> For the complete documentation index, see [llms.txt](https://docs.couchdrop.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.couchdrop.io/administration/users-and-groups/firewalls-and-acls.md).

# Firewalls and ACLs

A key security mechanism in Couchdrop is ACLs. ACLs limit access to particular IP addresses or netwrok ranges.

There are three levels of ACL controls in Couchdrop:

* User based
* Group based
* Tenant based

ACLs are additive, in that if the user authenticating originates from an IP address in a range at all three levels, then we will allow the request.&#x20;

Configuring an IP address or network range is simple:

<figure><img src="/files/SbiXu5dTNIkywwo0bK4j" alt=""><figcaption></figcaption></figure>
