Skip to content

[Cloudflare One] Add TCP SYN filtering guidance to order of enforcement#28673

Open
Encore-Encore wants to merge 2 commits intocloudflare:productionfrom
Encore-Encore:pcx-20932-tcp-syn-filtering-docs
Open

[Cloudflare One] Add TCP SYN filtering guidance to order of enforcement#28673
Encore-Encore wants to merge 2 commits intocloudflare:productionfrom
Encore-Encore:pcx-20932-tcp-syn-filtering-docs

Conversation

@Encore-Encore
Copy link
Contributor

Summary

  • Adds a new subsection "Filter TCP SYN packets with Cloudflare Network Firewall" below the "Connection establishment" section on the order of enforcement page
  • Documents that Gateway sends TCP SYN packets to the origin server before evaluating policies, so Network/HTTP Block policies do not prevent the initial TCP SYN from reaching the destination
  • Explains how Enterprise customers can use Cloudflare Network Firewall rules (packet filtering) to block traffic at the packet level before Gateway's connection establishment step
  • Includes step-by-step instructions and a link to the packet filtering docs

Related tickets

…nt docs

Document how to use Cloudflare Network Firewall to prevent TCP SYN
packets from reaching origin servers, since Gateway sends TCP SYN
before evaluating policies during connection establishment.

Resolves PCX-20932
@Encore-Encore Encore-Encore requested a review from a team as a code owner February 28, 2026 01:19
… earlier

- Use 'destination server' consistently instead of mixing with 'origin'
- Move Enterprise-only note before the step-by-step instructions so
  readers see the prerequisite upfront
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant