Redirector preferences

Path to function: Preferences > Redirector

On this page, optionally specify IP addresses that are permitted to bypass authentication via the redirector. If a user from a permitted IP address follows a redirector link, they are automatically directed to the requested content for IP authentication without needing to authenticate through single sign-on. (See How the redirector works.)

This feature enables users in a designated bypass zone, such as a library on campus, to go directly to the resources they request. Users located outside the zone, such as students working from home, are prompted to authenticate through OpenAthens. By using bypass with the redirector, you don’t need to create separate access routes for on-site and off-site users.

User follows redirector link

Location recognised


Location not recognised


Pass directly to resource
for IP authentication


Authenticate through OpenAthens
(permissions assessed,
stats recorded)

 

Access

Bypass works with any resource that has an access URL. (Resources lacking an access URL are indicated by an no-access-url-icon.png icon in your catalogue.)

If your domain has sub-organisations, you can optionally configure different IP addresses for different sub-organisations. This is useful if the sub-organisations are geographically dispersed and/or have different requirements for IP authentication.

You can also exclude specific resources from bypass. If you exclude a resource, users will always have to authenticate into that resource through OpenAthens regardless of their IP address. This setting is available only to domain owners.

When a user bypasses authentication based on their IP address, their request does not go through the OpenAthens authentication point. This has the following consequences:

Administrator permissions

If you have the Owner role, you can configure bypass for the whole domain and for sub-organisations. You can also specify individual resources to which bypass does not apply.

If you’re an organisation administrator, you can configure bypass only for the organisation(s) that you administer. You cannot exclude resources from bypass.

Specify permitted IP addresses

  1. Log into the Compass admin area as an administrator. Domain owners can configure bypass across the whole domain. Organisation administrators can configure bypass only for the organisation(s) they administer.

  2. (Optional.) To configure bypass for a specific sub-organisation, switch to the required sub-organisation before you begin. (If you’re an administrator for only one sub-organisation, your sub-organisation will be selected by default.)

  3. Go to Preferences > Redirector.

    Redirector preferences page. Under the heading 'Bypass authentication' is a large text field labeled 'IP addresses', which is currently empty. At the top of the page is a 'Save preferences' button.
  4. In the IP addresses field, enter each IP address from which users can bypass authentication. To enter multiple IP addresses, type each one on a new line. For example:

    123.3.23.12
    123.3.23.*
    123.3.22-23.*
    
  5. Press Save preferences.

To specify an IP range, use a wildcard (e.g. 123.3.23.*). You can include wildcards only in the last two octets of the address.

See also How to enter IP ranges when IT tells you something weird.

We do not support CIDR notation for writing IP addresses.

Exclude resources from bypass (domain owners only)

If required, you can exclude specific resources from bypass. Users will always have to authenticate into those resources through OpenAthens, regardless of their IP address. This feature is useful if you use restrictive mode, if a resource doesn’t permit IP-based authentication, or if you want all transfers to the resource to be recorded in statistics.

To exclude resources from bypass, you must be a domain owner. Exclusions apply across the whole domain and can’t be configured for individual sub-organisations.

  1. Log in to the Compass admin area as a domain owner.

  2. Go to Preferences > Redirector.

    Redirector preferences page. The 'IP addresses' field contains a short list of addresses. Following this, under the heading 'Do not apply to these resources, is a drop-down control labeled 'Add a resource'. At the top of the page is a 'Save preferences' button.
  3. Under Do not apply to these resources, click Add a resource. A search field opens.

    Search field displayed as an overlay beneath the 'Add a resource' control. The field contains the default text 'Type to start searching'. Below the field is a 'Loading' message.
  4. Start typing the name of the resource you want to exclude. Select the required resource from the list of search results.

    Search field contains the search query 'cambridge'. Following this, search results displayed in an overlay suggest a resource named 'Cambridge Core'.
  5. The selected resource is added to a list below. Press Save preferences to finish.

    The resource 'Cambridge Core' is now shown in a list following the 'Add a resource' control. At the top of the page is a 'Save preferences' button.

Remove a resource from the excluded list

  1. Log in to the Compass admin area as a domain owner.

  2. Go to Preferences > Redirector.

  3. Hover over the resource in the list. A Remove button appears.

    List of excluded resources under the heading 'Do not apply to these resources'. A resource called 'Cambridge Core' displays a 'Remove' button.
  4. Pres Remove.

  5. Press Save preferences to confirm your changes.

Anything to watch out for?

When users are passed directly to a resource through bypass, they do not pass though the OpenAthens authentication point. This means no statistics are recorded. It also means that restrictive mode (if used) will not apply.

Locations covered by redirector IP addresses rely on a resource's IP authentication for access. You need to take care to match the ranges you specify with what your resources permit.

  • If you specify a range of addresses that is too big - i.e. includes addresses that are not IP authenticated by your resources - then users may find themselves in a location where they cannot gain access

  • If you specify a range of addresses that is too small - i.e. does not cover all the addresses that are IP authenticated by your resources - then users may find themselves asked for OpenAthens credentials unexpectedly

Changes here are affected by the cache times of two separate components, so could take as much as 14 hours to become live (though they will usually be faster).

See also