# Lock down SFTP/SSH and phpMyAdmin access with IP allowlists

**URL:** https://community.kinsta.com/t/lock-down-sftp-ssh-and-phpmyadmin-access-with-ip-allowlists/3761
**Category:** News and Announcements
**Created:** [July 25, 2024, 3:45am UTC](https://community.kinsta.com/t/lock-down-sftp-ssh-and-phpmyadmin-access-with-ip-allowlists/3761 "2024-07-25T03:45:04Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![jeff](https://sea2.discourse-cdn.com/flex020/user_avatar/community.kinsta.com/jeff/32/16_2.png) [@jeff](https://community.kinsta.com/u/jeff)
#### Post date: [July 25, 2024, 3:45am UTC](https://community.kinsta.com/t/lock-down-sftp-ssh-and-phpmyadmin-access-with-ip-allowlists/3761/1 "2024-07-25T03:45:04Z")

</div>

Kinsta’s [Managed WordPress Hosting](https://kinsta.com/wordpress-hosting/) customers can now restrict access to their websites via SFTP/SSH and to their phpMyAdmin database dashboards to clients connecting only from allowed IP addresses.

This security enhancement is in addition to other recent updates to [SFTP/SSH configuration](https://kinsta.com/changelog/sftp-ssh-updates/) within the [MyKinsta dashboard](https://kinsta.com/mykinsta/) that help guard access to your websites. The earlier enhancements added support for:

- Disabling SFTP/SSH access.
- Disabling passwords as an authentication method.
- Auto-expiration of passwords.
- Downloading access configurations for use in third-party applications.

With the addition of IP allowlists for SFTP/SSH and [phpMyAdmin](https://kinsta.com/docs/wordpress-hosting/database-management/wordpress-database-access/), you can eliminate connection attempts from unknown IP addresses.

## How to configure IP allowlists in MyKinsta

IP allowlists are managed on the **Site Information** page in MyKinsta, found under **WordPress Sites** \> _ **sitename** _ \> **Info**.

On the **SFTP/SSH** panel, you’ll find an edit icon to the right of the **IP allowlist** label. Click that icon to begin adding or deleting IP addresses that are permitted to connect for shell or SFTP access:

 ![Screenshot showing the SFTP/SSH panel in MyKinsta and the edit icon for an IP allowlist.](https://us1.discourse-cdn.com/flex020/uploads/kinsta/original/2X/b/bfbca8d2b9aab06454f1a71ebcb1b22cd44e3805.png)Clicking the edit icon to manage an SFTP/SSH IP allowlist.

Similarly, you can specify IPs permitted to access the phpMyAdmin tool by clicking the edit icon beside the **IP allowlist** label in the **Database access** panel:

 ![Screenshot showing the database access panel in MyKinsta and the edit icon for an IP allowlist.](https://us1.discourse-cdn.com/flex020/uploads/kinsta/original/2X/9/98d18e858bde8c91b44b375cf365c6d2592fbf93.png)Clicking the edit icon to manage a phpMyAdmin IP allowlist.

Clicking the allowlist edit icon on either panel will launch an **Update IP allowlist** dialog like the one below:

 ![Screenshot showing the dialog or editing IP allowlists in MyKinsta.](https://us1.discourse-cdn.com/flex020/uploads/kinsta/original/2X/a/a2f6b3a3930697ee998e00da7d010e93a38a1d8f.png)Adding an IP address to an allowlist in MyKinsta.

Build an allowlist by entering valid addresses in the **Add IP addresses** field and clicking the **Add** button.

Some tips:

- You can add multiple IP addresses at once by separating them with commas.
- You can specify an IP address block using the usual syntax. Example: **35.238.77.1/32**.

When an allowlist is active for SFTP/SSH or phpMyAdmin, the number of IPs allowed will be shown on the service’s panel on the **Site Information** page:

 ![Screenshot showing a database access panel in MyKinsta a report of two addresses in an IP allowlist.](https://us1.discourse-cdn.com/flex020/uploads/kinsta/original/2X/1/1f3c4865d049983f07a571332c91be5227ce8846.png)This **Database access** panel indicates the phpMyAdmin allowlist contains two IPs.
### Removing addresses from the IP allowlist

There are two ways to remove entries within the **Update IP allowlist** dialog:

1. Click the trashcan icon beside individual entries.
2. Use the checkboxes to select entries in the list and then click the red **Remove IP address(es)** button.

 ![Screenshot showing an address highlighted in an IP allowlist and the button used to delete it.](https://us1.discourse-cdn.com/flex020/uploads/kinsta/original/2X/e/e7ee2e0571bc83db8b5590a7cde572496b52dbef.png)Removing the selected IP address from an allowlist.
## We take security seriously at Kinsta

Kinsta leverages the [Google Cloud](https://kinsta.com/google-cloud-alternative/) and [Cloudflare](https://kinsta.com/knowledgebase/cloudflare-integration/) to provide additional protection for customer websites, including firewalling, DDoS protection, and free wildcard SSL.

Independent auditors have also confirmed our compliance with [System and Organization Controls](https://kinsta.com/docs/service-information/soc-2/) (SOC) security standards. To learn more, read Kinsta’s SOC 2 Type II report. (You can Request it through our [Trust report page](https://trust.kinsta.com/).)

Get started with our secure environment by finding the best [web hosting&nbsp;plan](https://kinsta.com/pricing/) for you.

The post [Lock down SFTP/SSH and phpMyAdmin access with IP allowlists](https://kinsta.com/changelog/ip-allowlists/) appeared first on [Kinsta®](https://kinsta.com).

* * *
This is a companion discussion topic for the original entry at [https://kinsta.com/changelog/ip-allowlists/](https://kinsta.com/changelog/ip-allowlists/)
