Knowledge Hub · Security

What is Cloudflare Magic Transit, and who needs it?

Web Application & DDoS Protection · Answered by FirstNet Technology Services

Short answer

Magic Transit provides always-on DDoS protection for an entire IP range. Cloudflare advertises your IP prefixes from its global network using BGP, filters malicious traffic at the edge and tunnels clean traffic back to you.

In detail

Who it suits:

  • Organisations with their own ASN or IP space
  • Those needing DDoS protection beyond what their upstream carrier provides
  • Customers on FirstNet IP Transit who want always-on network-layer protection on top

How FirstNet delivers it:

  • Discovery of your public IP ranges, ASN and current routing
  • Design of the BGP topology, with GRE or IPsec tunnels for returning clean traffic
  • Failover validated with your network team during onboarding
  • Ongoing attack-event reviews and service reviews as part of the managed service

Magic Transit protects at the network layer (layer 3). Public web applications also benefit from Cloudflare's WAF and application-layer DDoS protection, which can be combined with it.

To onboard, FirstNet needs your public IP ranges and ASN, a named technical contact, and agreed change windows and acceptance criteria.

Source: FirstNet Web Application & DDoS Protection service page →

Didn’t answer your question?

Call