---
title: Create DNS Firewall Cluster
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/go)

[DNS Firewall](https://developers.cloudflare.com/api/go/resources/dns_firewall)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Create DNS Firewall Cluster

client.DNSFirewall.New(ctx, params) (\*[DNSFirewallNewResponse](<https://developers.cloudflare.com/api/go/resources/dns_firewall#(resource)%20dns_firewall%20%3E%20(model)%20DNSFirewallNewResponse%20%3E%20(schema)>), error)

POST/accounts/{account\_id}/dns\_firewall

Create a DNS Firewall cluster

##### Security

<details>

<summary>API Token</summary>



The preferred authorization scheme for interacting with the Cloudflare API. <a href="https://developers.cloudflare.com/fundamentals/api/get-started/create-token/">Create a token</a>.

**Example:**<code>Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY</code>

</details>

<details>

<summary>API Email + API Key</summary>



The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

**Example:**<code>X-Auth-Email: user@example.com</code>

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

**Example:**<code>X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194</code>

</details>

##### Accepted Permissions (at least one required)

`DNS Firewall Write`

##### ParametersExpand Collapse

<details>

<summary>

params DNSFirewallNewParams

</summary>

AccountID param.Field\[string]

Path param: Identifier.

maxLength32

<a href="#(resource)%20dns_firewall%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20account_id">Link to this property</a>

Name param.Field\[string]

Body param: DNS Firewall cluster name

maxLength160

minLength1

<a href="#(resource)%20dns_firewall%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20name">Link to this property</a>

UpstreamIPs param.Field\[\[]<a href="https://developers.cloudflare.com/api/go/resources/dns_firewall#(resource)%20dns_firewall%20%3E%20(model)%20upstream_ips%20%3E%20(schema)">UpstreamIPs</a>]

Body param

minLength1

<a href="#(resource)%20dns_firewall%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20upstream_ips">Link to this property</a>

AttackMitigation param.Field\[<a href="https://developers.cloudflare.com/api/go/resources/dns_firewall#(resource)%20dns_firewall%20%3E%20(model)%20attack_mitigation%20%3E%20(schema)">AttackMitigation</a>]Optional

Body param: Attack mitigation settings

<a href="#(resource)%20dns_firewall%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20attack_mitigation">Link to this property</a>

DeprecateAnyRequests param.Field\[bool]Optional

Body param: Whether to refuse to answer queries for the ANY type

<a href="#(resource)%20dns_firewall%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20deprecate_any_requests">Link to this property</a>

DNSFirewallIPCount param.Field\[int64]Optional

Body param: Number of IPv4 addresses to assign to the DNS Firewall cluster. Only used during cluster creation and cannot be changed later.

maximum10

minimum1

<a href="#(resource)%20dns_firewall%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20dns_firewall_ip_count">Link to this property</a>

ECSFallback param.Field\[bool]Optional

Body param: Whether to forward client IP (resolver) subnet if no EDNS Client Subnet is sent

<a href="#(resource)%20dns_firewall%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20ecs_fallback">Link to this property</a>

MaximumCacheTTL param.Field\[float64]Optional

Body param: By default, Cloudflare attempts to cache responses for as long as indicated by the TTL received from upstream nameservers. This setting sets an upper bound on this duration. For caching purposes, higher TTLs will be decreased to the maximum value defined by this setting.

This setting does not affect the TTL value in the DNS response Cloudflare returns to clients. Cloudflare will always forward the TTL value received from upstream nameservers.

maximum36000

minimum30

<a href="#(resource)%20dns_firewall%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20maximum_cache_ttl">Link to this property</a>

MinimumCacheTTL param.Field\[float64]Optional

Body param: By default, Cloudflare attempts to cache responses for as long as indicated by the TTL received from upstream nameservers. This setting sets a lower bound on this duration. For caching purposes, lower TTLs will be increased to the minimum value defined by this setting.

This setting does not affect the TTL value in the DNS response Cloudflare returns to clients. Cloudflare will always forward the TTL value received from upstream nameservers.

Note that, even with this setting, there is no guarantee that a response will be cached for at least the specified duration. Cached responses may be removed earlier for capacity or other operational reasons.

maximum36000

minimum30

<a href="#(resource)%20dns_firewall%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20minimum_cache_ttl">Link to this property</a>

NegativeCacheTTL param.Field\[float64]Optional

Body param: This setting controls how long DNS Firewall should cache negative responses (e.g., NXDOMAIN) from the upstream servers.

