
Technology
SecurityCloudflare
DNS, CDN, WAF, and Zero Trust access at the network edge
What it is
Cloudflare is an edge network platform that combines DNS, CDN, a web application firewall (WAF), DDoS protection, and Zero Trust access (Cloudflare Access and Tunnel) to expose internal applications without opening ports to the internet. It's one of the tools we use within DITAP Security to protect public sites and remote access.
We use it as a complementary layer to the traditional firewalls we implement at DITAP Security: it protects what faces the internet, while the perimeter firewall protects the client's internal network.
When we recommend it
We recommend Cloudflare when:
- The client has a public site or app that needs protection against DDoS attacks and application-layer malicious traffic.
- A remote team needs access to internal applications without relying on a full traditional VPN.
- The goal is to reduce latency for a geographically distributed user base by leveraging the global edge network.
- There's a need to shield the client's real infrastructure origin from what the internet sees, as an added layer of perimeter security.
- DNS and SSL/TLS certificates need centralized management across multiple subdomains or client properties.
How we implement it
Our Cloudflare implementation includes:
- DNS migration and record configuration with minimal downtime window.
- WAF rule tuning specific to the client's application, not just the default rule set.
- Cloudflare Access configuration with identity policies (integrated with the client's identity provider) and Tunnel to expose internal services securely.
- Ongoing traffic monitoring and rule tuning as abuse patterns are detected.
- Periodic review of SSL/TLS certificates and caching rule configuration to optimize site performance.
Alternatives
Cloudflare isn't the only perimeter security layer we implement:
Traditional firewall / appliance (Fortinet)
a better fit when full control of the physical perimeter and site-to-site VPN are needed, not just web application protection.
AWS CloudFront + Shield
a more integrated alternative when all of the client's infrastructure already lives on AWS.
Google Cloud Armor
a natural choice when the rest of the client's workload already runs on Google Cloud Platform.
DITAP is not an official partner of this vendor and holds no certification or exclusive commercial agreement with it. This page describes our real implementation experience on client projects.
Need to implement or migrate this at your company?
Let's talk about your specific case — site, number of users, budget — and we'll tell you honestly whether this is the right technology.