---
title: DNS Firewall
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/terraform)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# DNS Firewall

#### resource cloudflare\_dns\_firewall

##### required Expand Collapse

account\_id: String

Identifier.

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20account_id>)

name: String

DNS Firewall cluster name

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20name>)

upstream\_ips: Set\[String]

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20upstream_ips>)

##### optional Expand Collapse

dns\_firewall\_ip\_count?: Int64

Number of IPv4 addresses to assign to the DNS Firewall cluster. Only used during cluster creation and cannot be changed later.

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20dns_firewall_ip_count>)

deprecate\_any\_requests?: Bool

Whether to refuse to answer queries for the ANY type

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20deprecate_any_requests>)

ecs\_fallback?: Bool

Whether to forward client IP (resolver) subnet if no EDNS Client Subnet is sent

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20ecs_fallback>)

negative\_cache\_ttl?: Float64

This setting controls how long DNS Firewall should cache negative responses (e.g., NXDOMAIN) from the upstream servers.

This setting does not affect the TTL value in the DNS response Cloudflare returns to clients. Cloudflare will always forward the TTL value received from upstream nameservers.

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20negative_cache_ttl>)

ratelimit?: Float64

Maximum number of DNS queries per second that will be forwarded to your upstream nameservers. The limit is enforced per server, where each server receives a fraction of the configured value. The actual aggregate rate for a data center may vary depending on how many servers are present. Responses served from cache do not count toward this limit. Set to null to disable rate limiting.

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20ratelimit>)

maximum\_cache\_ttl?: Float64

By default, Cloudflare attempts to cache responses for as long as indicated by the TTL received from upstream nameservers. This setting sets an upper bound on this duration. For caching purposes, higher TTLs will be decreased to the maximum value defined by this setting.

This setting does not affect the TTL value in the DNS response Cloudflare returns to clients. Cloudflare will always forward the TTL value received from upstream nameservers.

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20maximum_cache_ttl>)

minimum\_cache\_ttl?: Float64

By default, Cloudflare attempts to cache responses for as long as indicated by the TTL received from upstream nameservers. This setting sets a lower bound on this duration. For caching purposes, lower TTLs will be increased to the minimum value defined by this setting.

This setting does not affect the TTL value in the DNS response Cloudflare returns to clients. Cloudflare will always forward the TTL value received from upstream nameservers.

Note that, even with this setting, there is no guarantee that a response will be cached for at least the specified duration. Cached responses may be removed earlier for capacity or other operational reasons.

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20minimum_cache_ttl>)

retries?: Float64

Number of retries for fetching DNS responses from upstream nameservers (not counting the initial attempt)

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20retries>)

<details>

<summary>

attack\_mitigation?: Attributes

Attack mitigation settings

</summary>

enabled?: Bool

When enabled, automatically mitigate random-prefix attacks to protect upstream DNS servers

<a href="#(resource)%20dns_firewall%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20attack_mitigation%20%3E%20(attribute)%20enabled">Link to this property</a>

only\_when\_upstream\_unhealthy?: Bool

Only mitigate attacks when upstream servers seem unhealthy

<a href="#(resource)%20dns_firewall%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20attack_mitigation%20%3E%20(attribute)%20only_when_upstream_unhealthy">Link to this property</a>

</details>

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20attack_mitigation>)

##### computed Expand Collapse

id: String

Identifier.

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

modified\_on: Time

Last modification of DNS Firewall cluster

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20modified_on>)

dns\_firewall\_ips: Set\[String]

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20dns_firewall_ips>)

### cloudflare\_dns\_firewall

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_dns_firewall" "example_dns_firewall" {
  account_id = "023e105f4ecef8ad9ca31a8372d0c353"
  name = "My Awesome DNS Firewall cluster"
  upstream_ips = ["192.0.2.1", "198.51.100.1", "2001:DB8:100::CF"]
  attack_mitigation = {
    enabled = true
    only_when_upstream_unhealthy = false
  }
  deprecate_any_requests = true
  dns_firewall_ip_count = 2
  ecs_fallback = false
  maximum_cache_ttl = 900
  minimum_cache_ttl = 60
  negative_cache_ttl = 900
  ratelimit = 600
  retries = 2
}
```

#### data cloudflare\_dns\_firewall

##### required Expand Collapse

dns\_firewall\_id: String

Identifier.

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20dns_firewall_id>)

account\_id: String

Identifier.

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20account_id>)

##### computed Expand Collapse

id: String

Identifier.

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

deprecate\_any\_requests: Bool

Whether to refuse to answer queries for the ANY type

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20deprecate_any_requests>)

ecs\_fallback: Bool

Whether to forward client IP (resolver) subnet if no EDNS Client Subnet is sent

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20ecs_fallback>)

maximum\_cache\_ttl: Float64

By default, Cloudflare attempts to cache responses for as long as indicated by the TTL received from upstream nameservers. This setting sets an upper bound on this duration. For caching purposes, higher TTLs will be decreased to the maximum value defined by this setting.

This setting does not affect the TTL value in the DNS response Cloudflare returns to clients. Cloudflare will always forward the TTL value received from upstream nameservers.

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20maximum_cache_ttl>)

minimum\_cache\_ttl: Float64

By default, Cloudflare attempts to cache responses for as long as indicated by the TTL received from upstream nameservers. This setting sets a lower bound on this duration. For caching purposes, lower TTLs will be increased to the minimum value defined by this setting.

This setting does not affect the TTL value in the DNS response Cloudflare returns to clients. Cloudflare will always forward the TTL value received from upstream nameservers.

Note that, even with this setting, there is no guarantee that a response will be cached for at least the specified duration. Cached responses may be removed earlier for capacity or other operational reasons.

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20minimum_cache_ttl>)

modified\_on: Time

Last modification of DNS Firewall cluster

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20modified_on>)

name: String

DNS Firewall cluster name

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20name>)

negative\_cache\_ttl: Float64

This setting controls how long DNS Firewall should cache negative responses (e.g., NXDOMAIN) from the upstream servers.

This setting does not affect the TTL value in the DNS response Cloudflare returns to clients. Cloudflare will always forward the TTL value received from upstream nameservers.

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20negative_cache_ttl>)

ratelimit: Float64

Maximum number of DNS queries per second that will be forwarded to your upstream nameservers. The limit is enforced per server, where each server receives a fraction of the configured value. The actual aggregate rate for a data center may vary depending on how many servers are present. Responses served from cache do not count toward this limit. Set to null to disable rate limiting.

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20ratelimit>)

retries: Float64

Number of retries for fetching DNS responses from upstream nameservers (not counting the initial attempt)

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20retries>)

dns\_firewall\_ips: Set\[String]

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20dns_firewall_ips>)

upstream\_ips: Set\[String]

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20upstream_ips>)

<details>

<summary>

attack\_mitigation: Attributes

Attack mitigation settings

</summary>

enabled: Bool

When enabled, automatically mitigate random-prefix attacks to protect upstream DNS servers

<a href="#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20attack_mitigation%20%3E%20(attribute)%20enabled">Link to this property</a>

only\_when\_upstream\_unhealthy: Bool

Only mitigate attacks when upstream servers seem unhealthy

<a href="#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20attack_mitigation%20%3E%20(attribute)%20only_when_upstream_unhealthy">Link to this property</a>

</details>

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20attack_mitigation>)

### cloudflare\_dns\_firewall

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_dns_firewall" "example_dns_firewall" {
  account_id = "023e105f4ecef8ad9ca31a8372d0c353"
  dns_firewall_id = "023e105f4ecef8ad9ca31a8372d0c353"
}
```

#### data cloudflare\_dns\_firewalls

##### required Expand Collapse

account\_id: String

Identifier.

