VLESS + Cloudflare: What Does a CDN Do in a Proxy Connection?
Technical Editorial Team · Published February 18, 2026 · Updated September 29, 2026
For ordinary websites, a content delivery network (CDN) often stores content on edge servers closer to users. Some proxy connections can also use supported web transports: the client connects to the CDN, which contacts the origin server. VLESS with Cloudflare refers to this kind of path.
In the WahooVPN blog, we'll use a third-party VLESS + Cloudflare deployment to explain the separate roles of the proxy protocol, web transport, and CDN.
What Do VLESS, WebSocket, and TLS Each Do?
VLESS defines how client and server exchange proxy requests. WebSocket carries those requests over a web connection, while TLS protects the transport. Separating these roles makes it easier to see where the CDN sits in the path.
Without a CDN, the client contacts the origin IP directly. With a CDN, it first contacts an edge address. The origin still handles the actual proxy requests behind it.
How Does Cloudflare Forward the Connection?
Cloudflare's reverse proxy supports WebSocket connections. One deployment has the client connect to a Cloudflare domain over WebSocket, after which the edge forwards the connection to the origin.
The path is “client → Cloudflare edge → origin.” The client establishes a connection to the edge, which forwards it to the origin. The origin ultimately processes the VLESS proxy requests.
How a CDN Changes the Entry Point
Network equipment first sees the IP the client connects to. For a direct origin connection, that's the origin's address; with a CDN, it's an edge address.
CDN edge addresses are often shared by multiple websites. This separates the public entry point from the origin and lets websites and proxy services use similar web infrastructure.
Origin settings, the domain, and the transport remain part of the setup. Understanding those components is more useful than thinking of a CDN as an “invisibility wall.”
When Does This Combination Fit?
VLESS + Cloudflare combines a web transport with the CDN's reverse proxy. It changes the client's entry point, but availability still depends on origin settings, Cloudflare's service rules, and the current network.