Administrators can limit selected user accounts to authorized Internet Protocol (IP) address ranges. The range list is configured once under Security, and the restriction is then enabled for each user who should be limited.
Important: Adding an authorized range does not restrict every user automatically. A user's Access Restriction must also be set to the restricted option.
Before you begin
- Obtain the public egress IP address or range used by your office, VPN, or secure gateway. The addresses shown in the form are examples.
- Keep a tested administrator account available from an unrestricted location until the rule has been confirmed. An incorrect range can prevent a restricted user from signing in.
- Plan the change with your network or security team if users move between offices, VPNs, or other networks.
Add an authorized IP address or range
- Sign in with an administrator account.
- Select Admin.
- Select Security, then open the Security tab.
- Under Add an authorized IP Address range here, enter the required Start Range.
- To authorize a range, enter the final address in End Range. To authorize one address, leave End Range blank; AuditFindings uses the start address as the end of the range.
- Select Add IP Range.
- Review the result under Authorized IP Address Range(s) for Restricted Accounts.
Apply the restriction to a user
- Select Admin > User Management.
- Open the User tab.
- Locate the user and select the edit icon.
- In the Edit User panel, set Access Restriction to the restricted option, shown in the current editor as Restrict to enforce IP range.
- Select Save.
Confirm the setting
Return to Admin > User Management > User and review the IP Restriction column. Restricted accounts can sign in only when their connection matches an authorized range. Accounts listed without a restriction are not limited by this setting.
Troubleshooting
- If a restricted user cannot sign in, confirm the user's current public egress IP address and compare it with the configured range.
- If users connect through a VPN or proxy, authorize the public egress address seen by AuditFindings, not an internal workstation address.
- If the restriction option is unavailable, ask an administrator to confirm your permission to manage Security and User Management settings.