<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Block IP Address based on IP Service Category using Enhanced Dynamic Network Zone
Okta Classic Engine
Okta Identity Engine
Network Zones
Overview

This article presents how to block IP addresses based on Proxy using an Enhanced Dynamic Zone. Enhanced Dynamic Zones are used to define the IP service categories, locations, and Autonomous System Numbers (ASNs) that are blocked or allowed in a zone. IP service categories include proxies, VPNs, and anonymizers.

Solution

Create Enhanced Dynamic Zone:

  1. In the Admin Console, go to Security > Networks.
  2. Select Add zone > Enhanced Dynamic Zone.  

Networks

  1. Enter a Zone name.

  2. Select Block access from IPs matching conditions to block the IP service category, locations, and ASNs in the zone.

Add Enhanced Dynamic Zone   

  1. Select Include the following IP service categories and enter ALL_PROXIES_VPNS to block all Proxies and VPNs.

Include IP service categories      

Alternatively, select All IP service categories except and enter WARP_VPN to only allow access from WARP_VPN and block access from all other connections, for example.

All IP service categories except WARP_VPN

 

  1. Select a Location option:

    • Include locations: The locations selected in the next step are included in the zone.

    • All locations except: The locations selected in the next step are excluded from the zone. All other locations are included.

  2. In the Location field, enter the country, state, or region, if applicable.

  3. Click Add Another to add more locations.   

  4. In the ISP autonomous system numbers (ASNs) field, enter the ASNs that must be included in the zone.

NOTE: For mobile carriers, using ASN is more reliable than IP-based geolocation. 

  1. Click Save.

  2. Set the network zone to Active.

 

Related References

Loading
Block IP Address based on IP Service Category using Enhanced Dynamic Network Zone