How to Block an IP Address or an IP Range Using a Network ACL in AWS
To block an IP address in AWS, add an inbound Deny rule to the network ACL of the subnet, with a lower rule number than the rule that allows the traffic. For example: rule 90 Deny, All traffic, source 203.0.113.25/32, placed before rule 100 Allow HTTP from 0.0.0.0/0. For a whole range use a CIDR such as 203.0.113.0/24. Security groups cannot do this, because they have allow rules only.
Come on, friends! A security guard stands at the society's main gate – he has a list: "don't let this person in". The network ACL is that guard, at the subnet's gate. And the flat's lock – the security group – can only say "these people may come in"; it cannot say "not these". So to block an IP, use the NACL. Note: the list is read from top to bottom and the first match wins.
चला मित्रांनो! Society च्या main gate वर security guard असतो – त्याच्याकडे यादी असते: "या माणसाला आत सोडू नका". Network ACL तोच guard आहे, subnet च्या gate वर. आणि flat चं lock – security group – फक्त "यांना आत या" म्हणतो, "यांना नको" म्हणू शकत नाही. म्हणून IP block करायचा असेल तर NACL. लक्ष द्या: यादी वरून खाली वाचली जाते, पहिला match जिंकतो.
चलो दोस्तों! Society के main gate पर security guard होता है – उसके पास एक list होती है: "इस आदमी को अंदर मत आने दो". Network ACL वही guard है, subnet के gate पर. और flat का lock – security group – सिर्फ "इन्हें अंदर आने दो" कहता है, "इन्हें नहीं" नहीं कह सकता. इसलिए IP block करना हो तो NACL. ध्यान दो: list ऊपर से नीचे पढ़ी जाती है, पहला match जीतता है.
Quick answer
Console: VPC → Network ACLs → the ACL of your web subnet → Inbound rules → Edit inbound rules → Add new rule:
Rule 90 All traffic Source 203.0.113.25/32 Deny <- blocks one IP
Rule 95 All traffic Source 198.51.100.0/24 Deny <- blocks a whole range
Rule 100 HTTP (80) Source 0.0.0.0/0 Allow
Rule * All traffic Source 0.0.0.0/0 Deny (default, cannot be removed)
The same with the AWS CLI:
aws ec2 create-network-acl-entry --network-acl-id acl-0123456789abcdef0 \
--ingress --rule-number 90 --protocol -1 --cidr-block 203.0.113.25/32 --rule-action deny
203.0.113.0/24 and 198.51.100.0/24 are reserved documentation ranges used here as examples. Put the real attacker IP from your logs.
What do I need before blocking an IP?
- The IP address you want to block. On an Nginx server:
sudo awk '{print $1}' /var/log/nginx/access.log | sort | uniq -c | sort -rn | headshows the addresses with the most requests. - The subnet of the server and its network ACL: open VPC → Subnets → your subnet → Network ACL tab.
- A way back in: never deny your own IP or
0.0.0.0/0on port 22 while you are connected.
How does the network ACL block one IP and allow others?
The network ACL checks rules from the lowest number. The request from 203.0.113.25 matches rule 90 Deny and is dropped at the subnet edge. The request from 198.51.100.7 skips rule 90, matches rule 100 Allow and reaches Nginx. Both addresses are documentation examples.
Network ACL rules सगळ्यात लहान number पासून check करतो. 203.0.113.25 वरून आलेली request rule 90 Deny ला match होते आणि subnet च्या edge वरच drop होते. 198.51.100.7 वरून आलेली request rule 90 सोडून rule 100 Allow ला match होते आणि Nginx पर्यंत पोहोचते. दोन्ही addresses documentation examples आहेत.
Network ACL rules को सबसे छोटे number से check करता है. 203.0.113.25 से आई request rule 90 Deny से match होती है और subnet के edge पर ही drop हो जाती है. 198.51.100.7 से आई request rule 90 छोड़कर rule 100 Allow से match होती है और Nginx तक पहुँचती है. दोनों addresses documentation examples हैं.
The rules of a network ACL are evaluated in order, starting with the lowest rule number, and the first rule that matches decides: allow or deny. Later rules are not looked at. If nothing matches, the final * rule denies the traffic. That is why the deny rule must have a smaller number than the allow rule.
How do I block an IP address or a range step by step?
Step 1 — Find the network ACL of the subnet
VPC → Subnets → select the subnet of your web server → Network ACL tab → click the acl-… ID. The default network ACL of a VPC allows all traffic in both directions (rules 100 Allow and * Deny).
Step 2 — Add the deny rule with a low number
Inbound rules → Edit inbound rules → Add new rule:
| Rule number | Type | Source | Allow/Deny |
|---|---|---|---|
90 |
All traffic | 203.0.113.25/32 |
Deny |
/32 means exactly one address. Save changes. The block works within seconds for new connections.
Step 3 — Block a whole range if needed
Add another rule, for example 95 → All traffic → 203.0.113.0/24 → Deny. /24 covers 256 addresses (203.0.113.0 – 203.0.113.255). Use the smallest range that covers the attacker so you do not block innocent users.
Step 4 — Check the order
The list must now read 90 Deny, 95 Deny, 100 Allow, * Deny. If your allow rule is number 100 and you add a deny as 110, it never runs, because rule 100 matches first.
