---
title: DNS Firewall
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/python)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# DNS Firewall

##### [List DNS Firewall Clusters](https://developers.cloudflare.com/api/python/resources/dns_firewall/methods/list)

dns\_firewall.list(DNSFirewallListParams\*\*kwargs) -> SyncV4PagePaginationArray\[[DNSFirewallListResponse](<https://developers.cloudflare.com/api/python/resources/dns_firewall#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_list_response%20%3E%20(schema)>)]

GET/accounts/{account\_id}/dns\_firewall

##### [DNS Firewall Cluster Details](https://developers.cloudflare.com/api/python/resources/dns_firewall/methods/get)

dns\_firewall.get(strdns\_firewall\_id, DNSFirewallGetParams\*\*kwargs) -> [DNSFirewallGetResponse](<https://developers.cloudflare.com/api/python/resources/dns_firewall#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/dns\_firewall/{dns\_firewall\_id}

##### [Create DNS Firewall Cluster](https://developers.cloudflare.com/api/python/resources/dns_firewall/methods/create)

dns\_firewall.create(DNSFirewallCreateParams\*\*kwargs) -> [DNSFirewallCreateResponse](<https://developers.cloudflare.com/api/python/resources/dns_firewall#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_create_response%20%3E%20(schema)>)

POST/accounts/{account\_id}/dns\_firewall

##### [Update DNS Firewall Cluster](https://developers.cloudflare.com/api/python/resources/dns_firewall/methods/edit)

dns\_firewall.edit(strdns\_firewall\_id, DNSFirewallEditParams\*\*kwargs) -> [DNSFirewallEditResponse](<https://developers.cloudflare.com/api/python/resources/dns_firewall#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_edit_response%20%3E%20(schema)>)

PATCH/accounts/{account\_id}/dns\_firewall/{dns\_firewall\_id}

##### [Delete DNS Firewall Cluster](https://developers.cloudflare.com/api/python/resources/dns_firewall/methods/delete)

dns\_firewall.delete(strdns\_firewall\_id, DNSFirewallDeleteParams\*\*kwargs) -> [DNSFirewallDeleteResponse](<https://developers.cloudflare.com/api/python/resources/dns_firewall#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_delete_response%20%3E%20(schema)>)

DELETE/accounts/{account\_id}/dns\_firewall/{dns\_firewall\_id}

##### ModelsExpand Collapse

<details>

<summary>

class AttackMitigation: …

Attack mitigation settings

</summary>

enabled: Optional\[bool]

When enabled, automatically mitigate random-prefix attacks to protect upstream DNS servers

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20attack_mitigation%20%3E%20(schema)%20%3E%20(property)%20enabled">Link to this property</a>

only\_when\_upstream\_unhealthy: Optional\[bool]

Only mitigate attacks when upstream servers seem unhealthy

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20attack_mitigation%20%3E%20(schema)%20%3E%20(property)%20only_when_upstream_unhealthy">Link to this property</a>

</details>

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(model)%20attack_mitigation%20%3E%20(schema)>)

str

Cloudflare-assigned DNS IPv4 address

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(model)%20firewall_ips%20%3E%20(schema)>)

str

Upstream DNS Server IPv4 address

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(model)%20upstream_ips%20%3E%20(schema)>)

<details>

<summary>

class DNSFirewallListResponse: …

</summary>

id: str

Identifier.

maxLength32

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_list_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

deprecate\_any\_requests: bool

Whether to refuse to answer queries for the ANY type

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_list_response%20%3E%20(schema)%20%3E%20(property)%20deprecate_any_requests">Link to this property</a>

dns\_firewall\_ips: List\[<a href="https://developers.cloudflare.com/api/python/resources/dns_firewall#(resource)%20dns_firewall%20%3E%20(model)%20firewall_ips%20%3E%20(schema)">FirewallIPs</a>]

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_list_response%20%3E%20(schema)%20%3E%20(property)%20dns_firewall_ips">Link to this property</a>

ecs\_fallback: bool

Whether to forward client IP (resolver) subnet if no EDNS Client Subnet is sent

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_list_response%20%3E%20(schema)%20%3E%20(property)%20ecs_fallback">Link to this property</a>

maximum\_cache\_ttl: float

By default, Cloudflare attempts to cache responses for as long as indicated by the TTL received from upstream nameservers. This setting sets an upper bound on this duration. For caching purposes, higher TTLs will be decreased to the maximum value defined by this setting.

