Restrict access to the information base from the Internet
Access restriction applies only to HTTP/HTTPS connections via a thin client or web client. Connecting via a thick client or via TCP/IP using a thin client will remain possible from any IP address.
By default, access to infobases over the internet is allowed from all IP addresses. You can restrict access so that users can only connect to infobases from IP addresses that you have added to the allowlist.
The allowlist of IP addresses is configured for the 1C server cluster and applies to all information bases in the cluster.
Add an address to the allowlist
-
Ensure that the IP address is static. You can check the address type with your provider.
-
In the Control panel, in the top menu, click Products and select Cloud 1C.
-
Go to 1C server clusters.
-
Open the cluster page → Connection tab.
-
In the Access settings section, click Edit.
-
In the IP allowlist for web publications line, click Add IP.
-
Enter the address. You can add:
- IPv4 address;
- subnet in the
198.51.100.0/29format.
-
Optional: to add another address, click Add IP and go back to step 6.
-
Click Save. The settings will apply once the cluster changes to the
ACTIVEstatus:- if the list was empty before configuration and you added IP addresses to it, all current connections will continue to work until they are terminated by users or the infobase administrator. After that, connecting from an IP address that is not in the list will not be possible;
- if there were already IP addresses in the list and you added an additional one, connecting from it will be possible immediately.
Remove an address from the allowlist for access
If you remove all addresses from the list, the access restriction will be completely lifted — connecting to the cluster's infobases will be possible from any IP address.
-
In the Control panel, in the top menu, click Products and select Cloud 1C.
-
Go to 1C server clusters.
-
Open the cluster page → Connection tab.
-
Select Thin client / WEB.
-
In the Access settings section, click Edit.
-
In the IP allowlist for web publications line, to the right of the desired address, click .
-
Click Save. The current connection from the removed address will continue working until closed by the user or the infobase administrator. After that, connecting from the removed address will not be possible.