You can use the Domain IP Filtering policy to manage IP-based access control for all managed APIs, managed API groups, and custom APIs within your organization. This policy defines access rules that either allow or deny IP addresses permission to invoke any API in your organization.
The Domain IP Filtering policy applies globally to every API in the organization by default. If you configure both managed API or managed API group and domain IP filtering policies, the managed API or managed API group policies take precedence over domain IP filtering policies.
When API Center receives an API invocation request, it checks the request's IP address against the IP filtering rules in the order they are listed. The first matching rule is applied to the request, either allowing or denying access.
You must use either allow rules or deny rules in the domain IP filtering policy. You can't use a combination of allow and deny rules.
Configuring a domain-level IP filtering policy provides centralized IP access control across all APIs in your organization, simplifying security management. You can combine the domain IP filtering policy with managed API, managed API group, or custom API-specific policies for greater flexibility. You can also control how policies are evaluated and enforced by ordering the rules.
Creating an IP filtering policy at the domain level
Create an IP filtering policy to assign to all managed APIs, managed API groups, and custom API in your organization.
1On the Configuration page, click the Domain IP Filtering tab.
2Click Add IP Filtering Rule.
3Select to allow or deny a range of addresses, and then fill in the IP range.
4Optionally, enter a description of the rule.
5Repeat steps 2 through 4 to create as many additional rules as required to define the policy. You can change the rule evaluation order by moving rules up or down in the list.
Note: You can't use a combination of allow and deny rules.
6Click Save.
To delete a rule, in the right-most column of the IP Filtering Rules list, rest on a row in the table and click Delete.