Deny requests from a list of countries
Create a countries network list and a firewall rule that denies each request from those countries, in Azion Console, the Azion CLI, or the API.
You can deny every client in a list of countries from Azion Console, the Azion CLI, or the API. A countries network list names the countries. One firewall rule denies each client that Azion places in one of them. Use it when your application serves no one in those countries. Their requests then end at the firewall with 403. To deny one network instead of a whole country, refer to Deny requests from one autonomous system.
Select the interface you will use. The prerequisites and each task on this page follow that choice.
Prerequisites
- A workload bound to a firewall, which carries the rule in this guide.
- Network Shield on for that firewall. A firewall is created with Network Shield on unless you turn it off.
- Access to Azion Console.
Create the countries list
A countries list holds one item per country: its uppercase ISO 3166-1 alpha-2 code, such as BR or US. Azion Console selects each country by name and sends its code. The API refuses a lowercase code or a name, such as br or Brazil, with 22015 Invalid Country. The list keeps the countries type for as long as it exists. An item takes no due date and no comment. A country therefore stays denied until a write of the list’s items leaves it out. For every field and type of a list, refer to Network list fields and List types.
To create the list with the Azion CLI, pass the codes to --items, separated by commas:
The CLI answers with the list’s ID:
The list Blocked countries exists, and the rule names it by that ID.
Create the rule that denies the list
The rule compares each request’s client address with the countries list through the Network criterion. Its Deny (403 Forbidden) behavior refuses every match. The rule stores the ID of the list, not the countries in it. A country you add to the list or remove from it changes what the rule denies, with no edit to the rule. For every criterion and behavior a rule accepts, refer to Rules Engine for Firewall.
To create the rule with the Azion CLI, save it as rule.json. Write the ID of your list in place of <network-list-id>, as a number without quotes:
Then create the rule from the file. Put the ID of the firewall bound to your workload in place of <firewall-id>:
The CLI answers with the rule’s ID:
The firewall holds the rule, active, and the rule denies every country in Blocked countries.
Confirm that the rule denies a listed country
The rule in this guide has no criterion besides Network, so it denies clients in the listed countries on every path of the workload. Their requests end at the firewall, and the application never receives them. A rule you create can take 6 minutes 29 seconds to 9 minutes 18 seconds to reach traffic across Azion’s distributed infrastructure. Until it does, those clients still reach the application.
Once the rule reaches traffic, a client that Azion places in a listed country receives HTTP 403. The answer carries Azion’s default error page, headed Forbidden. For example, a list that holds BR denies a client in Brazil. A denied request receives this response:
The Your IP row shows the address that Azion placed in a listed country. A later change to the countries in the list can take 46 seconds to about 100 seconds to reach traffic. In that window, answers can alternate between the old countries and the updated ones. Repeat the request until the answers agree. For what a denied client receives, refer to Deny (403 Forbidden).
Azion takes the country of an address from databases that external suppliers provide. That country can be wrong for some addresses. The Azion Terms of Service state that access control by country is applied on a best-effort basis. The same terms name restriction by IP address as the way to obtain the best level of control.
A Request Uri criterion limits the rule to one path. To try the rule on one path before it covers the whole workload, refer to Guard one path with a network list.