Network zones

Network zones

Besides the internal and external zones, you can define your own network zones, for example a branch office, a partner's network or a list of countries, and give each one its own authentication level.

Defining zones

Zones are defined on Security settings / General / Network zones (up to 64 zones). Each zone has:

Which zone applies:

  1. The internal network always wins: an address in the internal network is in the internal zone, even if a network zone also matches it
  2. Otherwise the network zones are checked from top to bottom and the first matching zone wins: use the arrows to change their priority
  3. If no zone matches, or the origin of the connection can't be determined, the external zone applies

You can't save a zone setting that would forbid your own access to the admin console from where you are connected.

Zone levels in access rules

Once a zone is defined, every access rule shows a line for it. Possible values:

Example

Company offices are in the internal network. A "Partners" zone lists the salesforce access rule for the group "Sales" is: internal -> 1 factor | external -> 2 factors | Partners -> Forbidden.

Renaming and deleting zones

LDAP and Radius applications do not provide the user's IP, so zones do not apply to them.


Revision #2
Created 27 September 2026 20:05:44 by WALLIX Admin
Updated 27 September 2026 20:14:04 by WALLIX Admin