Skip to main content
Some data sources — especially production databases and warehouses — only accept connections from approved IP addresses. Modus connects to your data sources from a fixed set of AWS NAT gateway egress IP addresses, which you can add to your firewall, security group, or database IP allowlist.

When you need this

You only need an allowlist if your data source restricts inbound network access. If Modus can already reach your instance, you can skip this. Common cases:
  • A cloud database with a security group or firewall (AWS RDS, Google Cloud SQL, Azure).
  • A warehouse with network policies (Snowflake, Amazon Redshift).
  • A self-hosted database behind a corporate firewall.

Modus’s egress IPs

Allowlist all of the following addresses — connections can originate from any of them across availability zones:
If your firewall requires a range, use the /32 CIDR shown above (a single host). Questions? Contact support@getmodus.com.

Add the IPs to your allowlist

Add each IP above as a /32 entry (a single host) to your data source’s inbound rules. Where to add them depends on your platform: Once the IPs are allowlisted, return to your integration guide to finish connecting.