Skip to content
Start here

Cf Interconnects

List interconnects
client.magicTransit.cfInterconnects.list(CfInterconnectListParams { account_id, xMagicNewHcTarget } params, RequestOptionsoptions?): CfInterconnectListResponse { interconnects }
GET/accounts/{account_id}/magic/cf_interconnects
List interconnect Details
client.magicTransit.cfInterconnects.get(stringcfInterconnectID, CfInterconnectGetParams { account_id, xMagicNewHcTarget } params, RequestOptionsoptions?): CfInterconnectGetResponse { interconnect }
GET/accounts/{account_id}/magic/cf_interconnects/{cf_interconnect_id}
Update interconnect
client.magicTransit.cfInterconnects.update(stringcfInterconnectID, CfInterconnectUpdateParams { account_id, automatic_return_routing, bgp, 8 more } params, RequestOptionsoptions?): CfInterconnectUpdateResponse { modified, modified_interconnect }
PUT/accounts/{account_id}/magic/cf_interconnects/{cf_interconnect_id}
Update multiple interconnects
client.magicTransit.cfInterconnects.bulkUpdate(CfInterconnectBulkUpdateParams { account_id, body, xMagicNewHcTarget } params, RequestOptionsoptions?): CfInterconnectBulkUpdateResponse { modified, modified_interconnects }
PUT/accounts/{account_id}/magic/cf_interconnects
ModelsExpand Collapse
CfInterconnectListResponse { interconnects }
interconnects?: Array<Interconnect>
id?: string

Identifier

maxLength32
automatic_return_routing?: boolean

True if automatic stateful return routing should be enabled for a tunnel, false otherwise. Requires the coupler_integration account flag to be enabled; requests setting this to true without that flag will be rejected.

bgp?: BGP { as_no, cloudflare_endpoint, customer_asn, 5 more }
Deprecatedas_no?: number

Deprecated. Use customer_asn.

formatint32
Deprecatedcloudflare_endpoint?: string

Read-only for v1.5; derived from interface_address.

formatipv4
customer_asn?: number

ASN used on the customer end of the BGP session.

formatint32
Deprecatedcustomer_endpoint?: string

Read-only for v1.5; derived from interface_address.

formatipv4
export_filter_id?: string

ID of the BGP filter profile applied to routes advertised to the customer.

extra_prefixes?: Array<string>

Prefixes in this list will be advertised to the customer device, in addition to the routes in the Magic routing table.

import_filter_id?: string

ID of the BGP filter profile applied to routes received from the customer.

md5_key?: string

MD5 key to use for session authentication.

Note that this is not a security measure. MD5 is not a valid security mechanism, and the key is not treated as a secret value. This is only supported for preventing misconfiguration, not for defending against malicious attacks.

The MD5 key, if set, must be of non-zero length and consist only of the following types of character:

  • ASCII alphanumerics: [a-zA-Z0-9]
  • Special characters in the set '!@#$%^&*()+[]{}<>/.,;:_-~= |`

In other words, MD5 keys may contain any printable ASCII character aside from newline (0x0A), quotation mark ("), vertical tab (0x0B), carriage return (0x0D), tab (0x09), form feed (0x0C), and the question mark (?). Requests specifying an MD5 key with one or more of these disallowed characters will be rejected.

colo_name?: string

The name of the interconnect. The name cannot share a name with other tunnels.

created_on?: string

The date and time the tunnel was created.

formatdate-time
description?: string

An optional description of the interconnect.

gre?: GRE { cloudflare_endpoint }

Omitted in responses for version 1.5 interconnects.

cloudflare_endpoint?: string

The IP address assigned to the Cloudflare side of the GRE tunnel created as part of the Interconnect.

health_check?: HealthCheck { direction, enabled, rate, 3 more }
direction?: "unidirectional" | "bidirectional"

The direction of the flow of the healthcheck. Either unidirectional, where the probe comes to you via the interconnect and the result comes back to Cloudflare via the open Internet, or bidirectional where both the probe and result come and go via the interconnect.

One of the following:
"unidirectional"
"bidirectional"
enabled?: boolean

Determines whether to run healthchecks for a tunnel.

