Professional Documents
Culture Documents
Magic Transit Protects Networks While Also Improving Performance 1
Magic Transit Protects Networks While Also Improving Performance 1
L7 Services
Added Latency WAF, CDN, etc)
Attack Traffic
‘Scrubbing centers’ are distant and few and dedicated to DDoS mitigation. This requires network traffic to travel to an alternate
data center for any additional L4-7 processing incurring additional delay.
DDoS Attack
BGP
Announcement GRE Tunnel
(or PNI
Ingress
Argo
(smart routing)
Cloudflare
Global Anycast Network
Customer Network
Every Cloudflare data center runs the full stack of L3-7 services, so network traffic is processed at the same location.
This means no trombone effect and very minimal latency. Network performance was a top concern
in how we developed Magic Transit; we wanted to be sure that our users weren’t sacrificing
performance for the sake of security.
50
40
30
20
10
07/14 17:45 07/18 12:00 07/22 06:15 07/26 00:30 07/29 18:45 08/02 13:00 08/06 07:15 08/10 01:30
Latency (ping round trip) performance (ms) with Magic Transit (blue) and without Magic Transit (gray)
50
40
30
20
10
07/14 17:45 07/18 12:00 07/22 06:15 07/26 00:30 07/29 18:45 08/02 13:00 08/06 07:15 08/10 01:30
Jitter performance (ms) with Magic Transit (blue) and without Magic Transit (gray)
40
20
07/14 17:45 07/18 12:00 07/22 06:15 07/26 00:30 07/29 18:45 08/02 13:00 08/06 07:15 08/10 01:30
Packet loss performance (percentage) with Magic Transit (blue) and without Magic Transit (gray)
In the test illustrated above, the blue line represents the performance using Magic Transit,
while the gray line represents the same without Magic Transit.
© 2020 Cloudflare Inc. All rights reserved. The Cloudflare logo is a trademark
of Cloudflare. All other company and product names may be trademarks of
the respective companies with which they are associated.