Configure a firewall policy
Restrict access to the application using an IP allowlist.
Use Firewall Policy to allow requests from selected IP addresses or CIDR ranges through the application's managed route. This policy does not replace application authentication or control every network path to a resource.
Enable the allowlist
- Open the container and select Firewall Policy.
- Enable Enable IP allowlist.
- Add the public IP addresses or CIDR ranges that need access. Include your own public IP before saving; Use my IP can fill it in.
- Optionally name entries, such as
Office. - Select Save policy and allow a few moments for the proxy configuration to update.
You must provide at least one entry when enabling the policy. Up to 32 entries are supported. Single IPv4 addresses use /32; single IPv6 addresses use /128. Duplicate entries must be removed.
Verify access
Open the application from an allowed network and confirm that it responds. If possible, also test from a network outside the allowlist. Account for VPNs or shared outbound gateways when identifying a client's public address.
Disable the allowlist
Disable Enable IP allowlist and select Save policy. Disabling the policy removes its saved IP list and stops filtering requests through this policy. Record any entries you need before disabling it.