Cloudflare One and SASE fundamentals

Secure Access Service Edge (SASE) combines network connectivity and security controls in a cloud-delivered platform. Cloudflare publishes this material openly through its Learning Center, product pages and developer learning paths.

Core components

ComponentPurpose
ZTNA — Zero Trust Network AccessIdentity- and context-based access to individual applications instead of broad network-level VPN access.
SWG — Secure Web GatewayInspects Internet traffic, blocks threats and enforces browsing policy.
RBI — Remote Browser IsolationRuns active web content remotely to isolate endpoints from browser-borne threats.
Cloud Email SecurityDetects phishing, impersonation and other email threats before delivery.
CASB — Cloud Access Security BrokerProvides visibility and controls for SaaS and cloud-service use, including security posture and sensitive data.
DLP — Data Loss PreventionIdentifies sensitive information in traffic and helps prevent unauthorised disclosure.
SD-WAN / NaaS — Network as a ServiceConnects sites and routes traffic across available network paths.
FWaaS — Firewall as a ServiceApplies centrally managed firewall policy from a cloud service.

Public Cloudflare learning material

  1. The evolution of corporate networks
  2. Stop hosting your own VPN service
  3. Secure remote access to critical infrastructure
  4. Connect and secure from any network to anywhere
  5. Protect users from Internet risks

Further public references

Related public learning paths

Cloudflare also publishes focused learning paths, including a WARP overview course.

version 1  ·  created 2026-09-17  ·  updated 2026-09-17  ·  tags cloudflare, sase, zero-trust, network-security, public-reference