---
name: azion-allow-only-the-addresses-in-a-list
description: >-
  Create a network list of allowed addresses and a firewall rule that denies every client outside it, in Azion Console, the Azion CLI, or the API.
---

# Allow only the addresses in a list

You can let only the clients in a [network list](/en/documentation/platform/firewall/network-shield/network-lists/) reach your application, from Azion Console, the [Azion CLI](/en/documentation/devtools/cli/), or the API. An `ip_cidr` list holds the addresses and ranges you allow. One [firewall](/en/documentation/platform/firewall/) rule then denies every client whose address is not in it. Use this for what only known clients should reach, such as an internal tool or a test environment. To deny the clients in a list and let everyone else through, refer to [Block requests by IP, ASN, or country](/en/documentation/guides/application-security/bots-and-network/blocklists-ip-addresses-edge/).

---

Select the interface for this guide. Its prerequisites and every task on this page switch to that interface.

## Prerequisites

- A [workload](/en/documentation/platform/workloads/) bound to a firewall. The allowlist rule goes on that firewall.
- [Network Shield](/en/documentation/platform/firewall/#network-shield) on for that firewall. It starts on in every firewall and stays on until someone turns it off.
- The public IP address of each client that must keep access, your own included.

**Console**

- An account that can sign in to [Azion Console](https://console.azion.com/).

**CLI**

- The Azion CLI, installed and authenticated with a [personal token](/en/documentation/fundamentals/personal-tokens/).
- The ID of the firewall that your workload is bound to.

**API**

- A [personal token](/en/documentation/fundamentals/personal-tokens/). Each request in this guide sends it in place of `[TOKEN VALUE]`.
- The ID of the firewall that your workload is bound to.

---

## Create the list of allowed addresses

The allowlist is a list of the `ip_cidr` type, shown as *IP/CIDR* in Azion Console. Each of its items is one IPv4 or IPv6 address or range, such as `203.0.113.0/24` or `198.51.100.7`. The rule compares the address of every client with these items and denies each address that matches none of them. For every field and type a list accepts, refer to [Network list fields](/en/documentation/platform/firewall/network-shield/network-lists/#network-list-fields) and [List types](/en/documentation/platform/firewall/network-shield/network-lists/#list-types).

> **Caution**
>
> Once the rule exists, every address missing from the list is denied, yours included, on each request the firewall receives. Put your own public IP address in the list before you create the rule. Also add your team, the monitors that check whether the application is available, and every partner integration that calls it.

**Console**

To create the allowlist in Azion Console:

1. **Open the Network Lists page**

   Access [Azion Console](https://console.azion.com/) > **Edge Libraries** > **Network Lists**.

2. **Select Network List**

3. **Name the list**

   In the **General** section, enter a **Name**. For example: `Allowed addresses`.

4. **Select the IP/CIDR type**

   In the **Network List Settings** section, select *IP/CIDR*. When the form opens, *ASN* is the selected type.

5. **Enter the allowed addresses**

   In the **List** field, enter one address or range per line. Write your public IP address in place of `<your-ip>`:

   ```text
   203.0.113.0/24
   198.51.100.7
   <your-ip>
   ```

6. **Save the list**

   Select **Save**.

Azion Console confirms with the message `Your network list has been created`. In **Network Lists**, the **List Type** column of the list reads *IP/CIDR*.

**CLI**

To create the allowlist with the Azion CLI, write it to a file named `network-list.json`. Put your public IP address in place of `<your-ip>`:

```json
{
  "name": "Allowed addresses",
  "type": "ip_cidr",
  "items": ["203.0.113.0/24", "198.51.100.7", "<your-ip>"],
  "active": true
}
```

Create the list from that file:

```bash
azion create network-list --file network-list.json
```

The output carries the ID of the list:

```text
Created Network List with ID <network-list-id>
```

Keep that ID, because the rule refers to `Allowed addresses` by it.

