Configuring Cloudflare as DDNS Provider

Options
Zyxel_Lynn
Zyxel_Lynn image  Zyxel Employee
5 Answers First Comment Friend Collector First Anniversary
edited August 18 in Other Topics

Modern Dynamic DNS Support

Zyxel firewalls now support Cloudflare as a standard DDNS provider, offering a more secure and modern alternative to traditional services.

Security via API Tokens

Unlike traditional DDNS services that rely on usernames and passwords, the Cloudflare integration uses API Tokens and Zone IDs. This provides a more secure authentication mechanism for updating the firewall's public IP address.

Configuration Requirements

For the update to succeed, several settings must be correctly configured in the Cloudflare dashboard:

  • Permissions: The API token must be granted "Edit" permissions for the DNS zone; "Read" permissions will cause the update to fail.

  • Proxy Status: The A record in Cloudflare must be set to "DNS Only" mode. If set to "Proxied," the DDNS update might retrieve a Cloudflare IP instead of the firewall's actual WAN IP.

Efficiency

To reduce unnecessary traffic, the firewall includes a mechanism to skip updates if the WAN IP address has not changed since the last successful sync.