This is a mechanism that "allows access only from specific IP addresses (or IP address ranges) and denies all others." By permitting access only through designated routes—such as your corporate network, branch offices, or VPN—you can significantly strengthen security.
Dive supports restriction by global IP addresses (IPv4/IPv6) and allows you to register them in three formats: Single, Range, or CIDR. After configuration, login attempts from IPs not included in the allowlist will be blocked, even from users with Owner permissions.
Who can configure this
Only users with Owner permission only.
What to check before you start
This is a powerful restriction. There is a risk that even the Owner could be locked out due to misconfiguration, so be sure to check the following:
- Confirm that the IP address you intend to set is a global IP (outbound IP assigned by your provider or VPN)
- Before configuring, always include your own global IP
- For approved IP addresses, we recommend taking a backup by using Export to Excel so you can verify them right after configuration
If you happen to be locked out, please contact us.
Configuration steps
- Log in to Dive and click "Owner Functions"
- Select the "Security" tab at the top and open the "IP Address Restriction Settings" card
-
Check "Use IP address restriction"
- Open the allowlist section and click one of the following depending on the format you want to register
-
"+ Add": Register a single IP address or CIDR format (e.g.,
192.168.0.0/24) - "+ Add by range": Register as a range from start IP to end IP
-
"+ Add": Register a single IP address or CIDR format (e.g.,
-
Enter the IP addresses you want to allow (supports the following three formats)
-
Single IP:
203.0.113.5/2001:db8::1 -
Range:
203.0.113.5to203.0.113.50 -
CIDR:
192.168.0.0/24/2001:db8::/32
If the format is incorrect while you're entering it, you'll see a red error message right away
-
Single IP:
- When finished, click "Save"
Safety feature at save time
When saving, if the network currently being used by your session (the IP from which you are accessing) is not included in the allowlist, the following message will appear. It will be added automatically, so click "OK". This prevents you from being locked out immediately after configuration.
Excel import and Export to Excel
You can also manage the allowlist of IPs in bulk using Excel. Even organizations managing multiple branch offices and VPNs can register a list prepared in Excel as-is.
- "Export to Excel": Download the current allowlist as an Excel file
- "Excel import": Import the allowlist from an Excel file (.xlsx)
Use this feature when you want to keep a backup for operational changes or audits.
Tips for effective use
- Always test before going live: Save with a minimal configuration that includes your own global IP, then confirm you can log out and log back in
- Force VPN access: Use this to prevent direct access from home or coffee shops and require all login attempts to go through VPN
- When expanding to new locations: When a new branch opens, be sure to add the local global IP to the allowlist before starting operations
- Mixed IPv4/IPv6 environments: Some providers use both IPv4 and IPv6. Including both in the allowlist is safer