Skip to content
LuxSci
Secure High Volume Email Secure Email Gateway Secure Marketing Secure Forms Secure Text Secure Email Hosting Secure Web Hosting
HIPAA Compliant Email HIPAA Compliant Marketing HIPAA Compliant Email Marketing HIPAA Compliant Forms HIPAA Compliant Hosting
API Access SMTP TLS Checker SecureLine Technology System Status Blog EOB Calculator
About Us Partners Support Contact Us
Login Contact Us
Secure High Volume Email Secure Email Gateway Secure Marketing Secure Forms Secure Text Secure Email Hosting Secure Web Hosting
HIPAA Compliant Email HIPAA Compliant Marketing HIPAA Compliant Email Marketing HIPAA Compliant Forms HIPAA Compliant Hosting
API Access SMTP TLS Checker SecureLine Technology System Status Blog EOB Calculator
About Us Partners Support Contact Us
Login Contact Us

Ultimate Control: Manage Access to Your Services with Custom Firewalls

October 13, 2012 • By Erik Kangas • In LuxSci Library: Security and Privacy, New Feature Announcements

Can I block this one IP that is scanning our accounts?  Can I restrict my account so that people can only access it from our office network, or require that they authenticate to WebMail first (using two-factor authentication)?

LuxSci is constantly asked for fine-grained access controls by customers who are in shared environments (sharing the same servers with many other accounts).  However, blocking access from IP addresses globally at the request of one customer may potentially affect other customers using the same system.

That is, until now. LuxSci customers can now configure their own custom firewalls to allow and deny access as they see fit without affecting other customers sharing the same server(s).

Layers of Firewalls

LuxSci has many layers of access controls and firewalls:

  1. Hardware Firewalls that protect many servers
  2. Software Firewalls protecting each individual server from traffic that passes the hardware firewalls
  3. NEW! Account Firewalls protecting access to specific accounts, domains, and users from traffic that is allowed past the software firewalls
  4. Account Settings which may further limit access to services based on account security policies, service licenses, etc.

Introducing Account Firewalls

Every LuxSci customer can now control access to the services provided by their accounts, independent of the access controls of all other accounts.

Specify rules at the user, domain, and account levels

For ultimate flexibility, firewall rules can be created to apply to:

  • Only a specific user,
  • All users in a domain, or
  • All users in an account
The user-level rules take precedence over the domain-wide rules, which take precedence over the account-wide rules.

Allow and Deny usage by IP and CIDR block:

You can configure allow and deny rules for specific IP addresses and for ranges of IP addresses designated by CIDR blocks (e.g. 1.2.3.4/24 is a range of 256 IP addresses).

“Allow” rules will take priority over “Deny” rules, but you can create “Deny All” rules that will effectively deny all access except from certain explicitly allowed IPs.

Allow and Deny usage by service

Control access for all services or by selected services.  Services that you can control access to include:

  • LuxSci’s Web Interface (e.g. WebMail)
  • Secure POP, Insecure POP
  • Secure IMAP, Insecure IMAP
  • Secure SMTP, Insecure SMTP
  • Secure FTP, Insecure FTP
Using these rules, you could, for example, block access to insecure POP, IMAP, and SMTP completely and allow access to the secure versions of these protocols from only specific IP ranges.

Grant Access to Other Services Via Web Interface Authentication

Let’s say that you have restricted access to everything so that only your office IP addresses can login to your account.  How does this help your remote or roaming users? You can’t know what IP address they will be coming from ahead of time, and you don’t want to have to manually allow them and change your firewall all of the time.

The solution? Use the optional “Web Interface Login Grants Access” feature of the firewall.  With this enabled, a remote user need only login successfully to the Web Interface to have his/her current IP addresses added to his/her personal firewall, allowing access to all services from that IP.  You can configure how long this temporary “allow list” access remains (from 1 day to 90 days).

If you enable two-factor authentication for the Web Interface logins, restrict WebMail access by Country or Region, use OpenID, or use our good password guessing restrictions for WebMail, then this truly and effectively blocks password guessing on your user accounts and provides a very solid layer of user access security.

Login Failure Alerts

LuxSci provides emailed login failure (and success) alerts to customers so that they can be informed quickly if someone is trying to gain access to their accounts.  While logins that are blocked by your custom user, domain, or account firewall rules will still be logged as login failures in your audit trails, these block logins will not be emailed to you in your alerts.

