Skip to content

Commit 1238698

Browse files
committed
MFW-2327: Document MFW changes on moving to Unified Routing
1 parent fc68ee5 commit 1238698

2 files changed

Lines changed: 44 additions & 2 deletions

File tree

Lines changed: 41 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
1+
---
2+
title: Unified Routing behavior changes
3+
pcx_content_type: concept
4+
description: Rule behavior differences for Cloudflare Network Firewall accounts moving from Legacy Routing to Unified Routing.
5+
products:
6+
- cloudflare-network-firewall
7+
---
8+
9+
Cloudflare Network Firewall rules can behave differently depending on whether your account uses Legacy Routing or [Unified Routing](/magic-transit/reference/traffic-steering/#unified-routing-mode). Review the following changes before you upgrade to Unified Routing.
10+
11+
## `ip.geoip.country`
12+
13+
The `ip.geoip.country` field is no longer supported on Unified Routing. Rewrite any rule that uses `ip.geoip.country` with the [`ip.src.country` and `ip.dst.country`](/cloudflare-network-firewall/reference/network-firewall-fields/#ipsrccountry) fields instead.
14+
15+
| Match type | Rule using `ip.geoip.country` | Equivalent rule |
16+
| --------------- | ------------------------------------------ | ------------------------------------------------------------------------- |
17+
| Equals | `ip.geoip.country eq "US"` | `ip.src.country eq "US" or ip.dst.country eq "US"` |
18+
| Does not equal | `ip.geoip.country ne "US"` | `ip.src.country ne "US" and ip.dst.country ne "US"` |
19+
| In a list | `ip.geoip.country in {"UK" "FR"}` | `ip.src.country in {"UK" "FR"} or ip.dst.country in {"UK" "FR"}` |
20+
| Not in a list | `not ip.geoip.country in {"UK" "FR"}` | `not ip.src.country in {"UK" "FR"} and not ip.dst.country in {"UK" "FR"}` |
21+
22+
## Rule evaluation for L3 traffic
23+
24+
Legacy Routing has limited support for L3 protocols. IPv6 support is limited to the `ip.src` and `ip.dst` fields. A rule is either exclusively applied to IPv4 packets or exclusively applied to IPv6 packets, based on the address family of the literal used in the rule.
25+
26+
On Unified Routing, as a first step to supporting IPv6 more broadly, a rule like this is also evaluated against IPv4 traffic.
27+
28+
| Rule | Routing mode | Behavior for IPv4 | Behavior for IPv6 |
29+
| --------------------- | ------------ | --------------------------- | -------------------------------------------------- |
30+
| `ip.src ne fe80::/64` | Legacy | IPv4 packets skip this rule | Matches for all traffic not sourced from fe80::/64 |
31+
| `ip.src ne fe80::/64` | Unified | Matches for all traffic | Matches for all traffic not sourced from fe80::/64 |
32+
33+
To restrict the rule to only match IPv6 traffic, update the expression to `ip.src in {::/0} and ip.src ne fe80::/64`.
34+
35+
IPv6 behavior is unchanged from Legacy Routing.
36+
37+
## Rule evaluation for L4 traffic
38+
39+
On Legacy Routing, the L4 protocol is inferred from the expression and only applied to packets of that protocol. `tcp.srcport eq 80` and `tcp.srcport ne 80` both apply only to TCP traffic. Packets of other protocols, for example UDP, will not match the expression.
40+
41+
On Unified Routing, Cloudflare Network Firewall does not infer the protocol, and rules must specify a protocol in the expression explicitly. `tcp.srcport eq 80` still only applies to TCP traffic, but `tcp.srcport ne 80` now matches both TCP and UDP traffic. To restrict the rule to only match TCP traffic, update the expression to `ip.proto eq "tcp" and tcp.srcport eq 80`.

‎src/content/docs/cloudflare-wan/reference/traffic-steering.mdx‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -250,8 +250,9 @@ Before upgrading, establish a Legacy Routing baseline and run a controlled Unifi
250250
If your account uses Legacy Routing, follow these steps to upgrade:
251251

252252
1. Evaluate Unified Routing features and performance against your current needs. Review the [routing mode comparison](#compare-routing-modes), [feature availability](#check-feature-availability-before-upgrading), and [performance guidance](#evaluate-performance).
253-
2. Identify suitable times for the upgrade. During the upgrade, Cloudflare One Client users can experience a remote access outage of up to three minutes.
254-
3. Contact your account team to request the change and provide a range of acceptable times.
253+
2. If you use Cloudflare Network Firewall, review [Unified Routing behavior changes](/cloudflare-network-firewall/about/unified-routing-changes/) and update any affected rules.
254+
3. Identify suitable times for the upgrade. During the upgrade, Cloudflare One Client users can experience a remote access outage of up to three minutes.
255+
4. Contact your account team to request the change and provide a range of acceptable times.
255256

256257
<AnchorHeading depth={2} title="Route evaluation with Zero Trust connections" />
257258

0 commit comments

Comments
 (0)