With the IP address restriction enabled, the Workspace dashboard can only be used from the IP addresses you allow. Use it to stop shared logins from former staff or access from outside the office. It's an Enterprise plan feature, and Workspace administrators set it up. This article covers how to enable it, the IP address formats, exempt members, what a blocked member sees, and what to do if you get locked out.
What you need to use the IP address restriction
Only administrators of an Enterprise plan Workspace can set up the IP address restriction. To prevent locking yourself out, your current IP address must be in the list, or you must be an exempt member, before the restriction can be enabled.
- The Workspace is on the Enterprise plan
- You are a Workspace administrator
- When enabling, your current IP address is in the list, or you are an exempt member
On other plans the section is shown but can't be changed. You can change the plan under "Usage & Billing".
Opening the settings screen
The IP address restriction lives in the Security section of the Workspace settings.
- Open "Settings" in the navigation menu
- Select "Workspace Settings"
- Choose "Security" in the left menu to show the "IP address restriction" section
The section has the following controls.
| Control | What it does |
|---|---|
| "Allow the dashboard only from allowed IP addresses" | Turns the restriction on or off. When on, access from an IP address that isn't in the list is blocked from the next action |
| Your current IP address | Shows the address you're connecting from and whether it's in the list. "Add current IP" adds it |
| Allowed IP addresses | The list of allowed addresses with the IP address / range, note, when it was added, and who added it. Each row can be removed |
| Add row | Enter an IP address and an optional note, then click "Add" |
| "Exempt members" | Members who can use the Workspace regardless of their IP address |
Click "Save" after making changes. Turning the restriction on shows a confirmation dialog before saving.
IP address formats
Allowed IP addresses can be entered as a single address, in CIDR notation, or as a dash range. Only IPv4 is supported.
| Format | Example | Description |
|---|---|---|
| Single address | 203.0.113.10 |
Allows one IP address |
| CIDR notation | 203.0.113.0/24 |
Allows a whole network. Prefixes from /8 to /32 are accepted |
| Range | 203.0.113.1-203.0.113.50 |
Allows everything from the start to the end address |
A Workspace can hold up to 100 entries. The same range can't be added twice. IPv6 addresses can't be added.
Ask your network administrator for your office IP addresses or CIDR blocks. Connections without a fixed IP address, such as mobile carriers, can change address on every connection and aren't a good fit for the list.
Exempt members
Exempt members can use the Workspace regardless of their IP address. Use it for administrators who travel often or members who have to work from outside the office.
Exempt members also protect against lockouts. If an administrator is exempt, they can get back into the dashboard and fix a mistaken list. Keep the exempt list as short as possible.
Changes to exempt members are recorded in the audit log as well.
What a blocked member sees
Opening the Workspace from an IP address that isn't allowed shows the screen "This Workspace can only be used from allowed IP addresses" instead of the dashboard.
The screen shows the current IP address, so the member can pass it on to an administrator and ask for it to be allowed. "Open another Workspace" switches to a Workspace without the restriction, and "Log out" signs out.
Signing in itself still works. Members are blocked only when they open a Workspace with the restriction enabled. A dashboard that was already open is blocked from its next action.
If you get locked out
An administrator can't enable the restriction while their current IP address is outside the list. That rule prevents the person doing the setup from locking themselves out.
If you still get locked out, for example because the office connection changed or the exempt member left the company, contact support through the inquiry form. After confirming your identity, support lifts the restriction, which is recorded in the audit log. Set it up again with the correct addresses afterwards.
Relation to the audit log
Every action on the IP address restriction is recorded in the audit log.
| Action | Shown in the audit log as |
|---|---|
| Restriction enabled | IP address restriction enabled |
| Restriction disabled | IP address restriction disabled |
| Allowed list or exempt members changed | IP address restriction changed (with before and after) |
| Access from an IP address that isn't allowed | Blocked by IP address restriction (with the source IP address) |
Blocked access is recorded once per 10 minutes for the same member and IP address. See Viewing and exporting the audit log for how to read the log.
Things to keep in mind
Keep the following in mind when using the IP address restriction.
- Access from the mobile app is restricted as well. Members who use the mobile app from outside the office should be exempt members or connect through an allowed connection
- The public API (API key) and LINE-side features such as LINE Login, rich menus, and broadcasts aren't restricted
- When the Workspace leaves the Enterprise plan, the restriction stops automatically. The stop is recorded in the audit log, and the list is kept
- The source IP address is the address used to reach Lumo. Depending on your office network or mobile carrier, the same member can show a different address on different days
When things don't work
Common problems with the IP address restriction and what to do.
| Situation | What to do |
|---|---|
| The section is shown but can't be changed | It's available on the Enterprise plan only. Check your plan |
| It can't be enabled (your current IP address isn't in the list) | Click "Add current IP" to add your address, or make yourself an exempt member, then save |
| A colleague got blocked | Add the IP address shown on their blocked screen to the list, or make them an exempt member |
| An IPv6 address can't be added | Only IPv4 is supported. Use an IPv4 address |
| Every administrator is locked out | Contact support through the inquiry form. Set the restriction up again after it's lifted |