Access Restrictions on Public IP Addresses

Platform Security: IP-Based Access Restriction for Octoja RMM From a platform security perspective, it would be highly desirable to implement a way to restrict access to Octoja RMM based on public IP addresses. Specifically, it should be possible to restrict access to the RMM interface exclusively to a defined list of trusted public IP addresses or IP ranges (IP allowlisting). This would ensure that administrative access occurs only from known and controlled networks (e.g., company locations, VPN endpoints). Benefits and Rationale:

Significant reduction in the attack surface, as unauthorized access attempts from the Internet are blocked from the outset Effective additional protective measure alongside existing authentication mechanisms (e.g., MFA) Increased compliance capability (e.g., in the context of NIS-2 or internal security policies) Improved control and traceability of administrative access

Optional desirable enhancements:

Management of permitted IP addresses via the admin interface Support for CIDR ranges Fallback/emergency access (e.g., temporary authorization) Logging and audit trail for blocked or permitted access

This feature would significantly contribute to hardening the platform and is an essential feature, particularly for security-critical environments.

Please authenticate to join the conversation.

Upvoters
Status

In Progress

Board
💡

Feature Request

Date

28 days ago

Subscribe to post

Get notified by email when there are changes.