Gateway Proxy Breaks Warp Connections

Additional information

Network policies

What is the error number?

N/A

What is the error message?

N/A

What is the issue you’re encountering

After enabling proxy fore network firewall warp client tunnel becomes unstable

What steps have you taken to resolve the issue?

I have created tunnels with and without gateway proxy enabled. I have logged packet capture and web developer logs.

What are the steps to reproduce the issue?

When creating a warp connect with proxy disabled and setting split tunnel route includes all traffic flows as expected. After enabling the gateway proxy to create ZTNA rules remote network traffic often breaks. Specifically access to the edge router http interface. When traffic is not routed through proxy web access to the router gateway works fine, once proxy is enabled i can see the gateway getting syn-ack to the remote warp client from local packet captures but web developer tools show no http headers and timeout, tls inspection disabled. Additionally after enabling the proxy in setting>networks the tunnel becomes very unstable. RDP traffic will work but occasionally drops and the tunnel will show a disconnected state on the cloudflare dashboard when the tunnel locally will show connected via warp-cli status. According to cloudflare docs traffic in the split tunnels includes should be on the 3/4 network layer and not be proxied via layer 7. If the gateway proxy gets disabled the tunnel will completly break and is unrecoverable and must unistalled and re-installed the function again. Everything works fine until enabling the proxy to use gateway firewall for network traffic, what gives?