CME Group Connection and Endpoint Access Standards

CME Group Connection and Endpoint Access Standards

To maintain continuous access to CME Group web applications, APIs, and GUIs, clients must support modern, resilient connectivity practices. CME Group regularly updates underlying infrastructure, IP ranges, and routing paths to optimize performance and business continuity readiness.

Core Standards

Prohibition of Hardcoded IP Addresses

Applications must resolve hostnames dynamically via DNS. Local hosts file entries or static IP configurations in code or config files are explicitly unsupported and will cause unexpected outages during routine maintenance or failover events.

Standard DNS TTL Compliance

Client DNS infrastructure and client applications must honor the Time-To-Live (TTL) values broadcast by CME Group authoritative DNS servers. Systems must not override TTLs or indefinitely cache IP address lookups.

Egress Firewall & Proxy Configuration

CME Group recommends that clients utilize Domain Name or FQDN-based egress filtering for *.cmegroup.com and *.cme.com. If FQDN filtering is not technically feasible, firewall allow-lists must be configured at the sub-network (CIDR block) level, where provided, rather than the individual IP address level to account for expansion.

Multi-Region and Cloud Resiliency

CME Group services utilize multi-cloud and hybrid-cloud routing (e.g., GCP and on-premise data centers). Endpoints may seamlessly shift between IP blocks during maintenance, disaster recovery testing, or automatic failover.

 




How was your Client Systems Wiki Experience? Submit Feedback

Copyright © 2024 CME Group Inc. All rights reserved.