.
@@ -371,13 +371,13 @@ Source IP preservation is required for:
| Connectivity option | Client-initiated traffic | Server-initiated traffic |
| ---- | ---- | ---- |
| Cloudflare Tunnel | Yes | No |
-| WARP client | Yes | Yes |
+| Cloudflare One Client | Yes | Yes |
| WARP Connector | Yes | Yes |
| GRE and IPsec tunnels | Yes | Yes |
| Cloudflare One Appliance | Yes | Yes |
| CNI | Yes | Yes |
-If your application requires server-initiated connections (for example, VoIP callbacks, database replication), use a bidirectional connectivity option such as WARP client, WARP Connector, Cloudflare WAN (IPsec/GRE), or CNI. Cloudflare Tunnel does not support server-initiated traffic.
+If your application requires server-initiated connections (for example, VoIP callbacks, database replication), use a bidirectional connectivity option such as Cloudflare One Client, WARP Connector, Cloudflare WAN (IPsec/GRE), or CNI. Cloudflare Tunnel does not support server-initiated traffic.
---
@@ -391,13 +391,13 @@ This pattern serves organizations with a distributed workforce and multiple phys
**Components:**
-- **WARP client** for remote employees, providing secure access from any location
+- **Cloudflare One Client** for remote employees, providing secure access from any location
- **IPsec tunnels** (via Cloudflare WAN) for branch offices with existing network infrastructure
- **Cloudflare Tunnel** for specific internal applications that need clientless browser access
**Traffic flow:**
-1. Remote employees connect through WARP, which on-ramps their traffic to Cloudflare.
+1. Remote employees connect through the Cloudflare One Client, which on-ramps their traffic to Cloudflare.
2. Gateway policies inspect and filter traffic based on user identity and device posture.
3. Traffic destined for branch office resources routes through IPsec tunnels to Cloudflare WAN-connected sites.
4. Traffic destined for specific applications routes through Cloudflare Tunnel to origin servers.
@@ -410,13 +410,13 @@ This pattern serves organizations with primarily cloud-based infrastructure and
- **Multi-Cloud Networking** for cloud VPCs (AWS, GCP, Azure), automating IPsec tunnel creation to Cloudflare WAN
- **Cloudflare Tunnel** for Kubernetes services and containerized applications
-- **WARP client** for employee devices
+- **Cloudflare One Client** for employee devices
**Traffic flow:**
1. Multi-Cloud Networking automatically creates IPsec tunnels between cloud VPCs and Cloudflare WAN.
2. Cloudflare Tunnel provides ingress for external-facing applications.
-3. Employees access cloud resources through the WARP client.
+3. Employees access cloud resources through the Cloudflare One Client.
**Alternative:** For organizations not using Cloudflare WAN, WARP Connector can provide bidirectional connectivity for cloud VPCs. Note that accounts on Legacy routing mode cannot use WARP Connector and Cloudflare WAN together.
@@ -428,13 +428,13 @@ This pattern serves organizations with strict compliance requirements that prohi
- **Cloudflare Network Interconnect (CNI)** for primary connectivity from data centers
- **IPsec tunnels** as backup connectivity in case of CNI issues
-- **WARP client** for remote employees
+- **Cloudflare One Client** for remote employees
**Traffic flow:**
1. Data center traffic routes through CNI, never touching the public Internet.
2. IPsec tunnels provide backup connectivity if CNI experiences issues.
-3. Remote employees connect through WARP over the public Internet (encrypted).
+3. Remote employees connect through the Cloudflare One Client over the public Internet (encrypted).
4. Gateway policies enforce compliance rules on all traffic regardless of connectivity method.
---
@@ -444,7 +444,7 @@ This pattern serves organizations with strict compliance requirements that prohi
- [SASE reference architecture](/reference-architecture/architectures/sase/) - Guide to deploying Cloudflare One
- [WAN transformation](/cloudflare-wan/wan-transformation/) - Plan your migration from legacy WAN to Cloudflare One
- [Cloudflare Tunnel](/cloudflare-one/networks/connectors/cloudflare-tunnel/)
-- [WARP client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/)
+- [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/)
- [WARP Connector](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/)
- [Cloudflare WAN](/cloudflare-wan/)
- WAN Connectors on-ramps - Full list of supported on-ramps
diff --git a/src/content/partials/networking-services/cloudflare-wan/reference/bandwidth-measurement.mdx b/src/content/partials/networking-services/cloudflare-wan/reference/bandwidth-measurement.mdx
index d118237ad96..53b598b6059 100644
--- a/src/content/partials/networking-services/cloudflare-wan/reference/bandwidth-measurement.mdx
+++ b/src/content/partials/networking-services/cloudflare-wan/reference/bandwidth-measurement.mdx
@@ -14,7 +14,7 @@ Cloudflare WAN bandwidth includes the sum of traffic routed to and from the Clou
- Cloudflare Tunnel
- [Cloudflare Network Interconnect](/network-interconnect/)
-For each tunnel, Cloudflare uses the highest 95th percentile value (ingress or egress traffic). The usage measurement excludes [WARP](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) traffic.
+For each tunnel, Cloudflare uses the highest 95th percentile value (ingress or egress traffic). The usage measurement excludes [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) traffic.
## 95th percentile calculation
diff --git a/src/content/partials/networking-services/cloudflare-wan/wan-transformation.mdx b/src/content/partials/networking-services/cloudflare-wan/wan-transformation.mdx
index 55d50d4b9ba..d02afa2fafb 100644
--- a/src/content/partials/networking-services/cloudflare-wan/wan-transformation.mdx
+++ b/src/content/partials/networking-services/cloudflare-wan/wan-transformation.mdx
@@ -49,7 +49,7 @@ WAN transformation is not an all-or-nothing change. Most organizations follow an
### 1. Secure user access
-Start by replacing VPN concentrators with Zero Trust Network Access (ZTNA). Deploy the WARP client on user devices and use Cloudflare Access to enforce identity-based policies for application access. This step secures remote and hybrid workers without changing your existing network infrastructure.
+Start by replacing VPN concentrators with Zero Trust Network Access (ZTNA). Deploy the Cloudflare One Client on user devices and use Cloudflare Access to enforce identity-based policies for application access. This step secures remote and hybrid workers without changing your existing network infrastructure.
For more information, refer to Cloudflare One.
diff --git a/src/content/partials/networking-services/cloudflare-wan/zero-trust/gateway.mdx b/src/content/partials/networking-services/cloudflare-wan/zero-trust/gateway.mdx
index 964a22c49f7..735c5c3409a 100644
--- a/src/content/partials/networking-services/cloudflare-wan/zero-trust/gateway.mdx
+++ b/src/content/partials/networking-services/cloudflare-wan/zero-trust/gateway.mdx
@@ -31,15 +31,15 @@ To inspect HTTPS traffic, you need to install a Cloudflare root certificate on e
### Installing certificates
-You can use the WARP client to automatically install a Cloudflare certificate on supported devices. If your device or application does not support certificate installation through WARP, you can manually install a certificate.
+You can use the Cloudflare One Client to automatically install a Cloudflare certificate on supported devices. If your device or application does not support certificate installation through the Cloudflare One Client, you can manually install a certificate.
### Exempting traffic from inspection
If you cannot or do not want to install the certificate, you can create Do Not Inspect policies to exempt incompatible Cloudflare WAN traffic from inspection or to disable TLS decryption entirely.
-Because Gateway cannot discern Cloudflare WAN traffic, you must use WARP client checks or the IP addresses associated with Cloudflare WAN to match traffic with Gateway policies.
+Because Gateway cannot discern Cloudflare WAN traffic, you must use Cloudflare One Client checks or the IP addresses associated with Cloudflare WAN to match traffic with Gateway policies.
-For example, if your organization onboards devices to Cloudflare WAN using WARP, you can exempt devices not running WARP using OS version checks:
+For example, if your organization onboards devices to Cloudflare WAN using the Cloudflare One Client, you can exempt devices not running the Cloudflare One Client using OS version checks:
| Selector | Operator | Value | Logic | Action |
| ---------------------------- | -------- | -------------------- | ----- | -------------- |
@@ -89,7 +89,7 @@ accDescr: Shows how DNS queries from Cloudflare WAN and WARP Connector flow thro
By default, the following traffic routed through IPsec/GRE tunnels and destined to public IP addresses is proxied/filtered through Cloudflare Gateway:
-- TCP, UDP, and ICMP traffic sourced from [RFC 1918](https://datatracker.ietf.org/doc/html/rfc1918) IPs or WARP devices.
+- TCP, UDP, and ICMP traffic sourced from [RFC 1918](https://datatracker.ietf.org/doc/html/rfc1918) IPs or devices.
- TCP and UDP traffic sourced from [BYOIP](/byoip/) or [Leased IPs](/magic-transit/cloudflare-ips/) and destined to a well-known port (`0`-`1023`).
By default, traffic destined to public IPs will be routed over the public Internet. If you want to configure specific public IP ranges to be routed through your IPsec/GRE tunnels instead of over the public Internet after filtering, contact your account team.
diff --git a/src/content/partials/networking-services/cloudflare-wan/zero-trust/warp.mdx b/src/content/partials/networking-services/cloudflare-wan/zero-trust/warp.mdx
index a2a24d61ca2..db7eaf50f1a 100644
--- a/src/content/partials/networking-services/cloudflare-wan/zero-trust/warp.mdx
+++ b/src/content/partials/networking-services/cloudflare-wan/zero-trust/warp.mdx
@@ -13,34 +13,34 @@ params:
---
:::note
-By default, Cloudflare WAN does not support direct WARP-to-WARP connections for devices with WARP enabled. Double encapsulation and asymmetric routing prevent these connections.
+By default, Cloudflare WAN does not support direct Peer-to-peer connections for devices with the Cloudflare One Client enabled. Double encapsulation and asymmetric routing prevent these connections.
-When a device is behind Cloudflare WAN, avoid enabling WARP. Instead, access the device using its local LAN IP from remote systems, rather than relying on WARP-to-WARP communication.
+When a device is behind Cloudflare WAN, avoid enabling WARP. Instead, access the device using its local LAN IP from remote systems, rather than relying on Peer-to-peer communication.
-If you do want to use WARP on a device behind Cloudflare WAN and connect to its WARP IP (within the `100.96.0.0/12` range), you will need to adjust your WARP profiles. Specifically, exclude the `100.96.0.0/12` subnet from the on-premises WARP profile, and include it in the off-premises profile.
+If you do want to use the Cloudflare One Client on a device behind Cloudflare WAN and connect to its virtual IP (within the `100.96.0.0/12` range), you will need to adjust your Cloudflare One Client profiles. Specifically, exclude the `100.96.0.0/12` subnet from the on-premises Cloudflare One Client profiles, and include it in the off-premises profile.
:::
import { GlossaryTooltip, Render } from "~/components";
-Use WARP as an on-ramp to Cloudflare WAN (formerly Magic WAN) and route traffic from user devices with WARP installed to any network connected with Cloudflare Tunnel or IP-layer tunnels (anycastGRE, IPsec, or [CNI](/network-interconnect/)). Take advantage of the integration between Cloudflare WAN and Cloudflare Network Firewall and enforce policies at Cloudflare's global network.
+Use WARP as an on-ramp to Cloudflare WAN (formerly Magic WAN) and route traffic from user devices with the Cloudflare One Client installed to any network connected with Cloudflare Tunnel or IP-layer tunnels (anycastGRE, IPsec, or [CNI](/network-interconnect/)). Take advantage of the integration between Cloudflare WAN and Cloudflare Network Firewall and enforce policies at Cloudflare's global network.
## Prerequisites
-Before you can begin using WARP as an on-ramp to Cloudflare WAN, you must set up your Zero Trust account.
+Before you can begin using the Cloudflare One Client as an on-ramp to Cloudflare WAN, you must set up your Zero Trust account.
## IP ranges
-When connecting a WARP device to Cloudflare WAN, you will have virtual IP addresses from WARP, in the `100.96.0.0/12` range.
+When connecting a device to Cloudflare WAN, you will have virtual IP addresses from the Cloudflare One Client, in the `100.96.0.0/12` range.
---
## Set up WARP with Cloudflare WAN
-### 1. Route packets back to WARP devices
+### 1. Route packets back to the Cloudflare One Client devices
-Route packets back to WARP devices from services behind an anycast GRE or other type tunnel. Complete this configuration before installing WARP. Otherwise, your infrastructure will not route packets correctly to Cloudflare global network and connectivity will fail.
+Route packets back to the Cloudflare One Client devices from services behind an anycast GRE or other type tunnel. Complete this configuration before installing WARP. Otherwise, your infrastructure will not route packets correctly to Cloudflare global network and connectivity will fail.
-Cloudflare will assign IP addresses from the WARP virtual IP (VIP) space to your WARP devices. To view your virtual IP address, go to [Cloudflare One](https://one.dash.cloudflare.com/), and select **{props.ztDashPath}**.
+Cloudflare will assign IP addresses from the virtual IP (VIP) space to your devices. To view your virtual IP address, go to [Cloudflare One](https://one.dash.cloudflare.com/), and select **{props.ztDashPath}**.
All packets with a destination IP in the VIP space need to be routed back through the tunnel. For example, with a single GRE tunnel named `gre1`, in Linux, the following command would add a routing rule that would route such packets:
@@ -50,7 +50,7 @@ ip route add 100.96.0.0/12 dev gre1
:::note[Note]
-After set up, **HTTP** and **Network logs** in Gateway will show the virtual IP address of your WARP device as the **Source IP**. DNS logs will continue to show the original WARP device IP because DNS traffic is sent over the public Internet to Cloudflare's public-facing resolver.
+After set up, **HTTP** and **Network logs** in Gateway will show the virtual IP address of your device as the **Source IP**. DNS logs will continue to show the original device IP because DNS traffic is sent over the public Internet to Cloudflare's public-facing resolver.
:::
### 2. Configure Split Tunnels
@@ -59,13 +59,13 @@ Configure Split Tunnels from your Zero Trust
Optionally, you can configure Split Tunnels to include IP ranges or domains you want to use for connecting to public IP addresses.
-### 3. Install the WARP client on your device
+### 3. Install the Cloudflare One Client on your device
-Refer to Deploy WARP to your organization for more information on whether to choose a manual or managed deployment.
+Refer to Deploy the Cloudflare One Client to your organization for more information on whether to choose a manual or managed deployment.
You can now access private IP addresses specified in the Split Tunnel configuration.
-You must log out and log back in with at least one WARP device to ensure the configuration updates on your device.
+You must log out and log back in with at least one device to ensure the configuration updates on your device.
WARP ingress IP.
-### WARP and {props.mwanConnectorName}
+### the Cloudflare One Client and {props.mwanConnectorName}
configure domain fallback for the server or service in WARP settings. This is needed because by default Cloudflare Zero Trust excludes common top level domains used for local resolution from being sent to Gateway for processing.
+Before testing, configure domain fallback for the server or service in the Cloudflare One Client settings. This is needed because by default Cloudflare Zero Trust excludes common top level domains used for local resolution from being sent to Gateway for processing.
-If WARP integration has been enabled for the account within the last day, log off and on again in the WARP client before testing.
+If WARP integration has been enabled for the account within the last day, log off and on again in the Cloudflare One Client before testing.
-To check if WARP is working correctly as an on-ramp, you can do a resolution test on a [fully qualified domain name (FQDN)](https://en.wikipedia.org/wiki/Fully_qualified_domain_name) for a server or service in the Cloudflare WAN. Test this from a user with a WARP device.
+To check if the Cloudflare One Client is working correctly as an on-ramp, you can do a resolution test on a [fully qualified domain name (FQDN)](https://en.wikipedia.org/wiki/Fully_qualified_domain_name) for a server or service in the Cloudflare WAN. Test this from a user with a device.
For example:
diff --git a/src/content/partials/networking-services/mconn/network-options/app-aware-policies/breakout-prioritized.mdx b/src/content/partials/networking-services/mconn/network-options/app-aware-policies/breakout-prioritized.mdx
index 164483937d8..7eb868cf827 100644
--- a/src/content/partials/networking-services/mconn/network-options/app-aware-policies/breakout-prioritized.mdx
+++ b/src/content/partials/networking-services/mconn/network-options/app-aware-policies/breakout-prioritized.mdx
@@ -388,7 +388,7 @@ To pin applications to a WAN port:
{ props.magicWord === "breakout" && (
<>
-
+
-## 2. Route Network Flow traffic through WARP
+## 2. Route Network Flow traffic through the Cloudflare One Client
-Depending on where you installed the WARP client, you may need to configure other devices on the subnet to route traffic through WARP. If you have access to your router and it runs a version/OS supported by the WARP client, we recommend using [Option 1](#option-1-default-gateway). This recommendation also applies if you have a software-based flow exporter (such as `softflowd`) and are not using a physical router to collect and export flows to Cloudflare.
+Depending on where you installed the Cloudflare One Client, you may need to configure other devices on the subnet to route traffic through the Cloudflare One Client. If you have access to your router and it runs a version/OS supported by the Cloudflare One Client, we recommend using [Option 1](#option-1-default-gateway). This recommendation also applies if you have a software-based flow exporter (such as `softflowd`) and are not using a physical router to collect and export flows to Cloudflare.
### Option 1: Default gateway
-If you installed a WARP client on your router or machine collector (something you can use to collect flow information, such as a computer, virtual machine or server), no additional configuration is necessary. All traffic will use the router as the default gateway. All you need to do is configure your flow export to send flow data to IP address `162.159.65.1` and port `2055` for NetFlow, or `162.159.65.1` and port `6343` for sFlow.
+If you installed a Cloudflare One Client on your router or machine collector (something you can use to collect flow information, such as a computer, virtual machine or server), no additional configuration is necessary. All traffic will use the router as the default gateway. All you need to do is configure your flow export to send flow data to IP address `162.159.65.1` and port `2055` for NetFlow, or `162.159.65.1` and port `6343` for sFlow.
### Option 2: Alternate gateway
-If you have access to the router but installed WARP on another machine, you can configure the router to export flow traffic to the machine running WARP. To do this:
+If you have access to the router but installed the Cloudflare One Client on another machine, you can configure the router to export flow traffic to the machine running the Cloudflare One Client. To do this:
1. Set the machine's IP address as the export destination on the router.
2. Configure the export port on the router to match the listening port on the WARP machine.
-3. Redirect traffic that arrives at your machine running WARP to the following Cloudflare's destination IPs and ports:
+3. Redirect traffic that arrives at your machine running the Cloudflare One Client to the following Cloudflare's destination IPs and ports:
- **For NetFlow**: IP address `162.159.65.1` and port `2055`.
- **For sFlow**: IP `162.159.65.1` and port `6343`.
- For example, if WARP is running on a machine in your network with the IP `10.10.10.10`, and you configured it to accept traffic on port `2055` or `6343`, you need to configure your flow export-capable router to send data to `10.10.10.10` and port `2055` or `6343`.
+ For example, if the Cloudflare One Client is running on a machine in your network with the IP `10.10.10.10`, and you configured it to accept traffic on port `2055` or `6343`, you need to configure your flow export-capable router to send data to `10.10.10.10` and port `2055` or `6343`.
-In the machine running WARP, you can redirect this traffic to Cloudflare using a proxy or redirect tool of your choice. Options include:
+In the machine running the Cloudflare One Client, you can redirect this traffic to Cloudflare using a proxy or redirect tool of your choice. Options include:
- Using `socat`, listen on the desired port for UDP traffic. Then, proxy that traffic to Network Flow's destination and port.
- `socat UDP-LISTEN:2055,reuseaddr,fork UDP:162.159.65.1:2055`
@@ -65,4 +65,4 @@ In the machine running WARP, you can redirect this traffic to Cloudflare using a
## 3. (Optional) Configure split tunnels
-If you do not want all the traffic in your device to be WARP-enabled, [configure split tunnels/proxy mode](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/) to either only allow Network Flow traffic towards `162.159.65.1` or exclude everything else.
+If you do not want all the traffic in your device to be Cloudflare One Client-enabled, [configure split tunnels/proxy mode](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/) to either only allow Network Flow traffic towards `162.159.65.1` or exclude everything else.
diff --git a/src/content/partials/networking-services/reference/traffic-steering.mdx b/src/content/partials/networking-services/reference/traffic-steering.mdx
index 2399b60d051..5192afd6063 100644
--- a/src/content/partials/networking-services/reference/traffic-steering.mdx
+++ b/src/content/partials/networking-services/reference/traffic-steering.mdx
@@ -27,7 +27,7 @@ import { AnchorHeading, Aside, Markdown, Render } from "~/components";
The {props.virtualNetworkName} is a virtual network overlay, private to your account, that spans all Cloudflare data centers globally. This overlay network provides:
- Magic Transit delivery for [Denial of Service (DoS)](/ddos-protection/) and {props.mFirewallName} filtered Internet traffic, from the entry data center where the traffic ingressed, to your publicly addressed edge/border network.
-- {props.productName} packet transport between IPsec/GRE tunnels, interconnects, [Cloudflare Load Balancer](/load-balancing/), and [Zero Trust](/cloudflare-one/) connections such as WARP Client, Remote Browser Isolation, Access, and Gateway.
+- {props.productName} packet transport between IPsec/GRE tunnels, interconnects, [Cloudflare Load Balancer](/load-balancing/), and [Zero Trust](/cloudflare-one/) connections such as Cloudflare One Client, Remote Browser Isolation, Access, and Gateway.
The {props.virtualNetworkName} supports routing the {props.productName} traffic through anycast tunnels using GRE and Internet Protocol Security (IPsec) or [CNI with Dataplane v2](/network-interconnect/). You can add entries to the {props.routingTableName} through static route configuration or through routes learned through BGP peering (beta).{ props.magicWord !== "Magic Transit" && (<> Traffic can also be routed automatically according to tracked flow state.>)}
@@ -200,7 +200,7 @@ Automatic Return Routing applies when:
- ICMP echo (ping) requests
- The traffic is destined for:
- Internet egress through Cloudflare
- - A WARP client
+ - A Cloudflare One Client
- A private network connected to Cloudflare through Cloudflare Tunnel
- A private network connected to Cloudflare through WARP Connector
diff --git a/src/content/partials/networking-services/routing/bgp-config-steps.mdx b/src/content/partials/networking-services/routing/bgp-config-steps.mdx
index 1574fdc060b..0496ba432db 100644
--- a/src/content/partials/networking-services/routing/bgp-config-steps.mdx
+++ b/src/content/partials/networking-services/routing/bgp-config-steps.mdx
@@ -20,6 +20,6 @@ import { Aside, Markdown } from "~/components";
7. In **MD5 key**, you can optionally enter the key for your network. Note that this is meant to prevent accidental misconfigurations and is not a security mechanism.
8. (Optional) In **Additional Advertised prefix list**, input any additional prefixes you want to advertise alongside your existing routes. Leave this blank if you do not want to advertise extra routes. Typical prefixes to configure here include:
- A route to `0.0.0.0/0`, the default route — to attract all Internet-bound traffic if using {props.productGatewayOrEgress}.
- - A route to `100.96.0.0/12`, the portion of CGNAT space [used by default with WARP clients](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/user-to-site/#add-ip-route-to-router).
+ - A route to `100.96.0.0/12`, the portion of CGNAT space [used by default with Cloudflare One Clients](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/user-to-site/#add-ip-route-to-router).
{ props.magicWord !== "Magic Transit" && ()}
9. Select **Save**.
diff --git a/src/content/partials/networking-services/routing/configure-cloudflare-source-ips.mdx b/src/content/partials/networking-services/routing/configure-cloudflare-source-ips.mdx
index 04f08cfc504..8dabf8c864e 100644
--- a/src/content/partials/networking-services/routing/configure-cloudflare-source-ips.mdx
+++ b/src/content/partials/networking-services/routing/configure-cloudflare-source-ips.mdx
@@ -31,7 +31,7 @@ Before you begin, ensure that:
- Cloudflare One subnets in the same account cannot overlap. Default allocations include:
- Cloudflare Source IPs (`100.64.0.0/12`)
- Hostname Route Token IPs (`100.80.0.0/16`)
- - WARP Clients (`100.96.0.0/12`)
+ - Cloudflare One Clients (`100.96.0.0/12`)
- Private Load Balancers (`100.112.0.0/16`)
- The source subnet cannot match or contain any existing route in your Cloudflare One routing table. The source subnet can be within a supernet route.
