Application-aware policies
Standard traffic policies match on network-layer attributes like IP addresses and port ranges. Application-aware policies go further — they identify traffic by the application generating it, so you can make routing and security decisions based on what the traffic is, not just where it is going.
Cloudflare One Appliance (formerly Magic WAN Connector) classifies traffic using the same application categories used across Cloudflare's Secure Web Gateway. This means routing decisions on the Appliance and security policies in Gateway use the same application definitions.
For the full list of recognized applications and categories, refer to Applications and app types.
With application-aware policies, you can:
- Break out traffic directly to the Internet — route specific applications directly to the Internet from the Appliance, bypassing Cloudflare's security filtering.
- Prioritize traffic — assign higher priority to specific applications so the Appliance processes them first when the network is congested.
For details, refer to the following pages: