# Azion CLI network-list

The Azion CLI `network-list` commands create, list, describe, update, and delete [network lists](/en/documentation/platform/firewall/network-shield/network-lists/). A network list is a named set of IP addresses and CIDR ranges, Autonomous System Numbers (ASNs), or countries, which a firewall rule matches the client of a request against. The options every command accepts, such as `--format`, `--out`, and `-y`, are on [Global options](/en/documentation/devtools/cli/globals/).

---

## Create

`azion create network-list` creates a network list with the name, type, and items you pass:

```bash
azion create network-list [flags]
```

| Flag       | Short | Type   | Default | Description                                                                                                                      |
| ---------- | ----- | ------ | ------- | -------------------------------------------------------------------------------------------------------------------------------- |
| `--active` | —     | string | —       | Turns the network list on (`true`) or off (`false`).                                                                             |
| `--file`   | —     | string | —       | Path to a JSON file with the attributes of the network list.                                                                     |
| `--items`  | —     | string | —       | **Required** unless `--file` is set. Items of the network list, separated by commas. Without it, the command asks for the items. |
| `--name`   | —     | string | —       | Name of the network list.                                                                                                        |
| `--type`   | —     | string | —       | Type of the items: `asn`, `countries`, or `ip_cidr`.                                                                             |

A `--type` value outside these three is refused:

```text
Error: Failed to create Network List: ["\"ipv4\" is not a valid choice."]
```

This command creates an active network list named `my-ip-list` with two CIDR ranges:

```bash
azion create network-list --name my-ip-list --type ip_cidr --items '192.0.2.0/24,198.51.100.7/32' --active true
```

The command prints the ID of the network list:

```text
Created Network List with ID 12365
```

---

## List

`azion list network-list` lists the network lists of your account, 50 to a page:

```bash
azion list network-list [flags]
```

| Flag          | Short | Type   | Default | Description                                                       |
| ------------- | ----- | ------ | ------- | ----------------------------------------------------------------- |
| `--details`   | —     | —      | —       | Adds the `TYPE` column to the `ID`, `NAME`, and `ACTIVE` columns. |
| `--filter`    | —     | string | —       | Name to filter the list by.                                       |
| `--order-by`  | —     | string | —       | Field to sort the list by.                                        |
| `--page`      | —     | int    | `1`     | Number of the page to return.                                     |
| `--page-size` | —     | int    | `50`    | Number of network lists on each page.                             |

This command lists the network lists of the account with their types:

```bash
azion list network-list --details
```

The command prints one row per network list. The list with ID `2` is the Tor exit node list that Azion provides to every account:

```text
ID     NAME                              ACTIVE  TYPE
2      Azion IP Tor Exit Nodes           true    ip_cidr
12364  my-allowed-countries              true    countries
12365  my-ip-list                        true    ip_cidr
12366  my-country-list                   true    countries
```

---

## Describe

`azion describe network-list` prints the type, the items, and the state of one network list:

```bash
azion describe network-list [flags]
```

| Flag                | Short | Type | Default | Description                         |
| ------------------- | ----- | ---- | ------- | ----------------------------------- |
| `--network-list-id` | —     | int  | —       | ID of the network list to describe. |

This command describes the network list with ID `12365`:

```bash
azion describe network-list --network-list-id 12365
```

The command prints the name, the type, the items, and the state of the network list:

```text
ID:              12365
Name:            my-ip-list
Type:            ip_cidr
Items:           ["192.0.2.0/24","198.51.100.7/32"]
Last Editor:     you@example.com
Last Modified:   "2026-01-01T12:00:00.710776Z"
Active:          true
```

With `--format json`, the command prints the full object: `active`, `created_at`, `id`, `is_versioned`, `items`, `last_editor`, `last_modified`, `name`, `type`, `version`, `version_id`, and `version_state`.