Step 5 — Test
From a machine with the blocked IP, curl -m 5 http://<WEB_PUBLIC_IP>/ must time out, while everyone else still gets the page. To test with your own IP safely, block it only on port 80 (Type HTTP) and keep SSH working, then remove the rule. 🚫
Ravindra Bagale's Tip
Students put the deny rule at number 110 and the allow at 100 – and say "it doesn't block, sir!" Note: the NACL doesn't read from the bottom; it reads from the lowest number, and the first match wins. Deny always before allow – 90 before 100. And space the numbers 10 apart, so there is room to insert a new rule in between.
Ravindra Bagale's Tip – मराठी
Students deny rule टाकतात 110 number ला, allow 100 ला – आणि म्हणतात "block होत नाही sir!" लक्ष द्या: NACL खालून नाही, लहान number पासून वाचतो आणि पहिला match जिंकतो. Deny नेहमी allow च्या आधी – 90, 100 च्या आधी. आणि numbers 10-10 च्या अंतराने द्या, मध्ये नवीन rule टाकायला जागा राहते.
Ravindra Bagale's Tip – हिंदी
Students deny rule 110 number पर डालते हैं, allow 100 पर – और कहते हैं "block नहीं होता sir!" ध्यान दो: NACL नीचे से नहीं, छोटे number से पढ़ता है और पहला match जीतता है. Deny हमेशा allow से पहले – 90, 100 से पहले. और numbers 10-10 के अंतर से दो, बीच में नया rule डालने की जगह रहती है.
Ravindra Bagale's Tip
Don't block your own IP! If you put a deny on port 22 and SSH stops, you then have to remove the rule from the console. If you want to test, do it only on the HTTP port. And the NACL applies to the subnet – every server in that subnet is protected, not just one.
Ravindra Bagale's Tip – मराठी
स्वतःचा IP block करू नका! Port 22 साठी deny लावला आणि SSH बंद झालं, मग console मधून rule काढावा लागतो. Test करायचं असेल तर फक्त HTTP port वर करा. आणि NACL subnet ला लागतो – त्या subnet मधले सगळे servers protect होतात, फक्त एक नाही.
Ravindra Bagale's Tip – हिंदी
अपना ही IP block मत करो! Port 22 के लिए deny लगाया और SSH बंद हो गया, तो फिर console से rule हटाना पड़ता है. Test करना हो तो सिर्फ HTTP port पर करो. और NACL subnet पर लगता है – उस subnet के सारे servers protect होते हैं, सिर्फ एक नहीं.
Why is my NACL block not working?
Ghabru naka 😅 — these are the usual ones:
| Symptom | Likely cause | Fix |
|---|---|---|
| Blocked IP still reaches the site | Deny rule number is higher than the allow rule | Renumber the deny below the allow (90 < 100) |
| Still reaches the site | Rule added to a different subnet's ACL | Open the server's subnet → Network ACL tab and edit that ACL |
| Still reaches the site | Traffic comes through a load balancer or CDN | The NACL of the web subnet sees the load balancer's IP; put the deny on the load balancer's subnets, or use AWS WAF |
| Whole site down for everyone | Deny source typed as 0.0.0.0/0, or /8 instead of /32 |
Fix the CIDR |
| Site loads for nobody after creating a new custom NACL | A new custom network ACL denies everything until you add rules | Add inbound allow rules and outbound ephemeral ports 1024–65535 |
NetworkAclEntryAlreadyExists in the CLI |
That rule number is taken | Use a free number |
Can a security group block an IP?
No. A security group has allow rules only; anything not allowed is dropped, but you cannot write "deny this one IP and allow everyone else". Use a network ACL (up to 20 rules per direction by default, adjustable up to 40) or, for many addresses or HTTP-level rules, AWS WAF on a load balancer or CloudFront. Details: Security group vs NACL.
Try it at home
With a friend's help (a different internet connection), add rule 90 Deny HTTP for the friend's IP, confirm their browser times out while yours still loads the page, then change the rule number to 110 and see the block stop working. Remove the rule at the end.
Learn it properly
Got it? Blocking an IP = a Deny rule in the NACL, with a number lower than the allow rule, source /32, or /24 for a range. A security group cannot deny. Test it, and remove the rule when the job is done.
समजलं का? IP block = NACL मध्ये Deny rule, number allow पेक्षा लहान, source /32 किंवा range साठी /24. Security group deny करू शकत नाही. Test करा, आणि काम झालं की rule काढा.
समझ आया? IP block = NACL में Deny rule, number allow से छोटा, source /32 या range के लिए /24. Security group deny नहीं कर सकता. Test करो, और काम हो जाए तो rule हटा दो.
Frequently asked questions
How do I block an IP address in AWS?
Add an inbound Deny rule to the network ACL of the subnet, with a lower rule number than the allow rule, for example rule 90 Deny for 203.0.113.25/32 before rule 100 Allow HTTP.
Can a security group block an IP address?
No. Security groups have allow rules only. Use a network ACL deny rule, or AWS WAF for HTTP-level blocking on a load balancer or CloudFront.
Why is my NACL deny rule not working?
Usually the deny rule has a higher number than an allow rule that matches first, it was added to another subnet's ACL, or the traffic arrives through a load balancer whose IP is what the web subnet sees.
In which order are NACL rules evaluated?
From the lowest rule number upwards. The first rule that matches decides, and the final * rule denies anything that did not match.
How do I block a whole IP range?
Use a CIDR in the deny rule, for example 203.0.113.0/24 for 256 addresses. Keep the range as small as possible.
How many rules can a network ACL have?
By default 20 inbound and 20 outbound rules, adjustable up to 40 per direction. For long block lists use AWS WAF IP sets.