Network Shield quickstart
Create a network list with your own IP address, deny it on one test path with a firewall rule, and confirm that the request is refused.
This guide instructs you through blocking your first request with a network list in Network Shield.
- Create a network list that holds your own public IP address.
- Deny that list on one test path with a firewall rule.
- Send a request to the test path and read the refusal.
Four objects take part in the block, and each one links to the next:
- A network list holds the addresses to match. In this guide, it holds your own public IP address.
- A rule in the Rules Engine of a firewall matches that list with the Network criterion and denies the request. A second criterion limits the rule to the
/network-shield-testpath, so the rest of your application keeps answering you. - The firewall carries the rule, and it must have Network Shield on. A firewall has Network Shield on by default.
- The workload that serves your application is bound to that firewall, so its requests pass through the rule.
A network list blocks nothing by itself. Until a rule on a firewall bound to a workload references it, the list matches no request.
Select an interface for this guide. The prerequisites and each stage switch to the interface you select.
Prerequisites
- An Azion account. To create one, refer to How to create an account on Azion.
- A workload that serves your application and is bound to a firewall. To bind one, refer to Bind a firewall to a workload.
- Network Shield on for that firewall, which is the default. To check the setting, refer to Set a firewall’s main settings.
- The Edit Network Lists and Edit Firewall permissions. For more information, refer to Network Lists.
- Your public IPv4 address, the one your requests to the workload come from.
- Access to Azion Console. To sign in, refer to How to access Azion Console.
Create a network list
A network list holds the entries that a rule matches, and its type fixes what kind of entry they are. The list in this stage has the ip_cidr type, IP/CIDR in Azion Console. It holds one item: your public IPv4 address with the /32 prefix, which covers that address alone. The type of a list never changes after creation.
To create the list in Azion Console:
Access Azion Console > Edge Libraries > Network Lists.
Select Network List.
In the General section, enter a Name. For example: network-shield-quickstart.
In the Network List Settings section, select IP/CIDR. The form opens with ASN selected.
In the List field, enter <your-ip>/32, with your public IPv4 address in place of <your-ip>.
Select Save.
Azion Console shows the message Your network list has been created. The list appears in Network Lists, with IP/CIDR in the List Type column.
Deny the list on a test path
A rule in Rules Engine for Firewall runs its behavior only when its criteria are true. The rule in this stage joins two criteria with and in one block, so both must be true. The Network criterion matches the addresses in your list, and a Request Uri criterion matches paths that start with /network-shield-test. The Deny (403 Forbidden) behavior then refuses the request.
The test path is how this guide tests a block without refusing real traffic. The rule denies only requests from your address to /network-shield-test, and it lets every other request through.
To create the rule in Azion Console:
Access Azion Console > Secure > Firewalls, and select the firewall.
Select Rule. The Create Rule drawer opens.
In the General section, enter a Name. For example: Deny my address on the test path.
In the Criteria section, select the Network variable and the matches operator.
If the variable reads Network - required Network Shield, the firewall has Network Shield off. The variable becomes selectable after you turn Network Shield on in Main Settings and save.
In the Select a Network dropdown, select the list you created. For example: network-shield-quickstart.
To add a condition that must also be true, select And.
In the added condition, select the Request Uri variable and the starts with operator, and enter /network-shield-test.
In the Behaviors section, select Deny (403 Forbidden).
Select Save.
Azion Console shows the message Rule successfully created. The rule appears in the Rules Engine tab, with Active in the Status column.
Verify that the request is denied
The check is the same whichever interface created the rule. Your workload answers on its workload domain, which ends in .map.azionedge.net. The commands write it as <your-workload-domain>.
A rule you add needs several minutes to take effect across Azion’s distributed infrastructure. Until then, the test path answers as any other path does. Wait, then send the request again. For more information, refer to How Firewall works.
Send a request to the test path. The -4 flag sends it over IPv4, the address family of the item in your list:
The firewall denies the request:
The body is Azion’s default error page, headed Forbidden. Its Your IP row shows the address that the firewall compared with the list, which is your own. No header names the firewall, the rule, or the list. The x-azion-request-id header identifies the request. To look up the request in the logs, refer to Real-Time Events.
Send the same request to another path of the workload:
The firewall lets the request through, and your application answers it:
Your application decides that status. An application that serves no content answers 204. What matters is that the response is not the 403 error page.
Network Shield now denies your address on /network-shield-test, and every other path still answers you.