1. Introduction to Network Sources
In enterprise cloud security, user credentials alone are often insufficient to grant high-privilege access. Organizations must enforce location-aware access control, ensuring that administrative actions can only be performed when requests originate from authorized network locations.
Oracle Cloud Infrastructure (OCI) delivers this capability through Network Sources.
A Network Source defines an allowed set of public IP addresses, CIDR blocks, or private VCN subnets. By referencing a Network Source inside an IAM policy where clause, administrators establish a zero-trust network perimeter around critical cloud management APIs.
2. Types of Network Sources
OCI supports two primary types of Network Sources:
- Public IP Network Sources: Contains one or more public IP addresses or public IPv4/IPv6 CIDR blocks (e.g., corporate office egress gateways or dedicated VPN exit nodes).
- Private VCN Network Sources: Contains private IP subnets within specific Virtual Cloud Networks (VCNs) in your tenancy. Requests originating from workloads inside these VCN subnets match the network source rules.
[!IMPORTANT]
VCN OCID Requirement for Private Network Sources
When defining a private Network Source for VCN traffic, OCI requires specifying both the VCN OCID AND the private subnet CIDR block. Specifying only the CIDR block will cause policy evaluation failure for private VCN traffic.
3. Binding Network Sources to IAM Policies
Once a Network Source is created, it is bound to IAM policy statements using the request.networkSource.name condition attribute:
Example Policy Statement:
Allow group DB-Admins to manage database-family in compartment Production where request.networkSource.name = 'Corp-HQ-Egress'
- Effect: Members of
DB-Adminscan manage production databases ONLY when their API calls originate from the public IP address range defined inCorp-HQ-Egress. API calls from any other location are denied.
4. OCI Web Console (GUI) Step-by-Step Walkthrough
Creating Network Sources and attaching them to policies is managed directly in the OCI Web Console GUI.
Step 1: Creating a Network Source in the Console
- Log in to the Oracle Cloud Console (
https://cloud.oracle.com). - Open Navigation Menu (
≡) ➔ Identity & Security ➔ Network Sources (under Identity). - Click Create Network Source.
- Enter details:
- Name:
Corp-HQ-Egress - Description:
Corporate office public IP gateway ranges. - Networks: Select Public Networks.
- Public IP Addresses: Enter
203.0.113.5/32,198.51.100.0/24. - Click Create.
Step 2: Binding the Network Source to a Policy
- Navigate to Identity & Security ➔ Policies.
- Select target compartment (e.g.,
Production). - Click Create Policy.
- Name the policy:
EnforceLocationDBAccess. - Enter policy statement:
text
Allow group Production-DB-Admins to manage database-family in compartment Production where request.networkSource.name = 'Corp-HQ-Egress' - Click Create.
5. Common Architectural Misconceptions & Pitfalls
Misconception 1: “Network Sources Replace VCN Security Lists and NSGs”
- Reality: Network Sources filter IAM Control Plane API calls (e.g., launching a VM or deleting a database). They do NOT filter data plane network traffic flowing directly to compute instances. Data plane traffic filtering is governed by Security Lists and Network Security Groups (NSGs).
Misconception 2: “Network Source IP Changes Require Updating Policy Statements”
- Reality: Policy statements reference the name of the Network Source (
Corp-HQ-Egress). If corporate IP addresses change, administrators update the IP entries inside the Network Source object; all bound IAM policies update instantly without modifying policy text.
6. OCI Network Sources vs. Google Cloud (GCP) VPC Service Controls
For cloud architects familiar with Google Cloud, the following table compares network perimeter controls:
| Feature | Google Cloud (GCP) | Oracle Cloud Infrastructure (OCI) | Key Technical Difference |
|---|---|---|---|
| API Location Restricting | GCP Access Context Manager & Access Levels | OCI Network Sources bound to policy conditions | OCI embeds network source matching directly into standard IAM policy where clauses. |
| Data Perimeter Protection | GCP VPC Service Controls (VPC-SC Service Perimeters) | Security Zones + Network Sources | Both protect control plane APIs from unauthorized geographic locations. |
| VCN Private IP Matching | GCP Ingress/Egress Rules in Access Levels | Private Network Sources requiring VCN OCID + CIDR | OCI explicitly validates VCN OCIDs for internal private network matching. |

