
Open
Posted
•
Ends in 4 days
Paid on delivery
My internal ERP sits behind a private domain that I’m ready to move under Cloudflare Zero Trust. The goal is simple: when someone tries to reach the ERP URL, the prompt must enforce multi-factor authentication and allow the session to open only if the request comes from one of our office computers on our Wi-Fi network. Anything originating elsewhere—home, café, mobile hotspot—should be denied outright. Here is what I need from you as the security specialist familiar with Cloudflare Access, Gateway, and device posture rules: • Configure the domain inside Cloudflare, enabling the security features that sit in front of the ERP server (Firewall, WAF, DDoS protection). • Create an Access policy that ties identity (Google Workspace / Azure AD, or another SSO you recommend) to mandatory MFA. TOTP or push-based authenticators are both acceptable. • Whitelist only the MAC-addressed office computers or, if you prefer a cleaner approach, use Cloudflare’s device client plus serial-number/device-certificate enforcement so that “Only office computers” truly means only those devices. • Ensure the policy respects our Wi-Fi network range; requests originating from any other subnet must be blocked without even showing a login screen. • Provide a short hand-off document (screenshots or screencast) covering the rules, how to onboard a new machine, and how to revoke access instantly if a laptop is lost. • Run end-to-end tests with me—first inside the office, then from an outside network—to confirm the lockout and the MFA prompt both work as intended. Success is measured when: 1. The ERP is accessible from the office Wi-Fi on approved computers after passing MFA. 2. A test request from an unapproved device or off-premises network fails automatically. 3. All settings are documented clearly enough that I can audit or adjust them later without guesswork. If you have recent experience hardening internal apps with Cloudflare and MFA, let’s secure this right away.
Project ID: 40382678
12 proposals
Open for bidding
Remote project
Active 1 day ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
12 freelancers are bidding on average ₹9,583 INR for this job

As a Network, Cybersecurity, VoIP, and System Engineer with over 10 years of experience, I have acquired extensive knowledge and skills that make me the ideal candidate for your project. I have a proven track record in implementing and hardening network infrastructures, especially when it comes to ensuring strong security measures for internal apps using platforms like Cloudflare and MFA. With my proficiency in Cloudflare Access, Gateway, and device posture rules, I am confident in configuring your private domain within Cloudflare to optimize the security features for your ERP server. Moreover, my thorough end-to-end testing approach aligns directly with your goal of measuring success. I will ensure not only unapproved devices or off-premises networks are blocked instantly but also provide you with a detailed hand-off document that covers all essential rules and provides a smooth onboarding process for new machines as well as clear steps for revoking access promptly if ever required. Your project's success is not just about the initial setup but also about future-proofing your security measures - and this is definitely where my expertise lies. Ultimately, what sets me apart from other candidates is my unwavering commitment to client satisfaction. You can always count on me to be available round-the-clock, promptly addressing any concerns or queries you may have now or in the future. Let's get started today and make sure we meet all your security needs efficiently!
₹10,000 INR in 3 days
7.0
7.0

Cloudflare Zero Trust | Access | MFA | Device Posture | Security Hi, I can secure your ERP behind Cloudflare Zero Trust so it’s only accessible from approved office devices on your Wi-Fi, with enforced MFA. I’ll configure Cloudflare Access + Gateway with: * SSO (Google/Azure AD) + mandatory MFA * Device-level restriction (WARP + posture checks / certificates for “office devices only”) * Network restriction (office IP/subnet only — block others before login) * WAF, firewall, and DDoS protection in front of the ERP I’ll validate end-to-end (inside vs outside network), ensuring access works only under the defined conditions and fails everywhere else. You’ll get a clear handover (rules, onboarding new devices, revoking access instantly). I have 15+ years of experience securing internal apps using Cloudflare Zero Trust and similar setups. Quick questions: Office has static public IP? Preferred IdP (Google or Azure AD)? Can start immediately. Rahul
₹15,000 INR in 7 days
2.8
2.8