@@ -44,7 +44,7 @@ The following Connectors are affected:
- IPsec
- CNI
- WARP Connector
-- WARP Client
+- Cloudflare One Client
## Configure source IPs
diff --git a/src/content/partials/networking-services/routing/traceroute.mdx b/src/content/partials/networking-services/routing/traceroute.mdx
index 61a72062372..df415478f2f 100644
--- a/src/content/partials/networking-services/routing/traceroute.mdx
+++ b/src/content/partials/networking-services/routing/traceroute.mdx
@@ -47,9 +47,9 @@ traceroute to 10.3.0.100 (10.3.0.100), 30 hops max, 60 byte packets
5 10.3.0.100 (10.3.0.100) 370.519 ms 370.541 ms 518.152 ms
```
-## WARP client
+## Cloudflare One Client
-Some Linux distributions default to a very strict setting for [reverse path filtering](https://sysctl-explorer.net/net/ipv4/rp_filter/). This strict setting attempts to drop fake traffic as a security measure. Performing a `traceroute` with this setting on can unintentionally drop `traceroute` packets. If you use WARP on Linux, set a less strict policy before attempting to perform a `traceroute`:
+Some Linux distributions default to a very strict setting for [reverse path filtering](https://sysctl-explorer.net/net/ipv4/rp_filter/). This strict setting attempts to drop fake traffic as a security measure. Performing a `traceroute` with this setting on can unintentionally drop `traceroute` packets. If you use the Cloudflare One Client on Linux, set a less strict policy before attempting to perform a `traceroute`:
```sh
sudo sysctl -w net.ipv4.conf.CloudflareWARP.rp_filter=2
From 3d245ff1091dfca3f34a666a8786e82cb5c52226 Mon Sep 17 00:00:00 2001
From: Ranbel Sun
Date: Mon, 16 Mar 2026 13:30:39 -0400
Subject: [PATCH 02/15] [ZT] Fix remaining standalone WARP references missed by
initial pass
Updates ~40 additional standalone 'WARP' references across 30 files
that were missed by the automated regex pass. Includes headings,
descriptions, prose, and table entries. Safe-list items preserved
(Mermaid diagrams, code blocks, dashboard UI labels, WARP session
feature names, consumer WARP refs, changelog prose).
---
.../docs/cloudflare-one/faq/devices-faq.mdx | 2 +-
.../docs/cloudflare-one/faq/troubleshooting.mdx | 14 +++++++-------
.../insights/logs/gateway-logs/index.mdx | 2 +-
.../integrations/service-providers/custom.mdx | 4 ++--
.../private-net/cloudflared/connect-cidr.mdx | 2 +-
.../connectors/cloudflare-tunnel/use-cases/smb.mdx | 2 +-
.../cloudflare-tunnel/use-cases/ssh/index.mdx | 2 +-
.../networks/routes/reserved-ips.mdx | 2 +-
.../setup/replace-vpn/device-to-device.mdx | 4 ++--
.../setup/replace-vpn/device-to-network.mdx | 2 +-
.../automated-deployment.mdx | 2 +-
.../user-side-certificates/custom-certificate.mdx | 2 +-
.../tutorials/clientless-access-private-dns.mdx | 2 +-
.../tutorials/m365-dedicated-egress-ips.mdx | 2 +-
.../docs/data-localization/compatibility.mdx | 2 +-
.../build-policies/test-your-first-application.mdx | 6 +++---
.../connect-devices-networks/choose-on-ramp.mdx | 2 +-
.../sase/sase-clientless-access-private-dns.mdx | 2 +-
.../access/enable-scim-on-dashboard.mdx | 4 ++--
.../partials/cloudflare-one/aws-resolver.mdx | 2 +-
.../gateway/client-notifications-OS.mdx | 2 +-
.../gateway/egress-selector-warp-version.mdx | 2 +-
.../learning-paths/zero-trust/install-agent.mdx | 2 +-
.../zero-trust/split-tunnel-settings.mdx | 2 +-
.../cloudflare-one-connectivity-options.mdx | 4 ++--
.../cloudflare-wan/zero-trust/gateway.mdx | 2 +-
.../cloudflare-wan/zero-trust/warp.mdx | 6 +++---
.../app-aware-policies/warp-traffic.mdx | 2 +-
.../mnm/tutorials/encrypt-network-flow-data.mdx | 2 +-
.../reference/traffic-steering.mdx | 2 +-
30 files changed, 44 insertions(+), 44 deletions(-)
diff --git a/src/content/docs/cloudflare-one/faq/devices-faq.mdx b/src/content/docs/cloudflare-one/faq/devices-faq.mdx
index d4ade922fd9..8cdd3790b91 100644
--- a/src/content/docs/cloudflare-one/faq/devices-faq.mdx
+++ b/src/content/docs/cloudflare-one/faq/devices-faq.mdx
@@ -32,7 +32,7 @@ the Cloudflare One Client is in part powered by 1.1.1.1. When visiting sites or
## Why is my device not connecting to a public Wi-Fi?
-The Wi-Fi network may have a captive portal that is blocking WARP from establishing a secure connection. In order to access the portal, and therefore the Internet, you will need to temporarily turn off WARP. After you login to the captive portal through your browser, you can turn WARP back on to access corporate resources.
+The Wi-Fi network may have a captive portal that is blocking the Cloudflare One Client from establishing a secure connection. In order to access the portal, and therefore the Internet, you will need to temporarily turn off the Cloudflare One Client. After you login to the captive portal through your browser, you can turn the Cloudflare One Client back on to access corporate resources.
For more information, refer to [Captive portal detection](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/captive-portals/).
diff --git a/src/content/docs/cloudflare-one/faq/troubleshooting.mdx b/src/content/docs/cloudflare-one/faq/troubleshooting.mdx
index 4c319e71720..ef3393d6033 100644
--- a/src/content/docs/cloudflare-one/faq/troubleshooting.mdx
+++ b/src/content/docs/cloudflare-one/faq/troubleshooting.mdx
@@ -43,7 +43,7 @@ Gateway presents an **HTTP Response Code: 526** error page in the following case
- The server certificate is revoked and fails a CRL check.
- There is at least one expired certificate in the certificate chain for the server certificate.
- The common name on the certificate does not match the URL you are trying to reach.
- - The common name on the certificate contains invalid characters (such as underscores). Gateway uses [BoringSSL](https://csrc.nist.gov/projects/cryptographic-module-validation-program/validated-modules/search?SearchMode=Basic&Vendor=Google&CertificateStatus=Active&ValidationYear=0) to validate certificates. Chrome's [validation logic](https://chromium.googlesource.com/chromium/src/+/refs/heads/main/net/cert/x509_certificate.cc#429) allows non-RFC 1305 compliant certificates, which is why the website may load when you turn off WARP.
+ - The common name on the certificate contains invalid characters (such as underscores). Gateway uses [BoringSSL](https://csrc.nist.gov/projects/cryptographic-module-validation-program/validated-modules/search?SearchMode=Basic&Vendor=Google&CertificateStatus=Active&ValidationYear=0) to validate certificates. Chrome's [validation logic](https://chromium.googlesource.com/chromium/src/+/refs/heads/main/net/cert/x509_certificate.cc#429) allows non-RFC 1305 compliant certificates, which is why the website may load when you turn off the Cloudflare One Client.
- **The connection from Gateway to the origin is insecure.** Gateway does not trust origins which:
- Only offer insecure cipher suites (such as RC4, RC4-MD5, or 3DES). You can use the [SSL Server Test tool](https://www.ssllabs.com/ssltest/index.html) to check which ciphers are supported by the origin.
@@ -220,7 +220,7 @@ To reset the encryption keys:
-macOS Big Sur and newer releases do not allow WARP to automatically trust the certificate. You must either [manually trust the certificate](/cloudflare-one/team-and-resources/devices/user-side-certificates/automated-deployment/#macos) as the user or [use a MDM to trust the certificate](/cloudflare-one/team-and-resources/devices/user-side-certificates/manual-deployment/#mobile-device-management-mdm-software).
+macOS Big Sur and newer releases do not allow the Cloudflare One Client to automatically trust the certificate. You must either [manually trust the certificate](/cloudflare-one/team-and-resources/devices/user-side-certificates/automated-deployment/#macos) as the user or [use a MDM to trust the certificate](/cloudflare-one/team-and-resources/devices/user-side-certificates/manual-deployment/#mobile-device-management-mdm-software).
After confirming that the certificate is installed and trusted on the end-user device, mark the certificate as **In-Use**. To mark the certificate as **In-Use**:
@@ -229,7 +229,7 @@ After confirming that the certificate is installed and trusted on the end-user d
3. In the detailed menu under **Basic Information**, select **Confirm and turn on certificate**.
4. Once turned on, the new certificate will now show as **In-Use** in Cloudflare One. **In-Use** indicates that the certificate is being used for inspection.
-It is recommended to have end users disconnect and reconnect WARP to expedite this change being reflected on their local machine. To verify the new certificate is being used correctly:
+It is recommended to have end users disconnect and reconnect the Cloudflare One Client to expedite this change being reflected on their local machine. To verify the new certificate is being used correctly:
1. Connect to the Cloudflare One Client.
2. Visit an HTTPS site.
@@ -243,7 +243,7 @@ The new certificate will be valid until the configured expiration date.
If the new certificate is not activating on the end-user device or you are getting a `Certificate is missing` warning even though the certificate is marked **In-Use**. Refer to the following troubleshooting options:
-1. Rotate the keys used by WARP to force activate the new certificate by running:
+1. Rotate the keys used by the Cloudflare One Client to force activate the new certificate by running:
```sh
warp-cli tunnel rotate-keys
@@ -287,11 +287,11 @@ However, if the user attempts to enter the override code at **1:00 PM** the same
If the user attempts to enter the override code at **11:59 AM** the next day, the override code will only be valid until **12:59 PM** (a one hour duration). The override code was generated at **12:00 PM** and 23 hours of its total 24 hour validity were counted as used from 12:00 PM to 11:00 AM the next day (a 23 hour duration).
-## I disabled WARP using an override code but WARP turned on by itself before my override code expired.
+## I disabled the Cloudflare One Client using an override code but it turned on by itself before my override code expired.
If you are using an [admin override code](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/#allow-admin-override-codes) with [Auto connect](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/#auto-connect) also enabled, the Cloudflare One Client will turn on automatically according to the Timeout set for **Auto connect**. Using an override code to override the WARP lock switch will not disable Auto connect. As best practice, review your Auto connect settings before sending the override code to the user.
-To prevent WARP from auto connecting while using an admin override code, disable Auto connect or set a longer **Timeout** for **Auto connect**. Note the changes you make to Auto connect while the end user is using the admin override code if you need to revert these changes later.
+To prevent the Cloudflare One Client from auto connecting while using an admin override code, disable Auto connect or set a longer **Timeout** for **Auto connect**. Note the changes you make to Auto connect while the end user is using the admin override code if you need to revert these changes later.
## I am getting the error `Failed to fetch user/group information from the identity provider`.
@@ -356,7 +356,7 @@ Some legacy Windows systems (such as Windows 10 Enterprise 1607 LTSB, which is b
To fix this:
1. Download and install the [.NET Framework 4.7.2 Runtime](https://dotnet.microsoft.com/en-us/download/dotnet-framework/net472) (make sure to install the **Runtime**, not the Developer Pack).
-2. Re-run the WARP installer.
+2. Re-run the Cloudflare One Client installer.
If the problem continues, try running the [.NET Repair Tool](https://www.microsoft.com/en-ca/download/details.aspx?id=30135), or check which .NET versions are installed by running the following command in PowerShell:
diff --git a/src/content/docs/cloudflare-one/insights/logs/gateway-logs/index.mdx b/src/content/docs/cloudflare-one/insights/logs/gateway-logs/index.mdx
index 855e48c5661..40fb6173b16 100644
--- a/src/content/docs/cloudflare-one/insights/logs/gateway-logs/index.mdx
+++ b/src/content/docs/cloudflare-one/insights/logs/gateway-logs/index.mdx
@@ -62,7 +62,7 @@ These settings will only apply to logs displayed in Cloudflare One. Logpush data
| **Email** | Email address of the user who registered the Cloudflare One Client where traffic originated from. |
| **User ID** | UUID of the user. Each unique email address in your organization will have a UUID associated with it. |
| **Registration ID** | UUID of the user's Cloudflare One Client registration. A unique registration ID is generated each time a device is registered for a particular email. The same physical device may have multiple registration IDs. |
-| **Device name** | Display name of the device returned by the operating system to the WARP client. Typically this is the hostname of a device. Not all devices will have a device name. Device names are not guaranteed to be unique. |
+| **Device name** | Display name of the device returned by the operating system to the Cloudflare One Client. Typically this is the hostname of a device. Not all devices will have a device name. Device names are not guaranteed to be unique. |
| **Device ID** | UUID of the device connected with the Cloudflare One Client. Each physical device in your organization will have a UUID. |
| **Last authenticated** | Date and time the user last authenticated their Zero Trust session. |
diff --git a/src/content/docs/cloudflare-one/integrations/service-providers/custom.mdx b/src/content/docs/cloudflare-one/integrations/service-providers/custom.mdx
index f7be6052c18..c0034b6d7a6 100644
--- a/src/content/docs/cloudflare-one/integrations/service-providers/custom.mdx
+++ b/src/content/docs/cloudflare-one/integrations/service-providers/custom.mdx
@@ -10,7 +10,7 @@ description: Configure custom device posture checks in Cloudflare One using a se
import { Render } from "~/components";
-Cloudflare One allows you to enforce custom device posture checks on your applications. This involves configuring a WARP service-to-service integration that periodically calls the external API of your choice, whether it is a third-party endpoint provider or a home built solution. When called, the API will receive device identifying information from Cloudflare and be expected to return a value between `0` to `100`. You can then set up a device posture check that determines if the returned value counts as a pass or fail; for example, you could allow access to a user only if their device has a posture value greater than `60`.
+Cloudflare One allows you to enforce custom device posture checks on your applications. This involves configuring a Cloudflare One Client service-to-service integration that periodically calls the external API of your choice, whether it is a third-party endpoint provider or a home built solution. When called, the API will receive device identifying information from Cloudflare and be expected to return a value between `0` to `100`. You can then set up a device posture check that determines if the returned value counts as a pass or fail; for example, you could allow access to a user only if their device has a posture value greater than `60`.
```mermaid
sequenceDiagram
@@ -99,7 +99,7 @@ Example response body:
### 1. Create a service token
-WARP uses an Access Client ID and Access Client Secret to securely authenticate to the external API. If you do not already have an Access Client ID and Access Client Secret, [create a new service token](/cloudflare-one/access-controls/service-credentials/service-tokens/#create-a-service-token).
+The Cloudflare One Client uses an Access Client ID and Access Client Secret to securely authenticate to the external API. If you do not already have an Access Client ID and Access Client Secret, [create a new service token](/cloudflare-one/access-controls/service-credentials/service-tokens/#create-a-service-token).
### 2. Create an Access application
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/connect-cidr.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/connect-cidr.mdx
index 8084d7dedb6..a6aab17a9d0 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/connect-cidr.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/connect-cidr.mdx
@@ -9,7 +9,7 @@ sidebar:
import { Render } from "~/components";
-This guide covers how to enable secure remote access to private IP addresses using `cloudflared` and WARP. You can connect an entire private network, a subnet, or an application defined by a static IP.
+This guide covers how to enable secure remote access to private IP addresses using `cloudflared` and the Cloudflare One Client. You can connect an entire private network, a subnet, or an application defined by a static IP.
## 1. Connect the server to Cloudflare
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/smb.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/smb.mdx
index fab7c8e7c4d..7d55fc13912 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/smb.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/smb.mdx
@@ -65,7 +65,7 @@ You can use Cloudflare Tunnel to create a secure, outbound-only connection from
Cloudflare Tunnel can also route applications through a public hostname, which allows users to connect to the application without the Cloudflare One Client. This method requires having `cloudflared` installed on both the server machine and on the client machine, as well as an active zone on Cloudflare. The traffic is proxied over this connection, and the user logs in to the server with their Cloudflare Access credentials.
-The public hostname method can be implemented in conjunction with routing over WARP so that there are multiple ways to connect to the server. You can reuse the same tunnel for both the private network and public hostname routes.
+The public hostname method can be implemented in conjunction with routing over the Cloudflare One Client so that there are multiple ways to connect to the server. You can reuse the same tunnel for both the private network and public hostname routes.
### 1. Connect the server to Cloudflare
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/index.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/index.mdx
index 0019e824f68..27ca438faf7 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/index.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/index.mdx
@@ -75,7 +75,7 @@ Cloudflare offers four ways to secure SSH:
**Best for:** Browser-based SSH access for quick administrative tasks
-**Key differentiator:** No SSH client or WARP required — connect directly from a browser
+**Key differentiator:** No SSH client or Cloudflare One Client required — connect directly from a browser
diff --git a/src/content/docs/cloudflare-one/networks/routes/reserved-ips.mdx b/src/content/docs/cloudflare-one/networks/routes/reserved-ips.mdx
index 1376d7deff6..2dffccad776 100644
--- a/src/content/docs/cloudflare-one/networks/routes/reserved-ips.mdx
+++ b/src/content/docs/cloudflare-one/networks/routes/reserved-ips.mdx
@@ -65,7 +65,7 @@ The default IPv4 range is `100.96.0.0/12`. If this range conflicts with services
Private Load Balancer IPs are virtual addresses allocated to [Private Network Load Balancers](/load-balancing/private-network/). Each private load balancer receives a `/32` address from the `100.112.0.0/16` range by default, which serves as the load balancer's virtual IP for traffic distribution to private endpoints. Alternatively, you can configure a custom [RFC 1918](https://datatracker.ietf.org/doc/html/rfc1918) `/32` address for each load balancer.
-## WARP Split Tunnel configuration
+## Split Tunnel configuration
For deployments that use the [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/), ensure that the [reserved IP ranges](#ipv4-ranges) required by your deployment route through [WARP Split Tunnels](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/) to Cloudflare. Configuration depends on whether your [Split Tunnels mode](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/#change-split-tunnels-mode) is set to **Exclude IPs and domains** or **Include IPs and domains**.
diff --git a/src/content/docs/cloudflare-one/setup/replace-vpn/device-to-device.mdx b/src/content/docs/cloudflare-one/setup/replace-vpn/device-to-device.mdx
index 0b71ae60dc7..73f5ca34bfd 100644
--- a/src/content/docs/cloudflare-one/setup/replace-vpn/device-to-device.mdx
+++ b/src/content/docs/cloudflare-one/setup/replace-vpn/device-to-device.mdx
@@ -49,7 +49,7 @@ Enrollment permissions control which users can connect devices to your account.
You can manage device enrollment permissions later in **Team & Resources** > **Devices**.
:::
-## Step 2: Complete WARP setup
+## Step 2: Complete Cloudflare One Client setup
**Devices**.
:::
-## Step 5: Complete WARP setup
+## Step 5: Complete Cloudflare One Client setup
-
With Cloudflare Browser Isolation and resolver policies, users can connect to private web-based applications via their private hostnames.
tags:
diff --git a/src/content/docs/cloudflare-one/tutorials/m365-dedicated-egress-ips.mdx b/src/content/docs/cloudflare-one/tutorials/m365-dedicated-egress-ips.mdx
index 5870cd5c9f1..4e57b4362d0 100644
--- a/src/content/docs/cloudflare-one/tutorials/m365-dedicated-egress-ips.mdx
+++ b/src/content/docs/cloudflare-one/tutorials/m365-dedicated-egress-ips.mdx
@@ -80,4 +80,4 @@ Your policy will block access for your selected users from any location except t
1. Using [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/), sign in to your Zero Trust organization with a user's account.
2. Go to any Microsoft 365 app within your organization. Entra ID should allow access.
-3. Disconnect WARP from your Zero Trust organization. Entra ID should block access to any Microsoft 365 applications.
+3. Disconnect the Cloudflare One Client from your Zero Trust organization. Entra ID should block access to any Microsoft 365 applications.
diff --git a/src/content/docs/data-localization/compatibility.mdx b/src/content/docs/data-localization/compatibility.mdx
index 9a25bbba0b7..6c7a85f9220 100644
--- a/src/content/docs/data-localization/compatibility.mdx
+++ b/src/content/docs/data-localization/compatibility.mdx
@@ -116,7 +116,7 @@ The table below provides a summary of the Data Localization Suite product's beha
| Digital Experience | ⚫️ | ⚫️ | 🚧 [^49] |
| DLP | ⚫️ [^19] | ⚫️ [^19] | 🚧 [^31] |
| Gateway | 🚧 [^20] | 🚧 [^21] | 🚧 [^22] |
-| WARP | ⚫️ | ⚫️ | 🚧 [^1] |
+| Cloudflare One Client | ⚫️ | ⚫️ | 🚧 [^1] |
[^1]: Logs / Analytics not available outside US region when using Customer Metadata Boundary.
diff --git a/src/content/docs/learning-paths/replace-vpn/build-policies/test-your-first-application.mdx b/src/content/docs/learning-paths/replace-vpn/build-policies/test-your-first-application.mdx
index add8e4b21bf..7229025a812 100644
--- a/src/content/docs/learning-paths/replace-vpn/build-policies/test-your-first-application.mdx
+++ b/src/content/docs/learning-paths/replace-vpn/build-policies/test-your-first-application.mdx
@@ -13,11 +13,11 @@ You have now set up your [Zero Trust organization](/learning-paths/replace-vpn/g
Test if the Access or Gateway policy that you configured is working by using a device with the Cloudflare One Client installed to reach an internal application or external website.
-If you cannot reach an application protected by Access or an external application through Gateway as expected, Cloudflare recommends starting with reviewing your WARP configuration.
+If you cannot reach an application protected by Access or an external application through Gateway as expected, Cloudflare recommends starting with reviewing your Cloudflare One Client configuration.
-### 1.1. Troubleshoot WARP
+### 1.1. Troubleshoot the Cloudflare One Client
-If your manual test fails, troubleshoot the Cloudflare One Client. Cloudflare recommends starting with reviewing your WARP configuration because misconfiguration is the most common cause of connectivity issues.
+If your manual test fails, troubleshoot the Cloudflare One Client. Cloudflare recommends starting with reviewing your Cloudflare One Client configuration because misconfiguration is the most common cause of connectivity issues.
- [WARP troubleshooting guide](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/troubleshooting-guide/): Step-by-step instructions to debug Cloudflare One Client issues.
- [Cloudflare One Client errors](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/client-errors/): If you are receiving an error, review the associated solutions.
diff --git a/src/content/docs/learning-paths/secure-internet-traffic/connect-devices-networks/choose-on-ramp.mdx b/src/content/docs/learning-paths/secure-internet-traffic/connect-devices-networks/choose-on-ramp.mdx
index 6d28d26cd5f..fc2b4bd1fa4 100644
--- a/src/content/docs/learning-paths/secure-internet-traffic/connect-devices-networks/choose-on-ramp.mdx
+++ b/src/content/docs/learning-paths/secure-internet-traffic/connect-devices-networks/choose-on-ramp.mdx
@@ -29,7 +29,7 @@ Cloudflare supports filtering HTTP/S traffic sent via a PAC file on a user devic
Cloudflare Browser Isolation runs a headless, Chromium-based browser for your users to accomplish their secure browsing needs. It can be activated via an Access application, a Gateway policy, or by using link-based isolation (reverse proxy). In this model, your users can connect from any device to a proxy website to browse the Internet while applying all your Gateway HTTP policies and inspection requirements.
-| | WARP | PAC Files | Clientless Browser Isolation |
+| | Cloudflare One Client | PAC Files | Clientless Browser Isolation |
| --------------------------------- | ------------------------------------ | -------------- | ------------------------------------- |
| Supported OS | macOS, Windows, Linux, iOS, Android | All desktop OS | All OS (with HTML5 compliant browser) |
| Configurable via MDM | Yes | Yes | N/A |
diff --git a/src/content/docs/reference-architecture/diagrams/sase/sase-clientless-access-private-dns.mdx b/src/content/docs/reference-architecture/diagrams/sase/sase-clientless-access-private-dns.mdx
index 5788f720aa0..ab20f960467 100644
--- a/src/content/docs/reference-architecture/diagrams/sase/sase-clientless-access-private-dns.mdx
+++ b/src/content/docs/reference-architecture/diagrams/sase/sase-clientless-access-private-dns.mdx
@@ -38,4 +38,4 @@ Follow this [tutorial](/cloudflare-one/tutorials/clientless-access-private-dns/)
## Related resources
-- [Tutorial: Access a web application via its private hostname without WARP](/cloudflare-one/tutorials/clientless-access-private-dns/)
+- [Tutorial: Access a web application via its private hostname without the Cloudflare One Client](/cloudflare-one/tutorials/clientless-access-private-dns/)
diff --git a/src/content/partials/cloudflare-one/access/enable-scim-on-dashboard.mdx b/src/content/partials/cloudflare-one/access/enable-scim-on-dashboard.mdx
index a1d841060a5..d56bcf7b4ad 100644
--- a/src/content/partials/cloudflare-one/access/enable-scim-on-dashboard.mdx
+++ b/src/content/partials/cloudflare-one/access/enable-scim-on-dashboard.mdx
@@ -17,9 +17,9 @@ import { Markdown } from "~/components"
* **Enable user deprovisioning**: [Revoke a user's active session](/cloudflare-one/access-controls/access-settings/session-management/#per-user) when they are removed from the SCIM application in {props.idp}. This will invalidate all active Access sessions and prompt for reauthentication for any [WARP session policies](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/client-sessions/).
