Block addresses until a date
Deny an address until a due date with a dated network list entry and a firewall rule, then end the block with a write of the list.
You can block an address until a date of your choice from Azion Console, the Azion CLI, or the API. For example, an address that abused a login form can stay blocked for one day. The entry for that address in an ip_cidr network list carries the due date. One firewall rule denies every address in the list. The date alone never lifts the block: the address stays denied until a write of the list’s items drops its entry. To block an address with no end date, refer to Block requests by IP, ASN, or country.
Select the interface for this guide. Its prerequisites and every task on this page switch to that interface.
Prerequisites
- A workload bound to a firewall. The rule that denies the list goes on that firewall.
- Network Shield on for that firewall. It starts on in every firewall and stays on until someone turns it off.
- An account that can sign in to Azion Console.
Create a list with a dated entry
Only a list of the ip_cidr type, shown as IP/CIDR in Azion Console, accepts annotations on its items. An annotated item is refused with 22011 in an asn list and with 22015 in a countries list. A due date follows the address after a space. It is --LT in uppercase, then a UTC date and time in whole seconds that ends in Z, such as --LT2030-01-01T00:00:00Z. A comment starts with # and goes last on the line, after any due date. A line that starts with # is not a comment, and the API refuses it with 22005.
The list in this guide holds two items. 198.51.100.7 carries a due date and the comment #login abuse, while 192.0.2.10 carries neither. The undated item keeps the list writable after the date passes. A write in which every item is past due is refused with 22019 All Network Items Are Expired. For the annotation grammar, refer to Item annotations. For the fields of a list and its three types, refer to Network list fields and List types.
To create the list with the Azion CLI, write it to a file named network-list.json. Write the UTC date and time when the block should end in place of 2030-01-01T00:00:00Z:
Create the list from that file:
The output carries the ID of the list:
The list stores both items as the file writes them, due date and comment included. Keep the ID, because the rule refers to the list by it.
Create the rule that denies the listed addresses
The rule reads the list through the Network criterion with its matches operator. Its Deny (403 Forbidden) behavior refuses each client that matches. It denies both addresses for as long as their items stay stored in the list. A due date that passes does not change what the rule matches. For every criterion and behavior a rule takes, refer to Rules Engine for Firewall.
To create the deny rule with the Azion CLI, write it to a file named rule.json. Put the ID of the list in place of <network-list-id>, as a number with no quotes:
Create the rule from that file on the firewall bound to your workload. Put the ID of that firewall in place of <firewall-id>:
The output carries the ID of the rule:
The rule is active on the firewall, and it reads Blocked addresses by its ID.
With the rule in traffic, a request from either address receives 403. A rule you add can take from 6 minutes 29 seconds to 9 minutes 18 seconds to get there across Azion’s distributed infrastructure. Send a request from a listed address again until it answers 403.
Remove the entry after its due date
Azion reads a due date only when the items of a list are written, and each write drops the items already past due. An item whose date passes after the write stays stored and keeps matching. Giving the list another name does not remove the item either.
A write of the list’s items is what ends the block. Send it from the interface you use, or from a job of your own. That job can be a scheduled script, or the security information and event management (SIEM) system that flagged the address. Sent after each due date, the write drops every item past due by then.
The Azion CLI removes the dated entry with --remove-item, which matches the item exactly as the list stores it. To read the stored items, describe the list:
The Items row still lists the dated entry:
Given the address alone, --remove-item removes nothing, yet it prints the same line as a removal. Pass the entry exactly as the Items row shows it, with its due date and comment:
The output carries the ID of the list that changed:
The list holds 192.0.2.10 alone, and a second describe of the list reads that one item back.
Once the write reaches traffic, the rule no longer denies 198.51.100.7. A change to the items of a list takes 46 seconds to about 100 seconds to get there, less than a rule you add. Until it settles, answers can switch between the old items and the updated ones. Repeat a request from that address until the answers agree. To try a list and a rule against your own address first, refer to Network Shield quickstart.