# ip address not allowed

`TNL_IP_POLICY_DENIED`

the public url's IP policy blocked this connection before any request reached the local service.

the IP policy denied this visitor before the local service

```text
+--[ where it stopped ]----------------------------------------+
|                                                              |
|  visitor                                                     |
|     |                                                        |
|     v                                                        |
|  tnl server                                                  |
|     |                                                        |
|     x  IP policy denied                                      |
|  local service (not contacted)                               |
|                                                              |
+--------------------------------------------------------------+
```

## what happened

- the visitor's current public IP address is outside the public url's allowed addresses
- IP addresses can change when a visitor changes networks or uses a VPN

## if you are visiting

- ask the public URL owner to allow your current IP address

## if you run tnl

- check `--allow-ip` and the public url's IP policy
- only use `--allow-all-ips` if the local service should be available to everyone

help: https://tnl.dev/e/ip-policy-denied
