Skip to content

Admin IP restriction

Admin IP restriction limits who can sign in as an admin to a small list of trusted IP addresses: your office, your VPN exit, your home IP. When the feature is enabled and a login attempt comes from an IP that is not on the list, the panel rejects it before the password is even checked. Customer logins are not affected. By default the feature is off and admins can sign in from anywhere.

  • The allow-list holds single IPv4 or IPv6 addresses, each with an optional description.
  • The list is managed with the vcli admin:ip command on the management server. Adding and removing IPs is deliberately command-line only, so a misconfigured panel session cannot accidentally lock every admin out.
  • The on/off state and the current list are visible in the panel under System > Settings, on the Security tab, in the Admin IP Restriction section (with the CLI commands listed next to it).
  • Active sign-ins and their IPs are visible under System > Sessions. See Sessions.
  • Console (SSH) access to the management server.
  • You know the public IP addresses your admins sign in from. Check System > Sessions for the IPs currently in use.

On the management server, run vcli admin:ip commands as root. In the admin panel, go to System > Settings and open the Security tab to see the state and the list.

Settings, Security tab

  1. Whitelist the IP you are connecting from first, so you do not lock yourself out:

    Terminal window
    vcli admin:ip add 203.0.113.45 --description="Office"
  2. Add any other trusted IPs (other admins, VPN exit IPs):

    Terminal window
    vcli admin:ip add 198.51.100.10 --description="VPN exit"
  3. Confirm the list:

    Terminal window
    vcli admin:ip list
  4. Turn the feature on:

    Terminal window
    vcli admin:ip enable

Changes apply immediately. No restart is required.

Terminal window
vcli admin:ip remove 203.0.113.45
Terminal window
vcli admin:ip disable
Command What it does
vcli admin:ip enable Turn the restriction on. Only whitelisted IPs can sign in as admin.
vcli admin:ip disable Turn the restriction off. Admin logins work from any IP.
vcli admin:ip list Show the current allow-list.
vcli admin:ip add <ip> Add an IP. Add --description="..." to label it.
vcli admin:ip remove <ip> Remove an IP.
  • Locked out after enabling the feature. SSH into the management server and either add your current IP with vcli admin:ip add <ip> or run vcli admin:ip disable.
  • Not sure what your public IP is. From your own machine run curl https://ifconfig.me, or look at your latest session under System > Sessions.
  • An admin is rejected although their IP is whitelisted. Their traffic arrives through a reverse proxy that does not forward the real client IP, so the panel sees the proxy’s address. Fix the proxy forwarding, then whitelist the IPs again.