IP Range Security: How to Protect a Multi-Site LIMS Without Locking Out Your Own Team
Table of contents
The perimeter that no longer exists (but is still useful)
In recent years, the dominant narrative in cybersecurity has been clear: the network perimeter is dead. With remote work, the cloud, and mobile devices, it no longer makes sense to assume that everything “inside” the network is trustworthy and everything “outside” is suspicious. The US National Institute of Standards and Technology (NIST) formalized this idea in Special Publication 800-207, which defines the Zero Trust model under the principle of “never trust, always verify.”
And yet the data show something uncomfortable: perimeter devices —firewalls, VPNs, remote access points— remain one of attackers’ favorite targets. According to Verizon’s 2025 DBIR report, attacks targeting these devices as a vulnerability-exploitation vector nearly multiplied eightfold in a single year, from 3% to 22% of recorded exploitation actions. And according to advisories from national cybersecurity agencies such as the US Cybersecurity and Infrastructure Security Agency (CISA), a large share of the incidents that have hit water infrastructure in recent months required no sophistication at all: it was enough for a system to be exposed directly to the internet, with no access restriction whatsoever.
The conclusion isn’t that the perimeter has stopped mattering. It’s that the perimeter is no longer enough on its own — and it isn’t superfluous either.
What exactly is IP range restriction?
Every device connected to the internet has an IP address: a kind of numeric license plate that identifies its network of origin. IP range restriction consists of configuring the LIMS to accept connections only from previously authorized addresses —or address ranges. If someone tries to access it from any other address, even with the correct username and password, the system denies entry.
Ranges are typically defined in CIDR notation (for example, 192.168.1.0/24 to cover an entire office subnet), and can be applied globally across the system or individually per user, depending on what each profile needs. A site with a fixed internet connection —which most accredited laboratories have— has a stable public IP or a range assigned by its provider, which makes it practical to maintain a list of authorized addresses with almost no upkeep.
Why it’s especially useful for multi-site laboratories
A laboratory with several sites —headquarters, branch offices, sample-receiving points— multiplies its exposure surface: each location is a potential entry point into the same centralized system. IP restriction lets you declare, site by site, which networks are entitled to connect to the LIMS, so an access attempt from an IP outside those locations —typically the pattern followed by automated attacks and mass scanning of exposed systems— is blocked before it even reaches the login screen.
ISO/IEC 17025 accreditation for multi-site laboratories already explicitly recognizes this challenge: maintaining centralized procedures, consistent document control, and a shared platform across locations is one of the specific difficulties multi-site labs face compared to single-site ones. A LIMS with IP access restriction configurable site by site makes precisely that consistency easier, without forcing every branch to share a single physical network.
The limits of IP restriction (and why it should never stand alone)
No single security measure works in isolation, and IP restriction has limits worth knowing before relying on it too heavily:
It doesn't protect field work well: A sampling technician connecting from a mobile network has a dynamic IP that’s often different each time. Strict IP restriction can end up locking out your own staff instead of an attacker.
It doesn't replace authentication: If an attacker manages to operate from inside an authorized network —for example, after compromising an office device— IP restriction won’t stop them. That’s why it must be combined with multi-factor authentication and role-based permissions.
IP addresses can be spoofed: Using spoofing techniques or by compromising a device inside the authorized network, an advanced attacker can bypass a restriction based solely on connection origin.
This is exactly the logic behind the Zero Trust model: it doesn’t reject network controls, but it rejects the idea that they’re enough on their own. IP restriction remains a reasonable, low-cost entry barrier —especially against the automated attacks and mass scanning of exposed systems that security agencies describe— but it works best as one layer within a defense-in-depth system, not as the only line of defense.
Regulatory framework: network segmentation and technical measures
Network segmentation frameworks
The NIST Cybersecurity Framework lists network segmentation among its reference controls for limiting an attacker’s ability to move across systems once inside a network, and ISO/IEC 27001 includes similar network-control requirements within its Annex A controls. Restricting access to a LIMS by IP range is, in practice, a form of segmentation applied to the system’s external perimeter. In the EU, Spain’s Esquema Nacional de Seguridad (Royal Decree 311/2022) offers a concrete example: it lists network segmentation among the reference measures public administrations and their providers must assess, graded by a basic/medium/high risk categorization.
GDPR and equivalent laws: technical measures proportionate to risk
Article 32 of the EU’s General Data Protection Regulation (GDPR) requires technical and organizational measures proportionate to the risk of the processing activity — a principle mirrored in other data protection laws such as the US state privacy statutes and the UK GDPR. For a laboratory with customer personal data across several sites, limiting by network which locations can access the system is a reasonable, low-cost technical measure that reinforces the rest of the controls —encryption, roles, authentication— without replacing them.
How IP restriction works in Zendo LIMS
Zendo LIMS includes a geolocation system that lets you create authorized IP ranges globally across the system or individually per user, designed specifically for multi-site scenarios:
| Laboratory scenario | Recommended configuration |
|---|---|
| Headquarters with a fixed connection | Globally authorized IP range for the entire site |
| Branch office or sample-receiving point | Specific IP range for that location, distinct from headquarters |
| Field sampling technician | No strict IP restriction; reinforce instead with multi-factor authentication and limited role permissions |
| External client (Web Portal) | No IP restriction; control is handled through portal isolation and its own permissions |
| User with administrative access | Per-user IP range, combined with MFA and inactivity lockout |
This range- and user-level configuration combines with, rather than replaces, the other layers already described in this series: HTTPS/TLS encryption, multi-factor authentication, inactivity lockout, and role-based permissions. No single layer —including this one— is meant to be a complete solution on its own.
Does your laboratory have multiple sites and need help deciding which IP ranges to authorize? Request a free consultation with the Zendo LIMS team.
Frequently asked questions
What is a static IP address and why does it matter for this setup?
A static IP is an address that doesn’t change over time, unlike a dynamic IP that an internet provider can reassign periodically. IP restriction works best with static connections or stable ranges, typical of a fixed site; with dynamic IPs, you need to update the authorized list or combine the measure with other security layers.
Does IP restriction replace a VPN?
No. A VPN encrypts and tunnels a remote user’s connection so it appears to originate from the corporate network; IP restriction simply decides which addresses can connect to the system. The two are complementary: many laboratories combine a VPN for remote staff with a list of authorized IPs for fixed sites.
Does it make sense to enable IP restriction if I already have multi-factor authentication?
Yes. MFA protects the user’s identity; IP restriction protects the system’s entry point. An attacker with stolen credentials but no access to an authorized network won’t be able to complete login, even if they get past the password. They’re independent layers that reinforce each other.
What happens if the laboratory changes internet provider or moves offices?
The authorized IP range for that site needs to be updated. That’s why it’s advisable to combine IP restriction with multi-factor authentication: if the range becomes outdated during a transition, the second verification factor keeps protecting access while the configuration is corrected.