Ravindra BagaleCourses & study guides Track your progress

Guides

How to Block an IP Address or an IP Range Using a Network ACL in AWS

To block an IP address in AWS, add an inbound Deny rule to the network ACL of the subnet, with a lower rule number than the rule that allows the traffic. For example: rule 90 Deny, All traffic, source 203.0.113.25/32, placed before rule 100 Allow HTTP from 0.0.0.0/0. For a whole range use a CIDR such as 203.0.113.0/24. Security groups cannot do this, because they have allow rules only.

Come on, friends! A security guard stands at the society's main gate – he has a list: "don't let this person in". The network ACL is that guard, at the subnet's gate. And the flat's lock – the security group – can only say "these people may come in"; it cannot say "not these". So to block an IP, use the NACL. Note: the list is read from top to bottom and the first match wins.

Quick answer

Console: VPC → Network ACLs → the ACL of your web subnet → Inbound rules → Edit inbound rules → Add new rule:

Rule 90   All traffic   Source 203.0.113.25/32   Deny     <- blocks one IP
Rule 95   All traffic   Source 198.51.100.0/24   Deny     <- blocks a whole range
Rule 100  HTTP (80)     Source 0.0.0.0/0         Allow
Rule *    All traffic   Source 0.0.0.0/0         Deny     (default, cannot be removed)

The same with the AWS CLI:

aws ec2 create-network-acl-entry --network-acl-id acl-0123456789abcdef0 \
  --ingress --rule-number 90 --protocol -1 --cidr-block 203.0.113.25/32 --rule-action deny

203.0.113.0/24 and 198.51.100.0/24 are reserved documentation ranges used here as examples. Put the real attacker IP from your logs.

What do I need before blocking an IP?

  • The IP address you want to block. On an Nginx server: sudo awk '{print $1}' /var/log/nginx/access.log | sort | uniq -c | sort -rn | head shows the addresses with the most requests.
  • The subnet of the server and its network ACL: open VPC → Subnets → your subnet → Network ACL tab.
  • A way back in: never deny your own IP or 0.0.0.0/0 on port 22 while you are connected.

How does the network ACL block one IP and allow others?

A network ACL blocking one IP address with a low rule number Two requests arrive at the network ACL of the public subnet. The request from 203.0.113.25 matches rule 90, Deny, and is dropped at the subnet edge. The request from 198.51.100.7 does not match rule 90, matches rule 100, Allow HTTP, and reaches the web server. Rules are checked from the lowest number and the first match wins. 203.0.113.25 (example) 198.51.100.7 (example) Network ACL web-public-1a Nginx Inbound 90 All traffic 203.0.113.25/32 DENY Inbound 100 HTTP 80 0.0.0.0/0 ALLOW * All DENY rule 90 matched → dropped HTTP :80 HTTP :80

The network ACL checks rules from the lowest number. The request from 203.0.113.25 matches rule 90 Deny and is dropped at the subnet edge. The request from 198.51.100.7 skips rule 90, matches rule 100 Allow and reaches Nginx. Both addresses are documentation examples.

The rules of a network ACL are evaluated in order, starting with the lowest rule number, and the first rule that matches decides: allow or deny. Later rules are not looked at. If nothing matches, the final * rule denies the traffic. That is why the deny rule must have a smaller number than the allow rule.

How do I block an IP address or a range step by step?

Step 1 — Find the network ACL of the subnet

VPC → Subnets → select the subnet of your web server → Network ACL tab → click the acl-… ID. The default network ACL of a VPC allows all traffic in both directions (rules 100 Allow and * Deny).

Step 2 — Add the deny rule with a low number

Inbound rules → Edit inbound rules → Add new rule:

Rule number Type Source Allow/Deny
90 All traffic 203.0.113.25/32 Deny

/32 means exactly one address. Save changes. The block works within seconds for new connections.

