Request a demo →
SUSPICIOUS LOGIN & IP BLOCKING

Known risky sources should not receive unrestricted login attempts.

Rainbow Secure lets authorized administrators manage IP access policy using blacklists and whitelists, individual addresses or ranges, and defined restriction periods. The control helps turn a suspicious source into an enforceable access decision.

Rainbow Secure blacklist IP access policy screen
IP policy for single addresses and ranges with effective dates
THE ACCESS PROBLEM

Repeated suspicious activity should produce a controlled response.

Security teams need a clear way to restrict a confirmed risky address, block a source range or define which IPs are approved for sensitive access—without relying on informal notes or manual memory.

Suspicious source Observed IP or range Policy decision Blacklist · whitelist · duration Login enforcement Allowed or restricted
POLICY CONTROLS

Define the source, scope and duration of an IP decision.

01

Single IP

Restrict or approve one known address.

02

IP range

Apply policy across a defined start and end range.

03

Blacklist

Prevent login access from identified risky sources.

04

Whitelist

Identify approved sources for a controlled access model.

05

Effective period

Use start, end or no-expiration settings according to policy.

OPERATIONAL GOVERNANCE

Blocking needs ownership—not only a button.

Define who may add, update, remove and export IP policies. Record the reason, scope and intended duration so temporary incident actions do not become unexplained permanent rules.

Source validation Confirm the IP or range before enforcement Business impact Check whether legitimate users share the source Expiration Use a review date for temporary restrictions Evidence Preserve the related activity and policy decision
RECOMMENDED USE CASES

Apply IP policy where source context is meaningful.

Confirmed malicious source

Block an address linked to repeated suspicious authentication attempts.

Administrative access

Limit sensitive logins to approved corporate or operational sources where appropriate.

Temporary incident response

Restrict an address or range during an active investigation with a defined review period.

Country and location policy

Coordinate IP controls with the organization’s broader location and country-access rules.

CONTROL THE SOURCE

Turn a suspicious IP into a governed access rule.

Bring one administrative, remote-access or incident-response scenario to a guided policy demonstration.

IP intelligence and blocking can reduce exposure but should not be treated as proof of user identity. Shared, dynamic, proxy and cloud addresses require careful validation to avoid disrupting legitimate access.