<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Block a Specific IP Address Using Okta Network Zones
Administration
Okta Classic Engine
Okta Identity Engine
Network Zones
Overview

A malicious actor using a specific IP address to attack an organization causes rate limit violations or user lockouts. Resolve this issue by creating a Network Zone in Okta to block the specific IP address from accessing the organization. When this issue occurs, the System Log displays the following messages:

 

Okta Rate Limit Warning

 

Okta Rate Limit Reached

 

Okta Burst Rate Limits Activated

 

Applies To
  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Network Zones
  • Security
Cause

A malicious actor uses a specific IP address to attack the organization, which results in rate limit violations or user lockouts.

Solution

How is a specific IP address blocked using Okta Network Zones?

Identify the malicious IP address from the System Log and configure an IP Zone in the Okta Admin Console to block access.

  1. Identify the IP address of the threat actor from the Rate Limits dashboard or the System Log.
  2. Navigate to the Okta Admin Console.
  3. Go to Security > Networks.
  4. Select Add zone and choose IP Zone.
  5. Enter a descriptive Zone name, such as "IP Addresses Blocked From Accessing Organization".
    Add IP Zone
  6. Select the checkbox for Block access from IPs matching conditions listed in this zone.
  7. In the Gateway IPs field, enter the IP address identified in the first step.
  8. Select Save.

NOTE: When Okta blocks an IP address, the System Log records the following event: security.request.blocked Blocked request from IP.

System Logs Event

Related References

Loading
Block a Specific IP Address Using Okta Network Zones