This setting does not affect the TTL value in the DNS response Cloudflare returns to clients. Cloudflare will always forward the TTL value received from upstream nameservers.

maximum36000

minimum30

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_list_response%20%3E%20(schema)%20%3E%20(property)%20maximum_cache_ttl">Link to this property</a>

minimum\_cache\_ttl: float

By default, Cloudflare attempts to cache responses for as long as indicated by the TTL received from upstream nameservers. This setting sets a lower bound on this duration. For caching purposes, lower TTLs will be increased to the minimum value defined by this setting.

This setting does not affect the TTL value in the DNS response Cloudflare returns to clients. Cloudflare will always forward the TTL value received from upstream nameservers.

Note that, even with this setting, there is no guarantee that a response will be cached for at least the specified duration. Cached responses may be removed earlier for capacity or other operational reasons.

maximum36000

minimum30

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_list_response%20%3E%20(schema)%20%3E%20(property)%20minimum_cache_ttl">Link to this property</a>

modified\_on: datetime

Last modification of DNS Firewall cluster

formatdate-time

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_list_response%20%3E%20(schema)%20%3E%20(property)%20modified_on">Link to this property</a>

name: str

DNS Firewall cluster name

maxLength160

minLength1

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_list_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

negative\_cache\_ttl: Optional\[float]

This setting controls how long DNS Firewall should cache negative responses (e.g., NXDOMAIN) from the upstream servers.

This setting does not affect the TTL value in the DNS response Cloudflare returns to clients. Cloudflare will always forward the TTL value received from upstream nameservers.

maximum36000

minimum30

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_list_response%20%3E%20(schema)%20%3E%20(property)%20negative_cache_ttl">Link to this property</a>

ratelimit: Optional\[float]

Maximum number of DNS queries per second that will be forwarded to your upstream nameservers. The limit is enforced per server, where each server receives a fraction of the configured value. The actual aggregate rate for a data center may vary depending on how many servers are present. Responses served from cache do not count toward this limit. Set to null to disable rate limiting.

maximum1000000000

minimum100

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_list_response%20%3E%20(schema)%20%3E%20(property)%20ratelimit">Link to this property</a>

retries: float

Number of retries for fetching DNS responses from upstream nameservers (not counting the initial attempt)

maximum2

minimum0

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_list_response%20%3E%20(schema)%20%3E%20(property)%20retries">Link to this property</a>

upstream\_ips: List\[<a href="https://developers.cloudflare.com/api/python/resources/dns_firewall#(resource)%20dns_firewall%20%3E%20(model)%20upstream_ips%20%3E%20(schema)">UpstreamIPs</a>]

minLength1

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_list_response%20%3E%20(schema)%20%3E%20(property)%20upstream_ips">Link to this property</a>

attack\_mitigation: Optional\[AttackMitigation]

Attack mitigation settings

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_list_response%20%3E%20(schema)%20%3E%20(property)%20attack_mitigation">Link to this property</a>

</details>

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_list_response%20%3E%20(schema)>)

<details>

<summary>

class DNSFirewallGetResponse: …

</summary>

id: str

Identifier.

maxLength32

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_get_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

deprecate\_any\_requests: bool

Whether to refuse to answer queries for the ANY type

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_get_response%20%3E%20(schema)%20%3E%20(property)%20deprecate_any_requests">Link to this property</a>

dns\_firewall\_ips: List\[<a href="https://developers.cloudflare.com/api/python/resources/dns_firewall#(resource)%20dns_firewall%20%3E%20(model)%20firewall_ips%20%3E%20(schema)">FirewallIPs</a>]