Step 3 — Block a whole range if needed

Add another rule, for example 95 → All traffic → 203.0.113.0/24 → Deny. /24 covers 256 addresses (203.0.113.0 – 203.0.113.255). Use the smallest range that covers the attacker so you do not block innocent users.

Step 4 — Check the order

The list must now read 90 Deny, 95 Deny, 100 Allow, * Deny. If your allow rule is number 100 and you add a deny as 110, it never runs, because rule 100 matches first.

Step 5 — Test

From a machine with the blocked IP, curl -m 5 http://<WEB_PUBLIC_IP>/ must time out, while everyone else still gets the page. To test with your own IP safely, block it only on port 80 (Type HTTP) and keep SSH working, then remove the rule. 🚫

Ravindra Bagale's Tip

Students put the deny rule at number 110 and the allow at 100 – and say "it doesn't block, sir!" Note: the NACL doesn't read from the bottom; it reads from the lowest number, and the first match wins. Deny always before allow – 90 before 100. And space the numbers 10 apart, so there is room to insert a new rule in between.

Ravindra Bagale's Tip

Don't block your own IP! If you put a deny on port 22 and SSH stops, you then have to remove the rule from the console. If you want to test, do it only on the HTTP port. And the NACL applies to the subnet – every server in that subnet is protected, not just one.

Why is my NACL block not working?

Ghabru naka 😅 — these are the usual ones:

Symptom Likely cause Fix
Blocked IP still reaches the site Deny rule number is higher than the allow rule Renumber the deny below the allow (90 < 100)
Still reaches the site Rule added to a different subnet's ACL Open the server's subnet → Network ACL tab and edit that ACL
Still reaches the site Traffic comes through a load balancer or CDN The NACL of the web subnet sees the load balancer's IP; put the deny on the load balancer's subnets, or use AWS WAF
Whole site down for everyone Deny source typed as 0.0.0.0/0, or /8 instead of /32 Fix the CIDR
Site loads for nobody after creating a new custom NACL A new custom network ACL denies everything until you add rules Add inbound allow rules and outbound ephemeral ports 1024–65535
NetworkAclEntryAlreadyExists in the CLI That rule number is taken Use a free number

Can a security group block an IP?

No. A security group has allow rules only; anything not allowed is dropped, but you cannot write "deny this one IP and allow everyone else". Use a network ACL (up to 20 rules per direction by default, adjustable up to 40) or, for many addresses or HTTP-level rules, AWS WAF on a load balancer or CloudFront. Details: Security group vs NACL.

Try it at home

With a friend's help (a different internet connection), add rule 90 Deny HTTP for the friend's IP, confirm their browser times out while yours still loads the page, then change the rule number to 110 and see the block stop working. Remove the rule at the end.

Got it? Blocking an IP = a Deny rule in the NACL, with a number lower than the allow rule, source /32, or /24 for a range. A security group cannot deny. Test it, and remove the rule when the job is done.

Frequently asked questions

How do I block an IP address in AWS?

Add an inbound Deny rule to the network ACL of the subnet, with a lower rule number than the allow rule, for example rule 90 Deny for 203.0.113.25/32 before rule 100 Allow HTTP.

Can a security group block an IP address?

No. Security groups have allow rules only. Use a network ACL deny rule, or AWS WAF for HTTP-level blocking on a load balancer or CloudFront.

Why is my NACL deny rule not working?

Usually the deny rule has a higher number than an allow rule that matches first, it was added to another subnet's ACL, or the traffic arrives through a load balancer whose IP is what the web subnet sees.

In which order are NACL rules evaluated?

From the lowest rule number upwards. The first rule that matches decides, and the final * rule denies anything that did not match.

How do I block a whole IP range?

Use a CIDR in the deny rule, for example 203.0.113.0/24 for 256 addresses. Keep the range as small as possible.

How many rules can a network ACL have?

By default 20 inbound and 20 outbound rules, adjustable up to 40 per direction. For long block lists use AWS WAF IP sets.