Thank you for using the origin protection feature of Edge Security Acceleration (ESA). The origin protection feature lets you obtain the origin CIDR blocks for ESA and add them to the whitelist of your origin server firewall. To optimize our service and provide a better experience, we are updating this feature starting November 7, 2025.
Update details
-
The list of available origin IP CIDR blocks will change: Full list of IP addresses (more IPs) → Converged list of IP addresses (fewer IPs).
-
If you use Cloud Firewall to automatically protect your origin server: Before: The origin protection feature was not required. → After: You must enable the origin protection feature and the "Auto-apply Latest Origin Fetch IP List" option.

-
The origin protection feature can be enabled only for cache architectures with two or more layers.

Impact of the changes
The Entrance plan does not support the origin protection feature. If your ESA plan does not support the origin protection feature, do not reference the ESA address book in Cloud Firewall. You can upgrade the ESA plan for using the origin protection feature.