IP Restrictions

Download as PDF

Overview

Every device connected to the Internet has a unique number assigned to it - an IP address. An IP address is used for targeted transport of data from the sender to the recipient.

You can control access to your website and Backstage for certain IP addresses with the following restrictions:

  • Global IP restrictions: You can deny access to your website or Backstage to users with certain IP addresses (Negative) or allow access to certain IP addresses (Positive). For example, this allows you to block IP addresses from countries with high abuse rate.
  • Access-related IP restrictions: You can apply IP restrictions to specific accesses or access groups. This is particularly useful when you want to ensure that access from a certain group is only permitted from a defined IP range. For example, to verify that requests are genuinely originating from a specific company.
  • Automatic IP restrictions (block): If a user exceeds a predefined number of failed login attempts within a specified time period, their IP address can be automatically blocked from further access.

Set up IP restrictions

To configure global and access-related IP restrictions, proceed as follows:

  1. Navigate to Administration > IP Restrictions > Active IP Restrictions and select Edit > New.
  2. The new restriction setup window opens.
  3. Enter a distinctive name for the restriction.
  4. Enable the Status option to activate the IP restriction.
  5. Select Backstage and/or Webgate option to define where the restriction should apply.
  6. Enter the IP address or a specific subnet (in long notation) you want to restrict.
  7. Select whether the IP restriction should be Positive (allow access) or Negative (deny access).
  8. In the Global field, select Yes to apply the restriction globally or No to limit it to specific accesses or access groups.
    • For the access-specific option, the system displays a list of accounts or access groups for you to select from.
      • Select accesses and click Add. Undo the selection with Remove.
  9. Confirm with Save.

Screenshot of the Active IP Restriction window showing setup options. The selected and highlighted options are: Status, Backstage, IP Address, Access Allowed, Global, and Selected Access.
Active IP Restrictions: Access granted to Backstage, specified IP address range, and only to selected Access

Note

You can also configure this IP restriction in the Authentication Restrictions section of a corresponding Access/Access Group.

Set up automatic IP blocking

If multiple attempts to login to your Webgate from the same IP address fail, the access from that IP address can be temporarily blocked. Both you and the affected user will automatically receive an email notification. Once blocked, the user will no longer be able to view media content or access data. In some cases, other users sharing the same IP address may also be impacted.

To enable automatic IP blocking, proceed as follows:

  1. Navigate to Administration > IP Restrictions > Webgate Configuration.
  2. Optional for multiple websites From the Select Website dropdown, select a website to apply IP blocking.
  3. Select Enable IP blocking to activate the feature.
  4. In Number of failed login attempts, set the allowed number.
  5. In Timeframe in minutes, set the time interval to consider the failed attempts.
  6. Enable E-mail alerts to receive notifications when automatic IP blocking is triggered. Enter a name and recipient email address.
  7. Click Save.

A screenshot of IP restriction configuration for webshop showing options to activate a temporary IP blocking, display a warning message, and receive email alerts.
Webgate Configuration: Automatic IP blocking

Note

When a user exceeds the allowed number of failed login attempts within the specified time, the system automatically blocks the IP address. You can view the restriction under Administration > IP Restrictions > Active IP Restrictions and manually remove it if needed.

Activate access blocking

In addition to IP blocking, you can also choose to block the specific access where the failed login attempts occurred. This access block becomes active if a successful login was recorded within the past two days, indicating a potential breach. If an access is blocked, you can lift the restriction in the associated master data record under “Accesses.”

To enable this feature, follow these steps:

  1. Navigate to Administration > IP Restrictions > Webgate Configuration
  2. Optional for multiple websites From the Select Website dropdown, select a website to apply access blocking.
  3. Enable Activate additional lock for accesses.
  4. Confirm with Save.

A screenshot of IP restriction configuration for webshop with the option to block the access additionally. The function is active and highlighted.
Webgate Configuration: Additional access blocking

A screenshot of Customer record with the Accesses tab selected and the warning message about blocking is visible.
Customer master data window: Blocked access notification

Note

The blocked access message appears in the customer, partner, or user’s master data record under the Accesses tab. You can remove the block directly from there by enabling the Access is Active option.

Activate IP block warning upon login

If multiple attempts to login to your Webgate from the same IP address fail, you can temporarily block access from this IP address. If the user is unsure about their password, we recommend using the "Forgot your password" feature. You can display a warning message in the login dialog after a specified number of failed attempts.

To display the warning, proceed as follows:

  1. Navigate to Administration > IP Restrictions > Webgate Configuration.
  2. Optional for multiple websites From the Select Website dropdown, choose a website to apply IP blocking.
  3. Enable Display warning message in case of impending IP block to activate the feature.
  4. Set the number of failed attempts allowed before displaying the warning.
  5. Click Save.

A screenshot of IP restriction configuration for webshop with the selected option to display a warning about IP blocking.
Webgate Configuration: Activate IP block message in the Webshop login dialog

Screenshot of a webshop login window with the IP block warning message.
IP block message in the Webshop login dialog

Note

The warning text also displays the number of tries left.

Configure messages for blocked users

When an IP address is blocked, the user with this IP address will see a system message. You can tailor a message for global, automatic, and access-related IP restrictions.

  1. Navigate to Administration > IP Restrictions > Message Configuration.
  2. Optional for multiple websites From the Select Website dropdown, select a website to apply the message.
  3. Activate the areas where you want to display the message:
    • Custom message for global IP restrictions
    • Custom message for automatic IP blocking
    • Custom message for access-related IP restrictions.
  4. Enter a heading and the message text for each activated language.
  5. Confirm with Save.

Screenshot of the Message Configuration window with the ‘Custom message for global IP restrictions’ setting selected. The customized system message for blocked users is shown in English.
Configuration for messages: Customize system messages for blocked users

Manage IP restrictions

You can view a list of IP restrictions in Administration > IP Restrictions > Active IP Restrictions.

Create new IP restriction

  • Edit menu > New.

Edit existing IP restriction

  • Double-click or select a restriction name and Edit > Open.
  • Make changes and click Save.

Delete existing IP restriction

  • Select an IP restriction and Edit > Unblock.

Note

The integrated table functions allow you to search, filter, and sort records. For more information on these functions, as well as how to set up custom views and use the export function, see Advanced Table Views.