Network Routing Architecture Update {#network-routing-ip-migration}
===================================================================

`Barclays` endpoints will be migrated from the current routing model to a new architecture using updated IP subnet ranges.  
This enhancement improves the performance, resiliency, and reliability of transaction delivery over the Internet. It will also enable seamless transaction routing across multiple Visa data centers, supporting more consistent and reliable transaction processing.  
**`Barclays` Endpoints and IP Addresses Included**  
Current Application and endpoints:  
**CAS/Test** : `apitest.cybersource.com` (current IP address: `66.185.182.49`)  
**Production** : `api.cybersource.com` (current IP address: `66.185.182.149`)  
**Potential Impact**  
Merchants who connect to the REST API endpoints (`apitest.cybersource.com` and `api.cybersource.com`) use a Domain Name System (DNS) should not be affected. DNS records will be updated automatically to use the new routing architecture.  
Merchants with networks configured to allowlist IP addresses or who have hardcoded IP addresses will likely be impacted. These merchants should update proxy or firewall settings to include the new Visa IP address ranges.  
There are no changes to TLS/SSL certificates or supported ciphers as part of this migration. However, `Barclays` continues to recommend trusting the root TLS certificates for all secure endpoints.  
**Migration Timeline**  
**CAS/Test**: October 15, 2026  
**Production**: January 31, 2027  
**Now Available**  
This technology is now available in both the test and production environments through these domains:  
**CAS/Test** : `apitest.visaacceptance.com`  
**Production** : `api.visaacceptance.com`  
Deploying in the CAS/Test Environment provides a safe environment to test and validate access. When testing is complete, you may migrate production processing.  
**How to Adopt This Change**  
To use the new routing architecture, your firewall or your commerce platform provider's firewall must be configured to permit outbound traffic to the Visa cloud.  
This large, dynamic IP address space represents a significant change from current access configurations. Therefore, it is critically important to test firewall configurations and confirm that connections are successful before migrating production traffic.  
Merchants who require IP address allowlists can use one of these options:  
**Option 1**: Merchants can add these specific subnet ranges to IP address allowlists:

* `198.217.128.0/17`
* `198.241.128.0/17`
* `66.185.176.0/20`

**Option 2**: Merchants can add these generic subnet ranges to IP address allowlists:

* `198.241.206.0/24`
* `198.241.207.0/24`

