# Cloudflare makes Unified Routing the default path for new WAN and Magic Transit networks

Cloudflare has moved Unified Routing to general availability for Cloudflare WAN and Magic Transit, replacing separate routing fabrics with one Cloudflare One data plane and unlocking flow-learned return routing, BGP over tunnels and cross-connector routing for new network designs.

The GA matters less as a label than as an architecture boundary. New Cloudflare WAN and Magic Transit deployments are now recommended onto a single routing fabric spanning Cloudflare One Client, Tunnel, IPsec, GRE and CNI, while legacy routing lacks several of the newer traffic-steering capabilities.

- Status: Active
- Published: 2026-09-20T21:02:37+12:00
- Updated: 2026-09-20T21:02:37+12:00
- Categories: Cloud & Infrastructure, Cloud Platforms, Edge & CDN
- Tags: BGP, Cloudflare, Magic Transit, network routing
- Canonical HTML: https://beyondthe.news/dossiers/cloudflare-unified-routing-ga-wan-magic-transit

## What changed

On September 18, Cloudflare made Unified Routing generally available for Cloudflare WAN and Magic Transit and recommended it for all new accounts. Unified Routing replaces the legacy model's separate WAN and Zero Trust routing systems with one Cloudflare One routing fabric across supported connection types including Cloudflare One Client, Cloudflare Tunnel, IPsec, GRE and Cloudflare Network Interconnect. The GA path carries features that depend on the unified data plane, including Automatic Return Routing, BGP over supported tunnel on-ramps, custom client subnets and routing between Mesh and WAN connections.

## Why it matters

For teams using Cloudflare as a private-network and Internet-edge layer, routing mode now determines which network designs are possible rather than merely how routes are displayed. Automatic Return Routing can preserve symmetric return paths without maintaining explicit return routes, while the unified fabric removes some of the precedence and connectivity boundaries between Zero Trust and WAN routes. New deployments therefore have a clear preferred architecture; existing legacy deployments need to evaluate feature parity and migration constraints before adopting newer routing capabilities.

## One routing fabric replaces two independent systems

Legacy Cloudflare WAN evaluates WAN routes separately from Zero Trust routes. Unified Routing applies route selection across supported connection types in one Cloudflare One data plane. That matters when private networks span user clients, tunnels, GRE/IPsec sites and interconnects: route specificity is evaluated across the unified fabric rather than inside separate systems, reducing cases where a route in one subsystem unexpectedly takes precedence over a more specific route in another.

## Automatic Return Routing can remove explicit return routes

Unified Routing is required for Automatic Return Routing. ARR learns which Cloudflare WAN connection a supported flow arrived on and sends matching return traffic back over that connection without requiring a static or dynamic return-route entry. Cloudflare documents support for traffic including new TCP connections, UDP and ICMP echo flows. The practical benefits are simpler route management, symmetric paths through stateful firewalls and support for overlapping private address space in relevant designs.

## BGP over GRE and IPsec becomes part of the new routing model

Cloudflare supports BGP peering over IPsec and GRE tunnel on-ramps under Unified Routing, allowing customer routers and the Cloudflare routing table to exchange routes dynamically rather than relying only on static configuration. The tunnel BGP capability remains beta even though Unified Routing itself is GA, so teams should distinguish the stability of the routing fabric from the availability state of individual features built on it.

## GA does not mean every network feature has reached parity

Cloudflare's comparison documentation still lists availability differences and beta features under Unified Routing. IPv6 remains beta for Cloudflare WAN and Magic Transit, BGP over CNI is closed beta and unavailable to new customers, and some network-firewall capabilities have been arriving incrementally. Existing customers should therefore treat GA as a migration decision to evaluate, not a signal to switch production routing without checking their specific features and route semantics.

## Key details

- Unified Routing became generally available for Cloudflare WAN and Magic Transit on September 18, 2026.
- Cloudflare recommends Unified Routing for all new accounts.
- The unified data plane spans Cloudflare One Client, Cloudflare Tunnel, IPsec, GRE and Cloudflare Network Interconnect.
- Automatic Return Routing requires Unified Routing and can return supported flows without static or dynamic return routes.
- Unified Routing supports Mesh-to-WAN connectivity that legacy routing does not.
- BGP over IPsec and GRE tunnels requires Unified Routing but remains beta.
- Route-selection semantics differ from the legacy system because supported connection types share one routing fabric.
- Some capabilities remain beta or limited even though the underlying Unified Routing mode is GA.

## Builder takeaways

- Use Unified Routing for new Cloudflare WAN or Magic Transit designs unless a required feature still depends on legacy behaviour.
- Before migrating an existing network, compare route-selection semantics and every firewall, IPv6, BGP and connector feature you depend on.
- ARR can reduce route-table maintenance for symmetric stateful traffic, but validate supported flow types and failure behaviour before removing explicit routes.
- If you use BGP over GRE or IPsec, treat that feature's beta status separately from Unified Routing's GA status.
- Test overlapping-prefix and cross-connector paths explicitly because moving from separate routing systems to one fabric can change which route wins.

## What to watch

- Whether Cloudflare provides a broader migration path or tooling for existing legacy-routing accounts.
- BGP over GRE/IPsec moving from beta to GA.
- Remaining Advanced Network Firewall feature parity under Unified Routing.
- IPv6 moving beyond beta for Cloudflare WAN and Magic Transit.
- Operational evidence from production migrations showing where unified route selection changes existing network behaviour.

## Uncertainties

- Cloudflare recommends Unified Routing for new accounts but does not make the GA announcement an instruction for every existing account to migrate immediately.
- Individual features on the unified data plane have different availability states; BGP over IPsec/GRE and IPv6 are not both fully GA.
- The available evidence is primarily Cloudflare documentation and changelog material; independent production migration evidence is limited.

## Sources

- [Unified Routing generally available](https://developers.cloudflare.com/changelog/post/2026-09-18-unified-routing-ga/) — Cloudflare · primary · 2026-09-18T00:00:00+12:00. GA announcement and recommendation for new accounts.
- [Cloudflare WAN traffic steering](https://developers.cloudflare.com/cloudflare-wan/reference/traffic-steering/) — Cloudflare · primary · 2026-09-18T00:00:00+12:00. Current comparison of legacy and unified routing, ARR behaviour and feature availability.
- [Configure routes — Cloudflare WAN](https://developers.cloudflare.com/cloudflare-wan/configuration/how-to/configure-routes/) — Cloudflare · primary · 2026-09-18T00:00:00+12:00. ARR and BGP configuration details and constraints.
- [Magic Transit changelog](https://developers.cloudflare.com/magic-transit/changelog/) — Cloudflare · primary · 2026-09-18T00:00:00+12:00. Historical beta-to-GA context and feature-parity milestones.