Why? Because if they are blocked by your firewall, there is no way they could login successfully or guess your password — so pushing notices of these failures to you would be just annoying.  Instead, if you see people scanning your account, you can go and explicitly block their IPs to both (a) stop their guessing attacks, and (b) stop yourself from getting further alerts about them.

Note that LuxSci does place automatic blocks on IPs that are apparently performing password guessing attacks on our servers.  However, it is always possible to guess slowly enough to fall “under the radar” of automated systems.  Account Firewalls allow you to manage these attacks yourself when you are alerted to them and decide that they are malicious and not just inadvertent.

Ready to Configure your Firewall?

Go to:

  • Account-wide Firewall
  • Domain-wide Firewall (choose your domain and select Security > Firewall)
  • Personal Firewall

 

 

 

Erik Kangas

About Erik Kangas

With 30 years engaged in to both academic research and software architecture, Erik Kangas is the founder and Chief Technology Officer of LuxSci, playing a core role in building the company into the market leader for HIPAA compliant, secure healthcare communications solutions that it is today. An international lecturer on messaging security, Erik also advises and consults on email technology strategies and best practices, secure architectures, and HIPAA compliance. Erik holds undergraduate degrees in physics and mathematics from Case Western Reserve University, and a doctoral degree in computational biophysics from MIT.

Follow: LinkedIn

Get in touch

Find The Best Solution For Your Organization
Talk To An Expert & Get A Quote

I consent to be contacted by LuxSci for this inquiry and other relevant content, products, and services. You may unsubscribe from these communications at any time. We're committed to your privacy. For more information, check out our Privacy Policy.


A member of our staff will reach out to you

Category

  • AAA Featured Articles (8)
  • Affiliates & Resellers (3)
  • Business Solutions (72)
  • Case Studies (8)
  • Collaboration (1)
  • Company Announcements (8)
  • Dedicated & Cloud Servers (15)
  • Email Archival (4)
  • Email data breach (1)
  • Faxing (1)
  • HIPAA Compliant Email Marketing (10)
  • HIPAA Compliant Forms (28)
  • HIPAA Email Compliance (72)
  • HIPAA Marketing (98)
  • HITRUST CSF (6)
  • Industry News (11)
  • LuxSci Help (4)
  • LuxSci Insider (12)
  • LuxSci Library: Email Programs and Devices (13)
  • LuxSci Library: HIPAA (104)
  • LuxSci Library: Insider Insight (2)
  • LuxSci Library: Security and Privacy (95)
  • LuxSci Library: The Technical Side of Email (53)
  • LuxSci Library: Web Design and Programming (4)
  • Mobile (8)
  • New Feature Announcements (88)
  • Patient Engagement (14)
  • Popular Posts (21)
  • Secure Text (7)
  • Secure Video (1)
  • SMTP Connector (3)
  • Spam (1)
  • Telehealth (8)

Recent Posts

  • The Case For Email Security
  • What Makes A HIPAA Compliant Website?
  • Why You Should Separate Your Transactional and Your Marketing Email Sending
  • What exactly does HIPAA say about Email Security?
  • Patient Engagement: Why Email is an Essential Channel
  • 6 Email Marketing Best Practices for Healthcare

Get Your Free E-Book!

LuxSci High Email Deliverability Best Practices Paper

High Email Deliverability Best Practices

What you'll learn:

  • How to optimize email performance
  • Key strategies to increase email deliverability rates
  • How email deliverability impacts marketing ROI
Get Free Ebook
LuxSci

Personalized Healthcare Engagement

LinkedIn G2 YouTube Facebook

Products

  • Secure High Volume Email
  • Secure Email Gateway
  • Secure Marketing
  • Secure Forms
  • Secure Text
  • Secure Email Hosting
  • Secure Web Hosting

Resources

  • SMTP TLS Checker
  • SecureLine Technology
  • System Status
  • Blog
  • Company
  • Support
  • Partners
  • Contact us
  • Report Security Concerns

Web Portal Links

  • LuxSci App: Phoenix
  • LuxSci App: Ashburn
  • LuxSci App: Staging
  • Premium Email Filtering
  • DNS Management
  • Secure Video
  • MobileSync Device Management
  • SecureSend
  • Affiliate Portal

Legal

  • Privacy Policy
  • GDPR Contract Addendum
  • HIPAA BAA
  • Legal

Copyright © 2004-2026 Lux Scientiae® Incorporated