What if your ERP never even exposes a login prompt unless the request already proves it belongs inside your office perimeter? I’d implement this using a layered Cloudflare Zero Trust design: first, proxy your ERP through Cloudflare with WAF, bot management, and strict firewall rules that drop all non-office IP ranges at the edge (no auth page leakage); second, enforce Access with SSO (Azure AD or Google Workspace) + mandatory MFA (TOTP/push), tied to device posture via Cloudflare WARP—issuing device certificates and validating serial/OS posture so only enrolled office machines pass; third, bind policies with an “AND” logic (identity + device + network) to guarantee access only from approved devices on your Wi-Fi subnet; finally, I’ll document onboarding/revocation (device enrollment, instant certificate revoke, user/session kill) and run live attack-path testing with you (office vs external) to prove hard denial outside and seamless MFA inside—clean, auditable, and zero guesswork going forward.
₹8,000 INR in 6 days
0.0
0.0

"Hello, I am a Cybersecurity specialist with a Cisco certification in Cybersecurity. I have professional experience in Web Application Penetration Testing. I can perform a comprehensive security assessment for your production environment, focusing on: Authentication & Authorization mechanisms. Input Validation (SQLi, XSS, etc.). In-depth vulnerability scanning and manual verification. I will provide you with a detailed report including findings and remediation steps. I am ready to start immediately. Best regards, Anas Sadek
₹7,000 INR in 7 days
0.0
0.0

Most freelancers will set up an Access policy tied only to your IdP and call it done. That's not enough a stolen credential from an approved email still gets in. I layer three independent conditions that all must pass simultaneously: verified identity + MFA, approved device posture, and office network origin. A single failed condition silently blocks the request no login prompt, no error hints. I am confident that I can achieve this in 1 week
₹9,000 INR in 7 days
0.0
0.0

At InfraNova Services, we specialize in securing critical infrastructure with a strong focus on practical, results-driven solutions. We can implement a robust Cloudflare MFA lockdown for your ERP, ensuring access is tightly controlled and aligned with your security requirements. Our approach focuses on identifying risks, closing gaps, and enforcing strict access policies. We can restrict ERP access to authorized office devices over your Wi-Fi using device-based controls such as client authentication, certificates, and network-level validation, combined with strong MFA enforcement through Cloudflare. With solid experience across cloud platforms, Windows environments, and network security, we ensure your setup is not only secure but also stable and easy to manage. You’ll receive clear documentation for onboarding new devices and revoking access when needed. Our goal is simple—lock down your ERP with precision, without adding unnecessary complexity. Let’s secure your system the right way.
₹11,000 INR in 7 days
0.0
0.0

Hi, I’m a DevOps engineer with over 4 years of experience working with clients such as EY and MercadoLibre (the largest e-commerce platform in Latin America). I’ve worked on securing internal applications using Zero Trust principles, so your requirement is very clear—restricting access by identity, device, and network is exactly the right approach. I can configure Cloudflare Access and Gateway to enforce MFA (via Google Workspace, Azure AD, or your preferred IdP), and set up strict policies combining identity, device posture, and network restrictions. This includes allowing access only from approved office devices (via Cloudflare WARP/device posture or certificates) and blocking any requests from outside your Wi-Fi network before authentication. I’ll also configure WAF, firewall, and DDoS protections in front of your ERP, and provide clear documentation on how to onboard/revoke devices and manage access policies. We can validate everything together with real tests (inside and outside your network) to ensure the setup behaves exactly as expected. I’m available to start right away. Best regards, Mauricio
₹12,500 INR in 7 days
0.0
0.0

Ahmedabad, India
Payment method verified
Member since Aug 29, 2018
₹12500-37500 INR
₹1500-12500 INR
₹1500-12500 INR
₹6000 INR
₹12500-37500 INR
₹1500-12500 INR
$30-250 USD
₹1500-12500 INR
₹250000-500000 INR
£20-250 GBP
$30-250 USD
$30-250 USD
$30-250 USD
₹750-1250 INR / hour
$30-250 USD
$250-750 USD
$30-250 USD
$30-250 USD
₹12500-37500 INR
$750-1500 USD
₹1500-12500 INR
$25-50 USD / hour
$30-50 USD / hour
$30-250 USD
$8-15 USD / hour