Skip to main content

Restrict access to the information base from the Internet

carefully

Access restriction applies only to HTTP/HTTPS connections via a thin client or web client. Connecting via a thick client or via TCP/IP using a thin client will remain possible from any IP address.

By default, access to information bases via the Internet is allowed from all IP addresses. You can restrict access — users will only be able to connect to information bases from IP addresses that you have added to the allowlist.

The allowlist of IP addresses is configured for the 1C server cluster and applies to all information bases in the cluster.

Add an address to the allowlist

  1. Ensure that the IP address is static. You can check the address type with your provider.

  2. In the Control panel, on the top menu, click Products and select Ready-to-use 1C Cloud.

  3. Go to the 1C Server Clusters section.

  4. Open the cluster page → tab Connection.

  5. In the Access settings block, click Edit.

  6. In the IP allowlist for web publication access line, click Add IP.

  7. Enter the address. You can add:

    • IPv4 address;
    • subnet in the format 198.51.100.0/29.
  8. Optional: to add another address, click Add IP and return to step 6.

  9. Click Save. The settings will apply when the cluster changes to status ACTIVE:

    • if the list was empty before configuration and you added IP addresses to it, all current connections will continue to work until they are terminated by users or the infobase administrator. After that, connecting from an IP address that is not in the list will not be possible;
    • if there were already IP addresses in the list and you added an additional one, connecting from it will be possible immediately.

Remove an address from the allowlist for access

If you remove all addresses from the list, the access restriction will be completely lifted — connecting to the cluster's infobases will be possible from any IP address.

  1. In the Control panel, in the top menu, click Products and select 1C Managed Cloud.

  2. Go to the section 1C Server Clusters.

  3. Open the cluster page → tab Connection.

  4. Select Thin Client / WEB.

  5. In the Access settings block, click Edit.

  6. In the IP allowlist for web publication access line, to the right of the required address, click .

  7. Click Save. The current connection from the removed address will continue to work until it is terminated by a user or the infobase administrator. After that, connecting from the removed address will not be possible.