Enhancing the Security and Resilience of Qualys API Services
At Qualys, we continuously invest in strengthening the security, availability, and resilience of our cloud platform to address the evolving threat landscape and deliver a reliable experience for our customers.
In 2023, we introduced Cloudflare Layer 7 DDoS protection for our portal services as part of our ongoing defense-in-depth strategy. This enhancement strengthened the availability and security of customer-facing services while improving protection against large-scale application-layer attacks.
Building on that success, we will now extend Cloudflare Layer 7 DDoS protection to dedicated API endpoints across all platform PODs. This leverages the same proven security architecture already protecting portal traffic, extending consistent protection across all customer-facing services.
What Is Changing?
Dedicated Qualys API endpoints (for example, qualysapi.<pod>. apps.qualys.com) will be protected by Cloudflare’s global application security and DDoS mitigation infrastructure.
This additional layer of protection will help strengthen the resilience and availability of Qualys API services against evolving application-layer threats while maintaining a seamless customer experience.
Why Are We Making This Change?
As cyber threats continue to evolve, Qualys remains committed to maintaining a robust defense-in-depth security posture.
By extending Cloudflare protection to Qualys API endpoints, we aim to:
- Enhance protection against Layer 7 DDoS attacks
- Improve API service availability and resilience
- Strengthen our ability to detect and mitigate emerging threats
- Provide a consistent security framework across Qualys services
- Further improve the reliability of customer integrations and automation workflows
Customer Impact
For the vast majority of customers, no action is required. Existing API endpoint URLs, authentication mechanisms, integrations, scripts, and automation workflows will continue to operate without modification. API endpoint URLs will not change, and customers should continue using their existing URLs. This enhancement also does not introduce any changes to authentication or functionality, including: API functionality, Authentication methods, Request formats, Response formats, and Existing integration workflows.
Firewall and Proxy Considerations
Most customers will not need to make any changes as part of this enhancement. However, customers who enforce outbound connectivity restrictions via firewalls, secure web gateways, proxies, or IP-based allowlists should review their configurations to ensure that connectivity to Cloudflare-protected Qualys services is permitted.
If your organization maintains explicit allowlists, ensure the following IP addresses are allowed:
162.159.152.21 and 162.159.153.243
These are the same IP addresses that were previously communicated as part of the Cloudflare protection enhancement for Qualys platform services.
Expected Service Impact
No service interruption is expected during the rollout of this enhancement. The deployment will be performed in phases across Qualys platform PODs, with Engineering, Operations, and Security teams closely monitoring service health, service continuity, and customer traffic throughout the implementation.
The phased rollout has been extended to give customers more time to make any needed changes. Updated rollout dates are listed in the table below. We apologize for any inconvenience this may cause and appreciate your patience as we work to improve our services and provide the best possible customer experience.
For commonly asked questions, see here. You can check your POD status here.
| POD | Release Date | Expected Implementation Time |
|---|---|---|
| CA POD 01 | 01-Sep-2026 | 06:00 AM – 08:00 AM UTC |
| AE POD 01 | 04-Sep-2026 | 03:00 AM – 05:00 AM UTC |
| IN POD 01 | 07-Sep-2026 | 03:00 PM – 05:00 PM UTC |
| AU POD 01 | 11-Sep-2026 | 06:00 AM – 08:00 AM UTC |
| KSA POD 01 | 18-Sep-2026 | 06:00 AM – 08:00 AM UTC |
| EU POD 01 | 21-Sep-2026 | 03:00 AM – 05:00 AM UTC |
| EU POD 02 | 25-Sep-2026 | 03:00 AM – 05:00 AM UTC |
| EU POD 03 | 27-Sep-2026 | 03:00 AM – 05:00 AM UTC |
| UK POD 01 | 01-Oct-2026 | 03:00 AM – 05:00 AM UTC |
| US POD 05 | 05-Oct-2026 | 06:00 AM – 08:00 AM UTC |
| US POD 04 | 09-Oct-2026 | 06:00 AM – 08:00 AM UTC |
| US POD 03 | 12-Oct-2026 | 06:00 AM – 08:00 AM UTC |
| US POD 02 | 16-Oct-2026 | 06:00 AM – 08:00 AM UTC |
| US POD 01 | 19-Oct-2026 | 06:00 AM – 08:00 AM UTC |
If you need any further assistance, please contact our support team here.
Frequently Asked Questions (FAQs)
Why is this enhancement implemented?
To combat Layer 7 Distributed Denial of Service (DDoS) attacks, Qualys is extending Cloudflare Layer 7 protection to dedicated Qualys API endpoints. This additional security layer improves Qualys’ ability to absorb and mitigate large-scale application-layer attacks while enhancing the overall availability and security of our cloud platform and services.
Why is allowlisting required?
Customers who use restrictive outbound firewall rules, proxy servers, secure web gateways, or IP-based allowlists may need to update their policies. Once Cloudflare protection is enabled for Qualys API endpoints, the protected FQDNs will resolve to the following IP addresses:
162.159.152.21 & 162.159.153.243
If your organization uses an allowlisting approach to connectivity, Cloudflare recommends permitting these IP addresses from your perimeter devices, such as firewalls, proxy servers, and web gateways.
Can customers allowlist domains (FQDNs) instead of IP addresses?
Yes. If your security policies support FQDN-based allowlisting, there is no requirement to allowlist the IPs separately.
Will there be any impact on customers during this implementation?
No Qualys API services are expected to be affected, provided customer environments allow connectivity to the Cloudflare-protected endpoints with outbound restrictions in place.
Will this change affect API functionality?
No. There are no changes to:
- API functionality
- Authentication methods
- Request formats
- Response formats
- Existing integrations
- Automation workflows
Customers can continue using the APIs as they do today.
Will there be any new API URLs?
No. Existing Qualys API endpoint URLs will remain unchanged. Customers should continue using their current API URLs.
The existing API FQDNs will resolve the Cloudflare-protected IP addresses after implementation. This enhancement does not introduce new URLs.
What happens if we do not allow listing these IP addresses?
Customers using restrictive outbound firewall, proxy, or IP-based allowlisting policies may be unable to reach the Qualys API services after their POD has been enabled for Cloudflare protection.
Customers using FQDN-based allowlisting or unrestricted outbound HTTPS connectivity are not expected to be impacted.
What ports and direction are required?
All traffic remains outbound from the customer environment to Qualys services using HTTPS.
- Protocol: TCP
- Port: 443
- Direction: Outbound
- No additional ports are required.
Do we need to remove any existing IP addresses from our allowlist?
No. The Cloudflare IP addresses are in addition to any existing connectivity requirements currently used by your environment. Existing allowlist entries do not need to be removed.
Will Qualys Cloud Agents use the new IP addresses?
No. Qualys Cloud Agents will continue to communicate with the Qualys Cloud Platform through their existing communication paths and are not affected by this enhancement.
Will Qualys Scanner Appliances require access to the new IP addresses?
Customers operating Scanner Appliances in environments with restrictive outbound access policies should ensure connectivity to the Cloudflare-protected IP addresses is permitted.
Will externally hosted scanners use the new IP addresses?
No, externally hosted Qualys scanners will continue to use their existing IP addresses and communication methods.
Are these IP addresses used exclusively for Qualys services?
Yes. The following IP addresses are dedicated to Qualys services presented through Cloudflare protection:
162.159.152.21 & 162.159.153.243
Will there be any downtime during implementation?
No service interruption is expected as part of this enhancement. Qualys Engineering, Operations, and Security teams will closely monitor customer traffic and service health throughout the rollout.