Article 09 – Network Sources: Restricting Access by IP and Subnet Boundaries

1. Introduction to Network Sources

In enterprise cloud security, user credentials alone are often insufficient to grant high-privilege access. Organizations must enforce location-aware access control, ensuring that administrative actions can only be performed when requests originate from authorized network locations.

Oracle Cloud Infrastructure (OCI) delivers this capability through Network Sources.

A Network Source defines an allowed set of public IP addresses, CIDR blocks, or private VCN subnets. By referencing a Network Source inside an IAM policy where clause, administrators establish a zero-trust network perimeter around critical cloud management APIs.

2. Types of Network Sources

OCI supports two primary types of Network Sources:

  1. Public IP Network Sources: Contains one or more public IP addresses or public IPv4/IPv6 CIDR blocks (e.g., corporate office egress gateways or dedicated VPN exit nodes).
  2. Private VCN Network Sources: Contains private IP subnets within specific Virtual Cloud Networks (VCNs) in your tenancy. Requests originating from workloads inside these VCN subnets match the network source rules.

[!IMPORTANT]
VCN OCID Requirement for Private Network Sources
When defining a private Network Source for VCN traffic, OCI requires specifying both the VCN OCID AND the private subnet CIDR block. Specifying only the CIDR block will cause policy evaluation failure for private VCN traffic.

3. Binding Network Sources to IAM Policies

Once a Network Source is created, it is bound to IAM policy statements using the request.networkSource.name condition attribute:

Example Policy Statement:
Allow group DB-Admins to manage database-family in compartment Production where request.networkSource.name = 'Corp-HQ-Egress'
  • Effect: Members of DB-Admins can manage production databases ONLY when their API calls originate from the public IP address range defined in Corp-HQ-Egress. API calls from any other location are denied.
4. OCI Web Console (GUI) Step-by-Step Walkthrough

Creating Network Sources and attaching them to policies is managed directly in the OCI Web Console GUI.

Step 1: Creating a Network Source in the Console
  1. Log in to the Oracle Cloud Console (https://cloud.oracle.com).
  2. Open Navigation Menu (≡) ➔ Identity & Security ➔ Network Sources (under Identity).
  3. Click Create Network Source.
  4. Enter details:
  5. Name: Corp-HQ-Egress
  6. Description: Corporate office public IP gateway ranges.
  7. Networks: Select Public Networks.
  8. Public IP Addresses: Enter 203.0.113.5/32, 198.51.100.0/24.
  9. Click Create.
Step 2: Binding the Network Source to a Policy
  1. Navigate to Identity & Security ➔ Policies.
  2. Select target compartment (e.g., Production).
  3. Click Create Policy.
  4. Name the policy: EnforceLocationDBAccess.
  5. Enter policy statement:
    text
    Allow group Production-DB-Admins to manage database-family in compartment Production where request.networkSource.name = 'Corp-HQ-Egress'
  6. Click Create.
5. Common Architectural Misconceptions & Pitfalls
Misconception 1: “Network Sources Replace VCN Security Lists and NSGs”
  • Reality: Network Sources filter IAM Control Plane API calls (e.g., launching a VM or deleting a database). They do NOT filter data plane network traffic flowing directly to compute instances. Data plane traffic filtering is governed by Security Lists and Network Security Groups (NSGs).
Misconception 2: “Network Source IP Changes Require Updating Policy Statements”
  • Reality: Policy statements reference the name of the Network Source (Corp-HQ-Egress). If corporate IP addresses change, administrators update the IP entries inside the Network Source object; all bound IAM policies update instantly without modifying policy text.
6. OCI Network Sources vs. Google Cloud (GCP) VPC Service Controls

For cloud architects familiar with Google Cloud, the following table compares network perimeter controls:

FeatureGoogle Cloud (GCP)Oracle Cloud Infrastructure (OCI)Key Technical Difference
API Location RestrictingGCP Access Context Manager & Access LevelsOCI Network Sources bound to policy conditionsOCI embeds network source matching directly into standard IAM policy where clauses.
Data Perimeter ProtectionGCP VPC Service Controls (VPC-SC Service Perimeters)Security Zones + Network SourcesBoth protect control plane APIs from unauthorized geographic locations.
VCN Private IP MatchingGCP Ingress/Egress Rules in Access LevelsPrivate Network Sources requiring VCN OCID + CIDROCI explicitly validates VCN OCIDs for internal private network matching.