# Securely expose Orthanc over the internet for C-STORE requests from authorized modalities only

**URL:** https://discourse.orthanc-server.org/t/securely-expose-orthanc-over-the-internet-for-c-store-requests-from-authorized-modalities-only/5749
**Category:** General
**Created:** [April 19, 2025, 1:26am UTC](https://discourse.orthanc-server.org/t/securely-expose-orthanc-over-the-internet-for-c-store-requests-from-authorized-modalities-only/5749 "2025-04-19T01:26:51Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![benjamin.golinvaux](https://discourse.orthanc-server.org/user_avatar/discourse.orthanc-server.org/benjamin.golinvaux/32/1508_2.png) [@benjamin.golinvaux](https://discourse.orthanc-server.org/u/benjamin.golinvaux)
#### Post date: [April 22, 2025, 9:24am UTC](https://discourse.orthanc-server.org/t/securely-expose-orthanc-over-the-internet-for-c-store-requests-from-authorized-modalities-only/5749/2 "2025-04-22T09:24:17Z")

</div>

Hello

Securely exposing DICOM requires DICOM TLS or a VPN/secure tunnel. The former is described [in the Orthanc Book](https://orthanc.uclouvain.be/book/faq/dicom-tls.html).

Regarding the filtering, if you don’t mind deleting the instances that have been stored by unauthorized entities, you could start from something like [this sample](https://github.com/orthanc-server/orthanc-setup-samples/blob/master/python-samples/filter-incoming-cstore-instance.py), but instead of using the remote AET, you could use the `RemoteIP` (see [the list of core metadata](https://orthanc.uclouvain.be/book/faq/features.html#core-metadata))

[This thread](https://discourse.orthanc-server.org/t/filtering-incoming-dicom-instances-using-metadata-with-python-plugin/2624/2) could also be of interest to you.

Another option is to perform the filtering in the Lua side, where it can prevent the DICOM to be stored altogether. At that stage, you cannot use metadata (they don’t exist yet), but the Lua callback supplies origin information:

- [Filtering incoming DICOM instances](https://orthanc.uclouvain.be/book/users/lua.html#filtering-incoming-dicom-instances)

- [Origin of the Instances](https://orthanc.uclouvain.be/book/users/lua.html#origin-of-the-instances) (contains the remote IP)

Hope this helps! Let us know how it goes…

---

_[View the full topic](https://discourse.orthanc-server.org/t/securely-expose-orthanc-over-the-internet-for-c-store-requests-from-authorized-modalities-only/5749)._
