Skip to content
RyzenHosting

Virtual servers

Always allowed addresses

Put your office, your home connection or a monitoring service on a list that reaches your server before the firewall rules are read.

Last reviewed 2026-10-04

The Always allowed addresses card sits above the firewall on the Security tab. Anything on this list reaches the server before the rules below are even read, on every port and every protocol.

It exists for one reason: so a mistake in your firewall rules can never lock you out.

Add your own address first

Do this before you start changing firewall rules.

  1. Open your server and click Security.
  2. In Always allowed addresses, click Add address.
  3. Put your own address in Address or network. One address such as 203.0.113.9, or a network such as 203.0.113.0/24.
  4. Put something in Note so you remember whose address it is.
  5. Click Add to the list.
  6. Check the switch at the top of the card is on.

Now, whatever you do to the rules below, that address still gets in.

The switch

The switch at the top of the card turns the whole list on and off. Turning it off keeps the addresses but stops them being allowed through. Turning it back on restores them.

With the list empty, nothing is allowed through this route and the switch does nothing useful.

Limits

  • The list holds up to 64 addresses.
  • An address can only appear once.
  • A note is capped at 120 characters.
  • Addresses can be a single IPv4 address, an IPv4 network in CIDR form, or an IPv6 address.

Entries you cannot remove

Four networks belong to our own platform and stay on the list so that management traffic keeps working. They show a padlock and the label Managed by us instead of a delete button.

These cover the host network your server runs on, the public address block, our monitoring service and the internal backup network. They do not give anyone a way into your operating system. They let the platform do the things the panel asks it to do, such as read the server's state or take a snapshot.

If you try to remove one, the panel refuses and tells you why.

What it does not do

This list is about reaching your server through the firewall. It is not an account permission and it has nothing to do with signing in. Putting your address here does not skip your root password, your SSH key or your Windows sign in.

It also sits in front of the firewall, not in front of your operating system. If something inside the server refuses a connection, this list will not change that.