This setting does not affect the TTL value in the DNS response Cloudflare returns to clients. Cloudflare will always forward the TTL value received from upstream nameservers.

maximum36000

minimum30

<a href="#(resource)%20dns_firewall%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20negative_cache_ttl">Link to this property</a>

Ratelimit param.Field\[float64]Optional

Body param: Maximum number of DNS queries per second that will be forwarded to your upstream nameservers. The limit is enforced per server, where each server receives a fraction of the configured value. The actual aggregate rate for a data center may vary depending on how many servers are present. Responses served from cache do not count toward this limit. Set to null to disable rate limiting.

maximum1000000000

minimum100

<a href="#(resource)%20dns_firewall%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20ratelimit">Link to this property</a>

Retries param.Field\[float64]Optional

Body param: Number of retries for fetching DNS responses from upstream nameservers (not counting the initial attempt)

maximum2

minimum0

<a href="#(resource)%20dns_firewall%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20retries">Link to this property</a>

</details>

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(method)%20create%20%3E%20(params)%20default>)

##### ReturnsExpand Collapse

<details>

<summary>

type DNSFirewallNewResponse struct{…}

</summary>

ID string

Identifier.

maxLength32

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20DNSFirewallNewResponse%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

DeprecateAnyRequests bool

Whether to refuse to answer queries for the ANY type

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20DNSFirewallNewResponse%20%3E%20(schema)%20%3E%20(property)%20deprecate_any_requests">Link to this property</a>

DNSFirewallIPs \[]<a href="https://developers.cloudflare.com/api/go/resources/dns_firewall#(resource)%20dns_firewall%20%3E%20(model)%20firewall_ips%20%3E%20(schema)">FirewallIPs</a>

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20DNSFirewallNewResponse%20%3E%20(schema)%20%3E%20(property)%20dns_firewall_ips">Link to this property</a>

ECSFallback bool

Whether to forward client IP (resolver) subnet if no EDNS Client Subnet is sent

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20DNSFirewallNewResponse%20%3E%20(schema)%20%3E%20(property)%20ecs_fallback">Link to this property</a>

MaximumCacheTTL float64

By default, Cloudflare attempts to cache responses for as long as indicated by the TTL received from upstream nameservers. This setting sets an upper bound on this duration. For caching purposes, higher TTLs will be decreased to the maximum value defined by this setting.

This setting does not affect the TTL value in the DNS response Cloudflare returns to clients. Cloudflare will always forward the TTL value received from upstream nameservers.

maximum36000

minimum30

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20DNSFirewallNewResponse%20%3E%20(schema)%20%3E%20(property)%20maximum_cache_ttl">Link to this property</a>

MinimumCacheTTL float64

By default, Cloudflare attempts to cache responses for as long as indicated by the TTL received from upstream nameservers. This setting sets a lower bound on this duration. For caching purposes, lower TTLs will be increased to the minimum value defined by this setting.

This setting does not affect the TTL value in the DNS response Cloudflare returns to clients. Cloudflare will always forward the TTL value received from upstream nameservers.

Note that, even with this setting, there is no guarantee that a response will be cached for at least the specified duration. Cached responses may be removed earlier for capacity or other operational reasons.

maximum36000

minimum30

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20DNSFirewallNewResponse%20%3E%20(schema)%20%3E%20(property)%20minimum_cache_ttl">Link to this property</a>

ModifiedOn Time

Last modification of DNS Firewall cluster

formatdate-time

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20DNSFirewallNewResponse%20%3E%20(schema)%20%3E%20(property)%20modified_on">Link to this property</a>

Name string

DNS Firewall cluster name

maxLength160

minLength1

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20DNSFirewallNewResponse%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

NegativeCacheTTL float64

This setting controls how long DNS Firewall should cache negative responses (e.g., NXDOMAIN) from the upstream servers.

This setting does not affect the TTL value in the DNS response Cloudflare returns to clients. Cloudflare will always forward the TTL value received from upstream nameservers.

maximum36000

minimum30

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20DNSFirewallNewResponse%20%3E%20(schema)%20%3E%20(property)%20negative_cache_ttl">Link to this property</a>

Ratelimit float64

Maximum number of DNS queries per second that will be forwarded to your upstream nameservers. The limit is enforced per server, where each server receives a fraction of the configured value. The actual aggregate rate for a data center may vary depending on how many servers are present. Responses served from cache do not count toward this limit. Set to null to disable rate limiting.

maximum1000000000

minimum100

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20DNSFirewallNewResponse%20%3E%20(schema)%20%3E%20(property)%20ratelimit">Link to this property</a>

Retries float64

Number of retries for fetching DNS responses from upstream nameservers (not counting the initial attempt)

maximum2

minimum0

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20DNSFirewallNewResponse%20%3E%20(schema)%20%3E%20(property)%20retries">Link to this property</a>

