Hi community members, happy Friday! In my end-of-week musings I'm trying to seek out best practices for hardening our SuiteCommerce instance in our Sandbox environment. We don't want search engines to be able to crawl it, and we don't want unauthorized visitors to access it. Preferably, we'd rather the rest of the world not even know it exists.
Here's what I've got so far: I've adjusted robots.txt to disallow all SE's from crawling the site, and have turned on the SC option "Password-protect the entire site."
But that doesn't seem like enough.
Typically when doing this for a normal website, I'll use web.config or .htaccess to restrict access by IP address (allow access only from these IP's, deny all others). I see in the Company Config there's an option for "IP Address Rules" - but that reads more like it's restricting Employee access from the Netsuite environment. I'm trying to restrict all users from the public-facing website.
Have any of you a method of doing this? Or is the "Password-protect the entire site" the best method available?
Thanks in advance!
-ben