Feature Availability: Enterprise Edition
Overview
The IP Address Restriction feature in ACCELQ allows Tenant Administrators to control and limit access to their ACCELQ tenant based on IP addresses. This feature enhances security by ensuring that only users connecting from approved networks or locations can access the ACCELQ platform.
Importance of IP Address Restriction
- Enhanced Security: By limiting access to specific IP addresses or ranges, you significantly reduce the risk of unauthorized access to your ACCELQ tenant.
- Compliance: Many industries require strict control over data access. IP restriction helps meet compliance requirements by ensuring that your ACCELQ instance is only accessible from approved locations.
- Audit Trail: IP-based access control provides a clear audit trail, making tracking and investigating suspicious access attempts easier.
Configuring IP Address Restrictions
To configure IP Address Restrictions:
- Log in to your ACCELQ tenant as a Tenant Administrator.
- Navigate to the Tenant Admin section.
- Look for the "IP Whitelisting" in the left-nav.
- Enable the IP Address Restriction feature.
- Add IP addresses, ranges, or subnets as needed.
Supported IP Formats
The IP Address Restriction feature supports various formats to accommodate different network configurations:
- IP Address(es): e.g. 192.168.1.1, 192.168.1.3
- IP Range: e.g. 192.168.1.1-192.168.1.10
- CIDR Notation: e.g. 192.168.1.0/24 (subnet)
Note: All the above options support both IPv4 and IPv6 formats (e.g., 2001:0db8:85a3:0000:0000:8a2e:0370:7334).
Important Consideration When Updating IP Whitelist
When a Tenant Admin modifies the IP Whitelist settings, the platform validates whether the current IP address of the admin is included in the updated list. If the admin's current IP address is excluded, the admin will immediately lose access to the ACCELQ tenant upon saving the changes.
Precautionary Steps:
-
Verify Your IP: Ensure your current IP address is included in the whitelist before updating.
-
Double-check Settings: Confirm all IP addresses carefully before saving changes.
-
Alternate Access: Ensure you have alternative access or another admin with appropriate permissions available, in case access is unintentionally lost.
ACCELQ displays a clear warning if your current IP address is not part of the updated whitelist, helping prevent unintended loss of access.
Disabling IP Restriction
To disable IP Restriction, click on the chevron icon besides the "Edit" button and select "Disable IP Restriction"
Best Practices
- Start Restrictive: Begin with a more restrictive list and gradually add IP addresses as needed, rather than starting with a broad range.
- Regular Review: Periodically review and update your IP restriction list to ensure it remains current and secure.
- Document Changes: Keep a log of changes to your IP restriction list, including the reason for each addition or removal.
- Use Subnets Wisely: When possible, use subnet notation instead of individual IP addresses to simplify management for larger networks.
- Consider Remote Workers: If your organization supports remote work, consider using a VPN solution in conjunction with IP restrictions.
- Test Thoroughly: After making changes to your IP restriction list, thoroughly test access from both allowed and disallowed IP addresses.
- Emergency Access: Have a plan for emergency access in case of unexpected issues with the IP restriction configuration.
- Monitor for Unusual Activity: Even with IP restrictions in place, continue to monitor for any unusual access patterns or attempts. You can find the audit log in the Tenant Admin > Audit Log section.
- Educate Users: Ensure that all users are aware of the IP restrictions and know how to request access from new locations if needed.
Troubleshooting
If users are unable to access ACCELQ after implementing IP restrictions:
- Verify that their current IP address is included in the allowed list.
- Check for any typos or formatting errors in the IP address entries.
- If using a VPN, confirm that the VPN's IP range is included in the allowed list.
Conclusion
IP Whitelisting is a powerful tool for enhancing the security of your ACCELQ tenant. By carefully configuring and managing this feature, you can significantly reduce the risk of unauthorized access while ensuring that legitimate users can seamlessly access the platform. Remember to balance security needs with usability to create an effective and efficient access control strategy.
Comments
0 comments
Please sign in to leave a comment.