SECURE

Network Shield

Programmable network-layer protection on Azion's distributed architecture. Filter traffic by IP/CIDR, ASN, and geolocation before it reaches your origin, across multi-cloud, hybrid, or on-premises environments.

Network Shield

edge locations filtering traffic globally

propagation time for network list updates

unwanted traffic blocked before reaching origin

Block threats at the network layer, before they consume resources

Programmable ACLs with instant global propagation.

Block traffic before origin

Use Network Lists of IP addresses, CIDR blocks, ASNs, and countries combined with Rules Engine to create layered defense policies.

Eliminate bandwidth waste from attacks

Block abusive traffic on Azion's distributed infrastructure so your origin servers never process malicious requests.

Propagate rules in seconds

Update Network Lists via Console or API and see changes live across all locations in seconds. No service interruptions, no downtime windows.

Protect any environment consistently

One set of rules protects workloads across AWS, GCP, Azure, on-premises data centers, and hybrid architectures. Consistent protection regardless of where your applications are hosted.

Share lists across firewalls

Create a catalog of Network Lists and reference them across multiple Firewall configurations. Update once, propagate everywhere.

Automate threat response at scale

Stream security events to your SIEM and trigger automated playbooks to update Network Lists via API. Use Functions to implement programmable, per-request decisions.

GPA
Magazine Luiza
Itaú
Renner
Caixa
Dafiti
Netshoes
Global Fashion Group
Herospark
Fourbank
Crefisa
Contabilizei
GPA Logo

"Azion shielded us from sophisticated cyberattacks and empowered us to modernize our infrastructure, reduce costs, and deliver the best shopping experiences to millions of customers across Latin America."

Allan Monteiro

CISO & Head of Technology

Recognized as a High Performer by G2, Winter 2026

Network Shield is part of Azion's Firewall platform, rated 4.5/5 stars by security professionals worldwide for ease of use, performance, and customer support.

See more

G2 badge of High Performer for Azion Firewall platform

Programmable network-layer security

Granular control over who accesses your applications, and from where.

Network Lists for programmable ACLs

Define access policies with lists that combine IP addresses, CIDR blocks, geolocation, ASNs, and reputation scores. Reference these lists directly in the Firewall Rules Engine. Updates propagate automatically across all associated firewalls, with no service interruption.

Docs

Network Shield Rules Engine configuration showing network list criteria and deny behavior

Rule-based traffic control with centralized list management

Create custom allowlists and blocklists using IPs, CIDR blocks, ASNs, countries, or Azion-managed lists like Tor Exit Nodes. Segment access by region or network type, and share the same lists across multiple firewalls for consistent policies at scale.

Learn More

Network List configuration showing IP/CIDR, ASN, and country-based blocklist creation

Automated threat response with real-time event streaming

Stream events to your SIEM in real time and trigger automated playbooks to update Network Lists via API. Changes propagate in seconds. Use Functions to implement programmable, per-request blocks and adapt your risk response dynamically.

Start Free

Architecture diagram showing Network Shield integration with SIEM and automated threat response workflow

Lock down your infrastructure

Use Origin Shield to restrict inbound traffic to your origin servers exclusively from Azion's trusted IP addresses.

The dynamic Network List is maintained by Azion and updated automatically. Configure your origin's firewall to accept only Origin Shield addresses, establishing a Layer 3/4 perimeter that blocks all direct external access.

Docs

Origin Shield architecture showing trusted Azion IP addresses connecting to origin servers

Frequently Asked Questions

What is Network Shield and how does it work?

Network Shield is a Firewall module on the Azion Web Platform that provides programmable network-layer protection. It allows you to create Network Lists based on IP/CIDR addresses, Autonomous System Numbers (ASNs), and countries (geolocation), then reference those lists in the Firewall Rules Engine to block, deny, or rate-limit traffic. When a request arrives at an Azion location, it's evaluated against your configured rules and network lists , filtering out known offenders before the request reaches your infrastructure.

What is the difference between Network Shield and a Web Application Firewall (WAF)?

Network Shield operates at the network layer (Layer 3/4), filtering traffic based on IP addresses, CIDR blocks, ASNs, and geolocation before requests are processed. WAF operates at the application layer (Layer 7), analyzing HTTP/HTTPS request content to detect attacks like SQL injection and XSS. Both are modules within Azion's Firewall and can be combined in the same firewall configuration for comprehensive protection — Network Shield blocks known bad actors and regions, while WAF inspects the content of allowed requests for application-level threats.

What types of Network Lists can I create?

Network Shield supports three types of Network Lists: IP/CIDR lists for blocking or allowing specific IP addresses and CIDR ranges, ASN lists for filtering traffic by Autonomous System Number (groups of IP networks managed by specific operators), and Country lists for geolocation-based access control. You can also use Azion-managed lists like the Tor Exit Nodes list, which is automatically maintained and updated by Azion's security team.

How quickly do Network List updates propagate?

Network List updates propagate across Azion's entire global infrastructure in seconds. When you update a list via Console or API, changes are automatically applied to all firewalls that reference that list — without any service interruption or downtime window. This near-instant propagation enables real-time threat response, allowing your security automation tools to update blocklists and see immediate effects across all locations.

Can I share Network Lists across multiple firewalls?

Yes. A single Network List can be associated with multiple firewalls and rules. When you update the list, changes propagate automatically to all associated firewalls. This centralized management approach ensures consistent security policies across all your applications without duplicating configuration or risking policy drift between environments.

What is Origin Shield and how does it relate to Network Shield?

Origin Shield is a security add-on that provides a dynamic Network List containing all IP/CIDR addresses used by Azion's infrastructure. By configuring your origin server's firewall to accept traffic only from Origin Shield addresses, you create a Layer 3/4 perimeter that blocks all direct external access to your origin. Origin Shield requires the Network Shield module to be enabled and is maintained automatically by Azion, with clients notified 7 days before any changes to the IP list.

How much does Network Shield cost?

Network Shield is included as a module within Azion's Firewall product. You can start with $300 in free credits to test the service with no credit card required. Pricing is usage-based with no hidden fees or infrastructure costs. Since Network Shield blocks unwanted traffic before it reaches your infrastructure, most customers see significant cost savings on bandwidth and infrastructure. For detailed pricing, visit the pricing page.

Can I automate Network List updates with my SIEM or security tools?

Yes. Network Shield integrates with your existing security infrastructure through the Azion API. Stream security events in real time to your SIEM using Data Stream, then use automated playbooks to update Network Lists via API with effects propagated in seconds. You can also use Functions to implement programmable per-request logic, enabling dynamic threat response that adapts to evolving attack patterns without manual intervention.

Access to all features.

$300 free credits

Modernize your Application Security