- You have a Cloudflare account
- You have a server / service you wish to expose via the tunnel
Settings Panel
This section covers the following six areas:- Account - This is mainly for billing
- General - This covers some core settings, e.g. branding and domains
- Network - This covers Gateway network settings, e.g. filtering, exclusions and some firewall settings
- Authentication - This is where we configure our IdP, e.g. Azure AD, Auth0, Discord etc
- Warp Client - This covers Warp client agent settings
- Download - Public download links for agents, SSL Inspection Root CA Certs etc
Account
If you’re in this page you’re most likely looking for active user seat duration, this is the bottom setting and defines how long a user remains within your ‘Users’ tab after leaving the organisation. By default we use ‘2 months’, the Cloudflare default at the time of writing is ‘3’.General
The most important setting to note here is ‘Team Site’ URL, you can use this setting to view a central login dashboard with all of your Cloudflare tunnelled applications in one place. :::note While you can implement a domain / url redirect for your cloudflareaccess.com subdomain you cannot implement a custom domain via cname at this time. ::: The block page is part of Gateway so won’t be used in this tutorial but the login page is so feel free to edit the colours, logos and any text you want displayed on the login page.Network
The only settings we turned on are:- Gateway: Exclude PII
- Firewall: Proxy (UDP & TCP Traffic)