How to restrict platform access to B2CORE IP addresses

Learn how to allow manager connections from B2CORE only from the B2BROKER IP range on MetaTrader 4, MetaTrader 5, and cTrader, using server firewall, platform firewall, and manager account whitelists

B2CORE connects to your trading platform with a manager account over a fixed set of IP addresses. Allowing manager access only from these addresses ensures that the manager credentials cannot be used from anywhere else, even if they are exposed.

All connections from B2CORE and B2COPY originate from the following range: 18.171.63.48–18.171.63.55 (18.171.63.48/29). Whitelist the entire range: the addresses within it are used interchangeably, and the address that serves your platform can change without prior notice.

Whitelisting levels

Access can be filtered at up to three levels. A connection is established only if every configured level permits it, so make sure the B2CORE range is allowed at each level your platform supports.

LevelWhat to allowWhere to configure
Server firewallInbound connections from the B2CORE range to the port used for the manager connectionWindows Firewall on the platform server, or the security group of your hosting provider
Platform firewallThe B2CORE range with the Permit always actionPlatform administrator: Security > Firewall in MetaTrader 5, IP Access list in MetaTrader 4
Manager accountThe B2CORE range in the IP whitelist of the manager account used by B2COREManager account settings on the platform, where the platform supports per-manager restrictions

In MetaTrader, the platform firewall rule must use the Permit always action. A rule with the Permit action can still be overridden by the automatic blocking that follows failed login attempts, and the B2CORE connection stops working without any changes on your side.

MetaTrader 5

To restrict access on MetaTrader 5:

On the platform server, add an inbound firewall rule that allows connections from 18.171.63.48–18.171.63.55 to the port specified in the Host field of your platform settings in B2CORE.

In the MetaTrader 5 Administrator, go to Security > Firewall and add a rule for the 18.171.63.48–18.171.63.55 range with the Permit always action.

Add a comment to the rule, for example B2CORE, so that the rule is not removed during future maintenance.

Open the settings of the manager account used by B2CORE and add the 18.171.63.48–18.171.63.55 range to its IP whitelist.

If the whitelist of this manager account is empty, connections are allowed from any address that the platform firewall permits.

MetaTrader 4

To restrict access on MetaTrader 4:

On the platform server, add an inbound firewall rule that allows connections from 18.171.63.48–18.171.63.55 to the port specified in the Host field of your platform settings in B2CORE.

In the MetaTrader 4 Administrator, open the IP Access list and add the 18.171.63.48–18.171.63.55 range with the Permit always action.

Open the settings of the manager account used by B2CORE and add the 18.171.63.48–18.171.63.55 range to its IP whitelist.

The IP whitelist of a MetaTrader 4 manager account accepts either a range or separate addresses, but not a range together with additional addresses. If you also need to allow another address, for example your own office, use a separate manager account for it.

cTrader

cTrader does not support per-manager IP restrictions. The whitelist is applied per environment at the hosting level and covers the Manager API and the Reporting API together.

  • If your cTrader server is hosted by Spotware, request the whitelisting of the 18.171.63.48–18.171.63.55 range for your environment from Spotware support.
  • If your cTrader server is hosted by you or by another provider, allow the range on the firewall of the host that serves the Manager API and Reporting API ports.

Before you apply the rules

Applying a restriction that does not include the full 18.171.63.48–18.171.63.55 range interrupts the connection between B2CORE and your platform: trading accounts stop being created and balance operations stop being processed. If you are unsure which port or manager account B2CORE uses, contact your account manager before you change the rules.

Last updated on

On this page