Kissflow DocsHelp center

Enhancing stability with static IP reservations

On January 7, 2024, Kissflow moved outbound integration traffic from dynamic to reserved static IPs, so safelisted firewall rules no longer need to change over time.

Kissflow sends outbound calls — including integration calls to external applications — through Google Cloud NAT. Before January 7, 2024, these calls used dynamic public IPs that could change over time, which meant customers who safelisted Kissflow IPs in their firewalls occasionally had to update their rules.

What changed

On January 7, 2024, Kissflow switched Cloud NAT to manual IP allocation, giving outbound traffic a fixed set of reserved static IPs. Firewall rules that safelist these IPs no longer need to be updated as Kissflow's underlying infrastructure changes.

Who was affected

This change only affected customers who had safelisted Kissflow IPs in their firewall to allow Kissflow's integration calls into their network. Customers without that configuration were not affected.

Affected customers needed to safelist the new static IPs alongside the existing ones before the cutover, then remove the old IPs afterward. The current, authoritative list of IPs to safelist is maintained in Safelisting IPs for external data connections — use that page for your region's IPs rather than any list from this notice.

Change window

The Cloud NAT migration was implemented on Sunday, January 7, 2024, during a period of minimal traffic. Integrations that were actively triggering during the cutover could have seen a disruption of less than one minute.

If you still see integration failures you believe are related to IP safelisting, contact Kissflow support.

On this page