An ID that does not exist fails with this error:

```text
Error: Failed to describe Network List: The given ID or API's endpoint doesn't exist or isn't available. Check that the identifying information is correct
```

---

## Update

`azion update network-list` changes the name, the items, or the active state of a network list:

```bash
azion update network-list [flags]
```

| Flag                | Short | Type   | Default | Description                                                                                                 |
| ------------------- | ----- | ------ | ------- | ----------------------------------------------------------------------------------------------------------- |
| `--active`          | —     | string | —       | Turns the network list on (`true`) or off (`false`).                                                        |
| `--add-item`        | —     | string | —       | Items to add to the network list, separated by commas. The items already in the list stay.                  |
| `--file`            | —     | string | —       | Path to a JSON file with the attributes to change.                                                          |
| `--items`           | —     | string | —       | Items of the network list, separated by commas. They replace every item the list holds.                     |
| `--name`            | —     | string | —       | New name of the network list.                                                                               |
| `--network-list-id` | —     | int    | —       | **Required**, with `--file` too. ID of the network list to update. Without it, the command asks for the ID. |
| `--remove-item`     | —     | string | —       | Items to remove from the network list, separated by commas. The other items stay.                           |
| `--type`            | —     | string | —       | Type of the items: `asn`, `countries`, or `ip_cidr`.                                                        |

`--items` replaces the whole list, while `--add-item` and `--remove-item` change only the items they name. To keep the items a list holds, use `--add-item`.

This command adds the range `203.0.113.5/32` to the network list with ID `12365`:

```bash
azion update network-list --network-list-id 12365 --add-item '203.0.113.5/32'
```

The command prints the ID of the updated network list:

```text
Updated Network List with ID 12365
```

The list then holds `192.0.2.0/24`, `198.51.100.7/32`, and `203.0.113.5/32`. The same list updated with `--items '192.0.2.10/32'` holds `192.0.2.10/32` alone.

---

## Delete

`azion delete network-list` deletes a network list:

```bash
azion delete network-list [flags]
```

| Flag                | Short | Type | Default | Description                       |
| ------------------- | ----- | ---- | ------- | --------------------------------- |
| `--network-list-id` | —     | int  | —       | ID of the network list to delete. |

This command deletes the network list with ID `12366`:

```bash
azion delete network-list --network-list-id 12366 -y
```

The command confirms the deletion:

```text
Network List 12366 was successfully deleted
```

---

## Use a JSON file

`azion create network-list` and `azion update network-list` read the attributes of the network list from a JSON file with `--file`. The file carries `items` as an array of strings.

This file creates an active network list named `my-country-list` that holds two countries:

```json
{
  "name": "my-country-list",
  "type": "countries",
  "items": ["BR", "US"],
  "active": true
}
```

Pass the file to the create command:

```bash
azion create network-list --file nl-create.json
```

The command prints the ID of the network list:

```text
Created Network List with ID 12366
```

On update, the command does not read `"id"` from the file. Pass `--network-list-id` on the command line, or the command asks for the ID. Fields the file leaves out keep their values. This file renames the network list with ID `12366` and adds `PT` to its items:

```json
{
  "id": 12366,
  "name": "my-country-list-updated",
  "items": ["BR", "US", "PT"]
}
```

Pass the file and the ID to the update command:

```bash
azion update network-list --network-list-id 12366 --file nl-update.json
```

The command prints the ID of the updated network list:

```text
Updated Network List with ID 12366
```

---

## Related resources

- [Global options](/en/documentation/devtools/cli/globals.md): The options every command accepts, such as `--format`, `--out`, and `-y`.
- [Network Lists](/en/documentation/platform/firewall/network-shield/network-lists.md): The item format of each list type, the item annotations, and the API errors a list returns.
- [Azion CLI firewall-rule](/en/documentation/devtools/cli/resources/firewall-rule.md): The commands that create the firewall rules that match requests against a network list.
- [Azion CLI firewall](/en/documentation/devtools/cli/resources/firewall.md): The commands that turn on Network Shield, which the rules that match a network list need.
