Saviynt unveils its cutting-edge Intelligence Suite products to revolutionize Identity Security!
Click HERE to see how Saviynt Intelligence is transforming the industry.
Saviynt Copilot Icon

Whitelisting IP Addresses for On-Prem SMTP Server with SC2.0

vivek9237
Regular Contributor
Regular Contributor

For connecting to on-prem SMTP server we need to whitelist the source IP address.

We need to know which IP address should be whitelisted and why? Should we whitelist the specific IP address of the SC2.0 server, or should we whitelist the whole Saviynt's CIDR range?

Thanks!

Regards,

Vivek Mohanty


If this reply answered your question, please click the Accept As Solution button to help future users who may have a similar problem.
8 REPLIES 8

rushikeshvartak
All-Star
All-Star

When connecting to an on-premises SMTP server from Saviynt's SC2.0 server, you generally need to whitelist the IP address or CIDR range used by Saviynt for outgoing connections. Here’s how to decide which IP addresses to whitelist:

  1. Specific IP Address of SC2.0 Server:

    • When to Use: If Saviynt provides a static IP address for the SC2.0 server or if you have a specific IP that you know is used for outbound SMTP connections, you should whitelist that specific IP address.
    • Benefits: It limits the exposure to only the necessary IP, enhancing security by reducing the range of IPs that have access to your SMTP server.
  2. Saviynt's CIDR Range:

    • When to Use: If Saviynt uses a range of IP addresses for their services or if the IP address of the SC2.0 server is dynamic and can change, you may need to whitelist the entire CIDR range provided by Saviynt.
    • Benefits: It ensures that even if the IP address changes, the connection will still be permitted. However, it broadens the scope of allowed IPs, which might pose a higher security risk.

Recommendation:

  • Check with Saviynt Support: They can provide the most accurate information about the IP address or CIDR range used for SMTP connections from SC2.0. This is important because whitelisting a range or specific IPs might depend on your specific setup and Saviynt’s network configuration.
  • Security Consideration: Always prefer whitelisting the specific IP address if available. If not, whitelist the CIDR range but monitor and manage the security implications carefully.

In summary, if you have a specific IP address, that is often the preferred choice due to its more precise control. If not, use the CIDR range and ensure you understand and manage the potential security risks.


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

vivek9237
Regular Contributor
Regular Contributor

I am not getting an exact answer from this. The question still remains. Do I need to whitelist the Saviynt CIDR range or SC2.0 IP address?
Thanks!

Regards,

Vivek Mohanty


If this reply answered your question, please click the Accept As Solution button to help future users who may have a similar problem.

Sc2 ip addresss

 


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

stalluri
Valued Contributor II
Valued Contributor II

@vivek9237 
Here is the Connectivity Flow.
Saviynt will whitelist the connectivity from their CIDR/SC Server to the SC 2.0 Client.
We have to whitelist the connectivity from the SC2.0 Client (IP of SC2.0 machine) to target applications.

sc 2.0 traffic.pngsc2.0 deatiled.pngsc2.0.png


https://docs.saviyntcloud.com/bundle/Saviynt-Connect-20-Resources/page/Content/Saviynt-Connect-20-Ar...



Best Regards,
Sam Talluri
If you find this a helpful response, kindly consider selecting Accept As Solution and clicking on the kudos button.

sudeshjaiswal
Saviynt Employee
Saviynt Employee

Hello @vivek9237,

To establish connectivity to SMTP first need to establish connectivity from SC2 client machine, for that SC2 client server private ip should be whitelisted SMTP server security/firewall rules.

Thanks.

If you find the above response useful, Kindly Mark it as "Accept As Solution".

vivek9237
Regular Contributor
Regular Contributor

@rushikeshvartak  @sudeshjaiswal thank you for your response. Even I think this should be the SC2.0 private IP. However, we had a call with Saviynt support and they suggested to whitelist the whole CIDR range even though the SMTP server is on prem. I believe as we are using SC2.0, the Saviynt pods IPs will be masked. Kindly reconfirm with the team.

Regards,

Vivek Mohanty


If this reply answered your question, please click the Accept As Solution button to help future users who may have a similar problem.

Saviynt uses cloudflare hence they must have suggested CIDR Range.


Regards,
Rushikesh Vartak
If this helped you move forward, click 'Kudos'. If it solved your query, select 'Accept As Solution'.

Hello @vivek9237 ,

You need to whitelist whole CIDR range,
For Aws : IP wont be masked, as the POD ip will be changing dynamically followed by any pod restart. 
For Azure : the IP will be masked.

Thanks

If you find the above response useful, Kindly Mark it as "Accept As Solution".