IP-based access control for blocks, Twig templates, routes, menu items, and taxonomy-tagged content. Show or hide content based on the visitor's network using CIDR notation.

Overview

The Internal Network module provides comprehensive IP-based access control for Drupal. It enables conditional rendering of blocks, template content, routes, menu items, and
taxonomy-tagged content based on configurable IP ranges using standard CIDR notation.

Whether you need to show internal-only content to office users, restrict login pages to VPN networks, hide pre-decisional documents from the public, or create intranet sections on a
public site — this module provides the tools you need.

Features

Block Visibility Condition
- Show or hide any block based on the visitor's IP address
- Integrates with Drupal's standard block visibility system
- Per-block IP range overrides or use global configuration
- Works with any block type

Twig Extension
- is_internal_network() function for use in any Twig template
- Conditionally render content based on the visitor's network

{% if is_internal_network() %}

This content is only visible to internal users.

{% endif %}

Route Access Restriction
- Block access to any Drupal route based on the visitor's IP
- Choose between 403 Forbidden or redirect to homepage
- Works with reverse proxies (respects X-Forwarded-For headers)

Menu Link Hiding
- Menu items linking to restricted routes are automatically hidden
- JavaScript-based approach preserves full page caching
- No extra configuration — just restrict a route and the link hides itself

Taxonomy Term Restriction (New in 1.1.0)
- Tag content with a restricted taxonomy term to control visibility by IP
- Two modes per term: hard deny (403) or soft hide (JS-based, cache-friendly)
- Works at the node level, paragraph level, or both
- Per-term IP range overrides and configurable bypass roles
- Soft dependency on Taxonomy — all other features work without it

Global Configuration
- Central admin page for IP ranges, logging, test mode, and bypass roles
- Test mode for development without being on the internal network
- Configurable test header for IP spoofing in non-production environments

Developer API
- Service: internal_network.helper for programmatic IP checks
- Twig function with optional parameter overrides
- AJAX endpoint /internal-network/status for client-side network detection
- PHPUnit test suite

Use Cases

- Intranet content: Show internal announcements, tools, or staff resources only to office users
- Security hardening: Restrict login, registration, or password reset to internal networks
- Pre-decisional content: Tag draft documents with a restricted term — external visitors can't see them
- Per-section restrictions: Show a "Staff Resources" paragraph only to users on the internal network, while the rest of the page stays public
- Multi-network access: Apply different IP ranges per term — procurement content on one network, HR content on another
- Staged rollouts: Show new features to internal users before public release
- Development/staging access: Protect non-production environments

How It Works

1. IP Detection: Detects the visitor's IP address, respecting X-Forwarded-For headers for reverse proxy setups
2. CIDR Matching: Checks IP addresses against configured ranges using standard CIDR notation (e.g., 192.168.0.0/16, 10.0.0.0/8)
3. Cache-friendly: Route blocking runs before page cache. Menu and content hiding use JavaScript to preserve full page caching while personalizing the display
4. Logging: Optional logging of all access decisions for debugging and auditing

Post-Installation

Navigate to /admin/config/system/internal-network to configure:
- Internal IP ranges (CIDR notation, one per line)
- Route restriction: enable/disable, routes to restrict, action (deny or redirect)
- Taxonomy term restriction: bypass roles (default: administrator)
- Logging and test mode settings

For taxonomy term restriction, navigate to any term edit form and expand "Internal Network Restriction" to enable per-term IP access control.

Project information

Releases