CORE MODULE

Setting up IP Restrictions

What you'll learn in this guide

How traffic flows in and out of CX Platform when integrations are involved, and what you'll need to do at your end to keep that traffic flowing securely.

Overview

When CX Platform connects to your systems — or your systems connect to ours — IP restrictions are one of the simplest ways to keep that traffic locked down. They tell each side which addresses to trust, and just as importantly, which ones to ignore.

There are two sides to this. The first is the traffic going out from CX Platform to your APIs, webhooks, or services. The second is traffic coming in from you to ours. Both need to be set up properly for an integration to work end to end, and both have a role to play in keeping things secure.

This guide walks through how each side works and what you'll need to do to get set up.

‍

Outbound IPs for integration

Whenever an integration needs CX Platform to call out to your environment — say, to push a delivery callback to your CRM, hit a webhook, or post to your API — that traffic leaves us from a known set of IP addresses.

To make sure those calls actually reach you, those outbound IPs need to be whitelisted on your firewalls or receiving systems. Without that step in place, your firewall will quietly drop the traffic and the integration won't behave the way you'd expect.

Here's how to get the list:

  1. Reach out to your CX Platform or raise a support ticket contact and request the current list of outbound IP addresses.
  2. Share the list with whoever manages your firewalls or receiving systems.
  3. Add those IPs to the appropriate allow lists so traffic from CX Platform isn't blocked.

‍

Keep the list up to date
‍
The outbound IPs may change if our infrastructure is updated. We'll let you know if that happens, but it's worth keeping the list somewhere your network team can find quickly so changes can be rolled out without disruption.

‍

Whitelisting your IPs with CX Platform

The other side of the picture is the traffic going the other way — your systems calling into CX Platform's APIs or integration endpoints. For that, we can whitelist the IP addresses or ranges you'll be calling from, so only traffic from those known sources gets through.

We're happy to accommodate these requests in most cases, with one preference worth flagging up front: smaller, well-defined ranges work best. The tighter the range, the stronger the security posture for everyone involved.

To request whitelisting:

  1. Put together the list of IP addresses or ranges you'll be sending traffic from.
  2. Send the list to your CX Platform contact along with a quick note on what they'll be used for (which integrations, which systems).
  3. We'll review the request and confirm once the addresses are in place.

‍

Large or expansive ranges
‍
If a request covers an unusually large number of addresses or a very broad range, we may come back to you to refine the scope or talk through alternative security measures. It's not a no — it's just a quick conversation to make sure we're keeping things tight on both sides.

‍

A quick recap

Two directions, two jobs. Outbound — whitelist our IPs on your end so our calls reach you. Inbound — let us know which of your IPs to allow in so your calls reach us. Get both set up, and your integration has a clean, secure path in either direction.

If you're not sure which IPs apply to your setup, or you'd like a hand sense-checking a range before you send it through, just reach out to your CX Platform contact — they'll point you in the right direction.