How frequent the health check is run. The default value is mid.

source?: string

The source IPv4 address used for bidirectional health checks. Supported only for version 1.5 interconnects. It is required when direction is bidirectional and must be omitted (and is cleared) when direction is unidirectional. The address must be within RFC1918 space, the approved link-local range 169.254.240.0/20, or the Cloudflare reserved range 198.41.199.224/27.

target?: MagicHealthCheckTarget { effective, saved } | string

The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to customer_gre_endpoint address. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target. Must be in object form if the x-magic-new-hc-target header is set to true and string form if x-magic-new-hc-target is absent or set to false.

One of the following:
MagicHealthCheckTarget { effective, saved }

The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to customer_gre_endpoint address. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target.

effective?: string

The effective health check target. If ‘saved’ is empty, then this field will be populated with the calculated default value on GET requests. Ignored in POST, PUT, and PATCH requests.

saved?: string

The saved health check target. Setting the value to the empty string indicates that the calculated default value will be used.

string

The type of healthcheck to run, reply or request. The default value is reply.

interface_address?: string

The IPv4 interface address for the interconnect. For MPLS Interconnects, use a /30 or /31 prefix. For GRE Interconnects, a /30 or /31 prefix may be used. Version 1.5 interconnects require a /31 prefix and may also use a prefix from the account’s authorized prefixes; otherwise, select the subnet from RFC 1918 or the approved link-local ranges.

interface_address6?: string

A 127 bit IPV6 prefix from within the virtual_subnet6 prefix space with the address being the first IP of the subnet and not same as the address of virtual_subnet6. Eg if virtual_subnet6 is 2606:54c1:7:0:a9fe:12d2::/127 , interface_address6 could be 2606:54c1:7:0:a9fe:12d2:1:200/127

modified_on?: string

The date and time the tunnel was last modified.

formatdate-time
mtu?: number

The Maximum Transmission Unit (MTU) in bytes for the interconnect. The minimum value is 576.

name?: string

The name of the interconnect. The name cannot share a name with other tunnels.

version?: string

Immutable interconnect version configured at creation time. One of:

  • “1”
  • “1.5”
  • “2”
virtual_port_reservation_id?: string

An identifier that correlates this interconnect with the corresponding V2 CNI interconnect resource.

maxLength32
CfInterconnectGetResponse { interconnect }
interconnect?: Interconnect { id, automatic_return_routing, bgp, 12 more }
id?: string

Identifier

maxLength32
automatic_return_routing?: boolean

True if automatic stateful return routing should be enabled for a tunnel, false otherwise. Requires the coupler_integration account flag to be enabled; requests setting this to true without that flag will be rejected.

bgp?: BGP { as_no, cloudflare_endpoint, customer_asn, 5 more }
Deprecatedas_no?: number

Deprecated. Use customer_asn.

formatint32
Deprecatedcloudflare_endpoint?: string

Read-only for v1.5; derived from interface_address.

formatipv4
customer_asn?: number

ASN used on the customer end of the BGP session.

formatint32
Deprecatedcustomer_endpoint?: string

Read-only for v1.5; derived from interface_address.

formatipv4
export_filter_id?: string

ID of the BGP filter profile applied to routes advertised to the customer.

extra_prefixes?: Array<string>

Prefixes in this list will be advertised to the customer device, in addition to the routes in the Magic routing table.

import_filter_id?: string

ID of the BGP filter profile applied to routes received from the customer.

md5_key?: string

MD5 key to use for session authentication.

Note that this is not a security measure. MD5 is not a valid security mechanism, and the key is not treated as a secret value. This is only supported for preventing misconfiguration, not for defending against malicious attacks.

The MD5 key, if set, must be of non-zero length and consist only of the following types of character:

  • ASCII alphanumerics: [a-zA-Z0-9]
  • Special characters in the set '!@#$%^&*()+[]{}<>/.,;:_-~= |`

In other words, MD5 keys may contain any printable ASCII character aside from newline (0x0A), quotation mark ("), vertical tab (0x0B), carriage return (0x0D), tab (0x09), form feed (0x0C), and the question mark (?). Requests specifying an MD5 key with one or more of these disallowed characters will be rejected.

colo_name?: string

The name of the interconnect. The name cannot share a name with other tunnels.

created_on?: string

The date and time the tunnel was created.

formatdate-time
description?: string

An optional description of the interconnect.

gre?: GRE { cloudflare_endpoint }

Omitted in responses for version 1.5 interconnects.

cloudflare_endpoint?: string

The IP address assigned to the Cloudflare side of the GRE tunnel created as part of the Interconnect.

health_check?: HealthCheck { direction, enabled, rate, 3 more }
direction?: "unidirectional" | "bidirectional"

The direction of the flow of the healthcheck. Either unidirectional, where the probe comes to you via the interconnect and the result comes back to Cloudflare via the open Internet, or bidirectional where both the probe and result come and go via the interconnect.

