Deny requests from one autonomous system
Deny every client of one network by its Autonomous System Number, with an asn network list and one firewall rule, in Azion Console, the CLI, or the API.
You can deny the requests of one autonomous system from Azion Console, the Azion CLI, or the API. An autonomous system is a network, and its Autonomous System Number (ASN) identifies it. An asn network list holds that number, and one firewall rule denies each client whose address belongs to the network. Use this rule when unwanted traffic comes from across one network, from more addresses than you can list. To deny by country instead, refer to Deny requests from a list of countries.
Select the interface you work in. The prerequisites and every task on this page switch to match it.
Prerequisites
- A workload bound to a firewall through its deployment. That firewall receives the rule you create in this guide.
- Network Shield turned on for that firewall. Network Shield is on by default when a firewall is created.
- Access to Azion Console.
Create the ASN list
An asn list holds one item per network: its Autonomous System Number, written as digits alone. Each item covers every address of its network, legitimate clients included. The API refuses an item that carries the AS prefix with 22011 Invalid ASN Number, so send 64496, not AS64496. An asn item also takes no annotation, which means no due date: a network stays in the list until a write of the list’s items leaves it out. Its type stays asn for the life of the list. For the fields of a list and the format of each type, refer to Network list fields and List types.
To create the list with the Azion CLI, run azion create network-list with the asn type:
The CLI prints the ID of the list it created:
The list Blocked networks holds 64496, and the rule refers to the list by that ID. To deny more networks, separate the numbers with commas inside --items.
Create the rule that denies the autonomous system
The rule compares the client address of each request with the asn list through the Network criterion. The criterion is true when that address belongs to a network in the list. The Deny (403 Forbidden) behavior then refuses the request. A rule holds the ID of its list, never a copy of the numbers. When you add an ASN to the list or remove one, the rule denies the updated set with no edit. For the criteria and behaviors that a rule can combine, refer to Rules Engine for Firewall.
azion create firewall-rule reads the rule from a JSON file, and the file refers to the list by its ID. To create the rule with the Azion CLI, save this body as rule.json. Put your list ID in place of <network-list-id>, as a bare number with no quotes:
Then create the rule from the file. Write the ID of the firewall bound to your workload in place of <firewall-id>:
The CLI prints the ID of the rule it created:
The firewall holds the rule, active, and the rule denies every client address in the autonomous system.
Confirm that the rule denies the autonomous system
The rule in this guide carries no criterion besides Network. It therefore denies the clients of a listed network on every path of the workload. The application never receives their requests. Expect the rule to reach traffic 6 minutes 29 seconds to 9 minutes 18 seconds after you create it. A workload bound shortly before can need several minutes for its first rule, and no duration is guaranteed. Until the rule reaches traffic, clients of the network still get through to the application.
After that, a client whose address belongs to a listed ASN receives HTTP 403 and Azion’s default error page, headed Forbidden. A request from an address in a listed network gets this response:
The Your IP row is the client address that the firewall compared with the list. Azion finds the ASN of an address in databases from external suppliers, and for some addresses that answer is inaccurate. The Azion Terms of Service state that access control works on a best-effort basis. For the best level of control, the same terms tell you to restrict access by IP address. For more information, refer to Terms of Service.
Once the rule is live, a change to the list’s items reaches traffic in 46 seconds to about 100 seconds. Meanwhile, one request can reflect the old items and the next one the updated items. Send the request again until the answers agree. For every propagation time, refer to Propagation. For the response that a denied client receives, refer to Deny (403 Forbidden).
To deny the network on one path only, add a Request Uri criterion to the same block. For the steps, refer to Guard one path with a network list.