Allow Azion's IP ranges at your origin
Find the Azion Origin Shield network list in Azion Console, the CLI, or the API, and let your origin accept traffic from its prefixes alone.
You can read Azion’s IP ranges from Azion Console, Azion CLI, or the API, and allow only them at your origin. To allow or deny client addresses in an Azion firewall rule instead, refer to Block requests by IP, ASN, or country.
When your application runs behind Azion, requests reach your origin from Azion’s distributed infrastructure, not from end users. A firewall filters the requests that pass through Azion. An origin that accepts connections only from Azion’s addresses also refuses the requests that try to reach it around that firewall.
Azion publishes those addresses as Azion Origin Shield, a network list of every IPv4 and IPv6 prefix that Azion’s infrastructure uses to connect to origins. Azion maintains the list, and accounts with Origin Shield receive it. In Network Shield, a firewall rule matches a network list. This list works outside Azion: your origin’s own firewall reads its prefixes, and no Azion rule takes part.
Select an interface. The prerequisites and the steps that find the list switch to it.
Prerequisites
- Origin Shield active on your account. Origin Shield activates when Origin IP ACL is enabled for at least one connector in your account. For more information, refer to Origin Shield.
- The View Network Lists permission, which lets you view network lists without changing them. For more information, refer to Network Lists.
- Access to the firewall that protects your origin server, where the allowlist goes.
- Access to Azion Console. To sign in, refer to How to access Azion Console.
Find the Azion Origin Shield list
The Azion Origin Shield list appears only in accounts with Origin Shield, beside the network lists you create. It is an IP/CIDR list, so each of its entries is one IPv4 or IPv6 prefix.
To find the list in Azion Console:
Access Azion Console > Edge Libraries > Network Lists.
Select the list named Azion Origin Shield. When the account holds many lists, the Name filter narrows the table.
In the List field, copy every line. Each line holds one prefix.
You have the prefixes that your origin’s firewall allows in Allow the ranges at your origin.
Allow the ranges at your origin
Your origin’s firewall enforces this allowlist, not an Azion firewall rule. It filters on the source address of each connection, at layers 3 and 4, so only Azion’s servers can connect to the origin. The list carries IPv6 prefixes for all of Azion’s data centers beside its IPv4 prefixes. The allowlist must accept both address families and hold every entry of the list.
To restrict your origin to Azion’s ranges:
In your origin’s firewall, allow inbound traffic from each IPv4 and IPv6 prefix you copied.
Deny inbound traffic from all other addresses. Make this change only after every prefix is allowed, or requests from Azion are refused until the allowlist is complete.
Only Azion’s infrastructure can connect to your origin, and a client that connects to the origin’s address directly is blocked. Traffic that reaches the origin without Azion, such as your own administrative access, is blocked too unless you allow it separately.
Use the same prefixes wherever your origin’s configuration names Azion’s addresses, for example the Nginx set_real_ip_from directive, or a cloud firewall such as AWS ELB.
Keep the allowlist current
Azion updates the prefixes of Azion Origin Shield, and the list can change often. The allowlist at your origin is a copy, and keeping it aligned with the list is your responsibility. Azion emails accounts with Origin Shield each time the list changes, and the servers behind the prefixes it adds go into production 7 days after it publishes the list. For more information on the announcement and the change history, refer to Origin Shield and to the Origin Shield entry of the Terms of Service.
To automate the update, run this read on a schedule and replace the allowlist at your origin with the prefixes it returns. Replace [TOKEN VALUE] with your personal token and <network-list-id> with the ID of the Azion Origin Shield list:
The call answers 200, and data.items holds the prefixes of the list. A schedule shorter than 7 days picks up each added prefix before its servers go into production. With Azion CLI, azion describe network-list --network-list-id <network-list-id> --format json prints the same list, with the prefixes in items.