One of the following:
"unidirectional"
"bidirectional"
enabled?: boolean

Determines whether to run healthchecks for a tunnel.

How frequent the health check is run. The default value is mid.

source?: string

The source IPv4 address used for bidirectional health checks. Supported only for version 1.5 interconnects. It is required when direction is bidirectional and must be omitted (and is cleared) when direction is unidirectional. The address must be within RFC1918 space, the approved link-local range 169.254.240.0/20, or the Cloudflare reserved range 198.41.199.224/27.

target?: MagicHealthCheckTarget { effective, saved } | string

The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to customer_gre_endpoint address. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target. Must be in object form if the x-magic-new-hc-target header is set to true and string form if x-magic-new-hc-target is absent or set to false.

One of the following:
MagicHealthCheckTarget { effective, saved }

The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to customer_gre_endpoint address. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target.

effective?: string

The effective health check target. If ‘saved’ is empty, then this field will be populated with the calculated default value on GET requests. Ignored in POST, PUT, and PATCH requests.

saved?: string

The saved health check target. Setting the value to the empty string indicates that the calculated default value will be used.

string

The type of healthcheck to run, reply or request. The default value is reply.

interface_address?: string

The IPv4 interface address for the interconnect. For MPLS Interconnects, use a /30 or /31 prefix. For GRE Interconnects, a /30 or /31 prefix may be used. Version 1.5 interconnects require a /31 prefix and may also use a prefix from the account’s authorized prefixes; otherwise, select the subnet from RFC 1918 or the approved link-local ranges.

interface_address6?: string

A 127 bit IPV6 prefix from within the virtual_subnet6 prefix space with the address being the first IP of the subnet and not same as the address of virtual_subnet6. Eg if virtual_subnet6 is 2606:54c1:7:0:a9fe:12d2::/127 , interface_address6 could be 2606:54c1:7:0:a9fe:12d2:1:200/127

modified_on?: string

The date and time the tunnel was last modified.

formatdate-time
mtu?: number

The Maximum Transmission Unit (MTU) in bytes for the interconnect. The minimum value is 576.

name?: string

The name of the interconnect. The name cannot share a name with other tunnels.

version?: string

Immutable interconnect version configured at creation time. One of:

  • “1”
  • “1.5”
  • “2”
virtual_port_reservation_id?: string

An identifier that correlates this interconnect with the corresponding V2 CNI interconnect resource.

maxLength32
CfInterconnectUpdateResponse { modified, modified_interconnect }
modified?: boolean
modified_interconnect?: ModifiedInterconnect { id, automatic_return_routing, bgp, 12 more }
id?: string

Identifier

maxLength32
automatic_return_routing?: boolean

True if automatic stateful return routing should be enabled for a tunnel, false otherwise. Requires the coupler_integration account flag to be enabled; requests setting this to true without that flag will be rejected.

bgp?: BGP { as_no, cloudflare_endpoint, customer_asn, 5 more }
Deprecatedas_no?: number

Deprecated. Use customer_asn.

formatint32
Deprecatedcloudflare_endpoint?: string

Read-only for v1.5; derived from interface_address.

formatipv4
customer_asn?: number

ASN used on the customer end of the BGP session.

formatint32
Deprecatedcustomer_endpoint?: string

Read-only for v1.5; derived from interface_address.

formatipv4
export_filter_id?: string

ID of the BGP filter profile applied to routes advertised to the customer.

extra_prefixes?: Array<string>

Prefixes in this list will be advertised to the customer device, in addition to the routes in the Magic routing table.

import_filter_id?: string

ID of the BGP filter profile applied to routes received from the customer.

md5_key?: string

MD5 key to use for session authentication.

Note that this is not a security measure. MD5 is not a valid security mechanism, and the key is not treated as a secret value. This is only supported for preventing misconfiguration, not for defending against malicious attacks.

