As a general rule, settings on the customer zone will override settings on the SaaS zone. In addition, O2O does not permit traffic directed to a custom hostname zone into another custom hostname zone.
The following table provides a list of compatibility guidelines for various Cloudflare products and features.
| Product | Customer zone | SaaS provider zone | Notes |
|---|---|---|---|
| Access | Yes | Yes | |
| Always Online | No | No | In an O2O setup, Always Online does not trigger on the eyeball zone because the upstream SaaS provider zone is still reachable. Enabling it on the SaaS provider zone is not recommended because the eyeball zone may cache Internet Archive responses. |
| API Shield | Yes | No | |
| Argo Smart Routing | No | Yes | Customer zones can still use Smart Routing for non-O2O traffic. |
| Bot Management | Yes | Yes | |
| Browser Integrity Check | Yes | Yes | |
| Cache | Yes* | Yes | Though caching is possible on a customer zone, it is generally discouraged (especially for HTML). Your SaaS provider likely performs its own caching outside of Cloudflare and caching on your zone might lead to out-of-sync or stale cache states. Customer zones can still cache content that are not routed through a SaaS provider's zone. |
| China Network | No | No | |
| DNS | Yes* | Yes | As a SaaS customer, do not remove the records related to your Cloudflare for SaaS setup. Otherwise, your traffic will begin routing away from your SaaS provider. |
| HTTP/2 prioritization ↗︎ | Yes | Yes* | This feature must be enabled on the customer zone to function. |
| Image resizing | Yes | Yes | |
| IPv6 | Yes | Yes | |
| IPv6 Compatibility | Yes | Yes* | If the customer zone has IPv6 Compatibility enabled, generally the SaaS zone should as well. If not, make sure the SaaS zone enables Pseudo IPv4. |
| Load Balancing | No | Yes | Customer zones can still use Load Balancing for non-O2O traffic. |
| Page Rules | Yes* | Yes | Page Rules that match the subdomain used for O2O may block or interfere with the flow of visitors to your website. |
| Origin Rules | No | Yes | |
| Client-side security (formerly Page Shield) | Yes | Yes | |
| Polish | Yes* | Yes | Polish only runs on cached assets. If the customer zone is bypassing cache for SaaS zone destined traffic, then images optimized by Polish will not be loaded from origin. |
| Rate Limiting | Yes* | Yes | Rate Limiting rules that match the subdomain used for O2O may block or interfere with the flow of visitors to your website. |
| Rocket Loader | No | No | |
| Security Level | Yes | Yes | |
| Spectrum | No | No | |
| Transform Rules | Yes* | Yes | Transform Rules that match the subdomain used for O2O may block or interfere with the flow of visitors to your website. |
| WAF custom rules | Yes | Yes | WAF custom rules that match the subdomain used for O2O may block or interfere with the flow of visitors to your website. |
| WAF managed rules | Yes | Yes | |
| Waiting Room | Yes | Yes | |
| WebSockets | No | No | |
| Workers | Yes* | Yes | Similar to Page Rules, Workers that match the subdomain used for O2O may block or interfere with the flow of visitors to your website. |
| Zaraz | Yes | No |