Require Gateway
With Require Gateway, you can allow access to your applications only to devices enrolled in your Zero Trust organization. Unlike Require WARP, which will check for any WARP instance (including the consumer version), Require Gateway will only allow requests coming from devices whose traffic is filtered by your organization's Cloudflare Gateway configuration. This policy is best used when you want to protect company-owned assets by only allowing access to employees.
- 
Cloudflare WARP client is deployed on the device. For a list of supported modes and operating systems, refer to WARP Client Checks. 
- 
In Zero Trust ↗, go to Settings > WARP Client. 
- 
In WARP client checks, select Add new. 
- 
Select Gateway, then select Save. 
- 
In Zero Trust ↗, go to Access > Applications. 
- 
Locate the application for which you want to require Gateway. Select Configure. 
- 
In the Policies tab, create a new Access policy or edit an existing policy. 
- 
In the policy builder, add an Include or Require rule which uses the Gateway selector. Save the policy. 
- 
Save the Access application. 
Before granting access to the application, the policy will check that the device is running the WARP client and enrolled in your Zero Trust organization.
Was this helpful?
- Resources
- API
- New to Cloudflare?
- Products
- Sponsorships
- Open Source
- Support
- Help Center
- System Status
- Compliance
- GDPR
- Company
- cloudflare.com
- Our team
- Careers
- © 2025 Cloudflare, Inc.
- Privacy Policy
- Terms of Use
- Report Security Issues
- Trademark