* **Remove user seat on deprovision**: [Remove a user's seat](/cloudflare-one/team-and-resources/users/seat-management/) from your Cloudflare One account when they are removed from the SCIM application in {props.idp}.
* **SCIM identity update behavior**: Choose what happens in Cloudflare One when the user's identity updates in {props.idp}.
- - _Automatic identity updates_: Automatically update the [User Registry identity](/cloudflare-one/team-and-resources/users/users/) when {props.idp} sends an updated identity or group membership through SCIM. This identity is used for Gateway policies and WARP [device profiles](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-profiles/); Access will read the user's updated identity when they reauthenticate.
+ - _Automatic identity updates_: Automatically update the [User Registry identity](/cloudflare-one/team-and-resources/users/users/) when {props.idp} sends an updated identity or group membership through SCIM. This identity is used for Gateway policies and Cloudflare One Client [device profiles](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-profiles/); Access will read the user's updated identity when they reauthenticate.
- _Group membership change reauthentication_: [Revoke a user's active session](/cloudflare-one/access-controls/access-settings/session-management/#per-user) when their group membership changes in {props.idp}. This will invalidate all active Access sessions and prompt for reauthentication for any [WARP session policies](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/client-sessions/). Access will read the user's updated group membership when they reauthenticate.
- - _No action_: Update the user's identity the next time they reauthenticate to Access or WARP.
+ - _No action_: Update the user's identity the next time they reauthenticate to Access or the Cloudflare One Client.
5. Select **Regenerate Secret**. Copy the **SCIM Endpoint** and **SCIM Secret**. You will need to enter these values into {props.idp}.
diff --git a/src/content/partials/cloudflare-one/aws-resolver.mdx b/src/content/partials/cloudflare-one/aws-resolver.mdx
index 77643c9f6f7..9a9d914decd 100644
--- a/src/content/partials/cloudflare-one/aws-resolver.mdx
+++ b/src/content/partials/cloudflare-one/aws-resolver.mdx
@@ -5,6 +5,6 @@
Avoid configuring your [Local Domain Fallback](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/local-domains/) or [Resolver Policy](/cloudflare-one/traffic-policies/resolver-policies/) to direct all `*.amazonaws.com` DNS resolution via AWS Route 53 Resolver.
-Some AWS endpoints (such as `ssm.us-east-1.amazonaws.com`) are public AWS endpoints that are not resolvable via internal VPC resolution. This can break AWS Console features for users on WARP.
+Some AWS endpoints (such as `ssm.us-east-1.amazonaws.com`) are public AWS endpoints that are not resolvable via internal VPC resolution. This can break AWS Console features for users on the Cloudflare One Client.
Only route specific Route 53 zones, or VPC Endpoints (such as `vpce.amazonaws.com`), through the internal VPC resolver.
\ No newline at end of file
diff --git a/src/content/partials/cloudflare-one/gateway/client-notifications-OS.mdx b/src/content/partials/cloudflare-one/gateway/client-notifications-OS.mdx
index 0e13488eb10..49ae473c61b 100644
--- a/src/content/partials/cloudflare-one/gateway/client-notifications-OS.mdx
+++ b/src/content/partials/cloudflare-one/gateway/client-notifications-OS.mdx
@@ -2,4 +2,4 @@
{}
---
-Ensure that your operating system allows notifications for WARP. Your device may not display notifications if focus, do not disturb, or screen sharing settings are turned on. To turn on client notifications on macOS devices running DisplayLink software, you may have to allow system notifications when mirroring your display. For more information, refer to the [macOS documentation](https://support.apple.com/guide/mac-help/change-notifications-settings-mh40583/mac).
+Ensure that your operating system allows notifications for the Cloudflare One Client. Your device may not display notifications if focus, do not disturb, or screen sharing settings are turned on. To turn on client notifications on macOS devices running DisplayLink software, you may have to allow system notifications when mirroring your display. For more information, refer to the [macOS documentation](https://support.apple.com/guide/mac-help/change-notifications-settings-mh40583/mac).
diff --git a/src/content/partials/cloudflare-one/gateway/egress-selector-warp-version.mdx b/src/content/partials/cloudflare-one/gateway/egress-selector-warp-version.mdx
index 6c95a9b5c96..8bb59a57775 100644
--- a/src/content/partials/cloudflare-one/gateway/egress-selector-warp-version.mdx
+++ b/src/content/partials/cloudflare-one/gateway/egress-selector-warp-version.mdx
@@ -4,7 +4,7 @@
import { Details } from "~/components"
-
+
| [Client modes](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/) |
| ----------------------------------------------------------------------------------------- |
diff --git a/src/content/partials/learning-paths/zero-trust/install-agent.mdx b/src/content/partials/learning-paths/zero-trust/install-agent.mdx
index ebf3b261e8f..50221f53efc 100644
--- a/src/content/partials/learning-paths/zero-trust/install-agent.mdx
+++ b/src/content/partials/learning-paths/zero-trust/install-agent.mdx
@@ -7,7 +7,7 @@ import { Details, Markdown, Render } from "~/components"
Most admins test by manually downloading the Cloudflare One Client and enrolling in your organization's Cloudflare Zero Trust instance.
-## Install WARP
+## Install the Cloudflare One Client
1. First, uninstall any existing third-party VPN software if possible. Sometimes products placed in a disconnected or disabled state will still interfere with the Cloudflare One Client.
2. If you are running third-party firewall or TLS decryption software, verify that it does not inspect or block traffic to the following destinations:
diff --git a/src/content/partials/learning-paths/zero-trust/split-tunnel-settings.mdx b/src/content/partials/learning-paths/zero-trust/split-tunnel-settings.mdx
index cb62ee20417..eb80c75bd1f 100644
--- a/src/content/partials/learning-paths/zero-trust/split-tunnel-settings.mdx
+++ b/src/content/partials/learning-paths/zero-trust/split-tunnel-settings.mdx
@@ -7,7 +7,7 @@ import { Render} from "~/components"
Split tunnel settings determine which traffic the Cloudflare One Client does and does not proxy.
-WARP offers two different split tunnel modes:
+The Cloudflare One Client offers two different split tunnel modes:
* If you intend to send all internal and external destination traffic through Cloudflare's global network, opt for **Exclude IPs and domains** mode. This mode will proxy everything through the WARP tunnel with the exception of IPs and hosts defined explicitly within the Split Tunnel list.
* If you intend to only use the Cloudflare One Client to proxy private destination traffic, you can operate in **Include IPs and domains** mode, in which you explicitly define which IP ranges and domains should be included in the WARP routing table.
diff --git a/src/content/partials/networking-services/cloudflare-one-connectivity-options.mdx b/src/content/partials/networking-services/cloudflare-one-connectivity-options.mdx
index bdf861237dc..89828d0d9d3 100644
--- a/src/content/partials/networking-services/cloudflare-one-connectivity-options.mdx
+++ b/src/content/partials/networking-services/cloudflare-one-connectivity-options.mdx
@@ -58,7 +58,7 @@ For detailed configuration, refer to the [Cloudflare Tunnel documentation](/clou
## Cloudflare One Client
-The Cloudflare One Client is a device agent that securely connects end-user devices to Cloudflare's global network. WARP encrypts traffic from the device using MASQUE (with post-quantum cryptography) or WireGuard and routes it through Cloudflare, where Gateway policies filter and inspect the traffic.
+The Cloudflare One Client is a device agent that securely connects end-user devices to Cloudflare's global network. The Cloudflare One Client encrypts traffic from the device using MASQUE (with post-quantum cryptography) or WireGuard and routes it through Cloudflare, where Gateway policies filter and inspect the traffic.
Use Cloudflare One Client to secure remote workforce devices, replace traditional VPN solutions, enforce DNS filtering and web security policies, implement device posture checks, and enable Peer-to-peer connectivity between enrolled devices.
@@ -344,7 +344,7 @@ When layering tunnels or using multiple encapsulation methods, account for overh
| ---- | ---- | ---- |
| GRE tunnel | 1,476 bytes | 1,436 bytes or lower |
| IPsec tunnel | 1,400-1,436 bytes (varies by encryption) | 1,360-1,396 bytes |
-| WARP behind Cloudflare WAN (double encapsulation) | ~1,300 bytes | Configure based on testing |
+| Cloudflare One Client behind Cloudflare WAN (double encapsulation) | ~1,300 bytes | Configure based on testing |
| WARP Connector to Cloudflare One Client | ~1,280 bytes | Configure based on testing. Traffic is encapsulated twice: by WARP Connector and again by Cloudflare before delivery to the Cloudflare One Client. |
Configure MSS clamping on your edge devices to ensure TCP traffic does not require fragmentation.
diff --git a/src/content/partials/networking-services/cloudflare-wan/zero-trust/gateway.mdx b/src/content/partials/networking-services/cloudflare-wan/zero-trust/gateway.mdx
index 735c5c3409a..3dbc6a789e8 100644
--- a/src/content/partials/networking-services/cloudflare-wan/zero-trust/gateway.mdx
+++ b/src/content/partials/networking-services/cloudflare-wan/zero-trust/gateway.mdx
@@ -49,7 +49,7 @@ For example, if your organization onboards devices to Cloudflare WAN using the C
| Passed Device Posture Checks | not in | iOS (OS version) | Or | Do Not Inspect |
| Passed Device Posture Checks | not in | Android (OS version) | | Do Not Inspect |
-If your organization onboards users to Cloudflare WAN using an on-ramp other than WARP, you can exempt devices from inspection using the IP addresses for your IPsec tunnels:
+If your organization onboards users to Cloudflare WAN using an on-ramp other than the Cloudflare One Client, you can exempt devices from inspection using the IP addresses for your IPsec tunnels:
| Selector | Operator | Value | Action |
| --------- | -------- | ---------------- | -------------- |
diff --git a/src/content/partials/networking-services/cloudflare-wan/zero-trust/warp.mdx b/src/content/partials/networking-services/cloudflare-wan/zero-trust/warp.mdx
index db7eaf50f1a..7edb591e2f6 100644
--- a/src/content/partials/networking-services/cloudflare-wan/zero-trust/warp.mdx
+++ b/src/content/partials/networking-services/cloudflare-wan/zero-trust/warp.mdx
@@ -15,7 +15,7 @@ params:
:::note
By default, Cloudflare WAN does not support direct Peer-to-peer connections for devices with the Cloudflare One Client enabled. Double encapsulation and asymmetric routing prevent these connections.
-When a device is behind Cloudflare WAN, avoid enabling WARP. Instead, access the device using its local LAN IP from remote systems, rather than relying on Peer-to-peer communication.
+When a device is behind Cloudflare WAN, avoid enabling the Cloudflare One Client. Instead, access the device using its local LAN IP from remote systems, rather than relying on Peer-to-peer communication.
If you do want to use the Cloudflare One Client on a device behind Cloudflare WAN and connect to its virtual IP (within the `100.96.0.0/12` range), you will need to adjust your Cloudflare One Client profiles. Specifically, exclude the `100.96.0.0/12` subnet from the on-premises Cloudflare One Client profiles, and include it in the off-premises profile.
:::
@@ -34,7 +34,7 @@ When connecting a device to Cloudflare WAN, you will have virtual IP addresses f
---
-## Set up WARP with Cloudflare WAN
+## Set up the Cloudflare One Client with Cloudflare WAN
### 1. Route packets back to the Cloudflare One Client devices
@@ -95,7 +95,7 @@ To learn which IP addresses and UDP ports you should exclude to accomplish this,
}}
/>
-## Test WARP integration
+## Test Cloudflare One Client integration
Before testing, configure domain fallback for the server or service in the Cloudflare One Client settings. This is needed because by default Cloudflare Zero Trust excludes common top level domains used for local resolution from being sent to Gateway for processing.
diff --git a/src/content/partials/networking-services/mconn/network-options/app-aware-policies/warp-traffic.mdx b/src/content/partials/networking-services/mconn/network-options/app-aware-policies/warp-traffic.mdx
index 7a321925334..92d9cdc9f2f 100644
--- a/src/content/partials/networking-services/mconn/network-options/app-aware-policies/warp-traffic.mdx
+++ b/src/content/partials/networking-services/mconn/network-options/app-aware-policies/warp-traffic.mdx
@@ -10,4 +10,4 @@ You may need to configure your firewall to allow this new traffic. Make sure to
- **Destination IPs**: `162.159.193.0/24`, `162.159.197.0/24`
- **Destination ports**: `443`, `500`, `1701`, `2408`, `4443`, `4500`, `8095`, `8443`
-Refer to WARP with firewall for more information on this topic.
+Refer to Cloudflare One Client with firewall for more information on this topic.
diff --git a/src/content/partials/networking-services/mnm/tutorials/encrypt-network-flow-data.mdx b/src/content/partials/networking-services/mnm/tutorials/encrypt-network-flow-data.mdx
index 131b3b6e040..6601c1923c1 100644
--- a/src/content/partials/networking-services/mnm/tutorials/encrypt-network-flow-data.mdx
+++ b/src/content/partials/networking-services/mnm/tutorials/encrypt-network-flow-data.mdx
@@ -50,7 +50,7 @@ If you installed a Cloudflare One Client on your router or machine collector (so
If you have access to the router but installed the Cloudflare One Client on another machine, you can configure the router to export flow traffic to the machine running the Cloudflare One Client. To do this:
1. Set the machine's IP address as the export destination on the router.
-2. Configure the export port on the router to match the listening port on the WARP machine.
+2. Configure the export port on the router to match the listening port on the Cloudflare One Client machine.
3. Redirect traffic that arrives at your machine running the Cloudflare One Client to the following Cloudflare's destination IPs and ports:
- **For NetFlow**: IP address `162.159.65.1` and port `2055`.
- **For sFlow**: IP `162.159.65.1` and port `6343`.
diff --git a/src/content/partials/networking-services/reference/traffic-steering.mdx b/src/content/partials/networking-services/reference/traffic-steering.mdx
index 5192afd6063..0f00b30950a 100644
--- a/src/content/partials/networking-services/reference/traffic-steering.mdx
+++ b/src/content/partials/networking-services/reference/traffic-steering.mdx
@@ -214,7 +214,7 @@ In this initial release, ARR does not change routing for traffic between Cloudfl
## Unified Routing mode (beta)
-The Unified Routing mode is the newer Cloudflare One data plane that uses a single routing fabric for all supported connection types. Unified Routing mode routes traffic across WARP, Cloudflare Tunnel, IPsec, GRE, and Cloudflare Network Interconnect (CNI) in a single system, making it easier to set up your Cloudflare One connections.
+The Unified Routing mode is the newer Cloudflare One data plane that uses a single routing fabric for all supported connection types. Unified Routing mode routes traffic across the Cloudflare One Client, Cloudflare Tunnel, IPsec, GRE, and Cloudflare Network Interconnect (CNI) in a single system, making it easier to set up your Cloudflare One connections.
In the {props.productName} dashboard, routing mode appears where you manage routes:
From a898c9255a5648e874a4108509982c7b6b604b03 Mon Sep 17 00:00:00 2001
From: Ranbel Sun
Date: Mon, 16 Mar 2026 13:42:27 -0400
Subject: [PATCH 03/15] [ZT] Fix broken anchor links from WARP heading renames
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Updates 27 anchor references across 20 files to match new heading slugs
after WARP → Cloudflare One Client heading renames. Includes:
- #3-route-private-network-ips-through-warp (6 refs)
- #warp-client → #cloudflare-one-client (3 refs)
- #warp-client-block-notifications (3 refs)
- #warp-device-ips → #device-ips (3 refs)
- #enable-warp-to-warp → #enable-peer-to-peer (2 refs)
- #warp-split-tunnel-configuration (2 refs)
- 8 other individual anchor fixes
---
.../private-net/cloudflared/private-dns.mdx | 2 +-
.../networks/connectors/cloudflare-tunnel/use-cases/smb.mdx | 2 +-
.../cloudflare-tunnel/use-cases/ssh/ssh-warp-to-tunnel.mdx | 2 +-
.../docs/cloudflare-one/networks/routes/add-routes.mdx | 2 +-
.../docs/cloudflare-one/networks/routes/reserved-ips.mdx | 6 +++---
.../cloudflare-one-client/configure/settings/index.mdx | 4 ++--
.../devices/user-side-certificates/manual-deployment.mdx | 2 +-
.../traffic-policies/egress-policies/egress-cloudflared.mdx | 2 +-
.../traffic-policies/http-policies/antivirus-scanning.mdx | 2 +-
.../cloudflare-one/tutorials/ai-wrapper-tenant-control.mdx | 2 +-
src/content/docs/data-localization/how-to/zero-trust.mdx | 2 +-
.../replace-vpn/build-policies/block-page.mdx | 4 ++--
.../configure-device-agent/enable-proxy.mdx | 2 +-
.../docs/load-balancing/private-network/warp-to-tunnel.mdx | 2 +-
...deploying-self-hosted-VoIP-services-for-hybrid-users.mdx | 4 ++--
.../gateway/egress-selector-split-tunnels.mdx | 2 +-
.../partials/cloudflare-one/tunnel/cgnat-split-tunnels.mdx | 2 +-
.../partials/cloudflare-one/tunnel/enable-gateway-proxy.mdx | 2 +-
.../cloudflare-one/tunnel/troubleshoot-private-networks.mdx | 2 +-
.../cloudflare-one-connectivity-options.mdx | 6 +++---
20 files changed, 27 insertions(+), 27 deletions(-)
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/private-dns.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/private-dns.mdx
index 33c8a14e0d1..cbd9d4c3f8d 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/private-dns.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/private-dns.mdx
@@ -21,7 +21,7 @@ To resolve private DNS queries:
:::note
- Ensure that **Split Tunnels** are configured to [include traffic to private IPs and hostnames](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/connect-cidr/#3-route-private-network-ips-through-warp).
+ Ensure that **Split Tunnels** are configured to [include traffic to private IPs and hostnames](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/connect-cidr/#3-route-private-network-ips-through-the-cloudflare-one-client).
:::
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/smb.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/smb.mdx
index 7d55fc13912..f9ae08677e2 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/smb.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/smb.mdx
@@ -11,7 +11,7 @@ The Server Message Block (SMB) protocol allows users to read, write, and access
Cloudflare Zero Trust offers two solutions for connecting to SMB servers:
-- [Private subnet routing with the Cloudflare One Client to Tunnel](#connect-to-smb-server-with-warp-to-tunnel)
+- [Private subnet routing with the Cloudflare One Client to Tunnel](#connect-to-smb-server-with-the-cloudflare-one-client-to-tunnel)
- [Public hostname routing with `cloudflared access`](#connect-to-smb-server-with-cloudflared-access)
## Set up an SMB server on Linux
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-warp-to-tunnel.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-warp-to-tunnel.mdx
index e57224de9a9..7bfb1e2c45c 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-warp-to-tunnel.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-warp-to-tunnel.mdx
@@ -111,7 +111,7 @@ When Gateway receives a request for your private hostname, it must resolve the h
#### Scenario A: Use the system resolver (Default)
-By default, `cloudflared` uses the private DNS resolver configured on its host machine (for example, in `/etc/resolv.conf` on Linux). If the machine running `cloudflared` can already resolve `ssh.internal.local` to its private IP using the local system resolver, no further configuration is required. You can skip to [Step 3.3](#33-configure-warp-clients).
+By default, `cloudflared` uses the private DNS resolver configured on its host machine (for example, in `/etc/resolv.conf` on Linux). If the machine running `cloudflared` can already resolve `ssh.internal.local` to its private IP using the local system resolver, no further configuration is required. You can skip to [Step 3.3](#33-configure-cloudflare-one-clients).
To check if `cloudflared` can successfully resolve `ssh.internal.local`, run the following command from the `cloudflared` host:
diff --git a/src/content/docs/cloudflare-one/networks/routes/add-routes.mdx b/src/content/docs/cloudflare-one/networks/routes/add-routes.mdx
index 236fec32980..ed85d8ffb71 100644
--- a/src/content/docs/cloudflare-one/networks/routes/add-routes.mdx
+++ b/src/content/docs/cloudflare-one/networks/routes/add-routes.mdx
@@ -50,7 +50,7 @@ To add a hostname route:
4. For **Tunnel**, select the Cloudflare Tunnel that is being used to connect your private network to Cloudflare.
5. Select **Create**.
-Cloudflare will now route requests to your private network. However, the route does not automatically capture traffic from end users. To enable client-side connectivity, refer to the [private hostname](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/connect-private-hostname/) or [public hostname](/cloudflare-one/traffic-policies/egress-policies/egress-cloudflared/#3-route-network-traffic-through-warp) setup guides.
+Cloudflare will now route requests to your private network. However, the route does not automatically capture traffic from end users. To enable client-side connectivity, refer to the [private hostname](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/connect-private-hostname/) or [public hostname](/cloudflare-one/traffic-policies/egress-policies/egress-cloudflared/#3-route-network-traffic-through-the-cloudflare-one-client) setup guides.
## Add a published application route
diff --git a/src/content/docs/cloudflare-one/networks/routes/reserved-ips.mdx b/src/content/docs/cloudflare-one/networks/routes/reserved-ips.mdx
index 2dffccad776..e5c211138cd 100644
--- a/src/content/docs/cloudflare-one/networks/routes/reserved-ips.mdx
+++ b/src/content/docs/cloudflare-one/networks/routes/reserved-ips.mdx
@@ -17,14 +17,14 @@ When planning your private network addressing and configuring [Split Tunnel](/cl
| ------------------------------------------------------------- | ---------------- | ------------ |
| [Cloudflare source IPs](#cloudflare-source-ips) | `100.64.0.0/12` | Yes |
| [Gateway initial resolved IPs](#gateway-initial-resolved-ips) | `100.80.0.0/16` | No |
-| [device IPs](#warp-device-ips) | `100.96.0.0/12` | Yes |
+| [device IPs](#device-ips) | `100.96.0.0/12` | Yes |
| [Private Load Balancer IPs](#private-load-balancer-ips) | `100.112.0.0/16` | Yes |
## IPv6 ranges
| Name | Default CIDR | Configurable |
| ------------------------------------------------------------- | -------------------------- | ------------ |
-| [device IPs](#warp-device-ips) | `2606:4700:0cf1:1000::/64` | No |
+| [device IPs](#device-ips) | `2606:4700:0cf1:1000::/64` | No |
| [Gateway initial resolved IPs](#gateway-initial-resolved-ips) | `2606:4700:0cf1:4000::/64` | No |
| [Cloudflare source IPs](#cloudflare-source-ips) | `2606:4700:0cf1:5000::/64` | No |
@@ -75,7 +75,7 @@ In **Exclude IPs and domains** mode, the CGNAT range (`100.64.0.0/10`) is exclud
Cloudflare recommends adding back the IPs that are not explicitly used for Cloudflare One services. This reduces the risk of conflicts with existing private network configurations that may use CGNAT address space.
-You can use the calculator below to determine which IP ranges to add back based on the Cloudflare One features you use. For example, if your deployment requires [Gateway initial resolved IPs](#gateway-initial-resolved-ips) (`100.80.0.0/16`) and [device IPs](#warp-device-ips) (`100.96.0.0/12`), delete `100.64.0.0/10` from Split Tunnels and add back `100.64.0.0/12`, `100.81.0.0/16`, `100.82.0.0/15`, `100.84.0.0/14`, `100.88.0.0/13`, and `100.112.0.0/12`.
+You can use the calculator below to determine which IP ranges to add back based on the Cloudflare One features you use. For example, if your deployment requires [Gateway initial resolved IPs](#gateway-initial-resolved-ips) (`100.80.0.0/16`) and [device IPs](#device-ips) (`100.96.0.0/12`), delete `100.64.0.0/10` from Split Tunnels and add back `100.64.0.0/12`, `100.81.0.0/16`, `100.82.0.0/15`, `100.84.0.0/14`, `100.88.0.0/13`, and `100.112.0.0/12`.
.pem`.
+Alternatively, you can download and install a certificate [using the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/user-side-certificates/automated-deployment/#install-a-certificate-using-the-cloudflare-one-client). the Cloudflare One Client will add the certificates to the device's system certificate store in `installed_certs/.pem`.
## 2. Verify the downloaded certificate
diff --git a/src/content/docs/cloudflare-one/traffic-policies/egress-policies/egress-cloudflared.mdx b/src/content/docs/cloudflare-one/traffic-policies/egress-policies/egress-cloudflared.mdx
index f4d19d907a1..e98c275633b 100644
--- a/src/content/docs/cloudflare-one/traffic-policies/egress-policies/egress-cloudflared.mdx
+++ b/src/content/docs/cloudflare-one/traffic-policies/egress-policies/egress-cloudflared.mdx
@@ -88,7 +88,7 @@ To route initial resolved IPs through the Cloudflare One Client:
### Private network IPs
-Your private network's CIDR block should also route through the WARP tunnel. For a detailed configuration example, refer to [Connect a private network](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/connect-cidr/#3-route-private-network-ips-through-warp).
