Troubleshooting AEM access issues with IP allowlisting

In Adobe Experience Manager (AEM), access to an environment can fail with a 403 – Not allowed error before the login page appears even when administrator permissions and configured allowlist entries appear correct. The issue occurs when the actual public egress IP address used by a device doesn’t match the IP addresses configured in the allowlist. To fix this issue, verify the public egress IP address used by each device and update the allowlist with the correct IP addresses.

Description description

Environment

Adobe Experience Manager (all versions) with IP allowlisting enabled for one or more environments, such as Author, Publish, Stage, or Production.

Issue/Symptoms

  • Unable to access an AEM environment and receive a 403 – Not allowed error before the login page appears.
  • The issue continues after confirming Administrator access and that the IP address is on the allowlist.
  • Access works from one device, such as a local machine, but not from other devices, such as virtual machines or cloud-hosted devices.

Cause

The common cause is a mismatch between the actual public egress IP address used by the client device and the IP addresses configured in the allowlist at the CDN or network edge layer. Administrator permissions in AEM do not override network-level IP restrictions.

Resolution resolution

Follow the steps below to resolve the issue.

  1. Determine the public egress IP address of each device that requires access. From the device, visit websites such as What Is My IP Address or ifconfig.me to identify the public IP address in use. For virtual machines or cloud-hosted devices, verify the public IP address used for outbound internet traffic instead of a private or internal IP address.
  2. Update the allowlist configuration by adding the correct public IP addresses for all devices that require access to the relevant AEM environment, such as Author or Publish. Verify that the allowlist applies to the correct environment and service.
  3. Remove outdated or duplicate IP addresses from the allowlist configuration.
  4. Wait a few minutes for the allowlist changes to propagate. Then retry access by using an incognito or private browser window to avoid cached authentication.
  5. Test access from each device and confirm successful access to the AEM environment.
  6. If access remains blocked, review available logs or error messages to identify the source IP address being blocked and update the allowlist with any additional required IP addresses.
recommendation-more-help
experience-cloud-kcs-help-kbarticles