BookmarkSubscribeRSS Feed
fnajera
Fluorite | Level 6

Hi team,

 

Hope you're doing very well.

 

We would like to know if we have any other alternative to use ip addresses to allow access, since our users have IP adresses that change very often, so it's complicated to add new ip's every time these change.

 

https://documentation.sas.com/doc/en/viyaakscdc/v_001/viyaakstasks/n0kldoq6spqxman129kk4f5klmq8.htm

 

I was thinking in two alternatives:

 

a) Add a Windows Virtual Machine in one of the non-adminster resource group, so the users can connect from this machine.

b)Use private endpoints, do you know if that's feasible? private-aks-cluster/images/architecture-two-node-pools.png at main · Azure-Samples/private-aks-clust...

 

I appreciate your kind help.

2 REPLIES 2
JuanS_OCS
Azurite | Level 17
Hi there,

There is no alternative per-se. It’s a network thing.
As you well guessed, you can only take a network perspective approach, forcing the users to log from a single ip or ip range.

Options that come to my mind, in addition to the ones you indicated.

- Client VPN connection: either the one of the organization or a new one towards your Viya subscription

- Set an additional reverse proxy with additional rules and MFA (Application Gateway)

- ensure Viya can be accessed only internally, no public ip addresses: Windows Virtual Desktop, Bastion, etc



fnajera
Fluorite | Level 6
Thank you Juan, I'll share this alternatives with our users.

hackathon24-white-horiz.png

The 2025 SAS Hackathon has begun!

It's finally time to hack! Remember to visit the SAS Hacker's Hub regularly for news and updates.

Latest Updates

Discussion stats
  • 2 replies
  • 1348 views
  • 1 like
  • 2 in conversation