Please enable WARP (with default route via our tunnel)

What is the name of the domain?

cloudflareaccess.com

What is the issue you’re encountering

Please enable WARP error when reauthenticating

What steps have you taken to resolve the issue?

We are testing Zero Access with WARP client to replace our VPN

One of the requirements is that some of our staff need to access legacy systems from an IP address we own.
We have setup a tunnel on that network , and use a default route to send traffic through there (0.0.0.0/0) on a virtual network.

Another requirement is that the sessions should only last 8 hours, so I tried enabling WARP client session duration in the firewall policy allow rule.

The problem is that when the session needs reauthentication , I keep getting the Error: Please enable WARP error
I suspect that my default route is stopping the warp detection from working.

Is there a way to exclude the cloudflare warp session related traffic from my default route?
I dont think split tunnel would work as its already on exclude mode with one or 2 unrelated ranges.

What are the steps to reproduce the issue?

enable firewall for network traffic
setup tunnel and add 0.0.0.0/0 as a route on a virtual network
enable Warp client session duration firewall policy allow rule.
wait for session to expire
try reauthenticate