The MD5 key, if set, must be of non-zero length and consist only of the following types of character:

  • ASCII alphanumerics: [a-zA-Z0-9]
  • Special characters in the set '!@#$%^&*()+[]{}<>/.,;:_-~= |`

In other words, MD5 keys may contain any printable ASCII character aside from newline (0x0A), quotation mark ("), vertical tab (0x0B), carriage return (0x0D), tab (0x09), form feed (0x0C), and the question mark (?). Requests specifying an MD5 key with one or more of these disallowed characters will be rejected.

colo_name?: string

The name of the interconnect. The name cannot share a name with other tunnels.

created_on?: string

The date and time the tunnel was created.

formatdate-time
description?: string

An optional description of the interconnect.

gre?: GRE { cloudflare_endpoint }

Omitted in responses for version 1.5 interconnects.

cloudflare_endpoint?: string

The IP address assigned to the Cloudflare side of the GRE tunnel created as part of the Interconnect.

health_check?: HealthCheck { direction, enabled, rate, 3 more }
direction?: "unidirectional" | "bidirectional"

The direction of the flow of the healthcheck. Either unidirectional, where the probe comes to you via the interconnect and the result comes back to Cloudflare via the open Internet, or bidirectional where both the probe and result come and go via the interconnect.

One of the following:
"unidirectional"
"bidirectional"
enabled?: boolean

Determines whether to run healthchecks for a tunnel.

How frequent the health check is run. The default value is mid.

source?: string

The source IPv4 address used for bidirectional health checks. Supported only for version 1.5 interconnects. It is required when direction is bidirectional and must be omitted (and is cleared) when direction is unidirectional. The address must be within RFC1918 space, the approved link-local range 169.254.240.0/20, or the Cloudflare reserved range 198.41.199.224/27.

target?: MagicHealthCheckTarget { effective, saved } | string

The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to customer_gre_endpoint address. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target. Must be in object form if the x-magic-new-hc-target header is set to true and string form if x-magic-new-hc-target is absent or set to false.

One of the following:
MagicHealthCheckTarget { effective, saved }

The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to customer_gre_endpoint address. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target.

effective?: string

The effective health check target. If ‘saved’ is empty, then this field will be populated with the calculated default value on GET requests. Ignored in POST, PUT, and PATCH requests.

saved?: string

The saved health check target. Setting the value to the empty string indicates that the calculated default value will be used.

string

The type of healthcheck to run, reply or request. The default value is reply.

interface_address?: string

The IPv4 interface address for the interconnect. For MPLS Interconnects, use a /30 or /31 prefix. For GRE Interconnects, a /30 or /31 prefix may be used. Version 1.5 interconnects require a /31 prefix and may also use a prefix from the account’s authorized prefixes; otherwise, select the subnet from RFC 1918 or the approved link-local ranges.

interface_address6?: string

A 127 bit IPV6 prefix from within the virtual_subnet6 prefix space with the address being the first IP of the subnet and not same as the address of virtual_subnet6. Eg if virtual_subnet6 is 2606:54c1:7:0:a9fe:12d2::/127 , interface_address6 could be 2606:54c1:7:0:a9fe:12d2:1:200/127

modified_on?: string

The date and time the tunnel was last modified.

formatdate-time
mtu?: number

The Maximum Transmission Unit (MTU) in bytes for the interconnect. The minimum value is 576.

name?: string

The name of the interconnect. The name cannot share a name with other tunnels.

version?: string

Immutable interconnect version configured at creation time. One of:

  • “1”
  • “1.5”
  • “2”
virtual_port_reservation_id?: string

An identifier that correlates this interconnect with the corresponding V2 CNI interconnect resource.

maxLength32
CfInterconnectBulkUpdateResponse { modified, modified_interconnects }
modified?: boolean
modified_interconnects?: Array<ModifiedInterconnect>
id?: string

Identifier

maxLength32
automatic_return_routing?: boolean

True if automatic stateful return routing should be enabled for a tunnel, false otherwise. Requires the coupler_integration account flag to be enabled; requests setting this to true without that flag will be rejected.

bgp?: BGP { as_no, cloudflare_endpoint, customer_asn, 5 more }
Deprecatedas_no?: number

Deprecated. Use customer_asn.

formatint32
Deprecatedcloudflare_endpoint?: string

Read-only for v1.5; derived from interface_address.

formatipv4
customer_asn?: number

ASN used on the customer end of the BGP session.

formatint32
Deprecatedcustomer_endpoint?: string

Read-only for v1.5; derived from interface_address.

formatipv4
export_filter_id?: string

ID of the BGP filter profile applied to routes advertised to the customer.

extra_prefixes?: Array<string>

Prefixes in this list will be advertised to the customer device, in addition to the routes in the Magic routing table.

import_filter_id?: string

ID of the BGP filter profile applied to routes received from the customer.

md5_key?: string

MD5 key to use for session authentication.