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_get_response%20%3E%20(schema)%20%3E%20(property)%20dns_firewall_ips">Link to this property</a>

ecs\_fallback: bool

Whether to forward client IP (resolver) subnet if no EDNS Client Subnet is sent

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_get_response%20%3E%20(schema)%20%3E%20(property)%20ecs_fallback">Link to this property</a>

maximum\_cache\_ttl: float

By default, Cloudflare attempts to cache responses for as long as indicated by the TTL received from upstream nameservers. This setting sets an upper bound on this duration. For caching purposes, higher TTLs will be decreased to the maximum value defined by this setting.

This setting does not affect the TTL value in the DNS response Cloudflare returns to clients. Cloudflare will always forward the TTL value received from upstream nameservers.

maximum36000

minimum30

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_get_response%20%3E%20(schema)%20%3E%20(property)%20maximum_cache_ttl">Link to this property</a>

minimum\_cache\_ttl: float

By default, Cloudflare attempts to cache responses for as long as indicated by the TTL received from upstream nameservers. This setting sets a lower bound on this duration. For caching purposes, lower TTLs will be increased to the minimum value defined by this setting.

This setting does not affect the TTL value in the DNS response Cloudflare returns to clients. Cloudflare will always forward the TTL value received from upstream nameservers.

Note that, even with this setting, there is no guarantee that a response will be cached for at least the specified duration. Cached responses may be removed earlier for capacity or other operational reasons.

maximum36000

minimum30

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_get_response%20%3E%20(schema)%20%3E%20(property)%20minimum_cache_ttl">Link to this property</a>

modified\_on: datetime

Last modification of DNS Firewall cluster

formatdate-time

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_get_response%20%3E%20(schema)%20%3E%20(property)%20modified_on">Link to this property</a>

name: str

DNS Firewall cluster name

maxLength160

minLength1

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_get_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

negative\_cache\_ttl: Optional\[float]

This setting controls how long DNS Firewall should cache negative responses (e.g., NXDOMAIN) from the upstream servers.

This setting does not affect the TTL value in the DNS response Cloudflare returns to clients. Cloudflare will always forward the TTL value received from upstream nameservers.

maximum36000

minimum30

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_get_response%20%3E%20(schema)%20%3E%20(property)%20negative_cache_ttl">Link to this property</a>

ratelimit: Optional\[float]

Maximum number of DNS queries per second that will be forwarded to your upstream nameservers. The limit is enforced per server, where each server receives a fraction of the configured value. The actual aggregate rate for a data center may vary depending on how many servers are present. Responses served from cache do not count toward this limit. Set to null to disable rate limiting.

maximum1000000000

minimum100

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_get_response%20%3E%20(schema)%20%3E%20(property)%20ratelimit">Link to this property</a>

retries: float

Number of retries for fetching DNS responses from upstream nameservers (not counting the initial attempt)

maximum2

minimum0

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_get_response%20%3E%20(schema)%20%3E%20(property)%20retries">Link to this property</a>

upstream\_ips: List\[<a href="https://developers.cloudflare.com/api/python/resources/dns_firewall#(resource)%20dns_firewall%20%3E%20(model)%20upstream_ips%20%3E%20(schema)">UpstreamIPs</a>]

minLength1

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_get_response%20%3E%20(schema)%20%3E%20(property)%20upstream_ips">Link to this property</a>

attack\_mitigation: Optional\[AttackMitigation]

Attack mitigation settings

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_get_response%20%3E%20(schema)%20%3E%20(property)%20attack_mitigation">Link to this property</a>

</details>

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_get_response%20%3E%20(schema)>)

<details>

<summary>

class DNSFirewallCreateResponse: …

</summary>

id: str

Identifier.

maxLength32

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_create_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

deprecate\_any\_requests: bool

Whether to refuse to answer queries for the ANY type

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_create_response%20%3E%20(schema)%20%3E%20(property)%20deprecate_any_requests">Link to this property</a>

dns\_firewall\_ips: List\[<a href="https://developers.cloudflare.com/api/python/resources/dns_firewall#(resource)%20dns_firewall%20%3E%20(model)%20firewall_ips%20%3E%20(schema)">FirewallIPs</a>]

