BookmarkSubscribeRSS Feed
fnajera
Fluorite | Level 6

Hi team,

 

Hope you're doing very well.

 

We would like to know if we have any other alternative to use ip addresses to allow access, since our users have IP adresses that change very often, so it's complicated to add new ip's every time these change.

 

https://documentation.sas.com/doc/en/viyaakscdc/v_001/viyaakstasks/n0kldoq6spqxman129kk4f5klmq8.htm

 

I was thinking in two alternatives:

 

a) Add a Windows Virtual Machine in one of the non-adminster resource group, so the users can connect from this machine.

b)Use private endpoints, do you know if that's feasible? private-aks-cluster/images/architecture-two-node-pools.png at main · Azure-Samples/private-aks-clust...

 

I appreciate your kind help.

2 REPLIES 2
JuanS_OCS
Amethyst | Level 16
Hi there,

There is no alternative per-se. It’s a network thing.
As you well guessed, you can only take a network perspective approach, forcing the users to log from a single ip or ip range.

Options that come to my mind, in addition to the ones you indicated.

- Client VPN connection: either the one of the organization or a new one towards your Viya subscription

- Set an additional reverse proxy with additional rules and MFA (Application Gateway)

- ensure Viya can be accessed only internally, no public ip addresses: Windows Virtual Desktop, Bastion, etc



fnajera
Fluorite | Level 6
Thank you Juan, I'll share this alternatives with our users.

SAS Innovate 2025: Register Now

Registration is now open for SAS Innovate 2025 , our biggest and most exciting global event of the year! Join us in Orlando, FL, May 6-9.
Sign up by Dec. 31 to get the 2024 rate of just $495.
Register now!

Discussion stats
  • 2 replies
  • 586 views
  • 1 like
  • 2 in conversation