Protect a device group
Restrict who can open tunnels to devices in a group by IP address and email. Configure these on the group’s Access control tab.
Open access control
- Go to Infrastructure → Device groups.
- Create a new group or edit an existing one.
- Switch to the Access control tab (beside General).
IP whitelist
- List the IP addresses or CIDR ranges that are allowed to reach tunnels for devices in this group.
- Leave the list empty to allow traffic from any source (subject to your organization’s other policies).
- Add a short description per entry (for example “Office VPN exit”) so future changes are safer.
Email access control
Control who may authenticate by email when opening tunnel access:
- Add individual email addresses for specific people.
- Add an entire email domain (for example your company domain) to authorize everyone with that domain.
- Leave the list empty to not restrict by email on top of other rules.
Free public email domains are typically blocked for domain-wide rules to reduce risk.
How the pieces work together
- IP rules limit where connections may originate.
- Email rules limit which identities may complete authentication for tunnel access.
- Test changes with a real connection from an allowed IP and an allowed identity before relying on them in production.
Tips
- Start with a clear baseline (for example allow office IPs only), then add exceptions.
- Document major changes in your internal change log so on-call staff know why access might fail after an update.
