Have there been changes to API security? Have they added Cloudflare as a provider?

carlosmoto
New here

Have there been changes to API security? Have they added Cloudflare as a provider?

Hi All 

 

I have a New Relic dashboard where I monitor API requests in real time.

 

Today at approximately 18:55 UTC, we detected a change in the source IPs.

 

Now we see that API requests are coming from a Cloudflare IP and not from the actual IPs.

I also see errors like:

 

[(‘SSL routines’, ‘’, ‘sslv3 alert handshake failure’)]

 

I guess you'd expect the change to be transparent, but we were affected.

 

Does anyone have any info?

 

I already have a support case open.

5 Replies 5
Jake-Young
Here to help

It looks like API calls using api.meraki.com get NAT'd to Cloudflare.  Calls to the direct shard appear to be working normally.

carlosmoto
New here

2025-08-18 14_50_38-.jpg

 

This is the image of what I see on the platform.

Normally, the IP addresses from which the requests were made were from GCP. They all started with 34.

 
Case 13404639
carlosmoto
New here

Decrease in requests with GCP IP addressesDecrease in requests with GCP IP addressesStart of requests with Cloudflare IPStart of requests with Cloudflare IPHere we see the decrease in requests with GCP IPs and the start of requests with Cloudflare IPs.

spaladug
Meraki Employee
Meraki Employee

@carlosmoto Thanks for letting us know and apologies it was a noticeable change. We just reverted the change and will investigate further.

Lee-C-F
Conversationalist

I was called out by our PRTG monitoring system c20:00 BST and after seeing the increase in 403 errors coinciding with the failure and the details logs stated access with my account was being attempted from unauthorised addresses, raised a Meraki case .. Is this this an IoC ? While holding, did my own checks and having seen the sources were cloudflare began to suspect technical error not mal-intent. Traceroute during the issue to api.meraki.com gave just 3 hops, the same as traceroute to one the 'my' bogus addresses. I was about to also raise with my ISP in case they knew of an global issue with Cloudflare when Meraki support came back and confirmed 1 Api.meraki.com has been moved to cloudflare earlier today.. and that other meraki users were reporting the issue and provided me your community thread... I think it was also stated that cloudflare were incorrectly source NAT'ing customer calls en route to api.meraki.com .. which to me seems to explain all the symptoms .. And then the issue apparently cleared

 

Thank you for posting, lets hope for a peaceful rest of the evening.

Get notified when there are additional replies to this discussion.