**API**

To create the allowlist with the API, send a `POST` request to `/v4/workspace/network_lists`. Put your personal token in place of `[TOKEN VALUE]` and your public IP address in place of `<your-ip>`:

```bash
curl -X POST https://api.azion.com/v4/workspace/network_lists \
  -H "Authorization: Token [TOKEN VALUE]" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{"name":"Allowed addresses","type":"ip_cidr","items":["203.0.113.0/24","198.51.100.7","<your-ip>"]}'
```

The API answers `201`. Its `state` of `executed` says the list was stored at once:

```json
{
  "state": "executed",
  "data": {
    "id": <network-list-id>,
    "name": "Allowed addresses",
    "type": "ip_cidr",
    "items": ["203.0.113.0/24", "198.51.100.7", "<your-ip>"],
    "last_editor": "<your-email>",
    "last_modified": "2026-01-01T12:00:00.000000Z",
    "created_at": "2026-01-01T12:00:00.000000Z",
    "active": true,
    "version_id": null,
    "version_state": null,
    "is_versioned": false,
    "version": null
  }
}
```

Keep the value of `data.id`. The rule sends it as a number.

---

## Create the rule that denies every other address

A [Rules Engine for Firewall](/en/documentation/platform/firewall/rules-engine/) rule can deny a request, but it has no behavior that admits one. A request that no rule stops goes on to the application. The allowlist rule therefore denies, and its *Network* criterion uses the *does not match* operator. That criterion is true for every client outside the list. For a client in the list it is false, so the rule runs nothing and the firewall goes on to its next rule.

**Console**

To create the allowlist rule in Azion Console:

1. **Open the firewall bound to your workload**

   Access [Azion Console](https://console.azion.com/) > **Secure** > **Firewalls**, and select the firewall.

2. **Select the Rules Engine tab**

3. **Select Rule**

   Azion Console opens the **Create Rule** drawer.

4. **Name the rule**

   In the **General** section, enter a **Name**. For example: `Allow only listed addresses`.

5. **Set the Network criterion**

   In the **Criteria** section, select the *Network* variable and the *does not match* operator.

   A variable that reads *Network - required Network Shield* means that Network Shield is off on this firewall. Turn it on in **Main Settings** > **Modules** and save the firewall, and the variable becomes selectable.

6. **Select the allowlist**

   In the **Select a Network** dropdown, select `Allowed addresses`.

7. **Add the Deny behavior**

   In the **Behaviors** section, select *Deny (403 Forbidden)*.

8. **Save the rule**

   Select **Save**.

Azion Console confirms with the message `Rule successfully created`. In the **Rules Engine** tab, the **Status** column of the rule reads *Active*.

**CLI**

To create the allowlist rule with the Azion CLI, write it to a file named `rule.json`. Put the ID of your list in place of `<network-list-id>`, as a number with no quotes:

```json
{
  "name": "Allow only listed addresses",
  "active": true,
  "criteria": [
    [
      { "variable": "${network}", "conditional": "if", "operator": "is_not_in_list", "argument": <network-list-id> }
    ]
  ],
  "behaviors": [
    { "type": "deny" }
  ]
}
```

Create the rule from that file on the firewall bound to your workload. Put the ID of that firewall in place of `<firewall-id>`:

```bash
azion create firewall-rule --firewall-id <firewall-id> --file rule.json
```

The output carries the ID of the rule:

```text
Created Firewall Rule with ID <rule-id>
```

The rule is active on the firewall, and it reads `Allowed addresses` by its ID.

**API**

To create the allowlist rule with the API, send a `POST` request to `/v4/workspace/firewalls/{firewall_id}/request_rules`. Write the ID of the firewall bound to your workload in place of `<firewall-id>`. Put `data.id` from the list response in place of `<network-list-id>`, as a number with no quotes:

```bash
curl -X POST https://api.azion.com/v4/workspace/firewalls/<firewall-id>/request_rules \
  -H "Authorization: Token [TOKEN VALUE]" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{
  "name": "Allow only listed addresses",
  "active": true,
  "criteria": [
    [
      { "variable": "${network}", "conditional": "if", "operator": "is_not_in_list", "argument": <network-list-id> }
    ]
  ],
  "behaviors": [
    { "type": "deny" }
  ]
}'
```

The API answers `202`, with a `state` of `pending`. Its `data` object returns the rule as the firewall stores it, with the rule's `id`, an empty `description`, and an `order`. That `order` is the position of the rule among the rules of the firewall.

