Loading
Get Started with B2C Commerce
Table of Contents
Select Filters

          No results
          No results
          Here are some search tips

          Check the spelling of your keywords.
          Use more general search terms.
          Select fewer filters to broaden your search.

          Search all of Salesforce Help
          Realm Security Rules for eCDN Zones

          Realm Security Rules for eCDN Zones

          Realm Security Rules let you define Managed IP Address Lists and Custom Firewall Rules that control how trusted IP traffic is handled across your eCDN zones. These rules replace the legacy Trusted IP configuration.

          Overview

          Note
          Note The Realm Security Rules tab is available only when the Enable eCDN Trusted IP Migration feature switch is enabled for your organization. If the tab is not visible in Business Manager, contact your Salesforce account team.

          Realm Security Rules provide two components that work together to manage trusted IP traffic:

          Managed IP Address Lists
          Named lists of IP addresses or CIDR ranges. You can scope a list to your entire realm (account level) or to a single zone (zone level). See Create and Manage Trusted IP Address Lists.
          Custom Firewall Rules
          Rules that reference your IP address lists and define a skip action, so traffic from trusted IPs bypasses selected security checks. See Create a Custom Firewall Rule for an eCDN Zone.
          Important
          Important Realm Security Rules replace the legacy Trusted IP list groups that were previously configured via the Firewall tab in the zone settings slider. If you had existing Trusted IP configurations, Salesforce migrates them automatically. See About the Trusted IP Migration to web application firewall (WAF) Custom Rules for details.

          Accessing Realm Security Rules

          To open the Realm Security Rules tab:

          1. In Business Manager, click the App Launcher, and then select Administration | Sites | Embedded CDN Settings.
          2. Locate the zone you want to configure and select Configure Zone from the dropdown menu.
            Embedded CDN Settings page showing the Configure Zone option in the zone actions dropdown menu
          3. Select the Security Rules tab.
          4. Select the Realm Security Rules sub-tab.

          Realm Security Rules tab — account level

          Realm Security Rules tab at the account level showing migrated Custom Firewall Rules and Managed IP Address Lists

          Custom Firewall Rule — skip action detail

          Edit Custom Rule dialog showing IP address list conditions and Skip actions configured for a migrated Trusted IP allowlist rule

          Account-Level vs. Zone-Level Scope

          Managed IP Address Lists and their associated Custom Firewall Rules can be scoped at two levels:

          Scope Where it applies Eligible zone types
          Account (Realm) Applies to all eligible zones in your realm, including development, staging, production, and sandbox instances. Proxy, Legacy, Default Domain zones
          Zone Applies only to the specific zone you are configuring. Two zones in the same realm can have independent zone-level lists with the same name without conflict. Proxy, Legacy, Default Domain zones
          Note
          Note Account-level changes affect all eligible zones across development, staging, and production. A warning banner is displayed when you make account-level changes on a Production instance. On non-production instances, the Realm Security Rules tab is read-only. Use the Production instance to create or modify account-level rules and lists.

          Realm Security Rules tab — zone level

          Realm Security Rules tab at the zone level showing Custom Firewall Rules and Managed IP Address Lists scoped to a single zone

          Zone Security Rules tab

          Zone Security Rules tab showing zone-level Custom Firewall Rules, Rate Limiting Rules, and WAF-v2 eCDN Managed Ruleset settings for a specific eCDN zone

          Behavior: What Traffic Is Bypassed

          When traffic originates from an IP address in a trusted list and matches a skip rule, the following security checks are bypassed:

          • Custom firewall rules
          • WAF managed rules
          • Rate limiting rules

          In addition, DDoS Layer 7 protections are automatically adjusted for accounts that have account-level trusted IP lists configured. This prevents false-positive challenges on legitimate high-volume traffic from trusted sources. No additional configuration is required for DDoS adjustments. For details on the specific managed rules that are overridden, see DDoS Layer 7 Override Details.

          Tip
          Tip Skip rules are evaluated before any blocking or rate-limiting rules and are automatically positioned at the top of the ruleset. If both an allowlist skip rule and a blocklist rule exist for a zone, the allowlist skip rule is positioned first. You do not need to manage rule ordering manually.

          Permissions

          Action Required Role
          View Realm Security Rules and Lists (any instance) eCDN Admin or eCDN Viewer
          Create, edit, or delete Rules and Lists eCDN Admin (Production instance only)

          On non-production instances (staging, development, sandbox), the Realm Security Rules tab is read-only. A blue information banner indicates: "Realm-level configuration is read-only on this instance. Use the Production instance to make changes."

          On Production, an amber warning banner indicates: "Account-level changes affect all zones (development, staging, and production)."

           
          Loading
          Salesforce Help | Article