---
name: azion-deny-requests-from-one-autonomous-system
description: >-
  Deny every client of one network by its Autonomous System Number, with an asn network list and one firewall rule, in Azion Console, the CLI, or the API.
---

# Deny requests from one autonomous system

You can deny the requests of one autonomous system from Azion Console, the [Azion CLI](/en/documentation/devtools/cli/), or the API. An autonomous system is a network, and its Autonomous System Number (ASN) identifies it. An `asn` [network list](/en/documentation/platform/firewall/network-shield/network-lists/) holds that number, and one [firewall](/en/documentation/platform/firewall/) rule denies each client whose address belongs to the network. Use this rule when unwanted traffic comes from across one network, from more addresses than you can list. To deny by country instead, refer to [Deny requests from a list of countries](/en/documentation/guides/application-security/bots-and-network/deny-countries/).

---

Select the interface you work in. The prerequisites and every task on this page switch to match it.

## Prerequisites

- A [workload](/en/documentation/platform/workloads/) bound to a firewall through its deployment. That firewall receives the rule you create in this guide.
- [Network Shield](/en/documentation/platform/firewall/#network-shield) turned on for that firewall. Network Shield is on by default when a firewall is created.

**Console**

- Access to [Azion Console](https://console.azion.com/).

**CLI**

- The Azion CLI, installed and configured with a [personal token](/en/documentation/fundamentals/personal-tokens/).
- The ID of the firewall that your workload is bound to.

**API**

- A [personal token](/en/documentation/fundamentals/personal-tokens/). Each request in this guide carries it in place of `[TOKEN VALUE]`.
- The ID of the firewall that your workload is bound to.

---

## Create the ASN list

An `asn` list holds one item per network: its Autonomous System Number, written as digits alone. Each item covers every address of its network, legitimate clients included. The API refuses an item that carries the `AS` prefix with `22011 Invalid ASN Number`, so send `64496`, not `AS64496`. An `asn` item also takes no annotation, which means no due date: a network stays in the list until a write of the list's items leaves it out. Its type stays `asn` for the life of the list. For the fields of a list and the format of each type, refer to [Network list fields](/en/documentation/platform/firewall/network-shield/network-lists/#network-list-fields) and [List types](/en/documentation/platform/firewall/network-shield/network-lists/#list-types).

**Console**

To create the list in Azion Console:

1. **Open the Network Lists page**

   Access [Azion Console](https://console.azion.com/) > **Edge Libraries** > **Network Lists**.

2. **Select Network List**

3. **Name the list**

   In the **General** section, enter a **Name**. For example: `Blocked networks`.

4. **Keep the ASN type**

   In the **Network List Settings** section, keep *ASN* as the type. The form opens with this type already chosen.

5. **Enter the ASN**

   In the **List** field, enter `64496`. To deny more networks, enter one ASN per line.

6. **Save the list**

   Select **Save**.

Azion Console confirms with the message `Your network list has been created`. The list appears in **Network Lists**, and its **List Type** column reads *ASN*.

**CLI**

To create the list with the Azion CLI, run `azion create network-list` with the `asn` type:

```bash
azion create network-list --name "Blocked networks" --type asn --items "64496"
```

The CLI prints the ID of the list it created:

```text
Created Network List with ID <network-list-id>
```

The list `Blocked networks` holds `64496`, and the rule refers to the list by that ID. To deny more networks, separate the numbers with commas inside `--items`.

**API**

To create the list with the API, send its body to `/v4/workspace/network_lists` in a `POST` request. Replace `[TOKEN VALUE]` with your personal token:

```bash
curl -X POST https://api.azion.com/v4/workspace/network_lists \
  -H "Authorization: Token [TOKEN VALUE]" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{"name":"Blocked networks","type":"asn","items":["64496"]}'
```

The API answers `201`. Its `state` of `executed` tells you that the list is stored already. This excerpt of the response keeps the fields that the rule depends on:

```json
{
  "state": "executed",
  "data": {
    "id": <network-list-id>,
    "name": "Blocked networks",
    "type": "asn",
    "items": ["64496"],
    ...
    "active": true,
    ...
  }
}
```

The list exists, and its `data.id` is the ID that the rule refers to. To deny more networks, send one string per ASN in `items`.

