Action Needed For Customers Who Self-Host Blackbaud CRM And Blackbaud Internet Solutions 7962

Action Needed For Customers Who Self-Host Blackbaud CRM And Blackbaud Internet Solutions

Published
On October 5 between 10 and 11 p.m. Eastern, Blackbaud will make a change to enhance the security of the Blackbaud Payment Serviceā„¢ that requires your attention. This change will impact the IP addresses associated with Blackbaud Payment Serviceā„¢, and updates are required for self-hosted customers to avoid disrupting your payment processing.

If your organization self-hosts Blackbaud applications ā€“ such as Blackbaud NetCommunityā„¢, Blackbaud Internet Solutionsā„¢, Blackbaud CRMā„¢, or Raiser's Edgeā„¢ ā€“ and uses Internet Protocol (IP) address-based firewall rules, you must allow all traffic from the IP addresses used by Section.IO below. They are a third-party service utilized by Blackbaud for networking purposes. The following CIDRs (IP ranges) must be allowed:
.
207.120.32.0/20 (207.120.32.0 - 207.120.47.255)
209.160.100.0/22 (209.160.100.0 - 209.160.103.255)

Allowing these new IP addresses will avoid a disruption in your payment processing service.

If your Blackbaud applications are all hosted by Blackbaud, no action is required. Additionally, self-hosted customers who use hostname-based firewall rules do not need to take action.

For more information, please review Knowledgebase article KB 50865. If you have any questions, please contact Customer Support.

Leave a Comment

2 Comments

Hi Kathryn, can you please update the notice to include when on October 5th this change will occur? We've provided similar feedback to our BBPS, Support, and Success contacts at Blackbaud. Thanks!

Done! It's On October 5 between 10 and 11 p.m. Eastern.

All Blackbaud applications, self-hosted or otherwise, initiate a connection to BBPS, never the other way around. BBPS and Section IO will never need inbound rules at the firewall.

Instead, the instructions should have stated that firewalls must allow traffic to these IPs, not from them. This corresponds to an outbound firewall rule.

Cheers,

Glen Kendell, CISSP

President and CEO | Concourse Hosting

Mobile: 206-399-3510

Schedule: https://calendly.com/glenkendell

Share: