Restrict an origin to Azion with Origin IP ACL
Turn on Origin IP ACL on a connector, and let your origin's firewall accept only the prefixes of the Azion Origin Shield list.
You restrict an origin to Azion’s addresses by turning on Origin IP ACL on its connector from Azion Console or the API, then allowing the Azion Origin Shield list at the origin’s firewall. To read that list from Azion Console, the Azion CLI, or the API, refer to Allow Azion’s IP ranges at your origin.
An origin on the public internet answers anyone who finds its address, so a client can reach it around the application and every protection in front of it. Origin IP ACL is part of Origin Shield on a connector of type http. It makes the Azion Origin Shield network list available to your account, with every IPv4 and IPv6 prefix that Azion’s infrastructure uses to connect to origins. Your origin’s firewall enforces the allowlist, not Azion.
- You turn on Origin Shield and Origin IP ACL on the connector.
- The
Azion Origin Shieldlist appears in your account. - Your origin’s firewall allows inbound traffic from each prefix of the list.
- Only after every prefix is allowed, the firewall denies every other source.
- A client that connects to the origin’s address directly is refused, while requests through your domain keep reaching the origin.
Prerequisites
- A connector of type
httpthat reaches your origin. Origin Shield applies to that type alone. To create one, refer to Connectors quickstart. - Access to the firewall that protects your origin server, where the allowlist goes.
- The View Network Lists permission, to read the list. For more information, refer to Network Lists.
- Access to Azion Console, for the Console procedure. Refer to Access Azion Console.
- A personal token and the ID of the connector, for the API procedure.
The examples use www.example.com for the domain the application serves. Replace it with yours.
Turn on Origin IP ACL on the connector
Origin Shield turns on at two levels. One switch enables Origin Shield on the connector, and inside it the Origin IP ACL switch stays off until you turn it on. Origin Shield and Load Balancer can both be on for the same connector.
To turn on Origin IP ACL in Azion Console:
Access Azion Console > Connectors, and select the connector that reaches your origin.
In Modules, turn on Origin Shield. The Origin IP ACL switch and the HMAC section appear.
Turn on Origin IP ACL.
The connector has Origin IP ACL on.
The connector has Origin IP ACL on, and the Azion Origin Shield list appears in your account once at least one connector has Origin IP ACL on. The switch reaches traffic over several minutes, and data centers apply it at different times.
Allow the list at your origin’s firewall
The allowlist filters on the source address of each connection, at layers 3 and 4, so it acts before your server reads a request. The list carries IPv6 prefixes for all of Azion’s data centers beside its IPv4 prefixes, and an allowlist with only the IPv4 prefixes refuses the connections Azion opens over IPv6.
Read the prefixes of the list as Find the Azion Origin Shield list describes. Then, to apply them at your origin:
In your origin’s firewall, allow inbound traffic from each IPv4 and IPv6 prefix of the list.
Deny inbound traffic from all other addresses. Make this change only after every prefix is allowed, or requests from Azion are refused until the allowlist is complete.
Only Azion’s infrastructure can connect to your origin. Traffic that reaches the origin without Azion, such as your own administrative access, is refused too unless you allow it separately.
Azion updates the list and emails every account with Origin Shield each time it changes. The servers behind an added prefix go into production 7 days after Azion publishes the list, so a job that reads the list on a schedule shorter than 7 days keeps your allowlist current. For that job, refer to Keep the allowlist current.
Confirm the origin refuses direct connections
The check compares a request through your domain with a connection to the origin’s own address.
To confirm the restriction:
The application answers as before, because the request reaches the origin from an Azion address.
From a host outside Azion, such as your own machine, send a request to the origin’s own address.
The origin’s firewall refuses the direct connection or lets it time out, while requests through www.example.com keep answering. Your origin accepts connections from Azion only.