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20account_id>)

##### optional Expand Collapse

max\_items?: Int64

Max items to fetch, default: 1000

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20max_items>)

##### computed Expand Collapse

<details>

<summary>

result: List\[Attributes]

The items returned by the data source

</summary>

id: String

Identifier.

<a href="#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20id">Link to this property</a>

deprecate\_any\_requests: Bool

Whether to refuse to answer queries for the ANY type

<a href="#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20deprecate_any_requests">Link to this property</a>

dns\_firewall\_ips: Set\[String]

<a href="#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20dns_firewall_ips">Link to this property</a>

ecs\_fallback: Bool

Whether to forward client IP (resolver) subnet if no EDNS Client Subnet is sent

<a href="#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20ecs_fallback">Link to this property</a>

maximum\_cache\_ttl: Float64

By default, Cloudflare attempts to cache responses for as long as indicated by the TTL received from upstream nameservers. This setting sets an upper bound on this duration. For caching purposes, higher TTLs will be decreased to the maximum value defined by this setting.

This setting does not affect the TTL value in the DNS response Cloudflare returns to clients. Cloudflare will always forward the TTL value received from upstream nameservers.

<a href="#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20maximum_cache_ttl">Link to this property</a>

minimum\_cache\_ttl: Float64

By default, Cloudflare attempts to cache responses for as long as indicated by the TTL received from upstream nameservers. This setting sets a lower bound on this duration. For caching purposes, lower TTLs will be increased to the minimum value defined by this setting.

This setting does not affect the TTL value in the DNS response Cloudflare returns to clients. Cloudflare will always forward the TTL value received from upstream nameservers.

Note that, even with this setting, there is no guarantee that a response will be cached for at least the specified duration. Cached responses may be removed earlier for capacity or other operational reasons.

<a href="#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20minimum_cache_ttl">Link to this property</a>

modified\_on: Time

Last modification of DNS Firewall cluster

<a href="#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20modified_on">Link to this property</a>

name: String

DNS Firewall cluster name

<a href="#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20name">Link to this property</a>

negative\_cache\_ttl: Float64

This setting controls how long DNS Firewall should cache negative responses (e.g., NXDOMAIN) from the upstream servers.

This setting does not affect the TTL value in the DNS response Cloudflare returns to clients. Cloudflare will always forward the TTL value received from upstream nameservers.

<a href="#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20negative_cache_ttl">Link to this property</a>

ratelimit: Float64

Maximum number of DNS queries per second that will be forwarded to your upstream nameservers. The limit is enforced per server, where each server receives a fraction of the configured value. The actual aggregate rate for a data center may vary depending on how many servers are present. Responses served from cache do not count toward this limit. Set to null to disable rate limiting.

<a href="#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20ratelimit">Link to this property</a>

retries: Float64

Number of retries for fetching DNS responses from upstream nameservers (not counting the initial attempt)

<a href="#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20retries">Link to this property</a>

upstream\_ips: Set\[String]

<a href="#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20upstream_ips">Link to this property</a>

<details>

<summary>

attack\_mitigation: Attributes

Attack mitigation settings

</summary>

enabled: Bool

When enabled, automatically mitigate random-prefix attacks to protect upstream DNS servers

<a href="#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20attack_mitigation%20%3E%20(attribute)%20enabled">Link to this property</a>

only\_when\_upstream\_unhealthy: Bool

Only mitigate attacks when upstream servers seem unhealthy

<a href="#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20attack_mitigation%20%3E%20(attribute)%20only_when_upstream_unhealthy">Link to this property</a>

</details>

<a href="#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20attack_mitigation">Link to this property</a>

</details>

[Link to this property](<#(resource)%20dns_firewall%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result>)

### cloudflare\_dns\_firewalls

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_dns_firewalls" "example_dns_firewalls" {
  account_id = "023e105f4ecef8ad9ca31a8372d0c353"
}
```