# Allow Azion's IP ranges at your origin

You can read Azion's IP ranges from Azion Console, [Azion CLI](/en/documentation/devtools/cli/), or the API, and allow only them at your origin. To allow or deny client addresses in an Azion firewall rule instead, refer to [Block requests by IP, ASN, or country](/en/documentation/guides/application-security/bots-and-network/blocklists-ip-addresses-edge/).

When your application runs behind Azion, requests reach your origin from Azion's distributed infrastructure, not from end users. A [firewall](/en/documentation/platform/firewall/) filters the requests that pass through Azion. An origin that accepts connections only from Azion's addresses also refuses the requests that try to reach it around that firewall.

Azion publishes those addresses as `Azion Origin Shield`, a [network list](/en/documentation/platform/firewall/network-shield/network-lists/) of every IPv4 and IPv6 prefix that Azion's infrastructure uses to connect to origins. Azion maintains the list, and accounts with [Origin Shield](/en/documentation/platform/connectors/#origin-shield) receive it. In [Network Shield](/en/documentation/platform/firewall/#network-shield), a firewall rule matches a network list. This list works outside Azion: your origin's own firewall reads its prefixes, and no Azion rule takes part.

---

Select an interface. The prerequisites and the steps that find the list switch to it.

## Prerequisites

- Origin Shield active on your account. Origin Shield activates when Origin IP ACL is enabled for at least one connector in your account. For more information, refer to [Origin Shield](/en/documentation/platform/connectors/#origin-shield).
- The **View Network Lists** permission, which lets you view network lists without changing them. For more information, refer to [Network Lists](/en/documentation/platform/firewall/network-shield/network-lists/#permissions).
- Access to the firewall that protects your origin server, where the allowlist goes.

**Console**

- Access to Azion Console. To sign in, refer to [How to access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).

**CLI**

- [Azion CLI](/en/documentation/devtools/cli/), installed and authorized. The commands on this page match Azion CLI 4.23.0.

**API**

- A personal token and `curl`. To create a token, refer to [Personal Tokens](/en/documentation/fundamentals/personal-tokens/).

---

## Find the Azion Origin Shield list

The `Azion Origin Shield` list appears only in accounts with Origin Shield, beside the network lists you create. It is an *IP/CIDR* list, so each of its entries is one IPv4 or IPv6 prefix.

**Console**

To find the list in Azion Console:

1. **Open the Network Lists page**

   Access [Azion Console](https://console.azion.com/) > **Edge Libraries** > **Network Lists**.

2. **Open the Azion Origin Shield list**

   Select the list named `Azion Origin Shield`. When the account holds many lists, the **Name** filter narrows the table.

3. **Copy the prefixes**

   In the **List** field, copy every line. Each line holds one prefix.

You have the prefixes that your origin's firewall allows in [Allow the ranges at your origin](#allow-the-ranges-at-your-origin).

**CLI**

To find the list with Azion CLI:

1. **List the network lists**

   Print every network list in the account, Azion-maintained lists included:

   ```bash
   azion list network-list
   ```

2. **Record the ID of the list**

   The command prints a table with the `ID`, `NAME`, and `ACTIVE` columns. Record the `ID` in the row whose `NAME` is `Azion Origin Shield`. The table shows 50 lists per page, and `--page` selects another page.

3. **Read the list**

   Replace `<network-list-id>` with that ID:

   ```bash
   azion describe network-list --network-list-id <network-list-id>
   ```

4. **Copy the prefixes**

   The command prints one field of the list per line. The `Items` line holds the prefixes as a JSON array of strings.

You have the prefixes that your origin's firewall allows in [Allow the ranges at your origin](#allow-the-ranges-at-your-origin). For a script, add `--format json`, which prints the list as a JSON object with the prefixes in `items`.

