IDI version 26.8 is now available.  Click here for details: IDI Updates.

Restricting Access to IDI Environments by Allowed IP Addresses

Prev Next

New settings let you specify a pre-defined list of allowed IP addresses to restrict access to IDI web modules (Customer Care, Orders, Workflow, etc…). This helps ensure your employees or contractors are only accessing IDI environments from networks, work spaces, and computers that have proper security controls in place.

You can opt to bypass this restriction for certain power users as appropriate for your organization. For example, you may want to let trusted associates that travel frequently to access web modules from IP addresses not included in the allowed list.

Access to required setup in Security for IDI platform users requires Manage Domain permission.

Setup - Creating Allowed IP Address Lists

This is done on a Domain/Environment basis:

  • From the Apps tray, select POLICY > Domains.

    (Show Picture)

  • On the Domain page, navigate to the applicable domain. Then set up and enable one or more lists in the Use IP Allow List section.

    Note

    OnlineBill domains should be left open (unrestricted), so your customers can access their OnlineBill accounts.

    (Show Picture)

  • Start by selecting one or more environments. Click APPLY to apply your selections. You’ll be prompted to confirm your selections. Click OK (or CANCEL) as needed.

    (Show Picture)

  • Then specify one or more IP Address ranges.

    Note

    At least one range must be specified before you can enable (use) this functionality. To add IP address ranges:

    • Click the Add button (blue + icon) on the far right side of the Use IP Allow List.

      (Show Picture)

    • In the Add dialog enter the Start and End values for the IP Address range.

      Note

      Enter values in IPv4 format. Click SAVE when you’re done.

      (Show Picture)

  • Add more ranges as needed.

  • When you’re finished specifying ranges and ready to enforce the IP address restrictions click ENABLE. You’ll be prompted to confirm this action. Click OK (or CANCEL) as needed.

    (Show Picture)

    Note

    Once enabled, the label on the button changes to DISABLE to let you disable the restrictions if needed.

Managing Allowed IP Address Lists

You can edit or delete a selected IP address range using the associated Edit (pencil) and Delete (red X) icons at the far right. On Delete actions, you’ll be prompted to confirm. Click OK (or CANCEL) as needed.

(Show Picture)

You can also disable all restrictions if needed by clicking DISABLE. You’ll be prompted to confirm the action. Click OK (or CANCEL) as needed.

(Show Picture)

Exempting Users from the Allowed IP Address Restriction

You may need to let certain power users access web modules from IP addresses not included in an allowed list. This is done on an individual user basis via the Users page.

  • From the Apps tray select USER > Users.

    (Show Picture)

  • On the Users page, navigate to the applicable user. Then, in the Account Settings section, click the EDIT button to enable the settings and toggle the Bypass IP Allow List check box as needed.

    (Show Picture)

IDI Setup - Global IP Allow List

Note

This functionality is only available to authorized IDI associates. It’s needed to let those associates and applicable IDI processes login on behalf of a user where the request originates from an IDI IP address. This setup requires Manage Companies permission.

From the Apps tray, select SYSTEM > Global IP Allow List.

(Show Picture)