<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
<channel>
<title><![CDATA[IceWarp Sdn Bhd]]></title>
<link><![CDATA[https://support.icewarp.com.my/]]></link>
<description />
<generator><![CDATA[Kayako fusion v4.91.0]]></generator>
<item>
<title><![CDATA[GeoIP Access Control for WebClient, IMAP, POP3, SMTP and /admin]]></title>
<link><![CDATA[https://support.icewarp.com.my/index.php?/Knowledgebase/Article/View/127]]></link>
<guid isPermaLink="false"><![CDATA[ec5decca5ed3d6b8079e2e7e7bacc9f2]]></guid>
<pubDate><![CDATA[Tue, 16 May 2023 07:34:48 +0800]]></pubDate>
<dc:creator />
<description><![CDATA[For optimal email security and effective prevention of unauthorized account access resulting from compromised passwords, we strongly advise implementing GeoIP restrictions on WebClient, IMAP, POP3, SMTP and the /admin web-based administration page.We offe...]]></description>
<content:encoded><![CDATA[<span>For optimal email security and effective prevention of unauthorized account access resulting from compromised passwords, we strongly advise implementing GeoIP restrictions on WebClient, IMAP, POP3, SMTP and the /admin web-based administration page.</span><br /><br /><span>We offer a highly effective access control solution using IceWarp's Firewall and Account Login IP Restriction that limits access exclusively to specified IP Addresses and/or sub-nets. This proven method has been successfully deployed for numerous customers and can be implemented as follows:</span><br /><br /><b>1)</b><span><span> </span>Obtain and regularly update the country specific IP and sub-nets list from a reputable GeoIP provider, eg.<span> </span></span><a class="moz-txt-link-freetext" href="http://www.ipdeny.com/ipblocks/data/countries/my.zone">http://www.ipdeny.com/ipblocks/data/countries/my.zone</a><br /><b>2)</b><span><span> </span>Incorporate the obtained list into an IceWarp Pattern, eg. System &gt; Advanced &gt; Patterns &gt; [GeoIP_MY]<br /><br /><span style="color: #ff0000;"><strong>** You must define a pattern for local IP addresses and subnets, which must include at least the localhost IP 127.0.0.1 . This local IP pattern should be consistently applied to all services where GeoIP-based access control is enabled.</strong></span></span><br /><br /><img src="https://dl.techbyte.co/Kayako/Images/kb128/kb128_01.png" alt="" width="1051" height="209" /><br /><br /><b>3)</b><span><span> </span>Apply the created Pattern(s) to the desired service(s), eg. System &gt; Services &gt; General &gt; Web &gt; Access &gt; Grant<br /><br /></span><b>(Apply the same Patterns to IMAP and POP3, DO NOT apply to SMTP (SMTP Restrictions will be managed by Login IP Restriction))</b><br /><br /><img src="https://dl.techbyte.co/Kayako/Images/kb128/kb128_02.png" alt="" width="612" height="585" /><br /><br /><strong>4)</strong><span> </span><b></b><span>Apply the created Pattern(s) for All Users / Domains Login IP Restrictions, eg. Domains &amp; Accounts &gt; Policies &gt; Login Policy &gt; Login IP Restriction &gt; Use account login IP restriction &gt; [Login Restriction...] &gt; *=[GeoIP_MY];[GeoIP_SG]<br /><br /><img src="https://dl.techbyte.co/Kayako/Images/kb128/kb128_04.png" alt="" width="824" height="469" /><br /></span><br /><b>5)</b><span><span> Restart ALL Services</span></span><br /><br /><span>By following these steps, you can significantly improve your access control measures and strengthen the security of your IceWarp environment.</span><br /><br /><b>The GeoIP based access grant can be implemented for the following scenarios:</b><br /><br /><span>- Country specific IP Addresses and/or sub-nets, eg. Malaysia, Singapore</span><br /><span>- Your assigned Static Public IP Addresses and/or sub-nets</span><br /><span>- Your assigned Internal IP Addresses and/or sub-nets</span><br /><span>- Specific Public IP addresses and/or sub-nets used permanently or on an ad-hoc basis</span><br /><br /><span>Please note that SMTP services require the ability to receive connections from any IP address or sub-net, making it impossible to enforce Service Firewall-based access restrictions. Instead, SMTP access control will be managed using Login IP Restrictions.</span><br /><br /><u><b>Enforce strict IP and/or subnet authorization for accessing /admin</b></u><br /><span>In order to guarantee that /admin is only exclusively accessed from authorized sources, entry to this web-based functionality will be confined to IP addresses and/or sub-nets that have been explicitly granted permission.</span><br /><br /><img src="https://dl.techbyte.co/Kayako/Images/kb128/kb128_03.png" alt="" width="651" height="378" /><br /><br /><b>What you will need to proceed?</b><br /><br /><b>1)<span> </span></b><span>List of Countries to allow by default</span><br /><b>2)</b><span><span> </span>List of Internal and Public IP Addresses and/or sub-nets you wish to grant access to WebClient, IMAP, POP3 and SMTP</span><br /><b>3)<span> </span></b><span>List of Internal and Public IP Addresses and/or sub-nets you wish to grant access to /admin</span><br /><br /><span>For any additional information or assistance, please do not hesitate to reach out to our support team via email on </span><a href="mailto:support@icewarp.com.my" target="_new">support@icewarp.com.my</a>]]></content:encoded>
</item>
</channel>
</rss>