11.01.2015 Views

salesforce_security_impl_guide

salesforce_security_impl_guide

salesforce_security_impl_guide

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Securing and Sharing Data<br />

Restricting Login IP Ranges in the Enhanced Profile User<br />

Interface<br />

• Partner Portal and Customer Portal users aren’t required to activate computers to log in.<br />

• For more information on API login faults, see the Core Data Types Used in API Calls topic in the SOAP API Developer's Guide.<br />

• If single sign-on is enabled for your organization, API and desktop client users can’t log into Salesforce unless their IP address is<br />

included on your organization’s list of trusted IP addresses or on their profile, if their profile has IP address restrictions set. Futhermore,<br />

the single sign-on authority usually handles login lockout policies for users with the “Is Single Sign-On Enabled” permission. However,<br />

if the <strong>security</strong> token is enabled for your organization, then your organization’s login lockout settings determine the number of times<br />

a user can attempt to log in with an invalid <strong>security</strong> token before being locked out of Salesforce.<br />

• These events count toward the number of times a user can attempt to log in with an invalid password before being locked out of<br />

Salesforce, as defined in your organization’s login lockout settings:<br />

– Each time a user is prompted to confirm his or her identity (when a user clicks Email me a verification code for example)<br />

– Each time a user incorrectly adds the <strong>security</strong> token or time-based token to the end of their password to log into the API or a<br />

client<br />

Restricting Login IP Ranges in the Enhanced Profile User Interface<br />

You can control login access on a user’s profile by specifying a range of IP addresses. When you<br />

define IP address restrictions for a profile, any login from a restricted IP address is denied.<br />

1. From Setup, click Manage Users > Profiles.<br />

2. Select a profile and click its name.<br />

3. In the profile overview page, click Login IP Ranges.<br />

4. Use any of these methods to change login IP address ranges for the profile.<br />

• If you want to add ranges, click Add IP Ranges. Enter a valid IP address in the IP Start<br />

Address and a higher IP address in the IP End Address field. The start and end<br />

addresses define the range of allowable IP addresses from which users can log in. To allow<br />

logins from a single IP address, enter the same address in both fields. For example, to allow<br />

logins from only 125.12.3.0, enter 125.12.3.0 as both the start and end addresses.<br />

• If you want to edit or remove ranges, click Edit or Delete for that range.<br />

• Optionally, enter a description for the range. If you maintain multiple ranges, use the<br />

Description field to provide details, such as which part of your network corresponds to this<br />

range.<br />

EDITIONS<br />

Available in:<br />

• Enterprise<br />

• Performance<br />

• Unlimited<br />

• Developer<br />

• Database.com<br />

USER PERMISSIONS<br />

To view login IP ranges:<br />

• “View Setup and<br />

Configuration”<br />

To edit and delete login IP<br />

ranges:<br />

• “Manage Profiles and<br />

Permission Sets”<br />

Both IP addresses in a range must be either IPv4 or IPv6. In ranges, IPv4 addresses exist in the<br />

IPv4-mapped IPv6 address space ::ffff:0:0 to ::ffff:ffff:ffff , where<br />

::ffff:0:0 is 0.0.0.0 and ::ffff:ffff:ffff is 255.255.255.255. A<br />

range can’t include IP addresses inside of the IPv4-mapped IPv6 address space if it also includes IP addresses outside of the IPv4-mapped<br />

IPv6 address space. Ranges such as 255.255.255.255 to ::1:0:0:0 or :: to ::1:0:0:0 are not allowed. You can set<br />

up IPv6 addresses in all organizations, but IPv6 is only enabled for login in sandbox organizations from the Spring ’12 release and<br />

later.<br />

Important:<br />

• Partner User profiles are limited to 5 IP addresses. If you want to increase this limit, contact <strong>salesforce</strong>.com.<br />

• The Salesforce Classic app can bypass IP range definitions set up for profiles. Salesforce Classic initiates a secure connection<br />

to Salesforce over the mobile carrier’s network, but the mobile carrier’s IP addresses might be outside of the IP ranges<br />

allowed on the user’s profile. To prevent bypassing IP definitions set on a user’s profile, “disable Salesforce Classic” in the<br />

Salesforce Help for that user.<br />

42

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!