CLOUDFLARE ONE · CITY OF PERTH
A path to consolidating DNS, remote access, and application delivery onto Cloudflare One — removing vendor sprawl and strengthening security posture.
Cloudflare One
Prepared for City of Perth · May 2026
SECTION 1
Current architecture, vendor landscape, and the pain points driving change.
CURRENT STATE
CURRENT CHALLENGES
VPN & Remote Access
Checkpoint VPN is a single point of failure
Corporate users, BYOD, and third-party vendors all share the same generic VPN — no device posture, no per-app controls, no audit trail.
Published Applications via Citrix
Citrix adds cost and complexity without Zero Trust
Applications published through Citrix require VDI infrastructure, ongoing licensing, and provide no identity-aware access controls at the network layer.
DNS Split Across Vendors
Melbourne IT holds authoritative DNS; Cloudflare holds 2 domains
Split DNS management creates operational overhead, inconsistent security policies, and limits visibility into DNS-based threats across all City domains.
SaaS & AI/API Visibility
No visibility into SaaS usage or AI/API traffic
With M365 E5, Dynamics, and Trend Servers in use, there is no unified view of what SaaS applications staff are accessing or what data is leaving the organisation.
SECTION 2
One platform replacing four discrete vendor solutions — DNS, VPN, application access, and security in a single control plane.
FUTURE STATE ARCHITECTURE
WORKSTREAM 1 · DNS
WORKSTREAM 1 · DNS
What changes
What you gain
WORKSTREAM 2 · REMOTE ACCESS
WORKSTREAM 2 · REMOTE ACCESS
Three access tiers — one platform
Security improvements over Checkpoint
WORKSTREAM 3 · APPLICATION ACCESS
WORKSTREAM 3 · APPLICATION ACCESS
How it works
What replaces Citrix
SECTION 3
The security and operational case for removing discrete vendor solutions.
OPERATIONAL BENEFITS
Replaced
Checkpoint — Remote VPN
Citrix — Published applications & VDI
Melbourne IT — Authoritative DNS
Cisco LAN/WAN — Network management complexity
Consolidated onto Cloudflare One
ZTNA — CF One Client + Clientless VPN
Cloudflare Access + Tunnels — App publishing
Cloudflare DNS — Full authoritative DNS
Single dashboard — One policy engine for all traffic
Organisations consolidating onto Cloudflare One report a 35% reduction in IT operations time and 20% reduction in licensing costs — Forrester TEI, January 2026. Source: Forrester Total Economic Impact™ Study
SECURITY BENEFITS
Zero Trust Access
DNS & Network Security
Application & API Visibility
NEXT STEPS
1
DNS Migration PoC
Migrate one domain from Melbourne IT to Cloudflare. Validate DNS resolution, WAF policies, and CDN performance. Low risk, high visibility win.
2
ZTNA Pilot
Deploy CF One Client to a pilot group of corporate users. Validate device posture, Entra ID integration, and access policies against one internal application.
3
Application Publishing PoC
Establish a Cloudflare Tunnel from Azure/NextDC and publish one Citrix-hosted application via Cloudflare Access. Demonstrate the Citrix replacement path.
Ready to start? Let's align on a PoC scope and timeline — Jason Clarke · jclarke@cloudflare.com