Block requests by IP, ASN, or country
Create a network list of IP addresses, ASNs, or countries and deny it in a firewall rule, from Azion Console, the Azion CLI, or the API.
You can block requests by IP address, Autonomous System Number (ASN), or country with Network Shield, from Azion Console, the Azion CLI, or the API.
The block takes two objects. A network list holds the entries to keep out. A rule in the Rules Engine of a firewall denies every request whose client the list covers. The list blocks nothing until a rule references it, and the rule acts only on a workload bound to its firewall.
Tor exit nodes already have a list that Azion maintains. To block them, refer to Block Tor exit nodes.
Select an interface. The prerequisites and each task on this page switch to it.
Prerequisites
- A firewall bound to the workload that serves your application. To bind one, refer to Bind a firewall to a workload, which covers both Workloads and the legacy Domains setting.
- Network Shield on for that firewall, which is the default for a firewall you create. To confirm it, refer to Set a firewall’s main settings.
- Edit Network Lists and Edit Firewall in your team permissions. For more information, refer to Network Lists.
- Access to Azion Console. To sign in, refer to How to access Azion Console.
Create the network list
Every item in a network list has the type of the list, and the type decides how many clients one item covers. Pick the type by what you want to keep out:
| To keep out | Type | Console label | Item format | Example |
|---|---|---|---|---|
| Specific addresses or ranges. | ip_cidr | IP/CIDR | An IPv4 or IPv6 address, with or without a prefix length. | 192.0.2.10, 198.51.100.0/24, 2001:db8::/32 |
| Every address in one autonomous system. | asn | ASN | The ASN, digits only. | 64496 |
| Every address located in one country. | countries | Countries | An ISO 3166-1 alpha-2 code, in two uppercase letters. | BR |
A countries or ASN item covers every client in that country or network, legitimate clients included. For how Azion places a client in a country or an ASN, refer to List matching.
The type never changes after you create the list, so a second kind of entry needs a second list. Exact duplicate items are removed without a warning. Equivalent notations are not duplicates, so 192.0.2.80 and 192.0.2.80/32 are both kept.
An ip_cidr item can also carry a --LT due date and a # comment. For the syntax, refer to Network Lists.
To create the list in Azion Console:
Access Azion Console > Edge Libraries > Network Lists.
Select Network List.
In the General section, enter a Name. For example: blocked-addresses. A rule’s Select a Network dropdown offers the list by this name.
In the Network List Settings section, select IP/CIDR, ASN, or Countries. ASN is selected when the form opens.
For IP/CIDR or ASN, enter one item per line in the List field. For example:
In this field, an ASN can also start with AS. For Countries, select one or more countries by name in the Countries field.
Select Save.
Azion Console confirms with Your network list has been created. The list appears in Network Lists, and its List Type column shows the type you selected.
Deny the list in a firewall rule
The rule compares the client IP address of each request with your list through the Network criterion, ${network} in the API. With the matches operator, is_in_list in the API, the criterion is true for a client in the list. The Deny (403 Forbidden) behavior, deny in the API, then refuses the request. The rule on this page has that one criterion, so it applies to every path of the workload.
Network Shield makes the Network criterion available on the firewall, while the behavior belongs to Firewall. To close the connection with no response instead of a 403, use Drop (Close Without Response), drop in the API. For every behavior a rule can run, refer to Rules Engine for Firewall.
To create the rule in Azion Console:
Access Azion Console > Secure > Firewalls, and select the firewall bound to your workload.
Select Rule to open the Create Rule drawer.
In the General section, enter a Name. For example: Deny blocked addresses.
In the General section, enter a Description.
In the Criteria section, set the variable to Network and the operator to matches. The condition then reads If Network matches, and the next field takes the list.
A variable that reads Network - required Network Shield means that Network Shield is off for the firewall. Turn Network Shield on in the Main Settings tab and select Save. The variable then becomes selectable.
Open the Select a Network dropdown and select your list. If the list does not exist yet, select Create Network List in the same dropdown, which opens the Create Network drawer.
In the Behaviors section, select Deny (403 Forbidden).
In the Status section, keep Active turned on.
Select Save.
Azion Console confirms with Rule successfully created. The Rules Engine tab lists the rule, and its Status column reads Active.
One list can back rules on many firewalls, and a change to its items changes what every one of those rules matches. While a rule references the list, you cannot delete the list (22018) or turn off Network Shield on the firewall (24005). To do either, delete or change the rule first.
Confirm the block
A rule you add takes several minutes to reach traffic across Azion’s distributed infrastructure. A new rule takes effect 6 minutes 29 seconds to 9 minutes 18 seconds after you create it. Until then, clients in the list still reach your application. For more information, refer to How Firewall works.
One request checks the rule, whichever interface created it. From a client that the list covers, send a request to your workload’s domain:
The firewall refuses the request with 403:
The response carries Azion’s default error page, headed Forbidden. The Your IP row holds the client address that the firewall checked against the list. The response names no firewall, rule, or list, and the x-azion-request-id header identifies the request in Real-Time Events.
A client outside the list receives your application’s response instead. A rule with Drop (Close Without Response) sends no HTTP response at all, so curl exits with an error:
To test a block on your own address and one path first, refer to Network Shield quickstart. If a listed client still reaches the application after that wait, refer to Troubleshoot Firewall.
The firewall refuses every request from the clients in your list, on every path of the workload.