INTEGRITY Cloudflare Docs

Private network routing

Private network routing allows you to proxy HTTP/HTTPS traffic from public hostnames to origins in your private network. When you enable this setting on a DNS record, Cloudflare routes traffic through your configured tunnel instead of over the public Internet.

For an end-to-end setup walkthrough using Cloudflare WAN (formerly Magic WAN) IPsec, refer to Set up a private origin via Cloudflare WAN.

Aspects to consider

Before you enable private network routing, consider the following:

IP ranges

The following private address ranges are automatically detected:

Range Description
10.0.0.0/8 Private (RFC 1918)
172.16.0.0/12 Private (RFC 1918)
192.168.0.0/16 Private (RFC 1918)
fc00::/7 Private (RFC 4193)
100.64.0.0/10 CGNAT (RFC 6598)

When you use an IP address from one of these ranges, the Use private network routing toggle turns on automatically. You can also turn it on manually for public IP addresses that are only reachable through your tunnel.

Enable private network routing

  1. In the Cloudflare dashboard, go to the DNS Records page.

    Go to Records ↗
  2. Select Add record or select Edit on an existing A or AAAA record.

  3. Enter the origin IP address.

  4. Verify that Proxy status is enabled (orange cloud).

  5. Turn on Use private network routing.

    For private IP addresses (for example, 10.0.0.50), the toggle turns on automatically. For public IP addresses used with private infrastructure, turn on the toggle manually.

  6. Select Save.

To create a record with private routing enabled, use a POST request and set private_routing to true:

Required API token permissions

At least one of the following token permissions is required:
  • DNS Write
Create DNS Record
curl "https://api.cloudflare.com/client/v4/zones/$ZONE_ID/dns_records" \
	--request POST \
	--header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
	--json '{
		"type": "A",
		"name": "app.example.com",
		"content": "10.0.0.50",
		"proxied": true,
		"private_routing": true
	}'

To enable private routing on an existing record, use a PATCH request:

Required API token permissions

At least one of the following token permissions is required:
  • DNS Write
Update DNS Record
curl "https://api.cloudflare.com/client/v4/zones/$ZONE_ID/dns_records/$DNS_RECORD_ID" \
	--request PATCH \
	--header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
	--json '{
		"private_routing": true
	}'

API field behavior

If you use the API to create or edit DNS records with private network routing, consider the following:

Scenario private_routing value
Proxied A/AAAA record with private IP Auto-set to true
Proxied A/AAAA record with public IP Defaults to false
Non-A/AAAA record types Field not supported

Also, if you manually set private_routing: false on a proxied A/AAAA record with private IP, the API will return an error.