+Your private network's CIDR block should also route through the WARP tunnel. For a detailed configuration example, refer to [Connect a private network](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/connect-cidr/#3-route-private-network-ips-through-the-cloudflare-one-client).
## 4. (Optional) Configure network policies
diff --git a/src/content/docs/cloudflare-one/traffic-policies/http-policies/antivirus-scanning.mdx b/src/content/docs/cloudflare-one/traffic-policies/http-policies/antivirus-scanning.mdx
index 6ed47f8b1ba..61e5a435e84 100644
--- a/src/content/docs/cloudflare-one/traffic-policies/http-policies/antivirus-scanning.mdx
+++ b/src/content/docs/cloudflare-one/traffic-policies/http-policies/antivirus-scanning.mdx
@@ -18,7 +18,7 @@ To turn on AV scanning:
1. In [Cloudflare One](https://one.dash.cloudflare.com), go to **Traffic policies** > **Traffic settings**.
2. In **Policy settings**, turn on **Scan files for malware**.
3. Choose whether to scan files for malicious payloads during uploads, downloads, or both. You can also block requests containing [non-scannable files](#non-scannable-files).
-4. (Optional) Turn on **Display AV block notification for WARP Client** to send [block notifications](#warp-client-block-notifications) to users connected to Gateway with the WARP Client when AV inspection blocks a file.
+4. (Optional) Turn on **Display AV block notification for WARP Client** to send [block notifications](#cloudflare-one-client-block-notifications) to users connected to Gateway with the WARP Client when AV inspection blocks a file.
When a request is blocked due to the presence of malware, Gateway will log the match as a Block decision in your [HTTP logs](/cloudflare-one/insights/logs/gateway-logs/#http-logs).
diff --git a/src/content/docs/cloudflare-one/tutorials/ai-wrapper-tenant-control.mdx b/src/content/docs/cloudflare-one/tutorials/ai-wrapper-tenant-control.mdx
index 18c45a51ff0..180c7873116 100644
--- a/src/content/docs/cloudflare-one/tutorials/ai-wrapper-tenant-control.mdx
+++ b/src/content/docs/cloudflare-one/tutorials/ai-wrapper-tenant-control.mdx
@@ -433,7 +433,7 @@ You can now block access to all unauthorized public AI agents with a Gateway [HT
This ensures that public AI agents are not accessible using a managed endpoint.
-Alternatively, you can prevent users from using public AI agents by displaying a [custom block message](/cloudflare-one/reusable-components/custom-pages/gateway-block-page/#customize-the-block-page), [redirect](/cloudflare-one/reusable-components/custom-pages/gateway-block-page/#redirect-to-a-block-page), or a [user notification](/cloudflare-one/traffic-policies/http-policies/#warp-client-block-notifications) directing users to the AI agent wrapper.
+Alternatively, you can prevent users from using public AI agents by displaying a [custom block message](/cloudflare-one/reusable-components/custom-pages/gateway-block-page/#customize-the-block-page), [redirect](/cloudflare-one/reusable-components/custom-pages/gateway-block-page/#redirect-to-a-block-page), or a [user notification](/cloudflare-one/traffic-policies/http-policies/#cloudflare-one-client-block-notifications) directing users to the AI agent wrapper.
## 6. Enforce Data Loss Prevention and Clientless Browser Isolation
diff --git a/src/content/docs/data-localization/how-to/zero-trust.mdx b/src/content/docs/data-localization/how-to/zero-trust.mdx
index fb21c16c74e..3a2eac11875 100644
--- a/src/content/docs/data-localization/how-to/zero-trust.mdx
+++ b/src/content/docs/data-localization/how-to/zero-trust.mdx
@@ -39,7 +39,7 @@ You are able to [configure SSH proxy and command logs](/cloudflare-one/traffic-p
Regional Services controls where Cloudflare decrypts traffic; because most DNS traffic is not encrypted, Gateway DNS cannot be regionalized using Regional Services.
-Refer to the [Cloudflare One Client settings](/data-localization/how-to/zero-trust/#warp-settings) section below for more information.
+Refer to the [Cloudflare One Client settings](/data-localization/how-to/zero-trust/#cloudflare-one-client-settings) section below for more information.
### Custom certificates
diff --git a/src/content/docs/learning-paths/replace-vpn/build-policies/block-page.mdx b/src/content/docs/learning-paths/replace-vpn/build-policies/block-page.mdx
index a8faa2516d7..b6af9150758 100644
--- a/src/content/docs/learning-paths/replace-vpn/build-policies/block-page.mdx
+++ b/src/content/docs/learning-paths/replace-vpn/build-policies/block-page.mdx
@@ -12,7 +12,7 @@ With Cloudflare Zero Trust, you can deliver actionable feedback to users when th
There are two different ways to surface block messages:
- [Custom block page](#custom-block-page)
-- [Cloudflare One Client block notifications](#warp-client-block-notifications)
+- [Cloudflare One Client block notifications](#cloudflare-one-client-block-notifications)
## Custom block page
@@ -24,7 +24,7 @@ The custom block page has a few drawbacks:
- The block page does not appear when users are blocked by a Gateway network policy.
- The custom block page only displays when the user loads a site in a browser. If, for instance, the user is allowed to visit a site but not allowed to upload a file, the file upload would fail silently and the user would not get a block page.
-To work around these limitations, we recommend using [Cloudflare One Client block notifications](#warp-client-block-notifications).
+To work around these limitations, we recommend using [Cloudflare One Client block notifications](#cloudflare-one-client-block-notifications).
:::note
diff --git a/src/content/docs/learning-paths/secure-internet-traffic/configure-device-agent/enable-proxy.mdx b/src/content/docs/learning-paths/secure-internet-traffic/configure-device-agent/enable-proxy.mdx
index b274e4098f7..82b8cdb0574 100644
--- a/src/content/docs/learning-paths/secure-internet-traffic/configure-device-agent/enable-proxy.mdx
+++ b/src/content/docs/learning-paths/secure-internet-traffic/configure-device-agent/enable-proxy.mdx
@@ -16,4 +16,4 @@ import { Render } from "~/components";
3. (Recommended) To proxy all port `443` traffic, including internal DNS queries, select **UDP**.
4. (Optional) To scan file uploads and downloads for malware, [enable anti-virus scanning](/cloudflare-one/traffic-policies/http-policies/antivirus-scanning/).
-Cloudflare will now proxy traffic from enrolled devices, except for the traffic excluded in your [split tunnel settings](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/#3-route-private-network-ips-through-warp). For more information on how Gateway forwards traffic, refer to [Gateway proxy](/cloudflare-one/traffic-policies/proxy/).
+Cloudflare will now proxy traffic from enrolled devices, except for the traffic excluded in your [split tunnel settings](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/#3-route-private-network-ips-through-the-cloudflare-one-client). For more information on how Gateway forwards traffic, refer to [Gateway proxy](/cloudflare-one/traffic-policies/proxy/).
diff --git a/src/content/docs/load-balancing/private-network/warp-to-tunnel.mdx b/src/content/docs/load-balancing/private-network/warp-to-tunnel.mdx
index 2c8aa9b3859..ae550147abf 100644
--- a/src/content/docs/load-balancing/private-network/warp-to-tunnel.mdx
+++ b/src/content/docs/load-balancing/private-network/warp-to-tunnel.mdx
@@ -132,7 +132,7 @@ In order for Cloudflare One Clients to connect to your load balancer, the load b
2. Find the [device profile](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-profiles/) you would like to modify and select **Edit**.
3. Under **Split Tunnels**, check whether your [Split Tunnels mode](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/#change-split-tunnels-mode) is set to **Exclude** or **Include**.
4. Select **Manage**. Depending on the mode:
- - **Exclude mode**: Delete the IP range that contains your load balancer IP. For example, if your load balancer has a Cloudflare-assigned CGNAT IP, delete `100.64.0.0/10`. We recommend [adding back the IPs](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/connect-cidr/#3-route-private-network-ips-through-warp) that are not being used by your load balancer.
+ - **Exclude mode**: Delete the IP range that contains your load balancer IP. For example, if your load balancer has a Cloudflare-assigned CGNAT IP, delete `100.64.0.0/10`. We recommend [adding back the IPs](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/connect-cidr/#3-route-private-network-ips-through-the-cloudflare-one-client) that are not being used by your load balancer.
:::note
Some IPs in the `100.64.0.0/10` range may be reserved for other Zero Trust services such as Gateway initial resolved IPs or WARP CGNAT IPs. These IPs should remain deleted from the Exclude list.
:::
diff --git a/src/content/docs/reference-architecture/diagrams/sase/deploying-self-hosted-VoIP-services-for-hybrid-users.mdx b/src/content/docs/reference-architecture/diagrams/sase/deploying-self-hosted-VoIP-services-for-hybrid-users.mdx
index dc9bfcd2a28..5581dc65e30 100644
--- a/src/content/docs/reference-architecture/diagrams/sase/deploying-self-hosted-VoIP-services-for-hybrid-users.mdx
+++ b/src/content/docs/reference-architecture/diagrams/sase/deploying-self-hosted-VoIP-services-for-hybrid-users.mdx
@@ -50,7 +50,7 @@ The above diagram shows the high level signaling and media paths.
4. The default gateway for the SIP server is `10.50.0.1`, but we have defined a static route such that for destination `100.96.0.0/12`, the next hop is the WARP Connector interface (`10.0.50.10`).
5. The SIP INVITE message will be routed across the WARP Connector to the Cloudflare network and then received by Bob.
6. Bob accepts and the SIP server will send SIP/SDP messages to both Alice and Bob specifying which parameters to use for the RTP (audio) data.
-7. For Direct Media paths where the SIP server is not in the audio path and the RTP streams are directly between Alice and Bob, ensure that [**Allow all Cloudflare One traffic to reach enrolled devices**](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp/#enable-warp-to-warp) has been enabled in Cloudflare. Audio streams in the Direct Media use case will not need to route over the WARP Connector.
+7. For Direct Media paths where the SIP server is not in the audio path and the RTP streams are directly between Alice and Bob, ensure that [**Allow all Cloudflare One traffic to reach enrolled devices**](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp/#enable-peer-to-peer) has been enabled in Cloudflare. Audio streams in the Direct Media use case will not need to route over the WARP Connector.
### Remote user to on-premise user
@@ -83,5 +83,5 @@ With Cloudflare's WARP Connector, remote users communicating with other remote u
## Related resources
- [Set up WARP Connector](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/)
-- [Enable Peer-to-peer connectivity](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp/#enable-warp-to-warp)
+- [Enable Peer-to-peer connectivity](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp/#enable-peer-to-peer)
- [About the Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/)
diff --git a/src/content/partials/cloudflare-one/gateway/egress-selector-split-tunnels.mdx b/src/content/partials/cloudflare-one/gateway/egress-selector-split-tunnels.mdx
index 1acfdc8dd04..a639506c0b6 100644
--- a/src/content/partials/cloudflare-one/gateway/egress-selector-split-tunnels.mdx
+++ b/src/content/partials/cloudflare-one/gateway/egress-selector-split-tunnels.mdx
@@ -6,6 +6,6 @@ import { Render, GlossaryTooltip } from "~/components"
In your WARP [device profile](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-profiles/), configure [Split Tunnels](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/) such that the initial resolved IPs route through the WARP tunnel. Configuration depends on your [Split Tunnels mode](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/#change-split-tunnels-mode):
-- **Exclude mode**: Delete `100.64.0.0/10` from your Split Tunnels list. We recommend [adding back the IP ranges](/cloudflare-one/networks/routes/reserved-ips/#warp-split-tunnel-configuration) that are not explicitly used for Cloudflare One services. This reduces the risk of conflicts with existing private network configurations that may use the CGNAT address space.
+- **Exclude mode**: Delete `100.64.0.0/10` from your Split Tunnels list. We recommend [adding back the IP ranges](/cloudflare-one/networks/routes/reserved-ips/#split-tunnel-configuration) that are not explicitly used for Cloudflare One services. This reduces the risk of conflicts with existing private network configurations that may use the CGNAT address space.
- **Include mode**: Add Split Tunnel entries for the following IP addresses:
diff --git a/src/content/partials/cloudflare-one/tunnel/cgnat-split-tunnels.mdx b/src/content/partials/cloudflare-one/tunnel/cgnat-split-tunnels.mdx
index 0160f4c0a93..32bad08d6a1 100644
--- a/src/content/partials/cloudflare-one/tunnel/cgnat-split-tunnels.mdx
+++ b/src/content/partials/cloudflare-one/tunnel/cgnat-split-tunnels.mdx
@@ -4,5 +4,5 @@
In your device profile, configure [Split Tunnels](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/) so that traffic to your [device IPs](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-ips/) goes through the WARP tunnel. Configuration depends on your [Split Tunnels mode](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/#change-split-tunnels-mode). For example, if your devices use the default `100.96.0.0/12` range:
-- **Exclude mode**: Delete `100.64.0.0/10` from your Split Tunnels list. We recommend [adding back the IP ranges](/cloudflare-one/networks/routes/reserved-ips/#warp-split-tunnel-configuration) that are not explicitly used for Cloudflare One services. This reduces the risk of conflicts with existing private network configurations that may use the CGNAT address space.
+- **Exclude mode**: Delete `100.64.0.0/10` from your Split Tunnels list. We recommend [adding back the IP ranges](/cloudflare-one/networks/routes/reserved-ips/#split-tunnel-configuration) that are not explicitly used for Cloudflare One services. This reduces the risk of conflicts with existing private network configurations that may use the CGNAT address space.
- **Include mode**: Add `100.96.0.0/12` to your Split Tunnels list.
diff --git a/src/content/partials/cloudflare-one/tunnel/enable-gateway-proxy.mdx b/src/content/partials/cloudflare-one/tunnel/enable-gateway-proxy.mdx
index 786d4189a03..49f44d321db 100644
--- a/src/content/partials/cloudflare-one/tunnel/enable-gateway-proxy.mdx
+++ b/src/content/partials/cloudflare-one/tunnel/enable-gateway-proxy.mdx
@@ -33,4 +33,4 @@ To start logging and filtering network traffic, turn on the Gateway proxy:
-Cloudflare will now proxy traffic from enrolled devices, except for the traffic excluded in your [split tunnel settings](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/#3-route-private-network-ips-through-warp). For more information on how Gateway forwards traffic, refer to [Gateway proxy](/cloudflare-one/traffic-policies/proxy/).
+Cloudflare will now proxy traffic from enrolled devices, except for the traffic excluded in your [split tunnel settings](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/#3-route-private-network-ips-through-the-cloudflare-one-client). For more information on how Gateway forwards traffic, refer to [Gateway proxy](/cloudflare-one/traffic-policies/proxy/).
diff --git a/src/content/partials/cloudflare-one/tunnel/troubleshoot-private-networks.mdx b/src/content/partials/cloudflare-one/tunnel/troubleshoot-private-networks.mdx
index 44fbec6ba49..00b12c71c0e 100644
--- a/src/content/partials/cloudflare-one/tunnel/troubleshoot-private-networks.mdx
+++ b/src/content/partials/cloudflare-one/tunnel/troubleshoot-private-networks.mdx
@@ -32,7 +32,7 @@ If there are no relevant Gateway logs, it means that WARP was unable to forward
Next, check if your Gateway Network logs (**Insights** > **Logs** > **Network logs**) show any traffic to the destination IP.
-If the Cloudflare One Client is connected but there are no network logs, it means that your private network IPs are not routing through the Cloudflare One Client. You can confirm this by [searching the routing table](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/client-architecture/#routing-table) on the device for the IP address of your application. Traffic to your application should route through the Cloudflare One Client interface. If another interface is used, [check your Split Tunnel configuration](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/#3-route-private-network-ips-through-warp).
+If the Cloudflare One Client is connected but there are no network logs, it means that your private network IPs are not routing through the Cloudflare One Client. You can confirm this by [searching the routing table](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/client-architecture/#routing-table) on the device for the IP address of your application. Traffic to your application should route through the Cloudflare One Client interface. If another interface is used, [check your Split Tunnel configuration](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/#3-route-private-network-ips-through-the-cloudflare-one-client).
## 4. Is the user blocked by a Gateway policy?
diff --git a/src/content/partials/networking-services/cloudflare-one-connectivity-options.mdx b/src/content/partials/networking-services/cloudflare-one-connectivity-options.mdx
index 89828d0d9d3..0126b68fe30 100644
--- a/src/content/partials/networking-services/cloudflare-one-connectivity-options.mdx
+++ b/src/content/partials/networking-services/cloudflare-one-connectivity-options.mdx
@@ -27,7 +27,7 @@ The following table provides a high-level comparison of all connectivity options
| Connectivity option | Protocol | Direction | Typical deployment model | Use when |
| ---- | ---- | ---- | ---- | ---- |
| [Cloudflare Tunnel](#cloudflare-tunnel) | HTTP/2, QUIC | Off-ramp only | Software daemon (`cloudflared`) on server | Exposing private applications without a public IP |
-| [Cloudflare One Client](#warp-client) | MASQUE (default), WireGuard | Bidirectional | Client software on end-user devices | Securing remote workforce devices |
+| [Cloudflare One Client](#cloudflare-one-client) | MASQUE (default), WireGuard | Bidirectional | Client software on end-user devices | Securing remote workforce devices |
| [WARP Connector](#warp-connector) | MASQUE, WireGuard | Bidirectional | Software client on Linux host | Connecting sites with IoT or VoIP devices |
| [DNS locations](#dns-locations) | DNS (DoH, DoT, IPv4/IPv6) | On-ramp only | DNS resolver configuration | Filtering DNS traffic without device agents |
| [Proxy endpoints](#proxy-endpoints) | HTTP/HTTPS | On-ramp only | Browser PAC file configuration | Filtering web traffic without device agents |
@@ -272,7 +272,7 @@ Use the following guidance to select the appropriate connectivity option for you
| Requirement | Recommended option |
| ---- | ---- |
| Expose a private web application without a public IP | [Cloudflare Tunnel](#cloudflare-tunnel) |
-| Secure end-user devices | [Cloudflare One Client](#warp-client) |
+| Secure end-user devices | [Cloudflare One Client](#cloudflare-one-client) |
| Replace traditional VPN for remote access | [Cloudflare Tunnel](#cloudflare-tunnel) (primary) + [WARP Connector](#warp-connector) (for bidirectional needs) |
| Connect a site with IoT devices or VoIP systems | [WARP Connector](#warp-connector) |
| Connect a branch office using existing routers | [GRE](#gre-tunnels) or [IPsec tunnels](#ipsec-tunnels) |
@@ -288,7 +288,7 @@ The team driving your connectivity project influences which option provides the
| Primary team | Recommended starting point | Rationale |
| ---- | ---- | ---- |
-| Security / InfoSec | [Cloudflare Tunnel](#cloudflare-tunnel) + [Cloudflare One Client](#warp-client) | Minimal network infrastructure changes required. Security controls are managed within the Cloudflare One dashboard. |
+| Security / InfoSec | [Cloudflare Tunnel](#cloudflare-tunnel) + [Cloudflare One Client](#cloudflare-one-client) | Minimal network infrastructure changes required. Security controls are managed within the Cloudflare One dashboard. |
| Network Operations | [Cloudflare WAN](#ipsec-tunnels) (IPsec/GRE) or [Cloudflare One Appliance](#cloudflare-one-appliance) | Familiar routing and tunnel configuration. Integrates with existing network equipment and workflows. |
| DevOps / Platform Engineering | [WARP Connector](#warp-connector) or [Cloudflare Tunnel](#cloudflare-tunnel) | Software-defined deployment. Scriptable via API. No hardware dependencies. |
| Facilities / Branch IT | [Cloudflare One Appliance](#cloudflare-one-appliance) | Zero-touch deployment with centralized management. No on-site networking expertise required. |
From 58d93f4122c188632860ea896a594f87bb31a461 Mon Sep 17 00:00:00 2001
From: Ranbel Sun
Date: Mon, 16 Mar 2026 13:44:51 -0400
Subject: [PATCH 04/15] =?UTF-8?q?[ZT]=20Fix=20grammar:=20'the=20Cloudflare?=
=?UTF-8?q?=20One=20Client=20devices'=20=E2=86=92=20'Cloudflare=20One=20Cl?=
=?UTF-8?q?ient=20devices'?=
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Remove unnecessary article 'the' before plural noun phrase in 6
instances across 5 files.
---
.../connectors/cloudflare-tunnel/private-net/warp-to-warp.mdx | 2 +-
.../docs/cloudflare-one/networks/routes/reserved-ips.mdx | 2 +-
src/content/docs/cloudflare-one/traffic-policies/proxy.mdx | 2 +-
.../cloudflare-one-connectivity-options.mdx | 2 +-
.../networking-services/cloudflare-wan/zero-trust/warp.mdx | 4 ++--
5 files changed, 6 insertions(+), 6 deletions(-)
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp.mdx
index 838ec1cbbac..1496715cd32 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp.mdx
@@ -21,7 +21,7 @@ This guide covers how to:
- Enable Peer-to-peer connectivity to establish a private network between your devices.
- Manage Split Tunnel preferences for the Cloudflare One Client to determine what traffic should be routed to the Cloudflare global network.
- Create Zero Trust security policies to restrict access.
-- Connect to virtual IP spaces from the Cloudflare One Client devices without any client-side configuration changes.
+- Connect to virtual IP spaces from Cloudflare One Client devices without any client-side configuration changes.
## Prerequisites
diff --git a/src/content/docs/cloudflare-one/networks/routes/reserved-ips.mdx b/src/content/docs/cloudflare-one/networks/routes/reserved-ips.mdx
index e5c211138cd..bf2b2e08acf 100644
--- a/src/content/docs/cloudflare-one/networks/routes/reserved-ips.mdx
+++ b/src/content/docs/cloudflare-one/networks/routes/reserved-ips.mdx
@@ -57,7 +57,7 @@ device IPs are virtual addresses assigned to each device registration. These IPs
- [Peer-to-peer connectivity (Peer-to-peer)](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp/) — allows devices to communicate directly with each other over Cloudflare's network.
- [WARP Connector](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/) — routes traffic between your private network and WARP devices.
-- [Cloudflare WAN](/cloudflare-one/networks/connectors/cloudflare-wan/) — on-ramps traffic from WAN tunnels to the Cloudflare One Client devices.
+- [Cloudflare WAN](/cloudflare-one/networks/connectors/cloudflare-wan/) — on-ramps traffic from WAN tunnels to Cloudflare One Client devices.
The default IPv4 range is `100.96.0.0/12`. If this range conflicts with services on your private network, you can configure custom IPv4 subnets drawn from RFC 1918 or CGNAT address space. For configuration instructions, refer to [Device IPs](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-ips/).
diff --git a/src/content/docs/cloudflare-one/traffic-policies/proxy.mdx b/src/content/docs/cloudflare-one/traffic-policies/proxy.mdx
index a6af84cad96..405cbcdec12 100644
--- a/src/content/docs/cloudflare-one/traffic-policies/proxy.mdx
+++ b/src/content/docs/cloudflare-one/traffic-policies/proxy.mdx
@@ -113,7 +113,7 @@ By default the [`cloudflared` Docker container](https://github.com/cloudflare/cl
## Turn on the Gateway proxy
-The Gateway proxy toggle only applies to traffic from the Cloudflare One Client devices. Gateway will always proxy traffic sent with [PAC files](/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/) or [Browser Isolation](/cloudflare-one/remote-browser-isolation/) regardless of this setting.
+The Gateway proxy toggle only applies to traffic from Cloudflare One Client devices. Gateway will always proxy traffic sent with [PAC files](/cloudflare-one/networks/resolvers-and-proxies/proxy-endpoints/) or [Browser Isolation](/cloudflare-one/remote-browser-isolation/) regardless of this setting.