---

## Create the rule that denies the autonomous system

The rule compares the client address of each request with the `asn` list through the *Network* criterion. The criterion is true when that address belongs to a network in the list. The *Deny (403 Forbidden)* behavior then refuses the request. A rule holds the ID of its list, never a copy of the numbers. When you add an ASN to the list or remove one, the rule denies the updated set with no edit. For the criteria and behaviors that a rule can combine, refer to [Rules Engine for Firewall](/en/documentation/platform/firewall/rules-engine/#criteria).

**Console**

To create the rule in Azion Console:

1. **Open the firewall bound to your workload**

   Access [Azion Console](https://console.azion.com/) > **Secure** > **Firewalls**. Select the firewall in the list.

2. **Select the Rules Engine tab**

3. **Select Rule**

   The **Create Rule** drawer opens.

4. **Name the rule**

   In the **General** section, enter a **Name**. For example: `Deny one autonomous system`.

5. **Set the Network criterion**

   In the **Criteria** section, select *Network* as the variable and *matches* as the operator.

   The variable reads *Network - required Network Shield* while Network Shield is off for this firewall. In that case, turn on **Network Shield** in **Main Settings** > **Modules** and select **Save**. The variable is selectable after the save.

6. **Select the list**

   In the **Select a Network** dropdown, select `Blocked networks`, the name you gave the list.

7. **Add the Deny behavior**

   In the **Behaviors** section, select the *Deny (403 Forbidden)* behavior.

8. **Save the rule**

   Select **Save**.

Azion Console confirms with the message `Rule successfully created`. The rule appears in the **Rules Engine** tab, with *Active* in its **Status** column.

**CLI**

`azion create firewall-rule` reads the rule from a JSON file, and the file refers to the list by its ID. To create the rule with the Azion CLI, save this body as `rule.json`. Put your list ID in place of `<network-list-id>`, as a bare number with no quotes:

```json
{
  "name": "Deny one autonomous system",
  "active": true,
  "criteria": [
    [
      { "variable": "${network}", "conditional": "if", "operator": "is_in_list", "argument": <network-list-id> }
    ]
  ],
  "behaviors": [
    { "type": "deny" }
  ]
}
```

Then create the rule from the file. Write the ID of the firewall bound to your workload in place of `<firewall-id>`:

```bash
azion create firewall-rule --firewall-id <firewall-id> --file rule.json
```

The CLI prints the ID of the rule it created:

```text
Created Firewall Rule with ID <rule-id>
```

The firewall holds the rule, active, and the rule denies every client address in the autonomous system.

**API**

To create the rule with the API, send its body to `/v4/workspace/firewalls/{firewall_id}/request_rules` in a `POST` request. Write the ID of the firewall bound to your workload in place of `<firewall-id>`. Replace `<network-list-id>` with the `data.id` of the list response, a bare number with no quotes:

```bash
curl -X POST https://api.azion.com/v4/workspace/firewalls/<firewall-id>/request_rules \
  -H "Authorization: Token [TOKEN VALUE]" \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{
  "name": "Deny one autonomous system",
  "active": true,
  "criteria": [
    [
      { "variable": "${network}", "conditional": "if", "operator": "is_in_list", "argument": <network-list-id> }
    ]
  ],
  "behaviors": [
    { "type": "deny" }
  ]
}'
```

The API answers `202`, with the rule as the firewall stored it:

```json
{
  "state": "pending",
  "data": {
    "id": <rule-id>,
    "name": "Deny one autonomous system",
    "active": true,
    "criteria": [[{ "conditional": "if", "variable": "${network}", "operator": "is_in_list", "argument": <network-list-id> }]],
    "behaviors": [{ "type": "deny" }],
    "description": "",
    "order": 0
  }
}
```

The firewall holds the rule. The platform adds two fields that the request did not send: an empty `description` and `order`. `order` gives the place of the rule among the firewall's rules and starts at `0`. On a firewall that holds rules already, it is higher.