UpstreamIPs \[]<a href="https://developers.cloudflare.com/api/go/resources/dns_firewall#(resource)%20dns_firewall%20%3E%20(model)%20upstream_ips%20%3E%20(schema)">UpstreamIPs</a>

minLength1

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20DNSFirewallNewResponse%20%3E%20(schema)%20%3E%20(property)%20upstream_ips">Link to this property</a>

<details>

<summary>

AttackMitigation <a href="https://developers.cloudflare.com/api/go/resources/dns_firewall#(resource)%20dns_firewall%20%3E%20(model)%20attack_mitigation%20%3E%20(schema)">AttackMitigation</a>Optional

Attack mitigation settings

</summary>

Enabled boolOptional

When enabled, automatically mitigate random-prefix attacks to protect upstream DNS servers

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20DNSFirewallNewResponse%20%3E%20(schema)%20%3E%20(property)%20attack_mitigation%20%2B%20(resource)%20dns_firewall%20%3E%20(model)%20attack_mitigation%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

OnlyWhenUpstreamUnhealthy boolOptional

Only mitigate attacks when upstream servers seem unhealthy

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20DNSFirewallNewResponse%20%3E%20(schema)%20%3E%20(property)%20attack_mitigation%20%2B%20(resource)%20dns_firewall%20%3E%20(model)%20attack_mitigation%20%3E%20(schema)%20%3E%20(property)%20only_when_upstream_unhealthy">Link to this property</a>

</details>

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20DNSFirewallNewResponse%20%3E%20(schema)%20%3E%20(property)%20attack_mitigation">Link to this property</a>

</details>

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(model)%20DNSFirewallNewResponse%20%3E%20(schema)>)

### Create DNS Firewall Cluster

Go

HTTPTypeScriptPythonGoTerraform

```
package main

import (
  "context"
  "fmt"

  "github.com/cloudflare/cloudflare-go"
  "github.com/cloudflare/cloudflare-go/dns_firewall"
  "github.com/cloudflare/cloudflare-go/option"
)

func main() {
  client := cloudflare.NewClient(
    option.WithAPIToken("Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY"),
  )
  dnsFirewall, err := client.DNSFirewall.New(context.TODO(), dns_firewall.DNSFirewallNewParams{
    AccountID: cloudflare.F("023e105f4ecef8ad9ca31a8372d0c353"),
    Name: cloudflare.F("My Awesome DNS Firewall cluster"),
    UpstreamIPs: cloudflare.F([]dns_firewall.UpstreamIPsParam{"192.0.2.1", "198.51.100.1", "2001:DB8:100::CF"}),
  })
  if err != nil {
    panic(err.Error())
  }
  fmt.Printf("%+v\n", dnsFirewall.ID)
}
```

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "id": "023e105f4ecef8ad9ca31a8372d0c353",
    "deprecate_any_requests": true,
    "dns_firewall_ips": [
      "203.0.113.1",
      "203.0.113.254",
      "2001:DB8:AB::CF",
      "2001:DB8:CD::CF"
    ],
    "ecs_fallback": false,
    "maximum_cache_ttl": 900,
    "minimum_cache_ttl": 60,
    "modified_on": "2014-01-01T05:20:00.12345Z",
    "name": "My Awesome DNS Firewall cluster",
    "negative_cache_ttl": 900,
    "ratelimit": 600,
    "retries": 2,
    "upstream_ips": [
      "192.0.2.1",
      "198.51.100.1",
      "2001:DB8:100::CF"
    ],
    "attack_mitigation": {
      "enabled": true,
      "only_when_upstream_unhealthy": false
    }
  }
}
```

##### Returns Examples

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": {
    "id": "023e105f4ecef8ad9ca31a8372d0c353",
    "deprecate_any_requests": true,
    "dns_firewall_ips": [
      "203.0.113.1",
      "203.0.113.254",
      "2001:DB8:AB::CF",
      "2001:DB8:CD::CF"
    ],
    "ecs_fallback": false,
    "maximum_cache_ttl": 900,
    "minimum_cache_ttl": 60,
    "modified_on": "2014-01-01T05:20:00.12345Z",
    "name": "My Awesome DNS Firewall cluster",
    "negative_cache_ttl": 900,
    "ratelimit": 600,
    "retries": 2,
    "upstream_ips": [
      "192.0.2.1",
      "198.51.100.1",
      "2001:DB8:100::CF"
    ],
    "attack_mitigation": {
      "enabled": true,
      "only_when_upstream_unhealthy": false
    }
  }
}
```