Cloudflare adds managed firewall rulesets to Unified Routing
Cloudflare's 25 September update adds managed rulesets to Unified Routing. Beta status and account entitlement matter for Magic Transit and WAN users.
Cloudflare announced on 25 September 2026 that Advanced Network Firewall managed rulesets are supported on accounts using Unified Routing. The change matters to operators evaluating filtering for traffic carried through Magic Transit or Cloudflare WAN. There is a qualification: the current feature matrix lists managed rulesets on Unified Routing as beta. See the dated announcement and availability table.
What changed
The development extends managed-ruleset support to this routing mode. It does not mean every firewall capability has the same availability. The matrix still lists rate limiting and full packet captures as unavailable on Unified Routing, so a migration assessment needs to cover the complete set of features a network depends on.
Cloudflare Network Firewall is an Enterprise service available with Magic Transit or Cloudflare WAN. Its managed-ruleset instructions require account entitlement before use. The rules are maintained by Cloudflare, while the customer controls their enablement. The documentation also describes a logging override and says managed-phase rules are disabled by default.
For an operator, this separates three questions: whether a routing mode supports a feature, whether the account has access to it, and whether the intended rules are actually enabled. An announcement answering the first question does not answer the other two.
Why it matters for BYOIP
For organizations evaluating Magic Transit for their own address space, the practical issue is which security controls can accompany a routing design. Our Cloudflare BYOIP profile provides the onboarding context. This update concerns traffic filtering; it does not announce new prefix-ownership checks or relaxed address-import requirements.
Our editorial recommendation is to revisit any evaluation that depended on managed-ruleset support in Unified Routing. Treat this as a reason to reassess that requirement, while retaining separate checks for the other controls and operational tools your team uses.
What to check before enabling it
- Confirm the account's routing mode and managed-ruleset entitlement with the team responsible for Cloudflare configuration.
- Write down the traffic the proposed rules should match and the legitimate traffic they must preserve. Include important applications behind the protected prefixes in that review.
- Consider an initial logging configuration for the selected rules, then review the matches before moving to enforcement. Logging alone is not evidence that traffic is being blocked.
- Assign an owner to investigate unexpected matches and define how the team will disable or adjust a rule if an application is affected.
- Keep routing migration and firewall-policy changes distinguishable in the change record. If both happen together, record enough evidence to tell which change caused an unexpected result.
Sources and further reading
The release notice establishes the September development. The linked feature matrix and setup documentation establish the current limits and account requirements. Recheck them before implementation because beta availability can change.
Sources
- Managed Rulesets supported in Unified Routing
Cloudflare · published 25 Sept 2026 · checked 28 Sept 2026
- Traffic steering - Unified Routing feature availability
Cloudflare · checked 28 Sept 2026
- Enable Managed Rulesets
Cloudflare · checked 28 Sept 2026
- Cloudflare Network Firewall overview
Cloudflare · checked 28 Sept 2026