Knowledge Hub · Security

Can we use Cloudflare from FirstNet alongside Zscaler or our existing WAF?

Web Application & DDoS Protection · Answered by FirstNet Technology Services

Short answer

Yes. Many customers run Zscaler for outbound users and Cloudflare for inbound apps. Where you have an existing WAF, FirstNet plans a phased migration rather than a rip-and-replace.

In detail

How coexistence usually works:

  • Zscaler, or another secure service edge, continues to secure staff browsing and SaaS access
  • Cloudflare protects your public-facing websites, applications and APIs with WAF, DDoS, bot protection and API Shield
  • An existing WAF stays in place while Cloudflare is onboarded in detection mode and tuned against real traffic
  • Applications move across in phases, with a documented rollback path until enforcement

FirstNet maps your current tools and identifies which contracts Cloudflare could retire over time, since it can consolidate separate WAF, DDoS, CDN, web gateway and VPN services. Consolidation is a choice, not a requirement, and Cloudflare is positioned to fit alongside what already works.

A WAF, CDN or VPN renewal is often a good moment to review the approach. Share renewal dates during discovery so the migration plan can line up with them.

Source: FirstNet Web Application & DDoS Protection service page →

Didn’t answer your question?

Call