← Back to plugin index

IP Address Context Extractor

Description

Configures client IP address to context mappings. If the IP of the client does not match, the fallback context is used.

To determine the client IP address behind a gateway, Airlock IAM requires one of these gateway settings:
  • Airlock Gateway (WAF): Verify that "Environment Cookies" are activated on all Loginapp mappings and that the environment cookie prefix in Airlock Gateway and Airlock IAM is the same. The client IP is sent by the WAF in the REMOTE_ADDR cookie (with respect to the configured prefix)
  • Airlock Microgateway: Make sure to extract the client's IP address in Airlock Microgateway Settings.
Type name
IpAddressContextExtractor
Class
com.airlock.iam.common.application.configuration.context.IpAddressContextExtractor
May be used by
Properties
Mappings (mappings)
Description
Defines a list of IPv4 ranges matched against the client IP to determine the configuration context.
Attributes
Plugin-List
Mandatory
Assignable plugins
Fallback Context (fallbackContext)
Description
Name of the context to be used if none of the IP range mappings match.
Leave empty to implicitly use the default context. If this plugin is used within a "Combining Context Extractor", use "[DEFAULT]" to explicitly return the default context if necessary.
Attributes
String
Optional
Example
CTX1
Example
EXT
Example
[DEFAULT]
Gateway (gateway)
Description
Settings regarding an Airlock Gateway or Airlock Microgateway reverse proxy placed in front of Airlock IAM.

The client IP address is extracted differently from the request based on this configuration:

  • Airlock Gateway (WAF): client IP is extracted from the environment cookie
  • Airlock Microgateway: client IP is extracted from the configured header
  • When no gateway is configured, the request's remote address is used as client IP

Attributes
Plugin-Link
Optional
Assignable plugins
YAML Template (with default values)

type: IpAddressContextExtractor
id: IpAddressContextExtractor-xxxxxx
displayName: 
comment: 
properties:
  fallbackContext:
  gateway:
  mappings: