Zero Trust Access + Tunnel
A private corporate intranet with no public IP, accessible only through identity-verified Cloudflare Access.
The Scenario
Imagine you work at a company that runs an internal dashboard on a server in the office. The server has no public IP address — it's completely invisible from the internet.
Remote employees need to access it, but the company doesn't want to set up a VPN. Instead, they use Cloudflare Tunnel to create a secure outbound connection from the private server to Cloudflare's edge, and Cloudflare Access to verify every user's identity before letting them through.
Key Concept
Cloudflare Tunnel creates an outbound connection from your private network to Cloudflare. No inbound firewall rules, no public IP, no VPN. Access adds identity verification at the edge.
Architecture
Remote Employee
VM 2: Browser
Any internet connection
Cloudflare Edge
DNS + Access Auth
Identity verification
Corporate Server
VM 1: Private IP
No public access
What You Need
- ✓ UTM with 2 VMs (or any virtualization): Ubuntu Server (VM 1) + any OS (VM 2). New to UTM? See the detailed UTM setup guide with step-by-step screenshots.
-
✓
A domain managed in Cloudflare DNS (e.g.,
joanazevedo.com) - ✓ Cloudflare account with Cloudflare One enabled (free tier)
- ✓ About 2-3 hours for first-time setup
Step-by-Step Setup
Prepare VM 1 — The Corporate Server
Install Ubuntu Server in UTM with Shared Network (NAT). This gives it internet access but keeps it private — no public IP, no port forwarding.
Install Python and create a simple Flask app on port 8080.
Install cloudflared
cloudflared is the lightweight agent that creates the secure tunnel from your
private network to Cloudflare.
Create and Configure the Tunnel
This creates a CNAME record in your Cloudflare DNS pointing to the tunnel.
Run the Tunnel
You should see "Connection registered." Now anyone on the internet can reach your private app (we'll lock it down next).
Add Cloudflare Access Protection
Go to Cloudflare One Dashboard:
- Navigate to Access → Applications
- Click Add an application
- Type: Self-hosted
- Application name: Corporate Intranet
- Domain:
intranet.YOUR-DOMAIN.com - Session duration: 24 hours
- Create policy: Allow → Include → Emails → your email
- Add the application
Test the Full Flow
On VM 2 (the remote employee), open a browser and visit:
You should see the Cloudflare Access login page. After authenticating with your email, you'll see the private corporate dashboard.
Try from an unauthorized email — Access will block them.
Make It Persistent
Run cloudflared and your app as system services so they survive reboots.
What You Learned
No Public IP Needed
The server stays completely private. All traffic flows through Cloudflare's edge.
Identity-First Security
Every request is authenticated. No VPN credentials to steal, no network perimeter to breach.
Granular Policies
Allow by email, group, IP address, country, or device posture. Different apps, different rules.
Audit Everything
Cloudflare logs every authentication attempt — who, when, from where, and whether they were allowed.
Live Status Check
This checks whether your current connection is going through Cloudflare's network:
Checking...
Look for the CF-RAY header in network responses to confirm traffic is going through Cloudflare.
Next: Gateway DNS Filtering
Once you have WARP installed on VM 2, we'll configure Cloudflare Gateway to block malicious sites at the DNS layer — before any connection is even made.
Go to Gateway DNS demo →