> **Note**
>
> The JSON body of the CLI and the API holds one block with one criterion, so that criterion opens with `if`. In that body, `${network}` names the *Network* criterion, `is_not_in_list` its *does not match* operator, and `deny` the *Deny (403 Forbidden)* behavior. The `argument` is the list ID as a JSON integer. The same ID in quotes is refused with `25042 Invalid Operator Argument Type`. A firewall with Network Shield off refuses the rule with `25047 Missing Required Modules`. For how criteria join inside a block, refer to [Criteria](/en/documentation/platform/firewall/rules-engine/#criteria). For the operators and errors of the *Network* criterion, refer to [The Network criterion](/en/documentation/platform/firewall/network-shield/network-lists/#the-network-criterion).

---

## Confirm that only listed clients reach the application

The only criterion of the allowlist rule is *Network*. It therefore acts on each request the firewall receives, whatever its path. A rule you add can take from 6 minutes 29 seconds to 9 minutes 18 seconds to reach traffic across Azion's distributed infrastructure. Until then, the firewall answers each request as it did before. Send the request again until its answer changes.

With the rule in traffic, a client whose address is outside the list receives `HTTP 403` and Azion's default error page, headed **Forbidden**. A request from such a client returns this response:

```text
$ curl -i https://<your-workload-domain>/
HTTP/2 403
server: nginx
date: Thu, 01 Jan 2026 12:00:00 GMT
content-type: text/html; charset=utf-8
x-content-type-options: nosniff
x-azion-request-id: <request-id>
x-azion-edge-location: <edge-location>
alt-svc: h3=":443"; ma=86400

<title>Azion - Default error page</title>
...
<h1 class="error-header__title">Forbidden</h1>
...
Your IP         192.0.2.44
Request ID      <request-id>
Status Code     403
Edge Location   <edge-location>
```

The `Your IP` row holds the address that the firewall compared with the allowlist. If the rule denies a client that must pass, add the address from that row to the list. A change to the items of a list reaches traffic in 46 seconds to about 100 seconds, sooner than a rule you add. Until it settles, answers can switch between the old items and the updated ones. Repeat the request until the answers agree. For the response a denied client gets, refer to [Deny (403 Forbidden)](/en/documentation/platform/firewall/rules-engine/#deny-403-forbidden).

A client in the list passes the allowlist rule, and the application decides what it receives. An application that serves no content answers `204`:

```text
$ curl -i https://<your-workload-domain>/
HTTP/2 204
server: nginx
date: Thu, 01 Jan 2026 12:00:00 GMT
x-azion-request-id: <request-id>
x-azion-edge-location: <edge-location>
alt-svc: h3=":443"; ma=86400
```

Being in the allowlist does not exempt a client from the other rules of the firewall. When a blocklist rule also matches that client, the blocklist rule denies it, in either order. To apply the allowlist to one path only, add a *Request Uri* criterion, `${request_uri}` in the API, to the same block. For that rule, refer to [Guard one path with a network list](/en/documentation/guides/application-security/bots-and-network/guard-one-path/).

---

## Next steps

- [Guard one path with a network list](/en/documentation/guides/application-security/bots-and-network/guard-one-path.md): Chain a Request Uri criterion in the same block, so a list rule covers one path and leaves the others open.
- [Network Lists](/en/documentation/platform/firewall/network-shield/network-lists.md): Each list type and item format, and every error that a list or a Network criterion returns.
- [How Firewall works](/en/documentation/platform/firewall/how-it-works.md#network-shield): Its Network Shield section explains how the operator turns one list into a blocklist or an allowlist.
- [Block requests by IP, ASN, or country](/en/documentation/guides/application-security/bots-and-network/blocklists-ip-addresses-edge.md): Build a list of addresses, networks, or countries to deny, and apply it to a firewall.
- [Troubleshoot Firewall](/en/documentation/platform/firewall/troubleshooting.md#network-shield): Its Network Shield section covers a legitimate client that a list rule refuses.
- [Firewall guides and tutorials](/en/documentation/platform/firewall/guides.md): Every guide for a firewall, with the other network list configurations among them.