> **Note**
>
> The rule body for the CLI and the API holds one criteria block with one criterion, and its `conditional` is `if`. In Azion Console terms, `${network}` is the *Network* criterion, `is_in_list` is *matches*, and `deny` is *Deny (403 Forbidden)*. A firewall with Network Shield off refuses the rule with `25047 Missing Required Modules`. A list ID in quotes, sent as a string, is refused with `25042 Invalid Operator Argument Type`. For the operators of this criterion and the errors it returns, refer to [The Network criterion](/en/documentation/platform/firewall/network-shield/network-lists/#the-network-criterion).

---

## Confirm that the rule denies the autonomous system

The rule in this guide carries no criterion besides *Network*. It therefore denies the clients of a listed network on every path of the workload. The application never receives their requests. Expect the rule to reach traffic 6 minutes 29 seconds to 9 minutes 18 seconds after you create it. A workload bound shortly before can need several minutes for its first rule, and no duration is guaranteed. Until the rule reaches traffic, clients of the network still get through to the application.

After that, a client whose address belongs to a listed ASN receives `HTTP 403` and Azion's default error page, headed **Forbidden**. A request from an address in a listed network gets this response:

```text
$ curl -i https://<your-workload-domain>/
HTTP/2 403
server: nginx
date: Thu, 01 Jan 2026 12:00:00 GMT
content-type: text/html; charset=utf-8
x-content-type-options: nosniff
x-azion-request-id: <request-id>
x-azion-edge-location: <edge-location>
alt-svc: h3=":443"; ma=86400

<title>Azion - Default error page</title>
...
<h1 class="error-header__title">Forbidden</h1>
...
Your IP         <your-ip>
Request ID      <request-id>
Status Code     403
Edge Location   <edge-location>
```

The `Your IP` row is the client address that the firewall compared with the list. Azion finds the ASN of an address in databases from external suppliers, and for some addresses that answer is inaccurate. The Azion Terms of Service state that access control works on a best-effort basis. For the best level of control, the same terms tell you to restrict access by IP address. For more information, refer to [Terms of Service](/en/documentation/agreements/tos/).

Once the rule is live, a change to the list's items reaches traffic in 46 seconds to about 100 seconds. Meanwhile, one request can reflect the old items and the next one the updated items. Send the request again until the answers agree. For every propagation time, refer to [Propagation](/en/documentation/platform/firewall/how-it-works/#propagation). For the response that a denied client receives, refer to [Deny (403 Forbidden)](/en/documentation/platform/firewall/rules-engine/#deny-403-forbidden).

To deny the network on one path only, add a *Request Uri* criterion to the same block. For the steps, refer to [Guard one path with a network list](/en/documentation/guides/application-security/bots-and-network/guard-one-path/).

---

## Next steps

- [Guard one path with a network list](/en/documentation/guides/application-security/bots-and-network/guard-one-path.md): Add a path criterion to the deny rule, so that the network loses one path and keeps the rest.
- [Block requests by IP, ASN, or country](/en/documentation/guides/application-security/bots-and-network/blocklists-ip-addresses-edge.md): Build a list of each type for real traffic, and apply each list to a firewall.
- [Network Lists](/en/documentation/platform/firewall/network-shield/network-lists.md): The item format of each list type, and every error that a list or a Network criterion returns.
- [How Firewall works](/en/documentation/platform/firewall/how-it-works.md#network-shield): Its Network Shield section explains how the Network criterion matches a client address with a list.
- [Firewall guides and tutorials](/en/documentation/platform/firewall/guides.md): The other configurations built on network lists, and every other guide for a firewall.
