BookmarkSubscribeRSS Feed
fnajera
Fluorite | Level 6

Hi team,

 

Hope you're doing very well.

 

We would like to know if we have any other alternative to use ip addresses to allow access, since our users have IP adresses that change very often, so it's complicated to add new ip's every time these change.

 

https://documentation.sas.com/doc/en/viyaakscdc/v_001/viyaakstasks/n0kldoq6spqxman129kk4f5klmq8.htm

 

I was thinking in two alternatives:

 

a) Add a Windows Virtual Machine in one of the non-adminster resource group, so the users can connect from this machine.

b)Use private endpoints, do you know if that's feasible? private-aks-cluster/images/architecture-two-node-pools.png at main · Azure-Samples/private-aks-clust...

 

I appreciate your kind help.

2 REPLIES 2
JuanS_OCS
Amethyst | Level 16
Hi there,

There is no alternative per-se. It’s a network thing.
As you well guessed, you can only take a network perspective approach, forcing the users to log from a single ip or ip range.

Options that come to my mind, in addition to the ones you indicated.

- Client VPN connection: either the one of the organization or a new one towards your Viya subscription

- Set an additional reverse proxy with additional rules and MFA (Application Gateway)

- ensure Viya can be accessed only internally, no public ip addresses: Windows Virtual Desktop, Bastion, etc



fnajera
Fluorite | Level 6
Thank you Juan, I'll share this alternatives with our users.

SAS Innovate 2025: Call for Content

Are you ready for the spotlight? We're accepting content ideas for SAS Innovate 2025 to be held May 6-9 in Orlando, FL. The call is open until September 25. Read more here about why you should contribute and what is in it for you!

Submit your idea!

Discussion stats
  • 2 replies
  • 393 views
  • 1 like
  • 2 in conversation