Note that this is not a security measure. MD5 is not a valid security mechanism, and the key is not treated as a secret value. This is only supported for preventing misconfiguration, not for defending against malicious attacks.

The MD5 key, if set, must be of non-zero length and consist only of the following types of character:

  • ASCII alphanumerics: [a-zA-Z0-9]
  • Special characters in the set '!@#$%^&*()+[]{}<>/.,;:_-~= |`

In other words, MD5 keys may contain any printable ASCII character aside from newline (0x0A), quotation mark ("), vertical tab (0x0B), carriage return (0x0D), tab (0x09), form feed (0x0C), and the question mark (?). Requests specifying an MD5 key with one or more of these disallowed characters will be rejected.

colo_name?: string

The name of the interconnect. The name cannot share a name with other tunnels.

created_on?: string

The date and time the tunnel was created.

formatdate-time
description?: string

An optional description of the interconnect.

gre?: GRE { cloudflare_endpoint }

Omitted in responses for version 1.5 interconnects.

cloudflare_endpoint?: string

The IP address assigned to the Cloudflare side of the GRE tunnel created as part of the Interconnect.

health_check?: HealthCheck { direction, enabled, rate, 3 more }
direction?: "unidirectional" | "bidirectional"

The direction of the flow of the healthcheck. Either unidirectional, where the probe comes to you via the interconnect and the result comes back to Cloudflare via the open Internet, or bidirectional where both the probe and result come and go via the interconnect.

One of the following:
"unidirectional"
"bidirectional"
enabled?: boolean

Determines whether to run healthchecks for a tunnel.

How frequent the health check is run. The default value is mid.

source?: string

The source IPv4 address used for bidirectional health checks. Supported only for version 1.5 interconnects. It is required when direction is bidirectional and must be omitted (and is cleared) when direction is unidirectional. The address must be within RFC1918 space, the approved link-local range 169.254.240.0/20, or the Cloudflare reserved range 198.41.199.224/27.

target?: MagicHealthCheckTarget { effective, saved } | string

The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to customer_gre_endpoint address. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target. Must be in object form if the x-magic-new-hc-target header is set to true and string form if x-magic-new-hc-target is absent or set to false.

One of the following:
MagicHealthCheckTarget { effective, saved }

The destination address in a request type health check. After the healthcheck is decapsulated at the customer end of the tunnel, the ICMP echo will be forwarded to this address. This field defaults to customer_gre_endpoint address. This field is ignored for bidirectional healthchecks as the interface_address (not assigned to the Cloudflare side of the tunnel) is used as the target.

effective?: string

The effective health check target. If ‘saved’ is empty, then this field will be populated with the calculated default value on GET requests. Ignored in POST, PUT, and PATCH requests.

saved?: string

The saved health check target. Setting the value to the empty string indicates that the calculated default value will be used.

string

The type of healthcheck to run, reply or request. The default value is reply.

interface_address?: string

The IPv4 interface address for the interconnect. For MPLS Interconnects, use a /30 or /31 prefix. For GRE Interconnects, a /30 or /31 prefix may be used. Version 1.5 interconnects require a /31 prefix and may also use a prefix from the account’s authorized prefixes; otherwise, select the subnet from RFC 1918 or the approved link-local ranges.

interface_address6?: string

A 127 bit IPV6 prefix from within the virtual_subnet6 prefix space with the address being the first IP of the subnet and not same as the address of virtual_subnet6. Eg if virtual_subnet6 is 2606:54c1:7:0:a9fe:12d2::/127 , interface_address6 could be 2606:54c1:7:0:a9fe:12d2:1:200/127

modified_on?: string

The date and time the tunnel was last modified.

formatdate-time
mtu?: number

The Maximum Transmission Unit (MTU) in bytes for the interconnect. The minimum value is 576.

name?: string

The name of the interconnect. The name cannot share a name with other tunnels.

version?: string

Immutable interconnect version configured at creation time. One of:

  • “1”
  • “1.5”
  • “2”
virtual_port_reservation_id?: string

An identifier that correlates this interconnect with the corresponding V2 CNI interconnect resource.

maxLength32