# Grant privileges based on IP

**URL:** <https://community.sonatype.com/t/grant-privileges-based-on-ip/12835>\
**Category:** Sonatype Nexus Repository\
**Tags:** security\
**Created:** [June 28, 2024, 5:56pm UTC](https://community.sonatype.com/t/grant-privileges-based-on-ip/12835 "2024-06-28T17:56:31Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mbrandizi](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/mbrandizi/32/3523_2.png) [@mbrandizi](https://community.sonatype.com/u/mbrandizi)\
**Post date:** [June 28, 2024, 5:56pm UTC](https://community.sonatype.com/t/grant-privileges-based-on-ip/12835/1 "2024-06-28T17:56:31Z")

</div>

Hi all,

I’d like to manage access to Sonatype Nexus 3 in this way:

- If a client connects from a list of whitelisted IPs (ie, our LAN), it can download artifacts from a given maven repository (and other functionality, like browsing/listing), without having to login

- Outside of the established IPs, the client wanting to access the same repo needs to authenticate with an account having the proper privileges.

- The same server has other repositories (eg, public) which are accessible in read-only mode by any client, without authentication (ie, as anonymous).

I can’t understand if this is somehow possible. Thanks in advance for any help.

---

<div class="post-metadata">

**Author:** ![mpiggott](https://avatars.discourse-cdn.com/v4/letter/m/f0a364/32.png) [@mpiggott](https://community.sonatype.com/u/mpiggott)\
**Post date:** [July 8, 2024, 7:46pm UTC](https://community.sonatype.com/t/grant-privileges-based-on-ip/12835/2 "2024-07-08T19:46:42Z")

</div>

This isn’t something that Nexus supports, it may be possible to implement using a reverse proxy such as nginx or Apache httpd.
