For AI agents: a documentation index is available at https://www.mongodb.com/docs/llms.txt — markdown versions of all pages are available by appending .md to any URL path.
Docs Menu

Configure IP Access List Entries

Note

This page applies to both Atlas Infinite and Atlas Core.

Atlas only allows client connections to the cluster from entries in the project's IP access list. Each entry is either a single IP address or a CIDR-notated range of addresses. For AWS clusters with one or more VPC Peering connections to the same AWS region, you can specify a Security Group associated with a peered VPC.

Before you add an entry to the IP access list, you must know the public IP address that you want to grant access to. Use an IP lookup tool, such as whatismyipaddress.com, to find the public IP address of the network you're connecting from.

If you connect from a virtual machine hosted on a cloud provider instead of your own network, use that provider's console to find the address:

Cloud Provider
Where to Find It

AWS

In the AWS EC2 console, select your instance, then check the Networking tab for the Public IPv4 address.

Google Cloud

In the Google Cloud console, go to the VM instances page. The External IP column shows the instance's public IP address.

Azure

In the Azure portal, select your virtual machine, click Networking, then check the IP configuration for the network interface.

Note

Public IP addresses for home and office networks can change over time. If you lose access to your cluster unexpectedly, verify that your current public IP address still matches an entry in the IP access list.

CIDR notation writes a range of IP addresses as a base address followed by a slash and a number, such as 192.168.1.0/24. The number specifies how many bits of the address are fixed as the network part, which determines how many addresses the range covers:

Notation
Addresses Covered
Example Use

/32

1 address

A single IP address, such as one client machine.

/24

256 addresses

A small office or home network.

/16

65,536 addresses

A large network block.

Note

The MongoDB Atlas Shared Responsibility Model defines the complementary duties of MongoDB and its customers in maintaining a secure and resilient data environment. Under this framework, MongoDB manages the security and operational integrity of the underlying platform, while customers are responsible for the configuration, management, and data policies of their specific deployments. For a detailed breakdown of ownership across security and operational excellence, see Shared Responsibility Model.

For Atlas clusters deployed on Google Cloud or Microsoft Azure, add the IP addresses of your Google Cloud or Azure services to Atlas project IP access list to grant those services access to the cluster.

The IP access list applies to all clusters in the project and can have up to 200 IP access list entries, with the following exception: projects with an existing sharded cluster created before August 25, 2017 can have up to 100 IP access list entries.

Atlas supports creating temporary IP access list entries that expire within a user-configurable 7-day period.

Note

To restrict access to MongoDB Atlas UI for specific IP addresses, configure the UI IP Access List for your Atlas organization. Although a standard IP Access List can't block access to the Atlas UI, the UI IP Access List lets you restrict access to your Atlas organization's management interface to only the trusted IP addresses or CIDR ranges you specify. You can also restrict sign-in to Atlas UI through your IdP authentication policies by using Atlas federated authentication.

When you create, delete, or change temporary and non-temporary IP access list entries, Atlas notifies you of these events in the project's Activity Feed. For example, if you modify the address of an IP access list entry, the Activity Feed reports the deletion of the old entry and the creation of the new entry.

To view the project's Activity Feed:

1
  1. If it's not already displayed, select the organization that contains your desired project from the Organizations menu in the navigation bar.

  2. If it's not already displayed, select your desired project from the Projects menu in the navigation bar.

  3. In the sidebar, click the icon next to Project Overview.

The Project Settings page displays.

2
  1. If it's not already displayed, select the organization that contains your desired project from the Organizations menu in the navigation bar.

  2. If it's not already displayed, select your desired project from the Projects menu in the navigation bar.

  3. In the sidebar, click Activity Feed under the Security header.

The Project Activity Feed page displays.

See also View All Activity.

Note

Activity Feed Considerations

  • Atlas does not report updates to an IP access list entry's comment in the Activity Feed.

  • When you modify the address of an IP access list entry, the Activity Feed reports two new activities: one for the deletion of the old entry and one for the creation of the new entry.

To manage IP Access List entries, you must have Project Owner or Project Network Access Manager access to the project.

Users with Organization Owner access must add themselves to the project as a Project Owner.

Select your interface to view the appropriate procedures.

Important

When you remove an entry from the IP access list, existing connections from the removed addresses may remain open for a variable amount of time. How much time passes before Atlas closes the connection depends on several factors, including:

  • how the connection was established

  • how the application or driver using the address behaves

  • which protocol (like TCP or UDP) the connection uses