Spinner logo QXQA

Did You Know?

Home / Security and Architecture / IP Whitelist Security

IP Whitelist Security

AXQA IP Whitelist Security allows administrators to restrict access to the complete workspace based on approved IPv4, IPv6, or CIDR network ranges.
The configuration includes validation and an automatic safety rollback designed to reduce the risk of administrators accidentally locking themselves out.


Why it matters

  • Restricts workspace access to approved networks.
  • Adds a network-level access layer beyond username and password authentication.
  • Supports corporate offices, VPN ranges, and controlled testing environments.
  • Reduces exposure from unknown network locations.

When to use it

  • When AXQA should only be accessible through a corporate network.
  • When users must connect through an approved VPN.
  • When restricting an enterprise workspace to known IP ranges.
  • When strengthening administrative access controls.

Core concepts

  • IP Whitelist – List of networks allowed to access the workspace.
  • IPv4 – Standard IPv4 network address.
  • IPv6 – IPv6 network address.
  • CIDR – Network range notation used to allow an entire network range.
  • Allow All – Configuration that disables IP restriction.
  • Safety Rollback – Temporary rollback protection after changing the whitelist.

How it works

  1. A request reaches the AXQA workspace.
  2. AXQA determines the client IP.
  3. The IP is compared with the configured allowlist.
  4. If the IP belongs to an approved IP or CIDR network, processing continues.
  5. Otherwise, access is denied.
  6. Unauthorized IP access attempts are recorded as security activity.
  7. After a whitelist change, AXQA temporarily keeps a rollback checkpoint.
  8. If the new configuration is not successfully confirmed, AXQA restores the previous configuration.

How to use it

Step 1: Open IP Whitelist Security

Open:

Security → IP Whitelist Security


Step 2: Add approved addresses

Enter one or more:

  • IPv4 addresses
  • IPv6 addresses
  • CIDR ranges
Example
203.0.113.10
2001:db8::10
203.0.113.0/24.

Entries can be provided as a supported comma-separated or multi-line list.


Step 3: Insert your Current IP

Use:

Insert My Current IP

to insert the network address currently detected by AXQA.

Review the detected value before saving.


Step 4: Test the configuration

Use:

Test Configuration

before saving.

AXQA checks whether your detected IP would remain allowed under the proposed rules.


Step 5: Save the whitelist

Save the configuration.

AXQA activates a temporary safety window.


Step 6: Confirm continued access

After the change, access the workspace through the intended network.

If the new whitelist works successfully, AXQA confirms the configuration.

If access cannot be confirmed during the safety period, the previous whitelist is automatically restored.


Step 7: Use Allow All when required

Enable Allow All when IP-based workspace restrictions should not be enforced.

Use this only when appropriate for the workspace security policy.


Best practices

  • Test the configuration before saving.
  • Include all required corporate or VPN networks.
  • Prefer CIDR ranges only when the complete range should actually be trusted.
  • Keep an approved administrative network available during configuration changes.
  • Review whitelist entries when network infrastructure changes.

Common mistakes

❌ Saving a whitelist without including your administrative network.
✔ Use Current IP and Test Configuration first.

❌ Adding a very broad CIDR range unnecessarily.
✔ Allow only the networks that require workspace access.

❌ Assuming a valid AXQA password bypasses the whitelist.
✔ IP Whitelist enforcement applies independently of normal user authentication.


Security & permissions

  • IP Whitelist configuration is restricted to Superusers.
  • AXQA supports IPv4, IPv6, and CIDR normalization.
  • Invalid network notation is rejected.
  • Requests from addresses outside the configured networks are denied.
  • Unauthorized network access generates Security Log activity.
  • A five-minute safety rollback protects recent whitelist changes from accidental lockout.

Related documentation

  • Security Architecture Overview
  • Login Attempts Blocker & Rate Limiting
  • Security Log Tracker & Live Security Monitoring
  • Security & Client Isolation

Tools

A+ A-

Version

1.2