<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Block an IP Address From Accessing an Organization Using a Network Zone
Administration
Okta Classic Engine
Okta Identity Engine
Network Zones
Overview

This article provides steps to block a specific IP address from accessing an organization by creating a Network Zone. This action is a necessary security measure when a malicious actor's activity causes rate limit violations or user lockouts, and the System Log displays messages such as:

 

Okta Rate Limit Warning

Okta Rate Limit Reached

Okta Burst Rate Limits Activated

 

Applies To
  • Network Zones
  • Security
Cause

A malicious actor is using a specific IP address to attack the organization. This activity results in rate limit violations or user lockouts.

Solution
  1. Identify the IP address of the threat actor from the Rate Limits Dashboard or the System Log.

  2. Navigate to the Okta Admin Console.
  3. Go to Security Networks.
  4. Select Add zone and choose IP Zone.
  5. Enter a descriptive Zone name, such as "IP Addresses Blocked From Accessing Organization".

Add IP Zone

  1. Select the checkbox for Block access from IPs matching conditions listed in this zone.
  2. In the Gateway IPs field, enter the IP address identified in the first step.
  3. Select Save.

NOTE: When an IP address is blocked, the following event is logged in the System Log:

security.request.blocked Blocked request from IP


System Logs Event 

 

Related References

Loading
Block an IP Address From Accessing an Organization Using a Network Zone