← Back to demos
🔒

Zero Trust Access + Tunnel

A private corporate intranet with no public IP, accessible only through identity-verified Cloudflare Access.

The Scenario

Imagine you work at a company that runs an internal dashboard on a server in the office. The server has no public IP address — it's completely invisible from the internet.

Remote employees need to access it, but the company doesn't want to set up a VPN. Instead, they use Cloudflare Tunnel to create a secure outbound connection from the private server to Cloudflare's edge, and Cloudflare Access to verify every user's identity before letting them through.

Key Concept

Cloudflare Tunnel creates an outbound connection from your private network to Cloudflare. No inbound firewall rules, no public IP, no VPN. Access adds identity verification at the edge.

Architecture

💻

Remote Employee

VM 2: Browser

Any internet connection

→ HTTPS →
☁️

Cloudflare Edge

DNS + Access Auth

Identity verification

→ Tunnel →
🖥️

Corporate Server

VM 1: Private IP

No public access

What You Need

Step-by-Step Setup

1

Prepare VM 1 — The Corporate Server

Install Ubuntu Server in UTM with Shared Network (NAT). This gives it internet access but keeps it private — no public IP, no port forwarding.

# Check your private IP ip addr show # Should show something like 10.0.0.5/24

Install Python and create a simple Flask app on port 8080.

2

Install cloudflared

cloudflared is the lightweight agent that creates the secure tunnel from your private network to Cloudflare.

# Download (ARM64 for Apple Silicon) curl -L --output cloudflared.deb \ https://github.com/cloudflare/cloudflared/releases/latest/download/cloudflared-linux-arm64.deb # Install sudo dpkg -i cloudflared.deb # Authenticate with your Cloudflare account cloudflared tunnel login # Opens browser — authorize and select your domain
3

Create and Configure the Tunnel

# Create a named tunnel cloudflared tunnel create corporate-intranet # Configure it cat > ~/.cloudflared/config.yml << 'EOF' tunnel: YOUR-TUNNEL-UUID credentials-file: /home/YOUR-USER/.cloudflared/YOUR-TUNNEL-UUID.json ingress: - hostname: intranet.YOUR-DOMAIN.com service: http://localhost:8080 - service: http_status:404 EOF # Route DNS to the tunnel cloudflared tunnel route dns corporate-intranet intranet.YOUR-DOMAIN.com

This creates a CNAME record in your Cloudflare DNS pointing to the tunnel.

4

Run the Tunnel

cloudflared tunnel run corporate-intranet

You should see "Connection registered." Now anyone on the internet can reach your private app (we'll lock it down next).

5

Add Cloudflare Access Protection

Go to Cloudflare One Dashboard:

  1. Navigate to Access → Applications
  2. Click Add an application
  3. Type: Self-hosted
  4. Application name: Corporate Intranet
  5. Domain: intranet.YOUR-DOMAIN.com
  6. Session duration: 24 hours
  7. Create policy: Allow → Include → Emails → your email
  8. Add the application
6

Test the Full Flow

On VM 2 (the remote employee), open a browser and visit:

https://intranet.YOUR-DOMAIN.com

You should see the Cloudflare Access login page. After authenticating with your email, you'll see the private corporate dashboard.

Try from an unauthorized email — Access will block them.

7

Make It Persistent

Run cloudflared and your app as system services so they survive reboots.

# Install cloudflared as a service sudo cloudflared service install sudo systemctl start cloudflared sudo systemctl enable cloudflared # Create a systemd service for your Flask app sudo systemctl start intranet-app sudo systemctl enable intranet-app

What You Learned

No Public IP Needed

The server stays completely private. All traffic flows through Cloudflare's edge.

Identity-First Security

Every request is authenticated. No VPN credentials to steal, no network perimeter to breach.

Granular Policies

Allow by email, group, IP address, country, or device posture. Different apps, different rules.

Audit Everything

Cloudflare logs every authentication attempt — who, when, from where, and whether they were allowed.

Live Status Check

This checks whether your current connection is going through Cloudflare's network:

Checking...

Look for the CF-RAY header in network responses to confirm traffic is going through Cloudflare.

Next: Gateway DNS Filtering

Once you have WARP installed on VM 2, we'll configure Cloudflare Gateway to block malicious sites at the DNS layer — before any connection is even made.

Go to Gateway DNS demo →