<div dir="ltr"><div><div>Hi Stefano,<br><br><div class="gmail_extra"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div>we need to limit access to a given SP<span></span> to users within a given IP range.</div>


<div>We can only work on the IdP side.<br></div></blockquote></div><br></div><div class="gmail_extra">I&#39;m not an expert, so maybe someone else can chime in, but I think it would depend on your configuration. You can put IP restrictions in webserver and firewall software, but you can&#39;t do that if you use the IdP for other SPs that don&#39;t have this IP restriction. If you have a custom auth piece it looks like you can read about <a href="https://wiki.shibboleth.net/confluence/display/SHIB2/IdPAuthIP" target="_blank">https://wiki.shibboleth.net/confluence/display/SHIB2/IdPAuthIP</a>. Or perhaps attempt something more fancy/custom.<br>


</div><br></div>Taking a step back, how do you currently do authentication? And what does the SP expect to receive back from you (do they do any authorization or does the SP just assume if they get a reply they are good?).<br>
<br></div><div>Regards,<br>Ian<br></div></div>