What changed
On September 18, Cloudflare made Unified Routing generally available for Cloudflare WAN and Magic Transit and recommended it for all new accounts. Unified Routing replaces the legacy model's separate WAN and Zero Trust routing systems with one Cloudflare One routing fabric across supported connection types including Cloudflare One Client, Cloudflare Tunnel, IPsec, GRE and Cloudflare Network Interconnect. The GA path carries features that depend on the unified data plane, including Automatic Return Routing, BGP over supported tunnel on-ramps, custom client subnets and routing between Mesh and WAN connections.
Why it matters
For teams using Cloudflare as a private-network and Internet-edge layer, routing mode now determines which network designs are possible rather than merely how routes are displayed. Automatic Return Routing can preserve symmetric return paths without maintaining explicit return routes, while the unified fabric removes some of the precedence and connectivity boundaries between Zero Trust and WAN routes. New deployments therefore have a clear preferred architecture; existing legacy deployments need to evaluate feature parity and migration constraints before adopting newer routing capabilities.
One routing fabric replaces two independent systems
Legacy Cloudflare WAN evaluates WAN routes separately from Zero Trust routes. Unified Routing applies route selection across supported connection types in one Cloudflare One data plane. That matters when private networks span user clients, tunnels, GRE/IPsec sites and interconnects: route specificity is evaluated across the unified fabric rather than inside separate systems, reducing cases where a route in one subsystem unexpectedly takes precedence over a more specific route in another.
Automatic Return Routing can remove explicit return routes
Unified Routing is required for Automatic Return Routing. ARR learns which Cloudflare WAN connection a supported flow arrived on and sends matching return traffic back over that connection without requiring a static or dynamic return-route entry. Cloudflare documents support for traffic including new TCP connections, UDP and ICMP echo flows. The practical benefits are simpler route management, symmetric paths through stateful firewalls and support for overlapping private address space in relevant designs.
BGP over GRE and IPsec becomes part of the new routing model
Cloudflare supports BGP peering over IPsec and GRE tunnel on-ramps under Unified Routing, allowing customer routers and the Cloudflare routing table to exchange routes dynamically rather than relying only on static configuration. The tunnel BGP capability remains beta even though Unified Routing itself is GA, so teams should distinguish the stability of the routing fabric from the availability state of individual features built on it.
GA does not mean every network feature has reached parity
Cloudflare's comparison documentation still lists availability differences and beta features under Unified Routing. IPv6 remains beta for Cloudflare WAN and Magic Transit, BGP over CNI is closed beta and unavailable to new customers, and some network-firewall capabilities have been arriving incrementally. Existing customers should therefore treat GA as a migration decision to evaluate, not a signal to switch production routing without checking their specific features and route semantics.