> ## Documentation Index
> Fetch the complete documentation index at: https://docs.timetracker.in/llms.txt
> Use this file to discover all available pages before exploring further.

# IP restrictions

> Allow-list your office networks in TimeTracker so people can only clock in or track time from work. How address ranges work and what they cannot detect.

An **office network** rule checks the internet address a person's connection
comes from. If it matches a range you listed, they count as being at work.

This is the reliable check on a computer.

## What an office network rule is

Your office has a public internet address, or a range of them, given to you by
your internet provider. Everyone connecting through that office shares it.

You list those ranges. Anyone connecting from one of them passes. Anyone else
does not.

<Warning>
  **A range is the whole network, not one person.** Everyone on that Wi-Fi matches,
  including guests, contractors and anyone in the coffee shop downstairs sharing the
  same building connection.
</Warning>

## When to use it

* A fixed office where people work from desks.
* Anywhere people use laptops rather than phones – a laptop's reported *place* is
  often kilometres out, but its network address is exact.
* A stricter control than a geofence, because faking a network address is much
  harder than faking a GPS position.

## Where the settings are

Open a rule and find the **Office networks** card: *"Anyone connecting from one of
these counts as being at work."*

It has two parts – the address you are connecting from right now, and the list of
ranges.

## Your current address

The card at the top reads **"You're connecting from `<address>`"** with the note:

> If that looks like your office, add it. Remember this is the address of the
> whole network – anyone on the same Wi-Fi will match it too.

Click **Add this address** to add exactly that one address as a range.

<Tip>
  The fastest way to set this up correctly is to sit in the office you want to
  allow, open the rule, and click **Add this address**.
</Tip>

### Two things this card may say instead

| Message                                            | What it means                                                                                                                                  |
| -------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- |
| **We couldn't read your address**                  | *"Location rules need the server to see where a request comes from. Until that works, any rule you write here will stop everyone."*            |
| **This server isn't reporting real addresses yet** | *"We see you as `<address>`, which is an internal address rather than your office's. Every person would look the same to a rule built on it."* |

Both mean network rules are not usable yet and need a hosting change. Places
still work – only network rules are affected.

## Adding a range

Click **Add address range**. Each row has:

| Field                | Placeholder      | Notes                                       |
| -------------------- | ---------------- | ------------------------------------------- |
| **Name**             | `Office`         | Optional label so you know which site it is |
| **Address or range** | `203.0.113.0/24` | The address, or a range in CIDR form        |

Up to **50** ranges per rule.

### Single address or range

| What you type    | What it means                                |
| ---------------- | -------------------------------------------- |
| `203.0.113.7`    | Exactly that one address                     |
| `203.0.113.0/24` | 256 addresses – a typical small office block |
| `2001:db8::/64`  | An IPv6 network                              |

Type an address with no `/` and it becomes an exact single-address rule.

### The live hint

Under each range you see how many addresses it covers – **1 address**, **256
addresses**, **16,777,216 addresses**.

<Warning>
  Read that number. If it says millions, you have written a range far wider than
  your office and you are allowing most of the internet.
</Warning>

Two other hints appear:

| Hint                                                                                    | Meaning                                                                        |
| --------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------ |
| **Not a valid address or range**                                                        | The text cannot be read as an address                                          |
| **This pins one device, and modern phones change that part often – use /64 or shorter** | An IPv6 range narrower than `/64`, which will break as phones rotate addresses |

## IPv4 and IPv6

Both work. A few details worth knowing:

| Rule               | Behaviour                                                      |
| ------------------ | -------------------------------------------------------------- |
| Mixed families     | An IPv4 rule never matches an IPv6 connection, and the reverse |
| Leading zeros      | `010.0.0.1` is rejected as ambiguous – write `10.0.0.1`        |
| Ports and brackets | Stripped automatically                                         |
| IPv6 prefixes      | Use `/64` or shorter. Phones rotate the part below that.       |

If your office has both IPv4 and IPv6, **add both**. A person on IPv6 will not
match your IPv4 range.

## Saving

The sticky bar at the bottom of the page saves the whole rule at once. Save
errors name the exact problem:

| Error                                          |
| ---------------------------------------------- |
| *"`<range>`" is not a valid address or range.* |
| *A rule can hold at most 50 address ranges.*   |

## Example

Northwind Studio's office is on `203.0.113.0/24`.