**API**

To find the list, send two `GET` requests to `/v4/workspace/network_lists`:

1. **Search the lists by name**

   Replace `[TOKEN VALUE]` with your personal token:

   ```bash
   curl "https://api.azion.com/v4/workspace/network_lists?name=Azion%20Origin%20Shield" \
     -H "Authorization: Token [TOKEN VALUE]" \
     -H "Accept: application/json"
   ```

2. **Record the ID of the list**

   The call answers `200`. Each entry of `results` carries the `id`, `name`, and `type` of a list, without its items. Record the `id` of the entry whose `name` is `Azion Origin Shield`.

   The `name` filter ignores case and matches part of a name, so a list of yours with the same words in its name also appears.

3. **Read the list**

   Replace `<network-list-id>` with that ID:

   ```bash
   curl https://api.azion.com/v4/workspace/network_lists/<network-list-id> \
     -H "Authorization: Token [TOKEN VALUE]" \
     -H "Accept: application/json"
   ```

4. **Copy the prefixes**

   The call answers `200` with the list in a `data` object. Its `items` array holds the prefixes, one string per prefix.

   To receive one address family at a time, add `?ipv4=true` or `?ipv6=true` to the read. Each returns only the items of that family.

You have the prefixes that your origin's firewall allows in [Allow the ranges at your origin](#allow-the-ranges-at-your-origin).

---

## Allow the ranges at your origin

Your origin's firewall enforces this allowlist, not an Azion firewall rule. It filters on the source address of each connection, at layers 3 and 4, so only Azion's servers can connect to the origin. The list carries IPv6 prefixes for all of Azion's data centers beside its IPv4 prefixes. The allowlist must accept both address families and hold every entry of the list.

To restrict your origin to Azion's ranges:

1. **Allow every prefix in the list**

   In your origin's firewall, allow inbound traffic from each IPv4 and IPv6 prefix you copied.

2. **Deny every other source**

   Deny inbound traffic from all other addresses. Make this change only after every prefix is allowed, or requests from Azion are refused until the allowlist is complete.

Only Azion's infrastructure can connect to your origin, and a client that connects to the origin's address directly is blocked. Traffic that reaches the origin without Azion, such as your own administrative access, is blocked too unless you allow it separately.

Use the same prefixes wherever your origin's configuration names Azion's addresses, for example the Nginx `set_real_ip_from` directive, or a cloud firewall such as AWS ELB.

---

## Keep the allowlist current

Azion updates the prefixes of `Azion Origin Shield`, and the list can change often. The allowlist at your origin is a copy, and keeping it aligned with the list is your responsibility. Azion emails accounts with Origin Shield each time the list changes, and the servers behind the prefixes it adds go into production 7 days after it publishes the list. For more information on the announcement and the change history, refer to [Origin Shield](/en/documentation/platform/connectors/#origin-shield) and to the Origin Shield entry of the [Terms of Service](/en/documentation/agreements/tos/).

To automate the update, run this read on a schedule and replace the allowlist at your origin with the prefixes it returns. Replace `[TOKEN VALUE]` with your personal token and `<network-list-id>` with the ID of the `Azion Origin Shield` list:

```bash
curl https://api.azion.com/v4/workspace/network_lists/<network-list-id> \
  -H "Authorization: Token [TOKEN VALUE]" \
  -H "Accept: application/json"
```

The call answers `200`, and `data.items` holds the prefixes of the list. A schedule shorter than 7 days picks up each added prefix before its servers go into production. With Azion CLI, `azion describe network-list --network-list-id <network-list-id> --format json` prints the same list, with the prefixes in `items`.

---

## Next steps

- [Network Lists](/en/documentation/platform/firewall/network-shield/network-lists.md#azion-maintained-lists): The lists Azion maintains, and the fields and API calls that every network list shares.
- [List matching](/en/documentation/platform/firewall/network-shield/list-matching.md#azion-maintained-lists): How a firewall rule matches a network list, and how the lists Azion maintains differ from yours.
- [Firewall best practices](/en/documentation/platform/firewall/best-practices.md#network-shield): Why a rule references the list Azion maintains instead of a copy of its items.
- [Origin Shield](/en/documentation/platform/connectors.md#origin-shield): How Origin Shield activates, how Azion announces a change to the list, and where its history shows.
