shiichan

New accounts start with just one anycast IP! The default changed for Magic Transit and Cloudflare WAN

Hey everyone, it's Shiichan! Today I found a small but handy default change on the networking side, so let me share it with you.

Cloudflare Changelog developers.cloudflare.com

What was announced?

According to Cloudflare's Changelog, new Magic Transit and Cloudflare WAN accounts are now assigned a single IPv4 anycast address by default.

Why one is enough

You might think, "Just one, is that okay?" But because it's anycast, it's fine. Cloudflare advertises your endpoint IP from many nodes across globally distributed data centers, so failures on Cloudflare's own network get absorbed automatically by routing to other nodes.

What changes

New accounts can start with a single anycast IP right away, without any extra request. Cloudflare's side handles redundancy through anycast, so what you need to think about is redundancy on your own network. The original post puts it like this:

To handle failures on your network, configure two tunnels from separate routers.

In other words, to prepare for failures on your own side, set up two tunnels from separate routers.

Dive Deep

If one address isn't enough and you want additional anycast IP addresses, you contact your account team.

For setting up tunnels, there are separate guides: Configure tunnel endpoints for Cloudflare WAN and Configure tunnel endpoints for Magic Transit, so read the one that matches your service.

Wrap-up

  • New Magic Transit / Cloudflare WAN accounts get one IPv4 anycast address by default
  • Failures on Cloudflare's side are covered automatically via anycast advertising
  • For your own redundancy, set up two tunnels from separate routers
  • Need more anycast IPs? Talk to your account team

If you're a network or infrastructure person about to stand up Magic Transit or Cloudflare WAN, keep this in mind around your first IP assignment and tunnel design and you won't get stuck!