Allow only the addresses in a list
Create a network list of allowed addresses and a firewall rule that denies every client outside it, in Azion Console, the Azion CLI, or the API.
You can let only the clients in a network list reach your application, from Azion Console, the Azion CLI, or the API. An ip_cidr list holds the addresses and ranges you allow. One firewall rule then denies every client whose address is not in it. Use this for what only known clients should reach, such as an internal tool or a test environment. To deny the clients in a list and let everyone else through, refer to Block requests by IP, ASN, or country.
Select the interface for this guide. Its prerequisites and every task on this page switch to that interface.
Prerequisites
- A workload bound to a firewall. The allowlist rule goes on that firewall.
- Network Shield on for that firewall. It starts on in every firewall and stays on until someone turns it off.
- The public IP address of each client that must keep access, your own included.
- An account that can sign in to Azion Console.
Create the list of allowed addresses
The allowlist is a list of the ip_cidr type, shown as IP/CIDR in Azion Console. Each of its items is one IPv4 or IPv6 address or range, such as 203.0.113.0/24 or 198.51.100.7. The rule compares the address of every client with these items and denies each address that matches none of them. For every field and type a list accepts, refer to Network list fields and List types.
To create the allowlist with the Azion CLI, write it to a file named network-list.json. Put your public IP address in place of <your-ip>:
Create the list from that file:
The output carries the ID of the list:
Keep that ID, because the rule refers to Allowed addresses by it.
Create the rule that denies every other address
A Rules Engine for Firewall rule can deny a request, but it has no behavior that admits one. A request that no rule stops goes on to the application. The allowlist rule therefore denies, and its Network criterion uses the does not match operator. That criterion is true for every client outside the list. For a client in the list it is false, so the rule runs nothing and the firewall goes on to its next rule.
To create the allowlist rule with the Azion CLI, write it to a file named rule.json. Put the ID of your list in place of <network-list-id>, as a number with no quotes:
Create the rule from that file on the firewall bound to your workload. Put the ID of that firewall in place of <firewall-id>:
The output carries the ID of the rule:
The rule is active on the firewall, and it reads Allowed addresses by its ID.
Confirm that only listed clients reach the application
The only criterion of the allowlist rule is Network. It therefore acts on each request the firewall receives, whatever its path. A rule you add can take from 6 minutes 29 seconds to 9 minutes 18 seconds to reach traffic across Azion’s distributed infrastructure. Until then, the firewall answers each request as it did before. Send the request again until its answer changes.
With the rule in traffic, a client whose address is outside the list receives HTTP 403 and Azion’s default error page, headed Forbidden. A request from such a client returns this response:
The Your IP row holds the address that the firewall compared with the allowlist. If the rule denies a client that must pass, add the address from that row to the list. A change to the items of a list reaches traffic in 46 seconds to about 100 seconds, sooner than a rule you add. Until it settles, answers can switch between the old items and the updated ones. Repeat the request until the answers agree. For the response a denied client gets, refer to Deny (403 Forbidden).
A client in the list passes the allowlist rule, and the application decides what it receives. An application that serves no content answers 204:
Being in the allowlist does not exempt a client from the other rules of the firewall. When a blocklist rule also matches that client, the blocklist rule denies it, in either order. To apply the allowlist to one path only, add a Request Uri criterion, ${request_uri} in the API, to the same block. For that rule, refer to Guard one path with a network list.