This is feature is only available if you are on the Enterprise tier or above. See Astro Plans and Pricing.
Prerequisites
- Organization Owner permissions
Set up IP Access list
- In the Astro UI, go to Settings, then in the Security section, click IP Access List.
- Click + New IP Address Range.
- Add the IP address range or ranges in CIDR format, and click Add Address Range
Accept a proxy or tunnel egress IP address
If you route Astro traffic through a forward proxy or secure tunnel (such as Zscaler), each request arrives with two source IP addresses: the IP address of the end user’s client and the public egress IP address of the proxy or tunnel. By default, Astro checks only the client IP address against your IP access list, so allowlisting your proxy’s egress ranges on their own doesn’t grant your users access. Turn on Proxy-Aware IP Allowlisting so that Astro also accepts the egress IP address as a valid match. Astro then allows a request when either the client IP address or the egress IP address falls within an allowed range. This setting is additive, so turning it on can only grant access. It never blocks a user who can already sign in.- In the Astro UI, go to Settings, then in the Security section, click IP Access List.
- Turn on Proxy-Aware IP Allowlisting.
Proxy-Aware IP Allowlisting doesn’t add any addresses to your IP access list. You must still add the egress IP address ranges of your proxy or tunnel in CIDR format for Astro to match requests against them.
Restore access
Because the IP Access List limits access to the Astro UI only to specific IP addresses, you can’t access the Astro UI if you’re not connected to a corresponding VPN or authorized network. To restore access for a user that is blocked, an Organization Owner needs to either:- Disable the IP Access list setting by deleting the list or
- Add the specific blocked user’s IP address to the IP Access list.