DNS proxy address changes

We have paranoid customers who block outgoing web requests except to a whitelist of certain IP addresses. Until yesterday this worked because the 2 IP addresses Cloudflare was providing us for our domain were stable. Then suddenly a third was added. Anybody know why that would happen? Is there a way to do this whitelisting without having to whitelist all Cloudflare IP ranges which seems excessive?

No. At least not with an IP based firewall, if your firewall can periodically resolve DNS records and update firewall rules, or apply rules based on the certificate being used then you have more options.

Sweet, thanks for the quick reply :slight_smile:

