Ir al contenido principal

IP Restrictions

Actualizado hoy

Introducción

IP restrictions let you lock Level logins down to a set of trusted IP addresses — your office network, VPN, or specific machines. Anyone trying to log in from outside that list gets blocked, even with valid credentials.


Configuring the IP Allowlist

⚠️ WARNING: Include your current IP address before enabling the allowlist. If you lock yourself out, you'll need to contact Level support to regain access.

  1. Navigate to Configuración → Seguridad.

  2. Scroll to the IP Allowlist section at the bottom of the page.

  3. Haga clic en Añadir IP Añadirress.

  4. Ingrese a trusted IP address or CIDR range (e.g., 68.191.123.208/28).

  5. Opcionally, add a description (e.g., "Office," "VPN exit node," "John's home office").

  6. Repeat for each address you want to allow.

  7. Habilitar the IP Allowlist toggle to start enforcing restrictions.

💡 CONSEJO: Use descriptions on every entry — "VPN" or "Headquarters" is much more useful than a bare IP six months from now when someone asks why a specific address is listed.


How It Works

When the allowlist is active, login attempts from any IP not on the list are blocked at authentication. The technician sees an error; they don't get through even if their credentials are correct.

ℹ️ NOTA: IP restrictions apply to web interface logins. They don't affect the Level agent's connection to Level's backend infrastructure — managed devices communicate independently of this setting.


Keeping the List Current

Network infrastructure changes. When it does, update the allowlist before the old IP is decommissioned — not after.

Common situations to watch for:

  • VPN IP changes after a provider switch

  • ISP-assigned dynamic IPs at branch offices

  • Añadiring a new remote technician who works from a fixed home IP

To remove an IP: click the trash icon next to the entry.

To disable the allowlist entirely: toggle IP Allowlist off. Logins immediately open to all IPs again.


Preguntas frecuentes

  • Who can manage the IP allowlist? Only Organization Admins can configure IP restrictions under Configuración → Seguridad.

  • What happens to technicians who are already logged in when I enable the allowlist? Activo sessions aren't terminated immediately. The restriction applies to new login attempts. Technicians on untrusted IPs will be blocked when their current session expires and they try to log back in.

  • Can I add a CIDR range instead of a single IP? Sí. Ingrese a valid CIDR range (e.g., 198.190.255.208/28) to allow an entire subnet.

  • I enabled the allowlist and now I'm locked out. What do I do? Contact Level support at [email protected]. They can disable the restriction so you can regain access.

  • Does this affect the Level agent on managed devices? No. The agent communicates with Level's backend directly and is not subject to the login IP allowlist. This setting only affects technician logins via the web interface.

¿Ha quedado contestada tu pregunta?