---
title: "Cloudflare"
canonical: "https://docs.infoblox.com/space/UniversalAssetInsights/1552613857/Cloudflare"
format: markdown
---
The integration between Cloudflare and Universal DDI delivers comprehensive, cloud-native visibility into internet-facing assets and edge security posture across global enterprise environments. Leveraging Cloudflare’s robust APIs and security analytics, Universal DDI continuously ingests telemetry from Cloudflare services—including DNS, CDN, Zero Trust, Magic Transit, and Gateway—to enrich asset intelligence with real-time traffic patterns, policy enforcement actions, and user access activity.

> ⚠️ Discovery data updates for DNS and IPAM are not supported if your account is configured with only the Infoblox Threat Defense license entitlement.

This integration enables dynamic discovery of cloud-hosted and remote endpoints, mapping their relationships to Cloudflare-managed domains, proxy services, firewall rules, and secure access policies. Administrators benefit from a centralized, API-driven asset inventory enhanced by Cloudflare’s insights into threat intelligence, request behavior, and web application protections.

When combined with Universal DDI’s IPAM and DNS telemetry, this unified perspective strengthens cyber defense capabilities, supports rapid incident investigation, and enables intelligent segmentation strategies aligned with zero-trust principles. The result is a resilient, high-performance network edge fortified by Cloudflare’s globally distributed security and performance infrastructure.

> ⚠️ **Read-only sync:** If you configure read-only sync, you cannot make any changes to Cloudflare DNS objects in the Infoblox Portal.
> ⚠️ 
> ⚠️ **Read/write sync**:  If you configure read/write sync, any changes made to the DNS objects in the Infoblox Portal will be synced to Cloudflare.

## API Permissions required for Cloudflare DNS discovery

To support DNS management using zones and records, add the following permissions to Cloudflare account API token: 

- Account:
  - Account Filter Lists: Read
- All zones:
  - Zone Settings: Edit
  - Zone: Edit
  - DNS: Edit

## Limitations of DNS Discovery with Cloudflare

DNS discovery with Cloudflare has the following limitations:

- Cloudflare does not support zone creation with unregistered domain names (for example, boost.boost)
- Cloudflare only supports limited IP ranges for proxied records:
  - 1.0.0.0/24 (IPV4)
  - 1.1.1.0/24 (IPv4)
  - 2606:4700:4700::/48 (IPV6)

To create a network discovery configuration for Cloudflare, complete the following:

- Go to** Integrations > Discovery > Cloud.**
- Click **Create > Cloudflare**.

> ℹ️ Before configuring discovery for Cloudflare, you must create credentials. For more information, see *[Creating Cloudflare Credentials](https://infoblox-docs.atlassian.net/wiki/spaces/UniversalAssetInsights/pages/1689618531)*.

> ⚠️ When a provider discovery job is deleted in Universal DDI, the DNS zone that was synchronized through that job remains in its original DNS view (for example, *default*), but it is no longer linked to any cloud provider and it will no longer participate in cloud synchronization. If a new discovery job is later created using the same DNS view name, UDDI automatically generates a new provider-linked DNS view (for example, *default-1*) to preserve the integrity of provider associations. To ensure that DNS record updates continue to synchronize with the cloud provider, administrators must add or modify records within the zone that resides under the active provider-linked view (such as *default-1*), rather than in the old, unsynchronized view (*default*).

Configure the following settings in the wizard:

> Macro (children)