# Ability to restrict agents by CIDR

**URL:** <https://forum.buildkite.community/t/ability-to-restrict-agents-by-cidr/913>\
**Category:** Features Requests\
**Created:** [February 10, 2020, 2:13am UTC](https://forum.buildkite.community/t/ability-to-restrict-agents-by-cidr/913 "2020-02-10T02:13:03Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![mtcmorris](https://sea2.discourse-cdn.com/flex016/user_avatar/forum.buildkite.community/mtcmorris/32/506_2.png) [@mtcmorris](https://forum.buildkite.community/u/mtcmorris)\
**Post date:** [February 10, 2020, 2:13am UTC](https://forum.buildkite.community/t/ability-to-restrict-agents-by-cidr/913/1 "2020-02-10T02:13:03Z")

</div>

We know the networks where all our agents should connect from.

Currently we can only restrict by who has access to the token which is difficult if a token was inadvertently leak. Ability to restrict agents by CIDR would give us a defence in depth control and reduce the importance of a buildkite agent access token
