Gateway Sentry

Products / Network Protection / Trusted Networks

Your Own Traffic, Always Welcome

Declare the networks you trust: your monitoring, your backend links, your office, or an entire cloud provider. The edge recognizes them as yours, per service, so your own operations never trip a defense.

per service trusted CIDRsIP groups reusable setsauto-updated provider lists

How Trust Works

Trusted CIDRs

Attach IPv4 ranges to any protected service. The edge treats traffic from those ranges as yours, so your own operations are never mistaken for someone else’s attack.

IP Groups

Define a named set once, for example your monitoring fleet, and attach it to as many services as you like. Update the group and every attachment follows; there is no per-service bookkeeping to drift out of date.

Why It Matters

Health checks, cross-server sync, and admin tooling can look exactly like abuse to a strict edge. Trust rules make sure your own infrastructure is never the casualty of your own protection.

Scoped, Not Global

Trust is granted per service, so a range you trust for your backend link is not automatically trusted for your public game port. The blast radius of a mistake stays small by construction.

Trusted Providers, Built In

Your stack is rarely just your networks: a CDN fronts the web origin, a cloud load balancer health-checks the API. Provider lists cover that half too.

Major Clouds & CDNs

Curated lists for major providers, including Cloudflare and Azure Front Door, ready to attach to any service the way you attach your own IP groups.

Auto-Updating

Each list is pulled from the provider’s published IP ranges and refreshed automatically. When a provider re-numbers, the list follows; nobody on your team chases changelogs.

Behind a CDN? Covered

If a provider sits in front of your origin, its fetch and health-check traffic is recognized for what it is, so your CDN and your protection never argue with each other.

Same Rules as Your Own

Provider lists attach per service, exactly like your own trusted CIDRs. Trust a provider on the web origin without trusting it anywhere else.

Built for Fleets

This is where hosting providers lean hardest: define the monitoring fleet or panel network as one IP group, attach it across the whole roster, and every new customer service inherits it on day one.

Part of Getting Started

Adding your own monitoring and backend ranges is one of the first hardening steps in the getting-started guide, right after locking your origin firewall down to the edge.

Frequently Asked Questions

What happens to traffic from a trusted network?
It is recognized as your own infrastructure, so that service’s defenses never fire against it. Trust is scoped per service, not global.
Can I reuse the same trusted ranges across services?
Yes. IP groups let you define a named set of ranges once and attach it to any number of services. Updating the group updates every service that uses it.
Does Gateway Sentry support trusted lists for cloud providers like Cloudflare or Azure Front Door?
Yes. Built-in provider lists cover major clouds and CDNs, including Cloudflare and Azure Front Door. Each list is pulled from the provider’s published IP ranges and updates automatically, so traffic from those platforms is always recognized without you maintaining the ranges yourself.

Get Protected in Minutes

Provision from the dashboard; usage-based billing from the first packet