Product → OPERATIONS GUIDE · FIREWALL AND ALLOWLIST
OPERATIONS GUIDE · FIREWALL AND ALLOWLIST
Manage RDP blocks and trusted administrator networks
Lira correlates failed RDP authentication, applies Windows Firewall blocks and keeps a controlled allowlist for administration paths. Use the allowlist to protect recovery, not to bypass MFA.
Use a pilot and keep an independent recovery channel. Lira changes access controls on real Windows servers. Keep console, hypervisor, iLO/iDRAC, VPN or tested WinRM access available before applying a policy.
Why the order matters Add the real external address or stable VPN CIDR before testing blocking policies.
Temporary blocks should expire automatically; permanent legacy rules must be reviewed and converted to a defined duration.
Allowlisting an address does not grant access by itself and does not replace MFA or least privilege.
Related security guidance
1. Add the correct trusted address Open Protection → Allowlist in the portal. Use Get my public IP while connected from the administration network. Add a single IPv4/IPv6 address or the smallest controlled CIDR; avoid broad ranges. If the address is currently blocked, adding it to the allowlist also removes the matching block after agent synchronization. 2. Understand the 72-hour block lifecycle New automatic blocks are temporary and carry an expiry timestamp. The agent applies the local Windows Firewall rule and reports the result to the portal. Expired rules are removed during the next maintenance cycle; refresh the list to see the recalculated count. Document a longer duration only when there is a clear incident owner and review date. 3. Investigate a false positive Open the block details and compare source IP, username, logon type and failure timestamps. Check whether a stale RDP client, saved credential or another operator caused the failures. Remove the block only after confirming the source; then rotate credentials if the attempts were not expected. Keep MFA enabled and test a fresh connection rather than relying on an existing session. Recovery when access is lost Open the portal from the same external network and add its detected public address to the allowlist. Wait for an online agent to synchronize the firewall policy. If the agent is offline, use console, hypervisor or previously configured WinRM access to restore the channel. Recheck the rule and audit entry before closing the incident.
Before changing blocks Identify the public address from the same network used for administration. Confirm a second recovery path. Record the server and source address. Check the rule duration and reason. Plan removal of temporary allowlist entries.
Common questions Why did the address not disappear immediately? The portal waits for the agent response and a fresh list refresh. A pending command is not the same as a completed firewall change.
Should I allowlist a whole office network? Only the smallest controlled range required for administration. A stable VPN or jump host is safer than a broad dynamic address range.
Protect the administration path before testing Confirm your public address, keep MFA enabled and use temporary, reviewable firewall rules.
Open the Lira console