New accounts start with just one anycast IP! The default changed for Magic Transit and Cloudflare WAN
Hey everyone, it's Shiichan! Today I found a small but handy default change on the networking side, so let me share it with you.
Cloudflare ChangelogWhat was announced?
According to Cloudflare's Changelog, new Magic Transit and Cloudflare WAN accounts are now assigned a single IPv4 anycast address by default.
Why one is enough
You might think, "Just one, is that okay?" But because it's anycast, it's fine. Cloudflare advertises your endpoint IP from many nodes across globally distributed data centers, so failures on Cloudflare's own network get absorbed automatically by routing to other nodes.
What changes
New accounts can start with a single anycast IP right away, without any extra request. Cloudflare's side handles redundancy through anycast, so what you need to think about is redundancy on your own network. The original post puts it like this:
To handle failures on your network, configure two tunnels from separate routers.
In other words, to prepare for failures on your own side, set up two tunnels from separate routers.
Dive Deep
If one address isn't enough and you want additional anycast IP addresses, you contact your account team.
For setting up tunnels, there are separate guides: Configure tunnel endpoints for Cloudflare WAN and Configure tunnel endpoints for Magic Transit, so read the one that matches your service.
Wrap-up
- New Magic Transit / Cloudflare WAN accounts get one IPv4 anycast address by default
- Failures on Cloudflare's side are covered automatically via anycast advertising
- For your own redundancy, set up two tunnels from separate routers
- Need more anycast IPs? Talk to your account team
If you're a network or infrastructure person about to stand up Magic Transit or Cloudflare WAN, keep this in mind around your first IP assignment and tunnel design and you won't get stuck!