Skip to content

Cloud on-ramps

Magic Cloud Networking (beta) allows you to create on-ramps from your cloud networks to Magic WAN. Cloudflare will create virtual private network (VPN) tunnels between Magic WAN and your virtual private cloud (VPC), configuring both sides of the connection on your behalf. Cloudflare orchestrates the cloud provider's native VPN functionality, without requiring deployment of any additional compute virtual machines (VMs).

Prerequisites

Before creating on-ramps from your cloud networks to Magic WAN, make sure you:

  • Have a Magic WAN account. Contact your account team to learn more.
  • Went through process of setting up your cloud provider.
  • Have the correct cloud resources. Refer to Reference to check resource by cloud provider.

Available on-ramps

Magic Cloud Networking has the following cloud on-ramps integrations:

  • AWS
  • Azure
  • GCP

Refer to Reference to learn more about how Cloudflare orchestrates VPN connectivity to your cloud networks.


Set up on-ramps

Create a Magic WAN cloud on-ramp

  1. Log in to the Cloudflare dashboard, and select your account.
  2. Select Magic WAN > Cloud on-ramps.
  3. Select Add new on-ramp.
  4. Give your new on-ramp a descriptive name.
  5. Select the network you want to connect to, and select Continue.
  6. Configure on-ramp shows where Cloudflare will install the new routes. Installing these routes is required to correctly configure both Magic WAN and your cloud provider, and ensure successful communication between them:
    • Add routes for your Magic WAN address space to your cloud network: Select this option to install routes for reaching Magic WAN in your cloud network's route tables (refer to Magic WAN Address Space to learn what routes are installed and how to customize them). If you prefer to do this manually, unselect this option.
    • Add routes for your cloud network to Magic WAN: Select this option to create routes for reaching your cloud network in Magic WAN.
  7. Select Continue. Applying your settings might take a few seconds to complete.
  8. Review the changes in your cloud environment, and select Approve changes.

You have successfully created your Magic WAN on-ramp. However, on-ramp creation can take up to an hour before you can use it.

Edit a Magic WAN cloud on-ramp

  1. Log in to the Cloudflare dashboard, and select your account.
  2. Select Magic WAN > Cloud on-ramps.
  3. Select the on-ramp you want to edit.
  4. Select Edit in the side panel.
  5. In Basic information, you can change the name and description of your on-ramp. Select Save when you are finished.
  6. In Configurations, you can modify where the required routes are installed. Select Continue.
    1. Select Save and review after making changes.
    2. Review your settings, and select Approve changes.

Delete a Magic WAN cloud on-ramp

  1. Log in to the Cloudflare dashboard, and select your account.
  2. Select Magic WAN > Cloud on-ramps.
  3. Select the on-ramp you want to delete.
  4. Select Edit in the side panel.
  5. Choose Detach or Destroy to proceed:
    • Detach: Cloudflare will stop managing the cloud resources that were created to build this on-ramp, but will leave them in place. On-ramp connectivity will not be impacted.
    • Destroy: Cloudflare will delete the resources that were created to build this on-ramp in the cloud provider, if possible. Resources cannot be deleted if other resources depend upon them. For example, if an AWS Customer Gateway was created for this on-ramp, but was subsequently used in a second on-ramp, destroying this on-ramp will not destroy the AWS Customer Gateway.

Magic WAN Address Space

By default, Cloudflare installs the following summarized routes in your cloud route tables to direct traffic to Magic WAN:

10.0.0.0/8
172.16.0.0./12
192.168.0.0/16
100.64.0.0./10

To override the defaults with custom prefixes:

  1. Log in to the Log in to the Cloudflare dashboard, and select your account.
  2. Select Magic WAN > Configuration.
  3. Select Magic WAN Address Space.
  4. Delete the prefixes, and enter your custom ones.
  5. When you are finished, select Save changes.

To install a default route to send all traffic to Magic WAN, enter 0.0.0.0/0 (on Azure, enter 0.0.0.0/1 and 128.0.0.0/1).

Set up with Terraform

You can download a Terraform configuration for a cloud on-ramp. You might want to do this to:

  • Review the proposed configuration for an on-ramp before deploying it with Cloudflare.
  • Deploy the on-ramp using your own infrastructure-as-code pipeline instead of deploying it with Cloudflare.

The download will contain two files:

  • main.tf: Terraform configuration for the new resources needed to create the on-ramp.
  • instructions.txt: Instructions for modifying resources that already exist in your cloud environment.

If you intend to plan and apply the downloaded configuration using Terraform, you will need to use the Cloudflare Terraform provider (in addition to the Terraform provider for the on-ramp's cloud service provider). Use your Cloudflare Global API Key, not an API Token.

Download Terraform configuration for a new on-ramp

  1. Log in to the Cloudflare dashboard, and select your account.
  2. Select Magic WAN > Cloud on-ramps.
  3. Select Add new on-ramp and begin the Create a Magic WAN cloud on-ramp workflow as normal.
  4. After the Configure route propagation step, select View download options instead of selecting Continue.
  5. Select a download option:
    1. Choose Download and continue to download the Terraform configuration, review the configuration, and then continue deploying the on-ramp with Cloudflare.
    2. Choose Download and exit to download the Terraform configuration that you will apply yourself.

Download Terraform configuration for an existing on-ramp

  1. Log in to the Cloudflare dashboard, and select your account.
  2. Select Magic WAN > Cloud on-ramps.
  3. Select the three dots for the on-ramp you want to download > Download Terraform.

Cost estimates

You can view estimated costs associated with your cloud resources in the Cloudflare dashboard.

  1. Log in to the Cloudflare dashboard, and select your account.
  2. Select Magic WAN > Cloud on-ramps.
  3. Find the cloud on-ramp for which you want to check the estimated costs.
  4. Select the three dots > Associated Resources.
  5. In the Associated Resources page, you can view the estimated monthly costs for all the resources associated with the on-ramp you chose. You can also search for a specific resource using the search box.