1. In [Cloudflare One](https://one.dash.cloudflare.com), go to **Traffic policies** > **Traffic settings**.
2. In **Proxy and inspection settings**, turn on **Allow Secure Web Gateway to proxy traffic**.
diff --git a/src/content/partials/networking-services/cloudflare-one-connectivity-options.mdx b/src/content/partials/networking-services/cloudflare-one-connectivity-options.mdx
index 0126b68fe30..00c11fd744c 100644
--- a/src/content/partials/networking-services/cloudflare-one-connectivity-options.mdx
+++ b/src/content/partials/networking-services/cloudflare-one-connectivity-options.mdx
@@ -321,7 +321,7 @@ Not all connectivity options work together in the same account. Review the follo
| Combination | Compatible | Notes |
| ---- | ---- | ---- |
| WARP Connector + Cloudflare WAN | Conditional | Requires Cloudflare One Unified Routing. Accounts on Legacy routing mode cannot use both. |
-| Cloudflare One Client + Cloudflare WAN | Yes | Cloudflare One Client users can access Cloudflare WAN-connected sites. Cloudflare WAN sites can also initiate connections to the Cloudflare One Client devices using their virtual IP addresses. |
+| Cloudflare One Client + Cloudflare WAN | Yes | Cloudflare One Client users can access Cloudflare WAN-connected sites. Cloudflare WAN sites can also initiate connections to Cloudflare One Client devices using their virtual IP addresses. |
| Cloudflare Tunnel + Cloudflare WAN | Yes | Avoid overlapping IP routes. Cloudflare Tunnel takes priority if the same CIDR is configured for both. |
| GRE + IPsec | Yes | Use for redundancy or migration scenarios. |
| CNI + GRE or IPsec | Yes | Use Internet-based GRE or IPsec tunnels as backup connectivity alongside CNI. |
diff --git a/src/content/partials/networking-services/cloudflare-wan/zero-trust/warp.mdx b/src/content/partials/networking-services/cloudflare-wan/zero-trust/warp.mdx
index 7edb591e2f6..9977e64c33c 100644
--- a/src/content/partials/networking-services/cloudflare-wan/zero-trust/warp.mdx
+++ b/src/content/partials/networking-services/cloudflare-wan/zero-trust/warp.mdx
@@ -36,9 +36,9 @@ When connecting a device to Cloudflare WAN, you will have virtual IP addresses f
## Set up the Cloudflare One Client with Cloudflare WAN
-### 1. Route packets back to the Cloudflare One Client devices
+### 1. Route packets back to Cloudflare One Client devices
-Route packets back to the Cloudflare One Client devices from services behind an anycast GRE or other type tunnel. Complete this configuration before installing WARP. Otherwise, your infrastructure will not route packets correctly to Cloudflare global network and connectivity will fail.
+Route packets back to Cloudflare One Client devices from services behind an anycast GRE or other type tunnel. Complete this configuration before installing WARP. Otherwise, your infrastructure will not route packets correctly to Cloudflare global network and connectivity will fail.
Cloudflare will assign IP addresses from the virtual IP (VIP) space to your devices. To view your virtual IP address, go to [Cloudflare One](https://one.dash.cloudflare.com/), and select **{props.ztDashPath}**.
From c31074df6d38e05ce3aa3ef1b22981d3be6c0afc Mon Sep 17 00:00:00 2001
From: Ranbel Sun
Date: Mon, 16 Mar 2026 13:45:46 -0400
Subject: [PATCH 05/15] =?UTF-8?q?[ZT]=20Fix=20phrasing:=20'Cloudflare=20On?=
=?UTF-8?q?e=20Client-enabled=20device'=20=E2=86=92=20'Cloudflare=20One=20?=
=?UTF-8?q?Client=20device'?=
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Updates 3 instances across 2 files. Also rewrites one awkward sentence
about routing traffic through the client.
---
.../cloudflare-one/traffic-policies/get-started/network.mdx | 2 +-
.../mnm/tutorials/encrypt-network-flow-data.mdx | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/src/content/docs/cloudflare-one/traffic-policies/get-started/network.mdx b/src/content/docs/cloudflare-one/traffic-policies/get-started/network.mdx
index 321fc50d5e6..b1b89c2c615 100644
--- a/src/content/docs/cloudflare-one/traffic-policies/get-started/network.mdx
+++ b/src/content/docs/cloudflare-one/traffic-policies/get-started/network.mdx
@@ -41,7 +41,7 @@ To verify your device is connected to Cloudflare One:
1. In [Cloudflare One](https://one.dash.cloudflare.com), go to **Traffic policies** > **Traffic settings**.
2. Under **Log traffic activity**, enable activity logging for all Network logs. This tells Cloudflare to record network-level traffic so you can confirm your device appears in the logs.
-3. On your Cloudflare One Client-enabled device, open a browser and visit any website. This generates traffic that should appear in the logs.
+3. On your Cloudflare One Client device, open a browser and visit any website. This generates traffic that should appear in the logs.
4. Determine the **Source IP** for your device (the public-facing address Cloudflare sees for your connection):
diff --git a/src/content/partials/networking-services/mnm/tutorials/encrypt-network-flow-data.mdx b/src/content/partials/networking-services/mnm/tutorials/encrypt-network-flow-data.mdx
index 16f72f2f1cc..1d7b56c0a19 100644
--- a/src/content/partials/networking-services/mnm/tutorials/encrypt-network-flow-data.mdx
+++ b/src/content/partials/networking-services/mnm/tutorials/encrypt-network-flow-data.mdx
@@ -4,7 +4,7 @@
import { APIRequest } from "~/components";
-You can encrypt the network flow data sent from your router to Cloudflare by [routing](https://www.cloudflare.com/learning/network-layer/what-is-routing/) your network flow traffic through a device running the Cloudflare One Client. Encrypted network flow traffic is then forwarded from the Cloudflare One Client-enabled device to Cloudflare's network flow endpoints.
+You can encrypt the network flow data sent from your router to Cloudflare by [routing](https://www.cloudflare.com/learning/network-layer/what-is-routing/) your network flow traffic through a device running the Cloudflare One Client. Encrypted network flow traffic is then forwarded from the Cloudflare One Client device to Cloudflare's network flow endpoints.
To learn more about the Cloudflare One Client, and to install it on Linux, macOS, or Windows, refer to the [Cloudflare One Client documentation](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/).
@@ -65,4 +65,4 @@ In the machine running the Cloudflare One Client, you can redirect this traffic
## 3. (Optional) Configure split tunnels
-If you do not want all the traffic in your device to be Cloudflare One Client-enabled, [configure split tunnels/proxy mode](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/) to either only allow Network Flow traffic towards `162.159.65.1` or exclude everything else.
+If you do not want all traffic on your device to route through the Cloudflare One Client, [configure split tunnels/proxy mode](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/) to either only allow Network Flow traffic towards `162.159.65.1` or exclude everything else.
From 4f54f2ad148e13eefede71b204946d836eab593d Mon Sep 17 00:00:00 2001
From: Ranbel Sun
Date: Mon, 16 Mar 2026 13:48:31 -0400
Subject: [PATCH 06/15] [ZT] Clarify WARP Check note in ZTNA design guide
Update the explanatory note to clarify that 'WARP' is the previous name
for the Cloudflare One Client, since the sentence references the
dashboard check name 'WARP Check (Mac OS)'.
---
.../design-guides/designing-ztna-access-policies.mdx | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/src/content/docs/reference-architecture/design-guides/designing-ztna-access-policies.mdx b/src/content/docs/reference-architecture/design-guides/designing-ztna-access-policies.mdx
index 39e4ddd37ad..e08269881a0 100644
--- a/src/content/docs/reference-architecture/design-guides/designing-ztna-access-policies.mdx
+++ b/src/content/docs/reference-architecture/design-guides/designing-ztna-access-policies.mdx
@@ -341,7 +341,7 @@ But notice we now enable "Isolate Application." What does this mean? This forces
In the example above, the SWG policy is matching any traffic heading to your company wiki, then enforcing RBI (to match the ZTNA application policy) and then disabling all interaction with the wiki.
-It also adds the device posture check "WARP Check (Mac OS)" to scan the user's device for the presence of our device agent. If the user's device does not have the agent installed and enabled, then the device posture check cannot occur and they will automatically fail to meet the policy requirements. If the user does have the device agent enabled, then they will pass the posture check and be granted full wiki access. Note that the Cloudflare One Client is the name used for our device agent.
+It also adds the device posture check "WARP Check (Mac OS)" to scan the user's device for the presence of our device agent. If the user's device does not have the agent installed and enabled, then the device posture check cannot occur and they will automatically fail to meet the policy requirements. If the user does have the device agent enabled, then they will pass the posture check and be granted full wiki access. Note that "WARP" is the previous name for the Cloudflare One Client, which is Cloudflare's device agent.
Essentially, the employee on an insecure device is permitted to view the wiki in a "read-only" mode, but is restricted from further interactions like uploading/downloading or copying/pasting confidential information.
From 221330626cda858324b5d551e230100b84a6ee6d Mon Sep 17 00:00:00 2001
From: Ranbel Sun
Date: Mon, 16 Mar 2026 14:06:34 -0400
Subject: [PATCH 07/15] [ZT] Add glossary entry for Cloudflare One Client,
update WARP client entry
- Add new 'Cloudflare One Client' glossary term (fixes build error from
GlossaryTooltip references)
- Update 'WARP client' entry to indicate it is the previous name
- Update 'Cloudflare One Agent' entry to reference new product name
---
src/content/glossary/cloudflare-one.yaml | 10 +++++++---
1 file changed, 7 insertions(+), 3 deletions(-)
diff --git a/src/content/glossary/cloudflare-one.yaml b/src/content/glossary/cloudflare-one.yaml
index 379c7f4563c..4285f0f43b9 100644
--- a/src/content/glossary/cloudflare-one.yaml
+++ b/src/content/glossary/cloudflare-one.yaml
@@ -55,7 +55,11 @@ entries:
- term: Cloudflare One Agent
general_definition: |-
- the name of the Cloudflare WARP client app on iOS and Android devices.
+ the name of the Cloudflare One Client app on iOS and Android devices.
+
+ - term: Cloudflare One Client
+ general_definition: |-
+ an application that connects corporate devices to Cloudflare for private network access, advanced web filtering, and other security functions.
- term: Cloudflare Tunnel
general_definition: |-
@@ -279,7 +283,7 @@ entries:
- term: WARP client
general_definition: |-
- an application that connects corporate devices to Cloudflare for private network access, advanced web filtering, and other security functions.
+ the previous name for the Cloudflare One Client, an application that connects corporate devices to Cloudflare for private network access, advanced web filtering, and other security functions.
- term: WARP CGNAT IP
general_definition: |-
@@ -299,4 +303,4 @@ entries:
- term: Quarantine policies
general_definition: |-
- Policies that block specific types of emails (usually malicious and suspicious emails), preventing emails from reaching the end-user or the next mail service provider. Emails that are quarantined are reviewed by administrators and potentially released if falsely flagged.
\ No newline at end of file
+ Policies that block specific types of emails (usually malicious and suspicious emails), preventing emails from reaching the end-user or the next mail service provider. Emails that are quarantined are reviewed by administrators and potentially released if falsely flagged.
From 2ad0b36fcbc7331557093cb0f54e27a7f14fa86d Mon Sep 17 00:00:00 2001
From: Ranbel Sun
Date: Mon, 16 Mar 2026 14:28:29 -0400
Subject: [PATCH 08/15] [ZT] Revert client-checks URL paths to
warp-client-checks
The warp-client-checks/ folder has not been renamed yet, so URL paths
must continue using /warp-client-checks/ to avoid broken links. The
folder rename will be handled in a separate structural change.
---
.../access-controls/policies/index.mdx | 4 +--
.../dlp-policies/common-policies.mdx | 2 +-
.../insights/logs/posture-logs.mdx | 2 +-
.../zero-trust/cloudflare-gateway.mdx | 4 +--
.../posture-checks/index.mdx | 6 ++--
.../warp-client-checks/antivirus.mdx | 2 +-
.../warp-client-checks/application-check.mdx | 2 +-
.../warp-client-checks/carbon-black.mdx | 2 +-
.../warp-client-checks/corp-device.mdx | 4 +--
.../warp-client-checks/device-uuid.mdx | 2 +-
.../warp-client-checks/disk-encryption.mdx | 2 +-
.../warp-client-checks/domain-joined.mdx | 2 +-
.../warp-client-checks/file-check.mdx | 6 ++--
.../warp-client-checks/firewall.mdx | 2 +-
.../warp-client-checks/index.mdx | 30 +++++++++----------
.../warp-client-checks/os-version.mdx | 2 +-
.../warp-client-checks/require-gateway.mdx | 4 +--
.../warp-client-checks/require-warp.mdx | 2 +-
.../warp-client-checks/sentinel-one.mdx | 2 +-
.../manual-deployment.mdx | 2 +-
.../network-policies/common-policies.mdx | 2 +-
.../recommended-network-policies.mdx | 2 +-
.../architectures/sase.mdx | 20 ++++++-------
.../designing-ztna-access-policies.mdx | 4 +--
.../cloudflare-one/access/bookmarks.mdx | 2 +-
.../get-started/create-network-policy.mdx | 4 +--
.../network/enforce-device-posture.mdx | 2 +-
27 files changed, 60 insertions(+), 60 deletions(-)
diff --git a/src/content/docs/cloudflare-one/access-controls/policies/index.mdx b/src/content/docs/cloudflare-one/access-controls/policies/index.mdx
index 3504367f97d..656123e54d9 100644
--- a/src/content/docs/cloudflare-one/access-controls/policies/index.mdx
+++ b/src/content/docs/cloudflare-one/access-controls/policies/index.mdx
@@ -160,8 +160,8 @@ Non-identity attributes are polled continuously, meaning they are-evaluated with
| SAML Group | Checks a SAML attribute name / value pair. This selector only displays if you use a [generic SAML](/cloudflare-one/integrations/identity-providers/generic-saml/) identity provider. | ✅ | ❌ | ✅ |
| OIDC Claim | Checks an OIDC claim name / value pair. This selector only displays if you use a [generic OIDC](/cloudflare-one/integrations/identity-providers/generic-oidc/) identity provider. | ✅ | ❌ | ✅ |
| Device posture | Checks device posture signals from the Cloudflare One Client or a third-party service provider. This selector only displays after you create a [device posture check](/cloudflare-one/reusable-components/posture-checks/). | ✅ | ✅ | ❌ |
-| Warp | Checks that the device is connected to the Cloudflare One Client, including the consumer version. This selector only displays after you enable the [WARP posture check](/cloudflare-one/reusable-components/posture-checks/client-checks/require-warp/). | ✅ | ✅ | ❌ |
-| Gateway | Checks that the device is connected to your Zero Trust instance through the Cloudflare One Client. This selector only displays after you enable the [Gateway posture check](/cloudflare-one/reusable-components/posture-checks/client-checks/require-gateway/). | ✅ | ✅ | ❌ |
+| Warp | Checks that the device is connected to the Cloudflare One Client, including the consumer version. This selector only displays after you enable the [WARP posture check](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-warp/). | ✅ | ✅ | ❌ |
+| Gateway | Checks that the device is connected to your Zero Trust instance through the Cloudflare One Client. This selector only displays after you enable the [Gateway posture check](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-gateway/). | ✅ | ✅ | ❌ |
1 For SaaS applications, Access can only enforce policies at the time
of initial sign on and when reissuing the SaaS session. Once the user has
diff --git a/src/content/docs/cloudflare-one/data-loss-prevention/dlp-policies/common-policies.mdx b/src/content/docs/cloudflare-one/data-loss-prevention/dlp-policies/common-policies.mdx
index 9ca827f67e1..d86a3da3c41 100644
--- a/src/content/docs/cloudflare-one/data-loss-prevention/dlp-policies/common-policies.mdx
+++ b/src/content/docs/cloudflare-one/data-loss-prevention/dlp-policies/common-policies.mdx
@@ -41,7 +41,7 @@ You can configure access on a per-user or group basis by adding [identity-based
Many Android applications (such as Google Drive) use certificate pinning, which is incompatible with Gateway inspection. If needed, you can create a [Do Not Inspect policy](/cloudflare-one/traffic-policies/http-policies/#do-not-inspect) so that the app can continue to function on Android:
-1. Set up an [OS version device posture check](/cloudflare-one/reusable-components/posture-checks/client-checks/os-version/) that checks for the Android operating system.
+1. Set up an [OS version device posture check](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/os-version/) that checks for the Android operating system.
2. Create the following HTTP policy in Gateway:
diff --git a/src/content/docs/cloudflare-one/insights/logs/posture-logs.mdx b/src/content/docs/cloudflare-one/insights/logs/posture-logs.mdx
index c4ebe602293..6d3b6daa18d 100644
--- a/src/content/docs/cloudflare-one/insights/logs/posture-logs.mdx
+++ b/src/content/docs/cloudflare-one/insights/logs/posture-logs.mdx
@@ -37,7 +37,7 @@ Enterprise users can generate more detailed logs with [Logpush](/cloudflare-one/
| Field | Description |
| ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Name** | Name of the [device posture check](/cloudflare-one/reusable-components/posture-checks/). |
-| **Type** | Type of [Cloudflare One Client check](/cloudflare-one/reusable-components/posture-checks/client-checks/) or [service provider check](/cloudflare-one/integrations/service-providers/). |
+| **Type** | Type of [Cloudflare One Client check](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/) or [service provider check](/cloudflare-one/integrations/service-providers/). |
| **Rule ID** | UUID of the device posture check. |
| **Conditions met** | Whether the device passed or failed the posture check criteria. Evaluates to `true` if the **Received values** match the **Expected values**. |
| **Expected values** | Values required to pass the device posture check. |
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/cloudflare-gateway.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/cloudflare-gateway.mdx
index 38504f7de91..406af50dba3 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/cloudflare-gateway.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/cloudflare-gateway.mdx
@@ -18,8 +18,8 @@ import { Render } from "~/components";
cfManualCertificatesURL: "/cloudflare-one/team-and-resources/devices/user-side-certificates/manual-deployment/",
decryptTlsURL: "/cloudflare-one/traffic-policies/http-policies/tls-decryption/",
doNotInspectURL: "/cloudflare-one/traffic-policies/http-policies/#do-not-inspect",
- warpChecksURL: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
- osVersionChecks: "/cloudflare-one/reusable-components/posture-checks/client-checks/os-version/",
+ warpChecksURL: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
+ osVersionChecks: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/os-version/",
mwanOnrampsURL: "/cloudflare-one/networks/connectors/cloudflare-wan/on-ramps/",
gatewayResolverPoliciesURL: "/cloudflare-one/traffic-policies/resolver-policies/",
gatewayInternalDnsURL: "/cloudflare-one/traffic-policies/resolver-policies/#internal-dns",
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/index.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/index.mdx
index 4c1a1de0d3b..c9fcd3b7b4c 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/index.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/index.mdx
@@ -13,7 +13,7 @@ With Cloudflare Zero Trust, you can configure Zero Trust policies that rely on a
Setup instructions and requirements vary depending on the device posture attribute. Refer to the links below to view the setup guide for your provider.
-- [Cloudflare One Client checks](/cloudflare-one/reusable-components/posture-checks/client-checks/) are performed by the Cloudflare One Client.
+- [Cloudflare One Client checks](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/) are performed by the Cloudflare One Client.
- [Service-to-service checks](/cloudflare-one/integrations/service-providers/) are performed by third-party device posture providers.
- [Access integration checks](/cloudflare-one/reusable-components/posture-checks/access-integrations/) are only configurable for Access applications. These attributes cannot be used in Gateway policies.
@@ -32,12 +32,12 @@ You can now use your device posture check in an [Access policy](/cloudflare-one/
:::caution[Gateway policy limitation]
-Gateway does not support device posture checks for the [Tanium Access integration](/cloudflare-one/reusable-components/posture-checks/client-checks/tanium/).
+Gateway does not support device posture checks for the [Tanium Access integration](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/tanium/).
:::
## 4. Ensure traffic is going through the Cloudflare One Client
-[Cloudflare One Client](/cloudflare-one/reusable-components/posture-checks/client-checks/) and [service-to-service](/cloudflare-one/integrations/service-providers/) posture checks rely on traffic going through the Cloudflare One Client to detect posture information for a device. In your [Split Tunnel configuration](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/), ensure that the following domains are included in the Cloudflare One Client:
+[Cloudflare One Client](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/) and [service-to-service](/cloudflare-one/integrations/service-providers/) posture checks rely on traffic going through the Cloudflare One Client to detect posture information for a device. In your [Split Tunnel configuration](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/), ensure that the following domains are included in the Cloudflare One Client:
- The IdP used to authenticate to Cloudflare Zero Trust if posture check is part of an Access policy.
- `.cloudflareaccess.com` if posture check is part of an Access policy.
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/antivirus.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/antivirus.mdx
index 55d7cd7fa6d..d87eada7c10 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/antivirus.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/antivirus.mdx
@@ -19,7 +19,7 @@ The Antivirus device posture attribute checks if any antivirus software is insta
product="cloudflare-one"
params={{
name: "Cloudflare One Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
+ link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
}}
/>
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/application-check.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/application-check.mdx
index f4c1fbe2380..da4e2aa17e0 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/application-check.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/application-check.mdx
@@ -16,7 +16,7 @@ The Application Check device posture attribute checks that a specific applicatio
product="cloudflare-one"
params={{
name: "Cloudflare One Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
+ link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
}}
/>
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/carbon-black.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/carbon-black.mdx
index e6688f964be..05776d6051d 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/carbon-black.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/carbon-black.mdx
@@ -17,7 +17,7 @@ Cloudflare One can check if [Carbon Black](https://www.carbonblack.com/) is runn
product="cloudflare-one"
params={{
name: "Cloudflare One Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
+ link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
}}
/>
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/corp-device.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/corp-device.mdx
index 956f6bf1e19..4265a81bb0b 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/corp-device.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/corp-device.mdx
@@ -16,7 +16,7 @@ Cloudflare One allows you to build Zero Trust rules based on device serial numbe
product="cloudflare-one"
params={{
name: "Cloudflare One Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
+ link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
}}
/>
@@ -71,4 +71,4 @@ You can use the following commands to check the serial number of your device. Th
### iOS, Android and ChromeOS
-Serial number checks are not supported on mobile devices. You can identify mobile devices by a [unique client ID](/cloudflare-one/reusable-components/posture-checks/client-checks/device-uuid) instead of by serial number.
+Serial number checks are not supported on mobile devices. You can identify mobile devices by a [unique client ID](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/device-uuid) instead of by serial number.
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/device-uuid.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/device-uuid.mdx
index 36b68f9806a..29938a2ef24 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/device-uuid.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/device-uuid.mdx
@@ -16,7 +16,7 @@ Cloudflare One allows you to build Zero Trust rules based on device UUIDs suppli
product="cloudflare-one"
params={{
name: "Cloudflare One Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
+ link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
}}
/>
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/disk-encryption.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/disk-encryption.mdx
index 63f5bffc4b8..1c8d22521c1 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/disk-encryption.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/disk-encryption.mdx
@@ -19,7 +19,7 @@ The Disk Encryption device posture attribute ensures that disks are encrypted on
product="cloudflare-one"
params={{
name: "Cloudflare One Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
+ link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
}}
/>
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/domain-joined.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/domain-joined.mdx
index cbc11581562..bf088bf9e46 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/domain-joined.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/domain-joined.mdx
@@ -19,7 +19,7 @@ The Domain Joined device posture attribute ensures that a user is a member of a
product="cloudflare-one"
params={{
name: "Cloudflare One Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
+ link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
}}
/>
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/file-check.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/file-check.mdx
index dedfd613808..f217ab35cf3 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/file-check.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/file-check.mdx
@@ -16,7 +16,7 @@ The File Check device posture attribute checks for the presence of a file on a d
product="cloudflare-one"
params={{
name: "Cloudflare One Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
+ link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
}}
/>
@@ -32,8 +32,8 @@ The File Check device posture attribute checks for the presence of a file on a d
1. **Name**: Enter a unique name for this device posture check.
2. **Operating system**: Select your operating system.
3. **File Path**: Enter a file path (for example, `c:\my folder\myfile.exe`).
- 4. **Signing certificate thumbprint (recommended)**: Enter the [thumbprint](/cloudflare-one/reusable-components/posture-checks/client-checks/application-check/#determine-the-signing-thumbprint) of the publishing certificate used to sign the file. Adding this information will enable the check to ensure that the file was signed by the expected software developer.
- 5. **SHA-256 (optional)**: Enter the [SHA-256 value](/cloudflare-one/reusable-components/posture-checks/client-checks/application-check/#determine-the-sha-256-value) of the file. This is used to ensure the integrity of the file on the device.
+ 4. **Signing certificate thumbprint (recommended)**: Enter the [thumbprint](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/application-check/#determine-the-signing-thumbprint) of the publishing certificate used to sign the file. Adding this information will enable the check to ensure that the file was signed by the expected software developer.
+ 5. **SHA-256 (optional)**: Enter the [SHA-256 value](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/application-check/#determine-the-sha-256-value) of the file. This is used to ensure the integrity of the file on the device.
