# IP policies

[In this section](https://my.tuna.am/team_ip_policies) you can configure access policies for tunnels from specific IP addresses and subnets.

![team_ip_policies_1](/en/assets/images/team_ip_policies_1-b6efb1916fbb84bbbcc4e979cba39ceb.png)

tip

This section is available to the **Founder**, **Owners** and **Administrators**.

## Overview

If you want to be sure that all tunnels and gateways are accessible only from specific subnets, you can create team-wide IP policies and block or allow certain subnets by CIDR.

![team_ip_policies_2](/en/assets/images/team_ip_policies_2-3032d9646251b7e280198f20bd0fc49d.png)
