Issue How to seucre a custom plesk login url?

thinkjarvis

Basic Pleskian
Server operating system version
Ubuntu 22.04.5 LTS
Plesk version and microupdate number
Plesk Obsidian Version 18.0.63 Update #4
I have a possible security issue when setting a custom plesk URL.

We've just moved to a new office and have a new IP address. The server is supposed to be blocked so only us and a few others can reach the Plesk login screen. 8443 is therefore restricted to our IP alopng with 22 and a few other vulnerable ports.

This particular server has a custom URL set in Plesk and I could access and log in to Plesk from the new IP address that is supposed to be blocked.

My question is - When you set a custom URL in plesk - Do port restrictions still work?
 
From your post it isn't entirely clear how you've restricted access to Plesk to certain IP addresses only. In case you've used a firewall to restrict access to port 8443, Plesk can still be access when using a custom URL. As a custom URL uses the default https port (443), instead of 8443. A better method might be to use the IP Access Restriction Management option in Tools & Settings to restrict access to Plesk to whitelisted IP's only.
 
Last edited:
Back
Top