5. Select **Save**.
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/firewall.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/firewall.mdx
index d1916644dc0..1a91f86a2af 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/firewall.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/firewall.mdx
@@ -19,7 +19,7 @@ The Firewall device posture attribute ensures that a firewall is running on a de
product="cloudflare-one"
params={{
name: "Cloudflare One Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
+ link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
}}
/>
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/index.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/index.mdx
index ae9fd69d4c6..0eceb1f5f27 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/index.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/index.mdx
@@ -18,18 +18,18 @@ These device posture checks are performed by the [Cloudflare One Client](/cloudf
| Device posture check | macOS | Windows | Linux | iOS | Android/ChromeOS |
| --------------------------------------------------------------------------------------------- | ----- | ------- | ----------- | --- | ---------------- |
-| [Antivirus](/cloudflare-one/reusable-components/posture-checks/client-checks/antivirus/) | ❌ | ✅ | ❌ | ❌ | ❌ |
-| [Application check](/cloudflare-one/reusable-components/posture-checks/client-checks/application-check/) | ✅ | ✅ | ✅ | ❌ | ❌ |
-| [Carbon Black](/cloudflare-one/reusable-components/posture-checks/client-checks/carbon-black/) | ✅ | ✅ | ✅ | ❌ | ❌ |
-| [Client certificate](/cloudflare-one/reusable-components/posture-checks/client-checks/client-certificate/) | ✅ | ✅ | ✅ | ❌ | ❌ |
-| [Device serial numbers](/cloudflare-one/reusable-components/posture-checks/client-checks/corp-device/) | ✅ | ✅ | ✅ | ❌ | ❌ |
-| [Device UUID](/cloudflare-one/reusable-components/posture-checks/client-checks/device-uuid/) | ❌ | ❌ | ❌ | ✅ | ✅ |
-| [Disk encryption](/cloudflare-one/reusable-components/posture-checks/client-checks/disk-encryption/) | ✅ | ✅ | ✅ | ❌ | ❌ |
-| [Domain joined](/cloudflare-one/reusable-components/posture-checks/client-checks/domain-joined/) | ❌ | ✅ | ❌ | ❌ | ❌ |
-| [File check](/cloudflare-one/reusable-components/posture-checks/client-checks/file-check/) | ✅ | ✅ | ✅ | ❌ | ❌ |
-| [Firewall](/cloudflare-one/reusable-components/posture-checks/client-checks/firewall/) | ✅ | ✅ | ❌ | ❌ | ❌ |
-| [OS version](/cloudflare-one/reusable-components/posture-checks/client-checks/os-version/) | ✅ | ✅ | ✅ | ✅ | ✅ |
-| [Require Gateway](/cloudflare-one/reusable-components/posture-checks/client-checks/require-gateway/) | ✅ | ✅ | ✅ | ✅ | ✅ |
-| [Require WARP](/cloudflare-one/reusable-components/posture-checks/client-checks/require-warp/) | ✅ | ✅ | ✅ | ✅ | ✅ |
-| [SentinelOne](/cloudflare-one/reusable-components/posture-checks/client-checks/sentinel-one/) | ✅ | ✅ | ✅ | ❌ | ❌ |
-| [Tanium (legacy)](/cloudflare-one/reusable-components/posture-checks/client-checks/tanium/) | ✅ | ✅ | ✅ | ❌ | ❌ |
+| [Antivirus](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/antivirus/) | ❌ | ✅ | ❌ | ❌ | ❌ |
+| [Application check](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/application-check/) | ✅ | ✅ | ✅ | ❌ | ❌ |
+| [Carbon Black](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/carbon-black/) | ✅ | ✅ | ✅ | ❌ | ❌ |
+| [Client certificate](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/client-certificate/) | ✅ | ✅ | ✅ | ❌ | ❌ |
+| [Device serial numbers](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/corp-device/) | ✅ | ✅ | ✅ | ❌ | ❌ |
+| [Device UUID](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/device-uuid/) | ❌ | ❌ | ❌ | ✅ | ✅ |
+| [Disk encryption](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/disk-encryption/) | ✅ | ✅ | ✅ | ❌ | ❌ |
+| [Domain joined](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/domain-joined/) | ❌ | ✅ | ❌ | ❌ | ❌ |
+| [File check](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/file-check/) | ✅ | ✅ | ✅ | ❌ | ❌ |
+| [Firewall](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/firewall/) | ✅ | ✅ | ❌ | ❌ | ❌ |
+| [OS version](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/os-version/) | ✅ | ✅ | ✅ | ✅ | ✅ |
+| [Require Gateway](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-gateway/) | ✅ | ✅ | ✅ | ✅ | ✅ |
+| [Require WARP](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-warp/) | ✅ | ✅ | ✅ | ✅ | ✅ |
+| [SentinelOne](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/sentinel-one/) | ✅ | ✅ | ✅ | ❌ | ❌ |
+| [Tanium (legacy)](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/tanium/) | ✅ | ✅ | ✅ | ❌ | ❌ |
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/os-version.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/os-version.mdx
index c6f5a66910b..09196c178cc 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/os-version.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/os-version.mdx
@@ -16,7 +16,7 @@ The OS Version device posture attribute checks whether the version of a device's
product="cloudflare-one"
params={{
name: "Cloudflare One Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
+ link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
}}
/>
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-gateway.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-gateway.mdx
index 27f11840753..3c98c7ac716 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-gateway.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-gateway.mdx
@@ -10,7 +10,7 @@ head:
import { Render } from "~/components";
-With Require Gateway, you can allow access to your applications only to devices enrolled in your Zero Trust organization. Unlike [Require WARP](/cloudflare-one/reusable-components/posture-checks/client-checks/require-warp/), which will check for any WARP instance (including the consumer version), Require Gateway will only allow requests coming from devices whose traffic is filtered by your organization's Cloudflare Gateway configuration. This policy is best used when you want to protect company-owned assets by only allowing access to employees.
+With Require Gateway, you can allow access to your applications only to devices enrolled in your Zero Trust organization. Unlike [Require WARP](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-warp/), which will check for any WARP instance (including the consumer version), Require Gateway will only allow requests coming from devices whose traffic is filtered by your organization's Cloudflare Gateway configuration. This policy is best used when you want to protect company-owned assets by only allowing access to employees.
## Prerequisites
@@ -19,7 +19,7 @@ With Require Gateway, you can allow access to your applications only to devices
product="cloudflare-one"
params={{
name: "Cloudflare One Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
+ link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
}}
/>
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-warp.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-warp.mdx
index d0f5e1aa76d..8d82ff48df2 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-warp.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-warp.mdx
@@ -25,7 +25,7 @@ Cloudflare One enables you to restrict access to your applications to devices ru
product="cloudflare-one"
params={{
name: "Cloudflare One Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
+ link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
}}
/>
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/sentinel-one.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/sentinel-one.mdx
index 513e4b6a9bf..6e0bb9a69fe 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/sentinel-one.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/sentinel-one.mdx
@@ -20,7 +20,7 @@ Cloudflare One can check if [SentinelOne](https://www.sentinelone.com/) is runni
product="cloudflare-one"
params={{
name: "Cloudflare One Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
+ link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
}}
/>
diff --git a/src/content/docs/cloudflare-one/team-and-resources/devices/user-side-certificates/manual-deployment.mdx b/src/content/docs/cloudflare-one/team-and-resources/devices/user-side-certificates/manual-deployment.mdx
index 1015e4d5bee..1074f187f7b 100644
--- a/src/content/docs/cloudflare-one/team-and-resources/devices/user-side-certificates/manual-deployment.mdx
+++ b/src/content/docs/cloudflare-one/team-and-resources/devices/user-side-certificates/manual-deployment.mdx
@@ -188,7 +188,7 @@ Windows offers two locations to install the certificate, each impacting which us
The root certificate is now installed and ready to be used.
:::caution
-If your certificate is installed in the **Local Machine Store**, the [device posture check](/cloudflare-one/reusable-components/posture-checks/client-checks/) looking for a certificate will fail. Install the certificate in the **Current User Store** to ensure a successful posture device check.
+If your certificate is installed in the **Local Machine Store**, the [device posture check](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/) looking for a certificate will fail. Install the certificate in the **Current User Store** to ensure a successful posture device check.
:::
### Linux
diff --git a/src/content/docs/cloudflare-one/traffic-policies/network-policies/common-policies.mdx b/src/content/docs/cloudflare-one/traffic-policies/network-policies/common-policies.mdx
index 7082542a101..70dd5036386 100644
--- a/src/content/docs/cloudflare-one/traffic-policies/network-policies/common-policies.mdx
+++ b/src/content/docs/cloudflare-one/traffic-policies/network-policies/common-policies.mdx
@@ -84,7 +84,7 @@ In the following API examples, `filters: ["l4"]` indicates that this is a networ
## Enforce device posture
-Require devices to have certain software installed or other configuration attributes. For instructions on enabling a device posture check, refer to the [device posture section](/cloudflare-one/reusable-components/posture-checks/). For example, you can use a list of [device serial numbers](/cloudflare-one/reusable-components/posture-checks/client-checks/corp-device/) to ensure users can only access an application if they connect with the Cloudflare One Client from a company device:
+Require devices to have certain software installed or other configuration attributes. For instructions on enabling a device posture check, refer to the [device posture section](/cloudflare-one/reusable-components/posture-checks/). For example, you can use a list of [device serial numbers](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/corp-device/) to ensure users can only access an application if they connect with the Cloudflare One Client from a company device:
-You can add a number of Cloudflare One Client device posture checks as needed, such as [Disk encryption](/cloudflare-one/reusable-components/posture-checks/client-checks/disk-encryption/) and [Domain joined](/cloudflare-one/reusable-components/posture-checks/client-checks/domain-joined/). For more information on device posture checks, refer to [Enforce device posture](/cloudflare-one/reusable-components/posture-checks/).
+You can add a number of Cloudflare One Client device posture checks as needed, such as [Disk encryption](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/disk-encryption/) and [Domain joined](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/domain-joined/). For more information on device posture checks, refer to [Enforce device posture](/cloudflare-one/reusable-components/posture-checks/).
## FinanceUsers-NET-HTTPS-FinanceServers (example)
diff --git a/src/content/docs/reference-architecture/architectures/sase.mdx b/src/content/docs/reference-architecture/architectures/sase.mdx
index 8581626febc..15286fb8c5f 100644
--- a/src/content/docs/reference-architecture/architectures/sase.mdx
+++ b/src/content/docs/reference-architecture/architectures/sase.mdx
@@ -497,16 +497,16 @@ Not only does the user identity need to be verified, but the security posture of
The following built-in posture checks are available:
-- [Application check](/cloudflare-one/reusable-components/posture-checks/client-checks/application-check/): Checks that a specific application process is running
-- [File check](/cloudflare-one/reusable-components/posture-checks/client-checks/file-check/): Checks for the presence of a file
-- [Firewall](/cloudflare-one/reusable-components/posture-checks/client-checks/firewall/): Checks if a firewall is running
-- [Disk encryption](/cloudflare-one/reusable-components/posture-checks/client-checks/disk-encryption/): Checks if/how many disks are encrypted
-- [Domain joined](/cloudflare-one/reusable-components/posture-checks/client-checks/domain-joined/): Checks if the device is joined to a Microsoft Active Directory domain
-- [OS version](/cloudflare-one/reusable-components/posture-checks/client-checks/os-version/): Checks what version of the OS is running
-- [Unique Client ID](/cloudflare-one/reusable-components/posture-checks/client-checks/device-uuid/): When using an MDM too, organizations can assign a verifiable UUID to a mobile, desktop, or laptop device
-- [Device serial number](/cloudflare-one/reusable-components/posture-checks/client-checks/corp-device/): Checks to see if the device serial matches a list of company desktop/laptop computers
-
-Cloudflare One can also integrate with any deployed endpoint security solution, such as [Microsoft Endpoint Manager](/cloudflare-one/integrations/service-providers/microsoft/), [Tanium](/cloudflare-one/integrations/service-providers/taniums2s/), [Carbon Black](/cloudflare-one/reusable-components/posture-checks/client-checks/carbon-black/), [CrowdStrike](/cloudflare-one/integrations/service-providers/crowdstrike/), [SentinelOne](/cloudflare-one/integrations/service-providers/sentinelone/), and more. Any data from those products can be passed to Cloudflare for use in access decisions.
+- [Application check](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/application-check/): Checks that a specific application process is running
+- [File check](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/file-check/): Checks for the presence of a file
+- [Firewall](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/firewall/): Checks if a firewall is running
+- [Disk encryption](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/disk-encryption/): Checks if/how many disks are encrypted
+- [Domain joined](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/domain-joined/): Checks if the device is joined to a Microsoft Active Directory domain
+- [OS version](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/os-version/): Checks what version of the OS is running
+- [Unique Client ID](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/device-uuid/): When using an MDM too, organizations can assign a verifiable UUID to a mobile, desktop, or laptop device
+- [Device serial number](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/corp-device/): Checks to see if the device serial matches a list of company desktop/laptop computers
+
+Cloudflare One can also integrate with any deployed endpoint security solution, such as [Microsoft Endpoint Manager](/cloudflare-one/integrations/service-providers/microsoft/), [Tanium](/cloudflare-one/integrations/service-providers/taniums2s/), [Carbon Black](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/carbon-black/), [CrowdStrike](/cloudflare-one/integrations/service-providers/crowdstrike/), [SentinelOne](/cloudflare-one/integrations/service-providers/sentinelone/), and more. Any data from those products can be passed to Cloudflare for use in access decisions.
All of the above device information, combined with data on the user identity and also the network the device is on, is available in Cloudflare to be used as part of the company policy. For example, organizations could choose to only allow administrators to SSH into servers when all of the following conditions are met: their device is free from threats, running the latest operating system, and joined to the company domain.
diff --git a/src/content/docs/reference-architecture/design-guides/designing-ztna-access-policies.mdx b/src/content/docs/reference-architecture/design-guides/designing-ztna-access-policies.mdx
index e08269881a0..47113601120 100644
--- a/src/content/docs/reference-architecture/design-guides/designing-ztna-access-policies.mdx
+++ b/src/content/docs/reference-architecture/design-guides/designing-ztna-access-policies.mdx
@@ -70,7 +70,7 @@ A critical part of application access is authenticating a user. Cloudflare has a
### Device posture
-The final prerequisite for building really effective access policies is to configure [device posture](/cloudflare-one/reusable-components/posture-checks/). When using the [device agent](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/), Cloudflare has access to a [variety of information](/cloudflare-one/reusable-components/posture-checks/client-checks/) about the device which can then be used in an access policy. When using an [agentless method](/reference-architecture/diagrams/sase/sase-clientless-access-private-dns/) to access applications, only the user identity information is available. We also support using device posture information from [other vendors](/cloudflare-one/integrations/service-providers/), such as Microsoft, Crowdstrike and Sentinel One.
+The final prerequisite for building really effective access policies is to configure [device posture](/cloudflare-one/reusable-components/posture-checks/). When using the [device agent](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/), Cloudflare has access to a [variety of information](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/) about the device which can then be used in an access policy. When using an [agentless method](/reference-architecture/diagrams/sase/sase-clientless-access-private-dns/) to access applications, only the user identity information is available. We also support using device posture information from [other vendors](/cloudflare-one/integrations/service-providers/), such as Microsoft, Crowdstrike and Sentinel One.

@@ -282,7 +282,7 @@ This is a very simple Access Group, with just two group selectors. Note that bec
As you can see, it defines that "all employees" are those in the Azure AD group "Full Time Employees", who are also in the group "Completed security training." The first selector defines the initial scope of the Access Group, and the second selector requires that they must also be in that specific group.
-This Access Group requires that three [device posture checks](/cloudflare-one/reusable-components/posture-checks/client-checks/) have been created for the [OS version](/cloudflare-one/reusable-components/posture-checks/client-checks/os-version/). For example, the posture check "Latest version of macOS" is defined as "macOS version is greater than or equal to 15.1" and reflects the latest version the company considers stable and secure (vs. the very latest OS version). Once included in the Access policy, this will enforce the logic we’ve established here - if any user wants to sign in as a 'Secure Employee', they'll need to meet these requirements.
+This Access Group requires that three [device posture checks](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/) have been created for the [OS version](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/os-version/). For example, the posture check "Latest version of macOS" is defined as "macOS version is greater than or equal to 15.1" and reflects the latest version the company considers stable and secure (vs. the very latest OS version). Once included in the Access policy, this will enforce the logic we’ve established here - if any user wants to sign in as a 'Secure Employee', they'll need to meet these requirements.
#### Employees on trusted devices
diff --git a/src/content/partials/cloudflare-one/access/bookmarks.mdx b/src/content/partials/cloudflare-one/access/bookmarks.mdx
index e600a0cf925..5f5d22666f7 100644
--- a/src/content/partials/cloudflare-one/access/bookmarks.mdx
+++ b/src/content/partials/cloudflare-one/access/bookmarks.mdx
@@ -55,5 +55,5 @@ The following policy features are not supported for bookmark applications:
If you attempt to assign a policy that uses an unsupported feature, the dashboard will display an error.
:::tip[Device posture policies]
-To show bookmarks only to users on managed devices, assign a policy that requires device posture checks (such as [Require Gateway](/cloudflare-one/reusable-components/posture-checks/client-checks/require-gateway/)). The bookmark will only appear in the App Launcher for users whose devices satisfy the posture requirements.
+To show bookmarks only to users on managed devices, assign a policy that requires device posture checks (such as [Require Gateway](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-gateway/)). The bookmark will only appear in the App Launcher for users whose devices satisfy the posture requirements.
:::
\ No newline at end of file
diff --git a/src/content/partials/cloudflare-one/gateway/get-started/create-network-policy.mdx b/src/content/partials/cloudflare-one/gateway/get-started/create-network-policy.mdx
index ab196f1a0a9..159dc74c8a7 100644
--- a/src/content/partials/cloudflare-one/gateway/get-started/create-network-policy.mdx
+++ b/src/content/partials/cloudflare-one/gateway/get-started/create-network-policy.mdx
@@ -12,7 +12,7 @@ To create a new network policy:
2. In the **Network** tab, select **Add a network policy**.
3. Name the policy.
4. Under **Traffic**, build a logical expression that defines the traffic you want to allow or block.
-5. Choose an **Action** to take when traffic matches the logical expression. For example, you can use a list of [device serial numbers](/cloudflare-one/reusable-components/posture-checks/client-checks/corp-device/) to ensure users can only access an application if they connect with the Cloudflare One Client from a company device:
+5. Choose an **Action** to take when traffic matches the logical expression. For example, you can use a list of [device serial numbers](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/corp-device/) to ensure users can only access an application if they connect with the Cloudflare One Client from a company device:
From 50134a3cac7848109b861476dd8024398ab363cb Mon Sep 17 00:00:00 2001
From: Ranbel Sun
Date: Mon, 16 Mar 2026 16:07:13 -0400
Subject: [PATCH 09/15] [ZT] Rename WARP folders/files and update links +
redirects
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Structural renames for WARP Client → Cloudflare One Client:
- warp-client-checks/ → client-checks/ (16 files)
- warp-to-warp.mdx → peer-to-peer.mdx
- rdp-warp-to-tunnel.mdx → rdp-device-client.mdx
- ssh-warp-to-tunnel.mdx → ssh-device-client.mdx
- warp-on-headless-linux.mdx → deploy-client-headless-linux.mdx
- zero-trust/warp.mdx → zero-trust/cloudflare-one-client.mdx (×2)
Adds 8 new redirects (1 splat + 7 static) and updates 5 existing
redirect destinations. Updates ~100 internal link references across
~55 files.
