SECURE
Network Shield
Programmable network-layer protection on Azion's distributed architecture. Filter traffic by IP/CIDR, ASN, and geolocation before it reaches your origin, across multi-cloud, hybrid, or on-premises environments.

edge locations filtering traffic globally
propagation time for network list updates
unwanted traffic blocked before reaching origin
Block threats at the network layer, before they consume resources
Block traffic before origin
Use Network Lists of IP addresses, CIDR blocks, ASNs, and countries combined with Rules Engine to create layered defense policies.
Eliminate bandwidth waste from attacks
Block abusive traffic on Azion's distributed infrastructure so your origin servers never process malicious requests.
Propagate rules in seconds
Update Network Lists via Console or API and see changes live across all locations in seconds. No service interruptions, no downtime windows.
Protect any environment consistently
One set of rules protects workloads across AWS, GCP, Azure, on-premises data centers, and hybrid architectures. Consistent protection regardless of where your applications are hosted.
Share lists across firewalls
Create a catalog of Network Lists and reference them across multiple Firewall configurations. Update once, propagate everywhere.
Automate threat response at scale
Stream security events to your SIEM and trigger automated playbooks to update Network Lists via API. Use Functions to implement programmable, per-request decisions.
Recognized as a High Performer by G2, Winter 2026
Network Shield is part of Azion's Firewall platform, rated 4.5/5 stars by security professionals worldwide for ease of use, performance, and customer support.

Programmable network-layer security
Network Lists for programmable ACLs
Define access policies with lists that combine IP addresses, CIDR blocks, geolocation, ASNs, and reputation scores. Reference these lists directly in the Firewall Rules Engine. Updates propagate automatically across all associated firewalls, with no service interruption.

Rule-based traffic control with centralized list management
Create custom allowlists and blocklists using IPs, CIDR blocks, ASNs, countries, or Azion-managed lists like Tor Exit Nodes. Segment access by region or network type, and share the same lists across multiple firewalls for consistent policies at scale.

Automated threat response with real-time event streaming
Stream events to your SIEM in real time and trigger automated playbooks to update Network Lists via API. Changes propagate in seconds. Use Functions to implement programmable, per-request blocks and adapt your risk response dynamically.

Lock down your infrastructure
Use Origin Shield to restrict inbound traffic to your origin servers exclusively from Azion's trusted IP addresses.
The dynamic Network List is maintained by Azion and updated automatically. Configure your origin's firewall to accept only Origin Shield addresses, establishing a Layer 3/4 perimeter that blocks all direct external access.

Protect networks across every use case
Frequently Asked Questions
What is Network Shield and how does it work?
Network Shield is a Firewall module on the Azion Web Platform that provides programmable network-layer protection. It allows you to create Network Lists based on IP/CIDR addresses, Autonomous System Numbers (ASNs), and countries (geolocation), then reference those lists in the Firewall Rules Engine to block, deny, or rate-limit traffic. When a request arrives at an Azion location, it's evaluated against your configured rules and network lists , filtering out known offenders before the request reaches your infrastructure.
What is the difference between Network Shield and a Web Application Firewall (WAF)?
Network Shield operates at the network layer (Layer 3/4), filtering traffic based on IP addresses, CIDR blocks, ASNs, and geolocation before requests are processed. WAF operates at the application layer (Layer 7), analyzing HTTP/HTTPS request content to detect attacks like SQL injection and XSS. Both are modules within Azion's Firewall and can be combined in the same firewall configuration for comprehensive protection — Network Shield blocks known bad actors and regions, while WAF inspects the content of allowed requests for application-level threats.
What types of Network Lists can I create?
Network Shield supports three types of Network Lists: IP/CIDR lists for blocking or allowing specific IP addresses and CIDR ranges, ASN lists for filtering traffic by Autonomous System Number (groups of IP networks managed by specific operators), and Country lists for geolocation-based access control. You can also use Azion-managed lists like the Tor Exit Nodes list, which is automatically maintained and updated by Azion's security team.
How quickly do Network List updates propagate?
Network List updates propagate across Azion's entire global infrastructure in seconds. When you update a list via Console or API, changes are automatically applied to all firewalls that reference that list — without any service interruption or downtime window. This near-instant propagation enables real-time threat response, allowing your security automation tools to update blocklists and see immediate effects across all locations.
Can I share Network Lists across multiple firewalls?
Yes. A single Network List can be associated with multiple firewalls and rules. When you update the list, changes propagate automatically to all associated firewalls. This centralized management approach ensures consistent security policies across all your applications without duplicating configuration or risking policy drift between environments.
What is Origin Shield and how does it relate to Network Shield?
Origin Shield is a security add-on that provides a dynamic Network List containing all IP/CIDR addresses used by Azion's infrastructure. By configuring your origin server's firewall to accept traffic only from Origin Shield addresses, you create a Layer 3/4 perimeter that blocks all direct external access to your origin. Origin Shield requires the Network Shield module to be enabled and is maintained automatically by Azion, with clients notified 7 days before any changes to the IP list.
How much does Network Shield cost?
Network Shield is included as a module within Azion's Firewall product. You can start with $300 in free credits to test the service with no credit card required. Pricing is usage-based with no hidden fees or infrastructure costs. Since Network Shield blocks unwanted traffic before it reaches your infrastructure, most customers see significant cost savings on bandwidth and infrastructure. For detailed pricing, visit the pricing page.
Can I automate Network List updates with my SIEM or security tools?
Yes. Network Shield integrates with your existing security infrastructure through the Azion API. Stream security events in real time to your SIEM using Data Stream, then use automated playbooks to update Network Lists via API with effects propagated in seconds. You can also use Functions to implement programmable per-request logic, enabling dynamic threat response that adapts to evolving attack patterns without manual intervention.
