Freshdesk Redirects

We are planning to implement an upstream reverse proxy (AWS CloudFront) in front of our custom domain (help.blend.com) to handle legacy URL 301 redirects at our network edge.

Our internal infrastructure team needs to verify a few details with your network operations and security teams before we deploy this change:

  1. Proxy & WAF Support: Our CloudFront distribution will connect to the Freshdesk origin using SNI (the native *.freshdesk.com endpoint) and will forward the Host: help.blend.com header via our forwarded headers configuration. Can you confirm that fronting our branded portal this way is fully supported and will not trip any native Freshdesk bot detection or WAF protections?

  2. Client IP & Rate-Limiting: We note that Freshdesk sits behind its own Cloudflare layer. Once we introduce CloudFront upstream, the primary client IP visible to Freshdesk will change to our CloudFront edge IPs. Can you confirm that this will not break any internal Freshdesk rate-limiting, security features, or geo-location capabilities?