---
public/__redirects | 20 +++++++++----
.../access-controls/policies/index.mdx | 4 +--
.../dlp-policies/common-policies.mdx | 2 +-
.../insights/logs/posture-logs.mdx | 2 +-
.../cloudflared/connect-private-hostname.mdx | 2 +-
.../cloudflare-tunnel/private-net/index.mdx | 2 +-
.../{warp-to-warp.mdx => peer-to-peer.mdx} | 0
.../cloudflare-tunnel/use-cases/rdp/index.mdx | 2 +-
.../use-cases/rdp/rdp-browser.mdx | 2 +-
.../rdp/rdp-cloudflared-authentication.mdx | 2 +-
...rp-to-tunnel.mdx => rdp-device-client.mdx} | 0
.../cloudflare-tunnel/use-cases/ssh/index.mdx | 2 +-
.../use-cases/ssh/ssh-browser-rendering.mdx | 2 +-
.../ssh/ssh-cloudflared-authentication.mdx | 2 +-
...rp-to-tunnel.mdx => ssh-device-client.mdx} | 0
.../ssh/ssh-infrastructure-access.mdx | 2 +-
.../manually/how-to/traceroute.mdx | 2 +-
.../connectors/cloudflare-wan/on-ramps.mdx | 2 +-
.../zero-trust/cloudflare-gateway.mdx | 6 ++--
.../{warp.mdx => cloudflare-one-client.mdx} | 2 +-
.../networks/routes/reserved-ips.mdx | 2 +-
.../antivirus.mdx | 2 +-
.../application-check.mdx | 2 +-
.../carbon-black.mdx | 2 +-
.../client-certificate.mdx | 0
.../corp-device.mdx | 4 +--
.../device-uuid.mdx | 2 +-
.../disk-encryption.mdx | 2 +-
.../domain-joined.mdx | 2 +-
.../file-check.mdx | 6 ++--
.../firewall.mdx | 2 +-
.../index.mdx | 30 +++++++++----------
.../os-version.mdx | 2 +-
.../require-gateway.mdx | 4 +--
.../require-warp.mdx | 2 +-
.../sentinel-one.mdx | 2 +-
.../tanium.mdx | 0
.../posture-checks/index.mdx | 6 ++--
.../setup/replace-vpn/device-to-device.mdx | 6 ++--
.../configure/device-ips.mdx | 2 +-
.../configure/device-profiles.mdx | 2 +-
.../modes/device-information-only.mdx | 2 +-
.../configure/modes/index.mdx | 2 +-
.../configure/settings/index.mdx | 6 ++--
.../deployment/mdm-deployment/index.mdx | 2 +-
.../deployment/mdm-deployment/parameters.mdx | 2 +-
.../mdm-deployment/partners/intune.mdx | 2 +-
.../troubleshooting/diagnostic-logs.mdx | 2 +-
.../manual-deployment.mdx | 2 +-
.../http-policies/common-policies.mdx | 4 +--
.../network-policies/common-policies.mdx | 2 +-
...x.mdx => deploy-client-headless-linux.mdx} | 2 +-
.../tutorials/extend-sso-with-workers.mdx | 2 +-
.../manually/how-to/traceroute.mdx | 2 +-
src/content/docs/cloudflare-wan/on-ramps.mdx | 2 +-
.../zero-trust/cloudflare-gateway.mdx | 6 ++--
.../{warp.mdx => cloudflare-one-client.mdx} | 2 +-
.../isolate-application.mdx | 2 +-
.../build-policies/policy-design.mdx | 2 +-
.../recommended-network-policies.mdx | 2 +-
.../architectures/sase.mdx | 20 ++++++-------
.../designing-ztna-access-policies.mdx | 4 +--
.../design-guides/network-vpn-migration.mdx | 4 +--
.../design-guides/zero-trust-for-saas.mdx | 4 +--
...-hosted-VoIP-services-for-hybrid-users.mdx | 4 +--
.../3rd-party-integration-guide.mdx | 2 +-
.../cloudflare-one/access/bookmarks.mdx | 2 +-
.../get-started/create-network-policy.mdx | 4 +--
.../network/enforce-device-posture.mdx | 2 +-
.../cloudflare-one-connectivity-options.mdx | 2 +-
70 files changed, 122 insertions(+), 114 deletions(-)
rename src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/{warp-to-warp.mdx => peer-to-peer.mdx} (100%)
rename src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/{rdp-warp-to-tunnel.mdx => rdp-device-client.mdx} (100%)
rename src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/{ssh-warp-to-tunnel.mdx => ssh-device-client.mdx} (100%)
rename src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/{warp.mdx => cloudflare-one-client.mdx} (96%)
rename src/content/docs/cloudflare-one/reusable-components/posture-checks/{warp-client-checks => client-checks}/antivirus.mdx (97%)
rename src/content/docs/cloudflare-one/reusable-components/posture-checks/{warp-client-checks => client-checks}/application-check.mdx (98%)
rename src/content/docs/cloudflare-one/reusable-components/posture-checks/{warp-client-checks => client-checks}/carbon-black.mdx (95%)
rename src/content/docs/cloudflare-one/reusable-components/posture-checks/{warp-client-checks => client-checks}/client-certificate.mdx (100%)
rename src/content/docs/cloudflare-one/reusable-components/posture-checks/{warp-client-checks => client-checks}/corp-device.mdx (93%)
rename src/content/docs/cloudflare-one/reusable-components/posture-checks/{warp-client-checks => client-checks}/device-uuid.mdx (97%)
rename src/content/docs/cloudflare-one/reusable-components/posture-checks/{warp-client-checks => client-checks}/disk-encryption.mdx (97%)
rename src/content/docs/cloudflare-one/reusable-components/posture-checks/{warp-client-checks => client-checks}/domain-joined.mdx (94%)
rename src/content/docs/cloudflare-one/reusable-components/posture-checks/{warp-client-checks => client-checks}/file-check.mdx (72%)
rename src/content/docs/cloudflare-one/reusable-components/posture-checks/{warp-client-checks => client-checks}/firewall.mdx (96%)
rename src/content/docs/cloudflare-one/reusable-components/posture-checks/{warp-client-checks => client-checks}/index.mdx (50%)
rename src/content/docs/cloudflare-one/reusable-components/posture-checks/{warp-client-checks => client-checks}/os-version.mdx (98%)
rename src/content/docs/cloudflare-one/reusable-components/posture-checks/{warp-client-checks => client-checks}/require-gateway.mdx (75%)
rename src/content/docs/cloudflare-one/reusable-components/posture-checks/{warp-client-checks => client-checks}/require-warp.mdx (95%)
rename src/content/docs/cloudflare-one/reusable-components/posture-checks/{warp-client-checks => client-checks}/sentinel-one.mdx (96%)
rename src/content/docs/cloudflare-one/reusable-components/posture-checks/{warp-client-checks => client-checks}/tanium.mdx (100%)
rename src/content/docs/cloudflare-one/tutorials/{warp-on-headless-linux.mdx => deploy-client-headless-linux.mdx} (98%)
rename src/content/docs/cloudflare-wan/zero-trust/{warp.mdx => cloudflare-one-client.mdx} (96%)
diff --git a/public/__redirects b/public/__redirects
index e4e6c653484..d8bbd5ae19b 100644
--- a/public/__redirects
+++ b/public/__redirects
@@ -2287,7 +2287,7 @@
/cloudflare-one/policies/zero-trust/common-configs/ /cloudflare-one/policies/access/ 301
/cloudflare-one/applications/casb/troubleshooting/ /cloudflare-one/applications/casb/troubleshooting/troubleshoot-integrations/ 301
/cloudflare-one/analytics/logs/activity-log/ /cloudflare-one/insights/logs/gateway-logs/ 301
-/cloudflare-one/identity/devices/os-version/ /cloudflare-one/identity/devices/warp-client-checks/os-version/ 301
+/cloudflare-one/identity/devices/os-version/ /cloudflare-one/reusable-components/posture-checks/client-checks/os-version/ 301
/cloudflare-one/insights/dex/fleet-status/ /cloudflare-one/insights/dex/monitoring/ 301
/cloudflare-one/policies/zero-trust/cors/ /cloudflare-one/access-controls/applications/http-apps/authorization-cookie/cors/ 301
/cloudflare-one/identity/users/groups/ /cloudflare-one/policies/access/groups/ 301
@@ -2320,7 +2320,7 @@
/cloudflare-one/tutorials/ssh/ /cloudflare-one/connections/connect-networks/use-cases/ssh/ 301
/support/traffic/argo-tunnel/ /cloudflare-one/connections/connect-networks/ 301
/cloudflare-one/faq/tunnel/ /cloudflare-one/faq/cloudflare-tunnels-faq/ 301
-/magic-wan/tutorials/warp/ /cloudflare-wan/zero-trust/warp/ 301
+/magic-wan/tutorials/warp/ /cloudflare-wan/zero-trust/cloudflare-one-client/ 301
/cloudflare-one/examples/ /cloudflare-one/api-terraform/ 301
/warp-client/teams/ /cloudflare-one/team-and-resources/devices/cloudflare-one-client/ 301
/cloudflare-one/integrations/identity-providers/azuread/ /cloudflare-one/integrations/identity-providers/entra-id/ 301
@@ -2360,8 +2360,8 @@
/cloudflare-one/identity/devices/access-integrations/mutual-tls-authentication/ /cloudflare-one/access-controls/service-credentials/mutual-tls-authentication/ 301
/cloudflare-one/identity/devices/crowdstrike/ /cloudflare-one/integrations/service-providers/crowdstrike/ 301
/cloudflare-one/identity/devices/microsoft/ /cloudflare-one/integrations/service-providers/microsoft/ 301
-/cloudflare-one/identity/devices/require-gateway/ /cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-gateway/ 301
-/cloudflare-one/identity/devices/require-warp/ /cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-warp/ 301
+/cloudflare-one/identity/devices/require-gateway/ /cloudflare-one/reusable-components/posture-checks/client-checks/require-gateway/ 301
+/cloudflare-one/identity/devices/require-warp/ /cloudflare-one/reusable-components/posture-checks/client-checks/require-warp/ 301
/cloudflare-one/identity/devices/service-providers/custom/ /cloudflare-one/integrations/service-providers/custom/ 301
/cloudflare-one/identity/devices/service-providers/ /cloudflare-one/integrations/service-providers/ 301
/cloudflare-one/policies/data-loss-prevention/exact-data-match/ /cloudflare-one/data-loss-prevention/detection-entries/#exact-data-match 301
@@ -2377,7 +2377,7 @@
/cloudflare-one/traffic-policies/initial-setup/network/ /cloudflare-one/traffic-policies/get-started/network/ 301
# More specific redirects from nav revamp (before catch-alls)
-/cloudflare-one/identity/devices/access-integrations/tanium/ /cloudflare-one/reusable-components/posture-checks/warp-client-checks/tanium/ 301
+/cloudflare-one/identity/devices/access-integrations/tanium/ /cloudflare-one/reusable-components/posture-checks/client-checks/tanium/ 301
/cloudflare-one/identity/authorization-cookie/application-token/ /cloudflare-one/access-controls/applications/http-apps/authorization-cookie/application-token/ 301
/cloudflare-one/identity/authorization-cookie/validating-json/ /cloudflare-one/access-controls/applications/http-apps/authorization-cookie/validating-json/ 301
/cloudflare-one/identity/authorization-cookie/ /cloudflare-one/access-controls/applications/http-apps/authorization-cookie/ 301
@@ -2410,7 +2410,13 @@
/cloudflare-one/email-security/settings/trusted-domains/ /cloudflare-one/email-security/settings/detection-settings/trusted-domains/ 301
/cloudflare-one/email-security/monitoring/search-email/ /cloudflare-one/email-security/investigation/search-email/ 301
-
+# WARP Client rename — file/folder slug renames
+/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp/ /cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/peer-to-peer/ 301
+/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-warp-to-tunnel/ /cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-device-client/ 301
+/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-warp-to-tunnel/ /cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-device-client/ 301
+/cloudflare-one/tutorials/warp-on-headless-linux/ /cloudflare-one/tutorials/deploy-client-headless-linux/ 301
+/cloudflare-wan/zero-trust/warp/ /cloudflare-wan/zero-trust/cloudflare-one-client/ 301
+/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/warp/ /cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/cloudflare-one-client/ 301
# ============================================================================
# DYNAMIC REDIRECTS
@@ -2619,6 +2625,8 @@
/magic-network-monitoring/* /network-flow/:splat 301
# Cloudflare One Client (formerly WARP Client)
+# Splat redirect for renamed posture checks folder
+/cloudflare-one/reusable-components/posture-checks/warp-client-checks/* /cloudflare-one/reusable-components/posture-checks/client-checks/:splat 301
# Splat redirects for renamed sub-folders (most specific first)
/cloudflare-one/team-and-resources/devices/warp/configure-warp/warp-settings/* /cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/:splat 301
/cloudflare-one/team-and-resources/devices/warp/configure-warp/warp-modes/* /cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/:splat 301
diff --git a/src/content/docs/cloudflare-one/access-controls/policies/index.mdx b/src/content/docs/cloudflare-one/access-controls/policies/index.mdx
index 656123e54d9..3504367f97d 100644
--- a/src/content/docs/cloudflare-one/access-controls/policies/index.mdx
+++ b/src/content/docs/cloudflare-one/access-controls/policies/index.mdx
@@ -160,8 +160,8 @@ Non-identity attributes are polled continuously, meaning they are-evaluated with
| SAML Group | Checks a SAML attribute name / value pair. This selector only displays if you use a [generic SAML](/cloudflare-one/integrations/identity-providers/generic-saml/) identity provider. | ✅ | ❌ | ✅ |
| OIDC Claim | Checks an OIDC claim name / value pair. This selector only displays if you use a [generic OIDC](/cloudflare-one/integrations/identity-providers/generic-oidc/) identity provider. | ✅ | ❌ | ✅ |
| Device posture | Checks device posture signals from the Cloudflare One Client or a third-party service provider. This selector only displays after you create a [device posture check](/cloudflare-one/reusable-components/posture-checks/). | ✅ | ✅ | ❌ |
-| Warp | Checks that the device is connected to the Cloudflare One Client, including the consumer version. This selector only displays after you enable the [WARP posture check](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-warp/). | ✅ | ✅ | ❌ |
-| Gateway | Checks that the device is connected to your Zero Trust instance through the Cloudflare One Client. This selector only displays after you enable the [Gateway posture check](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-gateway/). | ✅ | ✅ | ❌ |
+| Warp | Checks that the device is connected to the Cloudflare One Client, including the consumer version. This selector only displays after you enable the [WARP posture check](/cloudflare-one/reusable-components/posture-checks/client-checks/require-warp/). | ✅ | ✅ | ❌ |
+| Gateway | Checks that the device is connected to your Zero Trust instance through the Cloudflare One Client. This selector only displays after you enable the [Gateway posture check](/cloudflare-one/reusable-components/posture-checks/client-checks/require-gateway/). | ✅ | ✅ | ❌ |
1 For SaaS applications, Access can only enforce policies at the time
of initial sign on and when reissuing the SaaS session. Once the user has
diff --git a/src/content/docs/cloudflare-one/data-loss-prevention/dlp-policies/common-policies.mdx b/src/content/docs/cloudflare-one/data-loss-prevention/dlp-policies/common-policies.mdx
index d86a3da3c41..9ca827f67e1 100644
--- a/src/content/docs/cloudflare-one/data-loss-prevention/dlp-policies/common-policies.mdx
+++ b/src/content/docs/cloudflare-one/data-loss-prevention/dlp-policies/common-policies.mdx
@@ -41,7 +41,7 @@ You can configure access on a per-user or group basis by adding [identity-based
Many Android applications (such as Google Drive) use certificate pinning, which is incompatible with Gateway inspection. If needed, you can create a [Do Not Inspect policy](/cloudflare-one/traffic-policies/http-policies/#do-not-inspect) so that the app can continue to function on Android:
-1. Set up an [OS version device posture check](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/os-version/) that checks for the Android operating system.
+1. Set up an [OS version device posture check](/cloudflare-one/reusable-components/posture-checks/client-checks/os-version/) that checks for the Android operating system.
2. Create the following HTTP policy in Gateway:
diff --git a/src/content/docs/cloudflare-one/insights/logs/posture-logs.mdx b/src/content/docs/cloudflare-one/insights/logs/posture-logs.mdx
index 6d3b6daa18d..c4ebe602293 100644
--- a/src/content/docs/cloudflare-one/insights/logs/posture-logs.mdx
+++ b/src/content/docs/cloudflare-one/insights/logs/posture-logs.mdx
@@ -37,7 +37,7 @@ Enterprise users can generate more detailed logs with [Logpush](/cloudflare-one/
| Field | Description |
| ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Name** | Name of the [device posture check](/cloudflare-one/reusable-components/posture-checks/). |
-| **Type** | Type of [Cloudflare One Client check](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/) or [service provider check](/cloudflare-one/integrations/service-providers/). |
+| **Type** | Type of [Cloudflare One Client check](/cloudflare-one/reusable-components/posture-checks/client-checks/) or [service provider check](/cloudflare-one/integrations/service-providers/). |
| **Rule ID** | UUID of the device posture check. |
| **Conditions met** | Whether the device passed or failed the posture check criteria. Evaluates to `true` if the **Received values** match the **Expected values**. |
| **Expected values** | Values required to pass the device posture check. |
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/connect-private-hostname.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/connect-private-hostname.mdx
index da4dea5c064..871929f82af 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/connect-private-hostname.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/connect-private-hostname.mdx
@@ -36,7 +36,7 @@ Private hostname routing only works for applications connected with `cloudflared
| Connector | Compatibility | Minimum version |
| ------------------------------------------------------------------------------------------ | ------------- | -- |
| [cloudflared](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/) | ✅ | 2025.7.0 |
-| [Peer-to-peer](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp/) | ❌ | |
+| [Peer-to-peer](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/peer-to-peer/) | ❌ | |
| [WARP Connector](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/) | ❌ | |
| [Cloudflare WAN](/cloudflare-wan/zero-trust/cloudflare-gateway/) | ❌ | |
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/index.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/index.mdx
index b335147d92c..d59e27c820d 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/index.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/index.mdx
@@ -18,6 +18,6 @@ Administrators can optionally set [Gateway network policies](/cloudflare-one/tra
Here are the different ways you can connect your private network to Cloudflare:
- [**cloudflared**](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/cloudflared/) installs on a server in your private network to create a secure, outbound tunnel to Cloudflare. Cloudflare Tunnel using `cloudflared` only proxies traffic initiated from a user to a server. Any service or application running behind the tunnel will use the server's default routing table for server-initiated connectivity.
-- [**Peer-to-peer**](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp/) uses the [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) to establish peer-to-peer connectivity between two or more devices. Each device running the Cloudflare One Client can access services on any other device running the Cloudflare One Client via an assigned virtual IP address.
+- [**Peer-to-peer**](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/peer-to-peer/) uses the [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) to establish peer-to-peer connectivity between two or more devices. Each device running the Cloudflare One Client can access services on any other device running the Cloudflare One Client via an assigned virtual IP address.
- [**WARP Connector**](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/) installs on a Linux server in your private network to establish site-to-site, bidirectional, and mesh networking connectivity. The WARP Connector acts as a subnet router to relay client-initiated and server-initiated traffic between all devices on a private network and Cloudflare.
- [**Cloudflare WAN**](/cloudflare-one/networks/connectors/cloudflare-wan/) relies on configuring legacy networking equipment to establish anycast GRE or IPsec tunnels between an entire network location and Cloudflare.
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/peer-to-peer.mdx
similarity index 100%
rename from src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp.mdx
rename to src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/peer-to-peer.mdx
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/index.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/index.mdx
index 1a483ae18c7..05577ff248c 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/index.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/index.mdx
@@ -13,5 +13,5 @@ With Cloudflare Zero Trust, you can make your RDP server available over the Inte
Cloudflare offers three ways to secure RDP:
- [Browser-based RDP](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-browser/)
-- [RDP with Cloudflare One Client](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-warp-to-tunnel/)
+- [RDP with Cloudflare One Client](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-device-client/)
- [RDP with client-side cloudflared](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-cloudflared-authentication/)
\ No newline at end of file
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-browser.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-browser.mdx
index 4cab2d67911..01d1581b35c 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-browser.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-browser.mdx
@@ -17,7 +17,7 @@ There are two ways for users to [reach the RDP server in their browser](#4-conne
- **App Launcher (recommended)**: Users can log in to the [Access App Launcher](/cloudflare-one/access-controls/access-settings/app-launcher/) with their Cloudflare Access credentials and then initiate an RDP connection within the browser to their Windows machine. Users will authenticate to the Windows machine using their pre-configured Windows username and password. Cloudflare does not manage any credentials on the Windows server.
- **Direct URL**: A user may also navigate directly to the Windows server at `https:///rdp///`, where `vnet-id` is the virtual network assigned to the Cloudflare Tunnel route. The authentication flow is the same as for the App Launcher; first users must log in to Cloudflare Access and then use their Windows credentials to authenticate to the Windows machine.
-Browser-based RDP can be used in conjunction with [routing over WARP](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-warp-to-tunnel/) so that there are multiple ways to connect to the server. You can reuse the same Cloudflare Tunnel when configuring each connection method.
+Browser-based RDP can be used in conjunction with [routing over WARP](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-device-client/) so that there are multiple ways to connect to the server. You can reuse the same Cloudflare Tunnel when configuring each connection method.
## Prerequisites
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-cloudflared-authentication.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-cloudflared-authentication.mdx
index b94656145b1..abbb44c6eda 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-cloudflared-authentication.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-cloudflared-authentication.mdx
@@ -12,7 +12,7 @@ import { Render } from "~/components";
End users can connect to an RDP server without the Cloudflare One Client by authenticating through `cloudflared` in their native terminal. This method requires having `cloudflared` installed on both the server machine and on the client machine, as well as an active zone on Cloudflare. The traffic is proxied over this connection, and the user logs in to the server with their Cloudflare Access credentials.
-Client-side `cloudflared` can be used in conjunction with [routing over WARP](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-warp-to-tunnel/) and [Browser-based RDP](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-browser/) so that there are multiple ways to connect to the server. You can reuse the same Cloudflare Tunnel when configuring each connection method.
+Client-side `cloudflared` can be used in conjunction with [routing over WARP](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-device-client/) and [Browser-based RDP](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-browser/) so that there are multiple ways to connect to the server. You can reuse the same Cloudflare Tunnel when configuring each connection method.
## 1. Connect the server to Cloudflare
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-warp-to-tunnel.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-device-client.mdx
similarity index 100%
rename from src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-warp-to-tunnel.mdx
rename to src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/rdp/rdp-device-client.mdx
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/index.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/index.mdx
index 27ca438faf7..1a325fbf79a 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/index.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/index.mdx
@@ -49,7 +49,7 @@ Cloudflare offers four ways to secure SSH:
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-browser-rendering.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-browser-rendering.mdx
index 3da5b53452f..94b2cc00cb6 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-browser-rendering.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-browser-rendering.mdx
@@ -14,7 +14,7 @@ Cloudflare's browser-based terminal allows end users to connect to an SSH server
This method requires routing SSH access to the server through a public hostname. The traffic is proxied over this connection, and the user logs in to the server with their Cloudflare Access credentials.
-The browser-based terminal can be used in conjunction with [routing over WARP](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-warp-to-tunnel/) and [Access for Infrastructure](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-infrastructure-access/) so that there are multiple ways to connect to the server. You can reuse the same Cloudflare Tunnel when configuring each connection method.
+The browser-based terminal can be used in conjunction with [routing over WARP](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-device-client/) and [Access for Infrastructure](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-infrastructure-access/) so that there are multiple ways to connect to the server. You can reuse the same Cloudflare Tunnel when configuring each connection method.
## 1. Connect the server to Cloudflare
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-cloudflared-authentication.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-cloudflared-authentication.mdx
index 73ce842ef8f..855bb5bb3b9 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-cloudflared-authentication.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-cloudflared-authentication.mdx
@@ -12,7 +12,7 @@ import { Render } from "~/components";
End users can connect to an SSH server without the Cloudflare One Client by authenticating through `cloudflared` in their native terminal. This method requires having `cloudflared` installed on both the server machine and on the client machine, as well as an active zone on Cloudflare. The traffic is proxied over this connection, and the user logs in to the server with their Cloudflare Access credentials.
-Client-side `cloudflared` can be used in conjunction with [routing over WARP](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-warp-to-tunnel/) and [Access for Infrastructure](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-infrastructure-access/) so that there are multiple ways to connect to the server. You can reuse the same Cloudflare Tunnel when configuring each connection method.
+Client-side `cloudflared` can be used in conjunction with [routing over WARP](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-device-client/) and [Access for Infrastructure](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-infrastructure-access/) so that there are multiple ways to connect to the server. You can reuse the same Cloudflare Tunnel when configuring each connection method.
## 1. Connect the server to Cloudflare
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-warp-to-tunnel.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-device-client.mdx
similarity index 100%
rename from src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-warp-to-tunnel.mdx
rename to src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-device-client.mdx
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-infrastructure-access.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-infrastructure-access.mdx
index b1129a5ec1c..56baf9f99d2 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-infrastructure-access.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-infrastructure-access.mdx
@@ -10,7 +10,7 @@ sidebar:
import { Tabs, TabItem, Badge, Render, APIRequest } from "~/components";
-[Access for Infrastructure](/cloudflare-one/access-controls/applications/non-http/infrastructure-apps/) provides granular control over how users can connect to your SSH servers. This feature uses the same deployment model as [WARP-to-Tunnel](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-warp-to-tunnel/) but unlocks more policy options and command logging functionality.
+[Access for Infrastructure](/cloudflare-one/access-controls/applications/non-http/infrastructure-apps/) provides granular control over how users can connect to your SSH servers. This feature uses the same deployment model as [WARP-to-Tunnel](/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-device-client/) but unlocks more policy options and command logging functionality.
\ No newline at end of file
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/on-ramps.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/on-ramps.mdx
index 0548e294b60..1f38bc9bdf8 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/on-ramps.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/on-ramps.mdx
@@ -18,7 +18,7 @@ import { Render } from "~/components";
thirdPartyURL: "/cloudflare-one/networks/connectors/cloudflare-wan/configuration/manually/third-party/",
cniURL: "/cloudflare-one/networks/connectors/cloudflare-wan/network-interconnect/",
cfTunnelURL: "/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/cloudflare-tunnel/",
- warpURL: "/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/warp/",
+ warpURL: "/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/cloudflare-one-client/",
thirdPartyIntegrationURL: "/cloudflare-one/networks/connectors/cloudflare-wan/configuration/manually/third-party/"
}}
/>
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/cloudflare-gateway.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/cloudflare-gateway.mdx
index 406af50dba3..cbee5965e45 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/cloudflare-gateway.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/cloudflare-gateway.mdx
@@ -13,13 +13,13 @@ import { Render } from "~/components";
product="networking-services"
params={{
gatewayURL: "/cloudflare-one/traffic-policies/",
- warpURL: "/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/warp/",
+ warpURL: "/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/cloudflare-one-client/",
cfAutoCertificatesURL: "/cloudflare-one/team-and-resources/devices/user-side-certificates/automated-deployment/",
cfManualCertificatesURL: "/cloudflare-one/team-and-resources/devices/user-side-certificates/manual-deployment/",
decryptTlsURL: "/cloudflare-one/traffic-policies/http-policies/tls-decryption/",
doNotInspectURL: "/cloudflare-one/traffic-policies/http-policies/#do-not-inspect",
- warpChecksURL: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
- osVersionChecks: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/os-version/",
+ warpChecksURL: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
+ osVersionChecks: "/cloudflare-one/reusable-components/posture-checks/client-checks/os-version/",
mwanOnrampsURL: "/cloudflare-one/networks/connectors/cloudflare-wan/on-ramps/",
gatewayResolverPoliciesURL: "/cloudflare-one/traffic-policies/resolver-policies/",
gatewayInternalDnsURL: "/cloudflare-one/traffic-policies/resolver-policies/#internal-dns",
diff --git a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/warp.mdx b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/cloudflare-one-client.mdx
similarity index 96%
rename from src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/warp.mdx
rename to src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/cloudflare-one-client.mdx
index a77e4699085..aa020effea6 100644
--- a/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/warp.mdx
+++ b/src/content/docs/cloudflare-one/networks/connectors/cloudflare-wan/zero-trust/cloudflare-one-client.mdx
@@ -11,7 +11,7 @@ description: >-
import { Render } from "~/components";
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/application-check.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/application-check.mdx
similarity index 98%
rename from src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/application-check.mdx
rename to src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/application-check.mdx
index da4e2aa17e0..f4c1fbe2380 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/application-check.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/application-check.mdx
@@ -16,7 +16,7 @@ The Application Check device posture attribute checks that a specific applicatio
product="cloudflare-one"
params={{
name: "Cloudflare One Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
+ link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
}}
/>
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/carbon-black.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/carbon-black.mdx
similarity index 95%
rename from src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/carbon-black.mdx
rename to src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/carbon-black.mdx
index 05776d6051d..e6688f964be 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/carbon-black.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/carbon-black.mdx
@@ -17,7 +17,7 @@ Cloudflare One can check if [Carbon Black](https://www.carbonblack.com/) is runn
product="cloudflare-one"
params={{
name: "Cloudflare One Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
+ link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
}}
/>
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/client-certificate.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/client-certificate.mdx
similarity index 100%
rename from src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/client-certificate.mdx
rename to src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/client-certificate.mdx
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/corp-device.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/corp-device.mdx
similarity index 93%
rename from src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/corp-device.mdx
rename to src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/corp-device.mdx
index 4265a81bb0b..956f6bf1e19 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/corp-device.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/corp-device.mdx
@@ -16,7 +16,7 @@ Cloudflare One allows you to build Zero Trust rules based on device serial numbe
product="cloudflare-one"
params={{
name: "Cloudflare One Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
+ link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
}}
/>
@@ -71,4 +71,4 @@ You can use the following commands to check the serial number of your device. Th
### iOS, Android and ChromeOS
-Serial number checks are not supported on mobile devices. You can identify mobile devices by a [unique client ID](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/device-uuid) instead of by serial number.
+Serial number checks are not supported on mobile devices. You can identify mobile devices by a [unique client ID](/cloudflare-one/reusable-components/posture-checks/client-checks/device-uuid) instead of by serial number.