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_create_response%20%3E%20(schema)%20%3E%20(property)%20dns_firewall_ips">Link to this property</a>

ecs\_fallback: bool

Whether to forward client IP (resolver) subnet if no EDNS Client Subnet is sent

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_create_response%20%3E%20(schema)%20%3E%20(property)%20ecs_fallback">Link to this property</a>

maximum\_cache\_ttl: float

By default, Cloudflare attempts to cache responses for as long as indicated by the TTL received from upstream nameservers. This setting sets an upper bound on this duration. For caching purposes, higher TTLs will be decreased to the maximum value defined by this setting.

This setting does not affect the TTL value in the DNS response Cloudflare returns to clients. Cloudflare will always forward the TTL value received from upstream nameservers.

maximum36000

minimum30

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_create_response%20%3E%20(schema)%20%3E%20(property)%20maximum_cache_ttl">Link to this property</a>

minimum\_cache\_ttl: float

By default, Cloudflare attempts to cache responses for as long as indicated by the TTL received from upstream nameservers. This setting sets a lower bound on this duration. For caching purposes, lower TTLs will be increased to the minimum value defined by this setting.

This setting does not affect the TTL value in the DNS response Cloudflare returns to clients. Cloudflare will always forward the TTL value received from upstream nameservers.

Note that, even with this setting, there is no guarantee that a response will be cached for at least the specified duration. Cached responses may be removed earlier for capacity or other operational reasons.

maximum36000

minimum30

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_create_response%20%3E%20(schema)%20%3E%20(property)%20minimum_cache_ttl">Link to this property</a>

modified\_on: datetime

Last modification of DNS Firewall cluster

formatdate-time

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_create_response%20%3E%20(schema)%20%3E%20(property)%20modified_on">Link to this property</a>

name: str

DNS Firewall cluster name

maxLength160

minLength1

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_create_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

negative\_cache\_ttl: Optional\[float]

This setting controls how long DNS Firewall should cache negative responses (e.g., NXDOMAIN) from the upstream servers.

This setting does not affect the TTL value in the DNS response Cloudflare returns to clients. Cloudflare will always forward the TTL value received from upstream nameservers.

maximum36000

minimum30

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_create_response%20%3E%20(schema)%20%3E%20(property)%20negative_cache_ttl">Link to this property</a>

ratelimit: Optional\[float]

Maximum number of DNS queries per second that will be forwarded to your upstream nameservers. The limit is enforced per server, where each server receives a fraction of the configured value. The actual aggregate rate for a data center may vary depending on how many servers are present. Responses served from cache do not count toward this limit. Set to null to disable rate limiting.

maximum1000000000

minimum100

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_create_response%20%3E%20(schema)%20%3E%20(property)%20ratelimit">Link to this property</a>

retries: float

Number of retries for fetching DNS responses from upstream nameservers (not counting the initial attempt)

maximum2

minimum0

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_create_response%20%3E%20(schema)%20%3E%20(property)%20retries">Link to this property</a>

upstream\_ips: List\[<a href="https://developers.cloudflare.com/api/python/resources/dns_firewall#(resource)%20dns_firewall%20%3E%20(model)%20upstream_ips%20%3E%20(schema)">UpstreamIPs</a>]

minLength1

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_create_response%20%3E%20(schema)%20%3E%20(property)%20upstream_ips">Link to this property</a>

attack\_mitigation: Optional\[AttackMitigation]

Attack mitigation settings

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_create_response%20%3E%20(schema)%20%3E%20(property)%20attack_mitigation">Link to this property</a>

</details>

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_create_response%20%3E%20(schema)>)

<details>

<summary>

class DNSFirewallEditResponse: …

</summary>

id: str

Identifier.

