Short answer
Yes. Many customers run Zscaler for outbound users and Cloudflare for inbound apps. Where you have an existing WAF, FirstNet plans a phased migration rather than a rip-and-replace.
In detail
How coexistence usually works:
- Zscaler, or another secure service edge, continues to secure staff browsing and SaaS access
- Cloudflare protects your public-facing websites, applications and APIs with WAF, DDoS, bot protection and API Shield
- An existing WAF stays in place while Cloudflare is onboarded in detection mode and tuned against real traffic
- Applications move across in phases, with a documented rollback path until enforcement
FirstNet maps your current tools and identifies which contracts Cloudflare could retire over time, since it can consolidate separate WAF, DDoS, CDN, web gateway and VPN services. Consolidation is a choice, not a requirement, and Cloudflare is positioned to fit alongside what already works.
A WAF, CDN or VPN renewal is often a good moment to review the approach. Share renewal dates during discovery so the migration plan can line up with them.
Source: FirstNet Web Application & DDoS Protection service page →
Didn’t answer your question?