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/device-uuid.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/device-uuid.mdx
similarity index 97%
rename from src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/device-uuid.mdx
rename to src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/device-uuid.mdx
index 29938a2ef24..36b68f9806a 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/device-uuid.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/device-uuid.mdx
@@ -16,7 +16,7 @@ Cloudflare One allows you to build Zero Trust rules based on device UUIDs suppli
product="cloudflare-one"
params={{
name: "Cloudflare One Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
+ link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
}}
/>
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/disk-encryption.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/disk-encryption.mdx
similarity index 97%
rename from src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/disk-encryption.mdx
rename to src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/disk-encryption.mdx
index 1c8d22521c1..63f5bffc4b8 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/disk-encryption.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/disk-encryption.mdx
@@ -19,7 +19,7 @@ The Disk Encryption device posture attribute ensures that disks are encrypted on
product="cloudflare-one"
params={{
name: "Cloudflare One Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
+ link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
}}
/>
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/domain-joined.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/domain-joined.mdx
similarity index 94%
rename from src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/domain-joined.mdx
rename to src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/domain-joined.mdx
index bf088bf9e46..cbc11581562 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/domain-joined.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/domain-joined.mdx
@@ -19,7 +19,7 @@ The Domain Joined device posture attribute ensures that a user is a member of a
product="cloudflare-one"
params={{
name: "Cloudflare One Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
+ link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
}}
/>
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/file-check.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/file-check.mdx
similarity index 72%
rename from src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/file-check.mdx
rename to src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/file-check.mdx
index f217ab35cf3..dedfd613808 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/file-check.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/file-check.mdx
@@ -16,7 +16,7 @@ The File Check device posture attribute checks for the presence of a file on a d
product="cloudflare-one"
params={{
name: "Cloudflare One Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
+ link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
}}
/>
@@ -32,8 +32,8 @@ The File Check device posture attribute checks for the presence of a file on a d
1. **Name**: Enter a unique name for this device posture check.
2. **Operating system**: Select your operating system.
3. **File Path**: Enter a file path (for example, `c:\my folder\myfile.exe`).
- 4. **Signing certificate thumbprint (recommended)**: Enter the [thumbprint](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/application-check/#determine-the-signing-thumbprint) of the publishing certificate used to sign the file. Adding this information will enable the check to ensure that the file was signed by the expected software developer.
- 5. **SHA-256 (optional)**: Enter the [SHA-256 value](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/application-check/#determine-the-sha-256-value) of the file. This is used to ensure the integrity of the file on the device.
+ 4. **Signing certificate thumbprint (recommended)**: Enter the [thumbprint](/cloudflare-one/reusable-components/posture-checks/client-checks/application-check/#determine-the-signing-thumbprint) of the publishing certificate used to sign the file. Adding this information will enable the check to ensure that the file was signed by the expected software developer.
+ 5. **SHA-256 (optional)**: Enter the [SHA-256 value](/cloudflare-one/reusable-components/posture-checks/client-checks/application-check/#determine-the-sha-256-value) of the file. This is used to ensure the integrity of the file on the device.
5. Select **Save**.
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/firewall.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/firewall.mdx
similarity index 96%
rename from src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/firewall.mdx
rename to src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/firewall.mdx
index 1a91f86a2af..d1916644dc0 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/firewall.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/firewall.mdx
@@ -19,7 +19,7 @@ The Firewall device posture attribute ensures that a firewall is running on a de
product="cloudflare-one"
params={{
name: "Cloudflare One Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
+ link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
}}
/>
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/index.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/index.mdx
similarity index 50%
rename from src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/index.mdx
rename to src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/index.mdx
index 0eceb1f5f27..ae9fd69d4c6 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/index.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/index.mdx
@@ -18,18 +18,18 @@ These device posture checks are performed by the [Cloudflare One Client](/cloudf
| Device posture check | macOS | Windows | Linux | iOS | Android/ChromeOS |
| --------------------------------------------------------------------------------------------- | ----- | ------- | ----------- | --- | ---------------- |
-| [Antivirus](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/antivirus/) | ❌ | ✅ | ❌ | ❌ | ❌ |
-| [Application check](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/application-check/) | ✅ | ✅ | ✅ | ❌ | ❌ |
-| [Carbon Black](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/carbon-black/) | ✅ | ✅ | ✅ | ❌ | ❌ |
-| [Client certificate](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/client-certificate/) | ✅ | ✅ | ✅ | ❌ | ❌ |
-| [Device serial numbers](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/corp-device/) | ✅ | ✅ | ✅ | ❌ | ❌ |
-| [Device UUID](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/device-uuid/) | ❌ | ❌ | ❌ | ✅ | ✅ |
-| [Disk encryption](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/disk-encryption/) | ✅ | ✅ | ✅ | ❌ | ❌ |
-| [Domain joined](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/domain-joined/) | ❌ | ✅ | ❌ | ❌ | ❌ |
-| [File check](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/file-check/) | ✅ | ✅ | ✅ | ❌ | ❌ |
-| [Firewall](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/firewall/) | ✅ | ✅ | ❌ | ❌ | ❌ |
-| [OS version](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/os-version/) | ✅ | ✅ | ✅ | ✅ | ✅ |
-| [Require Gateway](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-gateway/) | ✅ | ✅ | ✅ | ✅ | ✅ |
-| [Require WARP](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-warp/) | ✅ | ✅ | ✅ | ✅ | ✅ |
-| [SentinelOne](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/sentinel-one/) | ✅ | ✅ | ✅ | ❌ | ❌ |
-| [Tanium (legacy)](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/tanium/) | ✅ | ✅ | ✅ | ❌ | ❌ |
+| [Antivirus](/cloudflare-one/reusable-components/posture-checks/client-checks/antivirus/) | ❌ | ✅ | ❌ | ❌ | ❌ |
+| [Application check](/cloudflare-one/reusable-components/posture-checks/client-checks/application-check/) | ✅ | ✅ | ✅ | ❌ | ❌ |
+| [Carbon Black](/cloudflare-one/reusable-components/posture-checks/client-checks/carbon-black/) | ✅ | ✅ | ✅ | ❌ | ❌ |
+| [Client certificate](/cloudflare-one/reusable-components/posture-checks/client-checks/client-certificate/) | ✅ | ✅ | ✅ | ❌ | ❌ |
+| [Device serial numbers](/cloudflare-one/reusable-components/posture-checks/client-checks/corp-device/) | ✅ | ✅ | ✅ | ❌ | ❌ |
+| [Device UUID](/cloudflare-one/reusable-components/posture-checks/client-checks/device-uuid/) | ❌ | ❌ | ❌ | ✅ | ✅ |
+| [Disk encryption](/cloudflare-one/reusable-components/posture-checks/client-checks/disk-encryption/) | ✅ | ✅ | ✅ | ❌ | ❌ |
+| [Domain joined](/cloudflare-one/reusable-components/posture-checks/client-checks/domain-joined/) | ❌ | ✅ | ❌ | ❌ | ❌ |
+| [File check](/cloudflare-one/reusable-components/posture-checks/client-checks/file-check/) | ✅ | ✅ | ✅ | ❌ | ❌ |
+| [Firewall](/cloudflare-one/reusable-components/posture-checks/client-checks/firewall/) | ✅ | ✅ | ❌ | ❌ | ❌ |
+| [OS version](/cloudflare-one/reusable-components/posture-checks/client-checks/os-version/) | ✅ | ✅ | ✅ | ✅ | ✅ |
+| [Require Gateway](/cloudflare-one/reusable-components/posture-checks/client-checks/require-gateway/) | ✅ | ✅ | ✅ | ✅ | ✅ |
+| [Require WARP](/cloudflare-one/reusable-components/posture-checks/client-checks/require-warp/) | ✅ | ✅ | ✅ | ✅ | ✅ |
+| [SentinelOne](/cloudflare-one/reusable-components/posture-checks/client-checks/sentinel-one/) | ✅ | ✅ | ✅ | ❌ | ❌ |
+| [Tanium (legacy)](/cloudflare-one/reusable-components/posture-checks/client-checks/tanium/) | ✅ | ✅ | ✅ | ❌ | ❌ |
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/os-version.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/os-version.mdx
similarity index 98%
rename from src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/os-version.mdx
rename to src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/os-version.mdx
index 09196c178cc..c6f5a66910b 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/os-version.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/os-version.mdx
@@ -16,7 +16,7 @@ The OS Version device posture attribute checks whether the version of a device's
product="cloudflare-one"
params={{
name: "Cloudflare One Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
+ link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
}}
/>
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-gateway.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/require-gateway.mdx
similarity index 75%
rename from src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-gateway.mdx
rename to src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/require-gateway.mdx
index 3c98c7ac716..27f11840753 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-gateway.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/require-gateway.mdx
@@ -10,7 +10,7 @@ head:
import { Render } from "~/components";
-With Require Gateway, you can allow access to your applications only to devices enrolled in your Zero Trust organization. Unlike [Require WARP](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-warp/), which will check for any WARP instance (including the consumer version), Require Gateway will only allow requests coming from devices whose traffic is filtered by your organization's Cloudflare Gateway configuration. This policy is best used when you want to protect company-owned assets by only allowing access to employees.
+With Require Gateway, you can allow access to your applications only to devices enrolled in your Zero Trust organization. Unlike [Require WARP](/cloudflare-one/reusable-components/posture-checks/client-checks/require-warp/), which will check for any WARP instance (including the consumer version), Require Gateway will only allow requests coming from devices whose traffic is filtered by your organization's Cloudflare Gateway configuration. This policy is best used when you want to protect company-owned assets by only allowing access to employees.
## Prerequisites
@@ -19,7 +19,7 @@ With Require Gateway, you can allow access to your applications only to devices
product="cloudflare-one"
params={{
name: "Cloudflare One Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
+ link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
}}
/>
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-warp.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/require-warp.mdx
similarity index 95%
rename from src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-warp.mdx
rename to src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/require-warp.mdx
index 8d82ff48df2..d0f5e1aa76d 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/require-warp.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/require-warp.mdx
@@ -25,7 +25,7 @@ Cloudflare One enables you to restrict access to your applications to devices ru
product="cloudflare-one"
params={{
name: "Cloudflare One Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
+ link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
}}
/>
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/sentinel-one.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/sentinel-one.mdx
similarity index 96%
rename from src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/sentinel-one.mdx
rename to src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/sentinel-one.mdx
index 6e0bb9a69fe..513e4b6a9bf 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/sentinel-one.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/sentinel-one.mdx
@@ -20,7 +20,7 @@ Cloudflare One can check if [SentinelOne](https://www.sentinelone.com/) is runni
product="cloudflare-one"
params={{
name: "Cloudflare One Client Checks",
- link: "/cloudflare-one/reusable-components/posture-checks/warp-client-checks/",
+ link: "/cloudflare-one/reusable-components/posture-checks/client-checks/",
}}
/>
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/tanium.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/tanium.mdx
similarity index 100%
rename from src/content/docs/cloudflare-one/reusable-components/posture-checks/warp-client-checks/tanium.mdx
rename to src/content/docs/cloudflare-one/reusable-components/posture-checks/client-checks/tanium.mdx
diff --git a/src/content/docs/cloudflare-one/reusable-components/posture-checks/index.mdx b/src/content/docs/cloudflare-one/reusable-components/posture-checks/index.mdx
index c9fcd3b7b4c..4c1a1de0d3b 100644
--- a/src/content/docs/cloudflare-one/reusable-components/posture-checks/index.mdx
+++ b/src/content/docs/cloudflare-one/reusable-components/posture-checks/index.mdx
@@ -13,7 +13,7 @@ With Cloudflare Zero Trust, you can configure Zero Trust policies that rely on a
Setup instructions and requirements vary depending on the device posture attribute. Refer to the links below to view the setup guide for your provider.
-- [Cloudflare One Client checks](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/) are performed by the Cloudflare One Client.
+- [Cloudflare One Client checks](/cloudflare-one/reusable-components/posture-checks/client-checks/) are performed by the Cloudflare One Client.
- [Service-to-service checks](/cloudflare-one/integrations/service-providers/) are performed by third-party device posture providers.
- [Access integration checks](/cloudflare-one/reusable-components/posture-checks/access-integrations/) are only configurable for Access applications. These attributes cannot be used in Gateway policies.
@@ -32,12 +32,12 @@ You can now use your device posture check in an [Access policy](/cloudflare-one/
:::caution[Gateway policy limitation]
-Gateway does not support device posture checks for the [Tanium Access integration](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/tanium/).
+Gateway does not support device posture checks for the [Tanium Access integration](/cloudflare-one/reusable-components/posture-checks/client-checks/tanium/).
:::
## 4. Ensure traffic is going through the Cloudflare One Client
-[Cloudflare One Client](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/) and [service-to-service](/cloudflare-one/integrations/service-providers/) posture checks rely on traffic going through the Cloudflare One Client to detect posture information for a device. In your [Split Tunnel configuration](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/), ensure that the following domains are included in the Cloudflare One Client:
+[Cloudflare One Client](/cloudflare-one/reusable-components/posture-checks/client-checks/) and [service-to-service](/cloudflare-one/integrations/service-providers/) posture checks rely on traffic going through the Cloudflare One Client to detect posture information for a device. In your [Split Tunnel configuration](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/), ensure that the following domains are included in the Cloudflare One Client:
- The IdP used to authenticate to Cloudflare Zero Trust if posture check is part of an Access policy.
- `.cloudflareaccess.com` if posture check is part of an Access policy.
diff --git a/src/content/docs/cloudflare-one/setup/replace-vpn/device-to-device.mdx b/src/content/docs/cloudflare-one/setup/replace-vpn/device-to-device.mdx
index 73f5ca34bfd..f6c28cad4d6 100644
--- a/src/content/docs/cloudflare-one/setup/replace-vpn/device-to-device.mdx
+++ b/src/content/docs/cloudflare-one/setup/replace-vpn/device-to-device.mdx
@@ -21,7 +21,7 @@ This guide follows the same steps as the **Get Started** onboarding wizard in th
## How it works
-The [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) is an app that you install on each device you want to connect. When you sign in to your Cloudflare account through the Cloudflare One Client (called "enrolling"), each device is assigned a [virtual IP address](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp/).
+The [Cloudflare One Client](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/) is an app that you install on each device you want to connect. When you sign in to your Cloudflare account through the Cloudflare One Client (called "enrolling"), each device is assigned a [virtual IP address](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/peer-to-peer/).
Devices use these virtual IPs to communicate with each other through Cloudflare's network. This works for most common types of network traffic, including web requests, remote desktop, file sharing, and ping.
@@ -91,6 +91,6 @@ For in-depth guidance on policy design and device posture checks, refer to the [
If you have issues connecting, try these steps:
-- **Windows users**: Windows Firewall blocks device-to-device traffic by default. You may need to add a firewall rule that allows incoming traffic from `100.96.0.0/12`. For details, refer to [Peer-to-peer connectivity](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp/#troubleshooting).
+- **Windows users**: Windows Firewall blocks device-to-device traffic by default. You may need to add a firewall rule that allows incoming traffic from `100.96.0.0/12`. For details, refer to [Peer-to-peer connectivity](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/peer-to-peer/#troubleshooting).
- [Troubleshoot WARP](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/): resolve Cloudflare One Client connection and enrollment issues.
-- [Peer-to-peer connectivity](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp/): review Peer-to-peer setup details and firewall requirements.
+- [Peer-to-peer connectivity](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/peer-to-peer/): review Peer-to-peer setup details and firewall requirements.
diff --git a/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-ips.mdx b/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-ips.mdx
index db047ec5c4d..9cfb08c6de3 100644
--- a/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-ips.mdx
+++ b/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-ips.mdx
@@ -26,7 +26,7 @@ import { Render, Details } from "~/components";
-A device IP identifies and routes traffic to a specific device in your Zero Trust organization. When a user registers the Cloudflare One Client (formerly WARP), Cloudflare assigns a virtual IPv4 and IPv6 address to the [device registration](/cloudflare-one/team-and-resources/devices/device-registration/). The Cloudflare One Client uses these IP addresses to create a [virtual network interface](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/client-architecture/#ip-traffic) on the device, which allows your private network to reach the device via [WARP-to-WARP](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp/), [WARP Connector](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/), or [Cloudflare WAN](/cloudflare-one/networks/connectors/cloudflare-wan/) on-ramps.
+A device IP identifies and routes traffic to a specific device in your Zero Trust organization. When a user registers the Cloudflare One Client (formerly WARP), Cloudflare assigns a virtual IPv4 and IPv6 address to the [device registration](/cloudflare-one/team-and-resources/devices/device-registration/). The Cloudflare One Client uses these IP addresses to create a [virtual network interface](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/client-architecture/#ip-traffic) on the device, which allows your private network to reach the device via [WARP-to-WARP](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/peer-to-peer/), [WARP Connector](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/), or [Cloudflare WAN](/cloudflare-one/networks/connectors/cloudflare-wan/) on-ramps.
You can verify device IPs and, if needed, reconfigure address pools to avoid overlapping IPs with existing internal resources.
diff --git a/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-profiles.mdx b/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-profiles.mdx
index e89d240c6a6..1a48aeb63d0 100644
--- a/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-profiles.mdx
+++ b/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-profiles.mdx
@@ -186,7 +186,7 @@ Apply a device profile based on the operating system of the device.
### Operating system version
-Apply a device profile based on the [OS version](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/os-version/#determine-the-os-version) of the device.
+Apply a device profile based on the [OS version](/cloudflare-one/reusable-components/posture-checks/client-checks/os-version/#determine-the-os-version) of the device.
| UI name | API example |
| ------------------------ | ------------------------- |
diff --git a/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/device-information-only.mdx b/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/device-information-only.mdx
index 6cf715f7b68..3d89d2d6927 100644
--- a/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/device-information-only.mdx
+++ b/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/device-information-only.mdx
@@ -120,7 +120,7 @@ To block traffic from devices that do not have a valid client certificate:
| Hostname | equals | `app.mycompany.com` | | |
5. Select **Deploy**.
-Posture only mode is now enabled on the device. To start enforcing device posture, set up a [WARP client check](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/) and add a _Require_ device posture rule to your [Access policy](/cloudflare-one/access-controls/policies/). When the device connects to the Access application for the first time, the browser will ask to use the client certificate installed by the Cloudflare One Client.
+Posture only mode is now enabled on the device. To start enforcing device posture, set up a [WARP client check](/cloudflare-one/reusable-components/posture-checks/client-checks/) and add a _Require_ device posture rule to your [Access policy](/cloudflare-one/access-controls/policies/). When the device connects to the Access application for the first time, the browser will ask to use the client certificate installed by the Cloudflare One Client.
 for zones in your account. To set up Posture only mode, refer to the [dedicated page](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/device-information-only/).
+Use when you only want to enforce [Cloudflare One Client device posture checks](/cloudflare-one/reusable-components/posture-checks/client-checks/) for zones in your account. To set up Posture only mode, refer to the [dedicated page](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/modes/device-information-only/).
| DNS filtering | Network filtering | HTTP filtering | Features enabled |
| ------------- | ----------------- | -------------- | ------------------------------------------------------------------------------------ |
diff --git a/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/index.mdx b/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/index.mdx
index 850b355786b..df923886909 100644
--- a/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/index.mdx
+++ b/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/index.mdx
@@ -144,12 +144,12 @@ The IP assigned to a device is permanent until the device unregisters from your
-Allows traffic on-ramped using [WARP-to-WARP](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp/), [WARP Connector](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/), or [Cloudflare WAN](/cloudflare-one/networks/connectors/cloudflare-wan/) to route to devices enrolled in your Zero Trust organization.
+Allows traffic on-ramped using [WARP-to-WARP](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/peer-to-peer/), [WARP Connector](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/), or [Cloudflare WAN](/cloudflare-one/networks/connectors/cloudflare-wan/) to route to devices enrolled in your Zero Trust organization.
Each device is assigned a virtual IP address in the CGNAT IP space (`100.96.0.0/12`) or a [custom device IP range](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/device-ips/). With this setting `Enabled`, users on your private network will be able to connect to these device IPs and access [TCP, UDP, and/or ICMP-based services](/cloudflare-one/traffic-policies/proxy/) on your devices. You can create [Gateway network policies](/cloudflare-one/traffic-policies/network-policies/) to control which users and devices can access the device IPs.
:::note
-Ensure that traffic destined to your device IPs routes from your private network to Cloudflare Gateway. For example, if you are making a [WARP-to-WARP](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp/) connection, you must configure your [Split Tunnel settings](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/) so that traffic to your device IPs routes through the WARP tunnel.
+Ensure that traffic destined to your device IPs routes from your private network to Cloudflare Gateway. For example, if you are making a [WARP-to-WARP](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/peer-to-peer/) connection, you must configure your [Split Tunnel settings](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/route-traffic/split-tunnels/) so that traffic to your device IPs routes through the WARP tunnel.
:::
## Global disconnection settings
@@ -177,7 +177,7 @@ Ensure that traffic destined to your device IPs routes from your private network
Requires the [Super Administrator](/cloudflare-one/roles-permissions/) role.
:::
-**Disconnect WARP on all devices** allows administrators to fail open the Cloudflare One Client in case of an incident occurring in your environment, independent from incidents or outages affecting Cloudflare's services. When you turn on **Disconnect WARP on all devices**, Cloudflare will disconnect all Windows, macOS, and Linux Cloudflare One Clients that are connected to your Zero Trust organization. This includes end user devices, [WARP Connector](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/) hosts, and [WARP-to-WARP](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-to-warp/) devices. End users will receive a notification on their device and the Cloudflare One Client will display [`Admin directed disconnect`](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/client-errors/#admin-directed-disconnect).
+**Disconnect WARP on all devices** allows administrators to fail open the Cloudflare One Client in case of an incident occurring in your environment, independent from incidents or outages affecting Cloudflare's services. When you turn on **Disconnect WARP on all devices**, Cloudflare will disconnect all Windows, macOS, and Linux Cloudflare One Clients that are connected to your Zero Trust organization. This includes end user devices, [WARP Connector](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/warp-connector/) hosts, and [WARP-to-WARP](/cloudflare-one/networks/connectors/cloudflare-tunnel/private-net/peer-to-peer/) devices. End users will receive a notification on their device and the Cloudflare One Client will display [`Admin directed disconnect`](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/client-errors/#admin-directed-disconnect).
To resume normal operations, turn off **Disconnect WARP on all devices**. The Cloudflare One Client will automatically reconnect.
diff --git a/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/index.mdx b/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/index.mdx
index f4d9f0b64fe..0f906b7f1ad 100644
--- a/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/index.mdx
+++ b/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/index.mdx
@@ -157,7 +157,7 @@ The Cloudflare One Client for Linux allows for an automated install via the pres
Refer to [deployment parameters](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/parameters/) for a list of accepted arguments.
-To learn how to automate Cloudflare One Client deployment on headless servers, refer to our [tutorial](/cloudflare-one/tutorials/warp-on-headless-linux/).
+To learn how to automate Cloudflare One Client deployment on headless servers, refer to our [tutorial](/cloudflare-one/tutorials/deploy-client-headless-linux/).
## iOS
diff --git a/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/parameters.mdx b/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/parameters.mdx
index 9f787112bac..ecb7fc9bb41 100644
--- a/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/parameters.mdx
+++ b/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/parameters.mdx
@@ -344,7 +344,7 @@ This parameter replaces the old `enabled` property, which can no longer be used
Only valid for iOS and Android/ChromeOS.
:::
-Assigns a unique identifier to the device for the [device UUID posture check](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/device-uuid).
+Assigns a unique identifier to the device for the [device UUID posture check](/cloudflare-one/reusable-components/posture-checks/client-checks/device-uuid).
**Value Type:** `string`
diff --git a/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/partners/intune.mdx b/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/partners/intune.mdx
index 04a44d75c78..bedcbf31235 100644
--- a/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/partners/intune.mdx
+++ b/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/partners/intune.mdx
@@ -442,7 +442,7 @@ By completing this step, you preconfigure the Cloudflare One Agent with your [Ze
### Intune configuration
-Intune allows you to insert [predefined variables](https://learn.microsoft.com/en-us/mem/intune/apps/app-configuration-policies-use-ios#tokens-used-in-the-property-list) into the XML configuration file. For example, you can set the [`unique_client_id`](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/parameters/#unique_client_id) key to `{{deviceid}}` for a [device UUID posture check](/cloudflare-one/reusable-components/posture-checks/warp-client-checks/device-uuid/) deployment.
+Intune allows you to insert [predefined variables](https://learn.microsoft.com/en-us/mem/intune/apps/app-configuration-policies-use-ios#tokens-used-in-the-property-list) into the XML configuration file. For example, you can set the [`unique_client_id`](/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/parameters/#unique_client_id) key to `{{deviceid}}` for a [device UUID posture check](/cloudflare-one/reusable-components/posture-checks/client-checks/device-uuid/) deployment.
### Per-app VPN for iOS
diff --git a/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/diagnostic-logs.mdx b/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/diagnostic-logs.mdx
index d347e393e6b..7ab7e957d59 100644
--- a/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/diagnostic-logs.mdx
+++ b/src/content/docs/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/diagnostic-logs.mdx
@@ -113,7 +113,7 @@ The `warp-debugging-info--