maxLength32

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_edit_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

deprecate\_any\_requests: bool

Whether to refuse to answer queries for the ANY type

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_edit_response%20%3E%20(schema)%20%3E%20(property)%20deprecate_any_requests">Link to this property</a>

dns\_firewall\_ips: List\[<a href="https://developers.cloudflare.com/api/python/resources/dns_firewall#(resource)%20dns_firewall%20%3E%20(model)%20firewall_ips%20%3E%20(schema)">FirewallIPs</a>]

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_edit_response%20%3E%20(schema)%20%3E%20(property)%20dns_firewall_ips">Link to this property</a>

ecs\_fallback: bool

Whether to forward client IP (resolver) subnet if no EDNS Client Subnet is sent

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_edit_response%20%3E%20(schema)%20%3E%20(property)%20ecs_fallback">Link to this property</a>

maximum\_cache\_ttl: float

By default, Cloudflare attempts to cache responses for as long as indicated by the TTL received from upstream nameservers. This setting sets an upper bound on this duration. For caching purposes, higher TTLs will be decreased to the maximum value defined by this setting.

This setting does not affect the TTL value in the DNS response Cloudflare returns to clients. Cloudflare will always forward the TTL value received from upstream nameservers.

maximum36000

minimum30

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_edit_response%20%3E%20(schema)%20%3E%20(property)%20maximum_cache_ttl">Link to this property</a>

minimum\_cache\_ttl: float

By default, Cloudflare attempts to cache responses for as long as indicated by the TTL received from upstream nameservers. This setting sets a lower bound on this duration. For caching purposes, lower TTLs will be increased to the minimum value defined by this setting.

This setting does not affect the TTL value in the DNS response Cloudflare returns to clients. Cloudflare will always forward the TTL value received from upstream nameservers.

Note that, even with this setting, there is no guarantee that a response will be cached for at least the specified duration. Cached responses may be removed earlier for capacity or other operational reasons.

maximum36000

minimum30

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_edit_response%20%3E%20(schema)%20%3E%20(property)%20minimum_cache_ttl">Link to this property</a>

modified\_on: datetime

Last modification of DNS Firewall cluster

formatdate-time

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_edit_response%20%3E%20(schema)%20%3E%20(property)%20modified_on">Link to this property</a>

name: str

DNS Firewall cluster name

maxLength160

minLength1

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_edit_response%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

negative\_cache\_ttl: Optional\[float]

This setting controls how long DNS Firewall should cache negative responses (e.g., NXDOMAIN) from the upstream servers.

This setting does not affect the TTL value in the DNS response Cloudflare returns to clients. Cloudflare will always forward the TTL value received from upstream nameservers.

maximum36000

minimum30

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_edit_response%20%3E%20(schema)%20%3E%20(property)%20negative_cache_ttl">Link to this property</a>

ratelimit: Optional\[float]

Maximum number of DNS queries per second that will be forwarded to your upstream nameservers. The limit is enforced per server, where each server receives a fraction of the configured value. The actual aggregate rate for a data center may vary depending on how many servers are present. Responses served from cache do not count toward this limit. Set to null to disable rate limiting.

maximum1000000000

minimum100

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_edit_response%20%3E%20(schema)%20%3E%20(property)%20ratelimit">Link to this property</a>

retries: float

Number of retries for fetching DNS responses from upstream nameservers (not counting the initial attempt)

maximum2

minimum0

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_edit_response%20%3E%20(schema)%20%3E%20(property)%20retries">Link to this property</a>

upstream\_ips: List\[<a href="https://developers.cloudflare.com/api/python/resources/dns_firewall#(resource)%20dns_firewall%20%3E%20(model)%20upstream_ips%20%3E%20(schema)">UpstreamIPs</a>]

minLength1

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_edit_response%20%3E%20(schema)%20%3E%20(property)%20upstream_ips">Link to this property</a>

attack\_mitigation: Optional\[AttackMitigation]

Attack mitigation settings

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_edit_response%20%3E%20(schema)%20%3E%20(property)%20attack_mitigation">Link to this property</a>

</details>

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_edit_response%20%3E%20(schema)>)