<Steps>
  <Step title="Maya sits in the studio">
    She opens the `Studio` rule.
  </Step>

  <Step title="She reads her own address">
    The card says **You're connecting from 203.0.113.42**.
  </Step>

  <Step title="She asks IT for the range">
    IT confirms the whole office is `203.0.113.0/24`.
  </Step>

  <Step title="She adds it">
    Name `Studio`, range `203.0.113.0/24`. The hint reads **256 addresses**.
  </Step>

  <Step title="She adds the IPv6 range too">
    Their provider also gives an IPv6 `/64`. Without it, anyone on IPv6 would be
    stopped.
  </Step>

  <Step title="She saves and watches">
    A week in Watching confirms nobody in the studio is caught.
  </Step>
</Steps>

Ana Ferreira working from home connects from a different address, so she does not
match. That is the point of the rule.

## What an IP check cannot detect

Be honest with your team about all of these.

| It cannot tell                     | Why                                                                                          |
| ---------------------------------- | -------------------------------------------------------------------------------------------- |
| **Whether someone is using a VPN** | A VPN just changes the address you see. If it presents the office address, the check passes. |
| **Who a person is on the network** | An address identifies the network, not a person. Everyone on that Wi-Fi matches.             |
| **A remote desktop**               | Someone at home controlling an office machine looks exactly like someone in the office.      |
| **A guest on your Wi-Fi**          | They match your office range like anyone else.                                               |

<Note>
  There is **no VPN detection** anywhere in TimeTracker. If you need to stop VPN use,
  that belongs on your network, not in this product.
</Note>

## The gap after someone leaves

A check stays good for the interval you set – 5, 15, 30 or 60 minutes – plus a
short allowance for patchy Wi-Fi. Somebody who passes a check and then walks out
can keep working until it expires.

Shorten the interval if that matters. It costs more checks and slightly more
interruption.

## Combining with places

In **The rule** card, **Someone counts as here when they are**:

| Option                              | What passes                                             |
| ----------------------------------- | ------------------------------------------------------- |
| **On an office network**            | The network alone                                       |
| **At one of the places**            | The place alone                                         |
| **Both the network and the place**  | Both must pass. Strictest.                              |
| **Either the network or the place** | Either is enough. Best for a mixed desk-and-field team. |

**Either** is the usual choice when some people are on laptops in the office and
others are on phones at client sites.

## Permissions

| Action                      | Capability        | Roles        |
| --------------------------- | ----------------- | ------------ |
| Add and edit address ranges | `location.manage` | Owner, Admin |

## Common questions

<AccordionGroup>
  <Accordion title="What address do I put in?">
    Your office's **public** address range, from whoever runs your network. Not
    `192.168.x.x` or `10.x.x.x` – those are internal and identical in every
    office in the world.
  </Accordion>

  <Accordion title="My office address changes. What then?">
    Ask your provider for a static address, or use a range wide enough to cover
    what they hand you. A rule built on an address that changes will stop people
    at random.
  </Accordion>

  <Accordion title="Can someone get around it with a VPN?">
    Yes, if the VPN puts them on your office network. TimeTracker cannot detect a
    VPN. Network rules make casual working-from-anywhere obvious, not impossible.
  </Accordion>

  <Accordion title="Why is my IPv6 range rejected as too narrow?">
    Anything narrower than `/64` pins one device. Modern phones change that part of
    their address regularly, so a narrow rule stops working within hours.
  </Accordion>

  <Accordion title="How many ranges can I add?">
    Up to 50 per rule. That is enough for a lot of offices.
  </Accordion>

  <Accordion title="Do people on the office guest Wi-Fi pass?">
    If the guest network shares your public address, yes. Ask IT whether guest
    traffic leaves on a different address.
  </Accordion>
</AccordionGroup>

## Troubleshooting

**Everyone is stopped.** Your rule requires a network but has no ranges, or the
ranges are wrong. Sit in the office and compare the **You're connecting from**
card against what you typed.

**Some people are stopped and others are not, in the same office.** Almost always
IPv6. Some machines use it, some do not. Add both families.

**The card says it cannot read your address.** Network rules need your hosting to
pass the real address through. Places still work in the meantime.

**The card shows an internal address.** Same cause. Every person looks identical
to a rule built on it, so do not build one until this is fixed.

## Related guides

<CardGroup cols={2}>
  <Card title="Location rules overview" icon="map-pin" href="/location-rules/overview">
    The concept and what it cannot see.
  </Card>

  <Card title="Create a location rule" icon="plus" href="/location-rules/create-a-policy">
    The full end-to-end walkthrough.
  </Card>

  <Card title="GPS restrictions" icon="location-dot" href="/location-rules/gps-restrictions">
    The other kind of check.
  </Card>

  <Card title="Activity log" icon="clock-rotate-left" href="/location-rules/activity-log">
    See which address each check reported.
  </Card>

  <Card title="Location permissions" icon="shield" href="/location-rules/location-permissions">
    Who can manage rules.
  </Card>

  <Card title="Time Clock" icon="fingerprint" href="/time-clock/overview">
    The most common thing a rule limits.
  </Card>
</CardGroup>
