At Salesforce, we understand that the confidentiality, integrity, and availability of your data is vital to your business, and we take the protection of your data seriously. In October 2024, Commerce Cloud is changing access to demandware.net hostnames for Staging instances by creating customer-specific Content Delivery Network (CDN) zones and firewall rules to allow Business Manager and other legitimate traffic from only Commerce Cloud trusted sources. This change helps protect your environments and data from malicious activity such as distributed denial of service (DDoS) or bot attacks.
What’s changing?
As of October 2024, Commerce Cloud will start blocking traffic that doesn’t originate from Commerce Cloud eCDN from accessing the dotted or hyphenated demandware.net hostnames for Staging instances. This change rejects calls made with direct IP to SFCC PODs or hostnames in the ‘dot’ form i.e. staging.* or 'hyphenated' form i.e. staging-* to access Open Commerce API (OCAPI) or Storefront.
How is my org affected?
This change affects Commerce Cloud customers who use the staging- or staging. hostnames to access OCAPI or Storefront. Change these dotted and/or hyphenated hostnames to a vanity hostname to avoid any impact from the change.
Implementations that use the Commerce Cloud eCDN or a stacked CDN configuration in front of the Commerce Cloud eCDN, for example, using a vanity hostname such as brand.com, www.brand.com, aren’t affected. If you access Business Manager via staging-realm-customer.demandware.net, you aren’t affected because Business Manager is considered internal to the Commerce Cloud B2C ecosystem.
When is the change happening?
The change is enforced on October 7th 2024 where the change will be enforced for all existing staging instances. At that point, all staging instances will reject calls for staging instances made to hostnames in the dotted or hyphenated form for demandware.net.
How can I prepare?
Please take the following actions:
What steps do I take to deprecate non-SNI traffic?
Update your supported web browsers.
Review stacked Akamai configurations for non-SNI traffic going to a SFCC/Cloudflare root domain.
Which specific services are still allowed to access the hyphenated demandware.net hostname?
Please note that not all Salesforce services will be included in these new firewall rules by Commerce Cloud.
Get Help
Direct questions about this change to the B2C Commerce Trailblazer Group. If you notice a critical impact to environments during enforcement, or if the new firewall rules are not working as expected, you can raise a case with Commerce Cloud Support.
002628746

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.