<details>

<summary>

class DNSFirewallDeleteResponse: …

</summary>

id: Optional\[str]

Identifier.

maxLength32

<a href="#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_delete_response%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

</details>

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(model)%20dns_firewall_delete_response%20%3E%20(schema)>)

#### DNS FirewallAnalytics

#### DNS FirewallAnalyticsReports

##### [Table](https://developers.cloudflare.com/api/python/resources/dns_firewall/subresources/analytics/subresources/reports/methods/get)

Deprecated

dns\_firewall.analytics.reports.get(strdns\_firewall\_id, ReportGetParams\*\*kwargs) -> [Report](<https://developers.cloudflare.com/api/python/resources/dns#(resource)%20dns.analytics.reports%20%3E%20(model)%20report%20%3E%20(schema)>)

GET/accounts/{account\_id}/dns\_firewall/{dns\_firewall\_id}/dns\_analytics/report

#### DNS FirewallAnalyticsReportsBytimes

##### [By Time](https://developers.cloudflare.com/api/python/resources/dns_firewall/subresources/analytics/subresources/reports/subresources/bytimes/methods/get)

Deprecated

dns\_firewall.analytics.reports.bytimes.get(strdns\_firewall\_id, BytimeGetParams\*\*kwargs) -> [ByTime](<https://developers.cloudflare.com/api/python/resources/dns#(resource)%20dns.analytics.reports.bytimes%20%3E%20(model)%20by_time%20%3E%20(schema)>)

GET/accounts/{account\_id}/dns\_firewall/{dns\_firewall\_id}/dns\_analytics/report/bytime

#### DNS FirewallReverse DNS

##### [Show DNS Firewall Cluster Reverse DNS](https://developers.cloudflare.com/api/python/resources/dns_firewall/subresources/reverse_dns/methods/get)

dns\_firewall.reverse\_dns.get(strdns\_firewall\_id, ReverseDNSGetParams\*\*kwargs) -> [ReverseDNSGetResponse](<https://developers.cloudflare.com/api/python/resources/dns_firewall#(resource)%20dns_firewall.reverse_dns%20%3E%20(model)%20reverse_dns_get_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/dns\_firewall/{dns\_firewall\_id}/reverse\_dns

##### [Update DNS Firewall Cluster Reverse DNS](https://developers.cloudflare.com/api/python/resources/dns_firewall/subresources/reverse_dns/methods/edit)

dns\_firewall.reverse\_dns.edit(strdns\_firewall\_id, ReverseDNSEditParams\*\*kwargs) -> [ReverseDNSEditResponse](<https://developers.cloudflare.com/api/python/resources/dns_firewall#(resource)%20dns_firewall.reverse_dns%20%3E%20(model)%20reverse_dns_edit_response%20%3E%20(schema)>)

PATCH/accounts/{account\_id}/dns\_firewall/{dns\_firewall\_id}/reverse\_dns

##### ModelsExpand Collapse

<details>

<summary>

class ReverseDNSGetResponse: …

</summary>

ptr: Dict\[str, str]

Map of cluster IP addresses to PTR record contents

<a href="#(resource)%20dns_firewall.reverse_dns%20%3E%20(model)%20reverse_dns_get_response%20%3E%20(schema)%20%3E%20(property)%20ptr">Link to this property</a>

</details>

[Link to this property](<#(resource)%20dns_firewall.reverse_dns%20%3E%20(model)%20reverse_dns_get_response%20%3E%20(schema)>)

<details>

<summary>

class ReverseDNSEditResponse: …

</summary>

ptr: Dict\[str, str]

Map of cluster IP addresses to PTR record contents

<a href="#(resource)%20dns_firewall.reverse_dns%20%3E%20(model)%20reverse_dns_edit_response%20%3E%20(schema)%20%3E%20(property)%20ptr">Link to this property</a>

</details>

[Link to this property](<#(resource)%20dns_firewall.reverse_dns%20%3E%20(model)%20reverse_dns_edit_response%20%3E%20(schema)>)