WARP is a Cloudflare client installed on a phone or computer: it wraps the device's outgoing traffic into the Cloudflare network. It is not Tunnel and not a regular VPN, even though the connection looks similar from the outside.
What WARP does and does not do
WARP encrypts the channel between the device and the nearest Cloudflare node and in some cases speeds up access to resources inside that network. It does not hide you from Cloudflare itself and does not let you pick an exit country on the free plan.
- Does: encrypts traffic from the device to the Cloudflare network, switches the DNS resolver to its own.
- Does not: hide the device address from Cloudflare, change the visible exit country for free, or publish a home service to the outside world.
WARP, Tunnel and VPN: the difference
These three products solve different problems, and people mix them up because the terms sound alike. The table below separates them by purpose, who starts the connection, and what is visible from outside.
| Criterion | WARP | Tunnel | VPN |
|---|---|---|---|
| Purpose | protects the user device traffic | publishes an internal service without a public IP | encrypts the channel and changes the visible address |
| Who starts the connection | the user device | the server running the service | the user device |
| What is visible outside | the Cloudflare network address instead of the provider address | only the domain on Cloudflare, the server stays hidden | the address of the VPN server |
Publishing a service without a public IP is covered in detail in the article on Cloudflare Tunnel.
WARP client modes
The client can be switched between modes, and they differ in exactly what is sent through the Cloudflare network.
- WARP mode: all device traffic goes through the Cloudflare network.
- DNS-only mode: only DNS queries go through Cloudflare, other traffic goes directly.
- Gateway mode: a corporate option with filtering rules set by an administrator.
How to install and connect WARP
Installation is not tied to a specific client version and follows the same pattern everywhere.
- Install the app from the official source for your platform.
- Open the app and connect as a private user, or sign in to an existing account.
- Allow the app to create a VPN connection on the system, otherwise the tunnel will not come up.
- Turn the WARP switch on and wait for the connection status.
- Check that the indicator shows an active connection before relying on it.
Why WARP will not connect
Most failures fall into a handful of typical causes, and the table below helps find yours.
| Symptom | Likely cause | Check |
|---|---|---|
| The connection hangs on attempt | outgoing UDP is blocked on the network | try another network or mobile data |
| The client turns on and disconnects right away | conflict with another VPN client on the device | turn off the other VPN client and try again |
| The connection fails at the office | a corporate filter blocks the protocol | ask the network administrator which protocols are allowed |
| The connection status does not update | the device clock is off | check the device time and time zone |
| The client reports the port is busy | another process is already using the needed port | close the conflicting app and restart the client |
How WARP affects access to your server
Once WARP is on, the device's outgoing address changes to a Cloudflare network address instead of the usual provider address. If the server's firewall is set up by geography or by specific addresses, such a connection can get blocked, and access will need to be restored with a separate rule.
When WARP is not needed
WARP is useful as client-side channel encryption, but it does not solve the task of publishing your own service without a public IP. If you are looking for a general introduction to Cloudflare and its free features, start with the article on what Cloudflare is.