NO.38 A user with the proper role issues the following commands when setting up and activating network policies:
CREATE OR REPLACE NETWORK POLICY foo_policy
ALLOWED_IP_LIST = (‘1.1.1.0/24’, ‘2.2.2.0/24’, ‘3.3.3.0/24’)
BLOCKED_IP_LIST = (‘1.1.1.1’)
COMMENT = ‘Account level policy’;
ALTER ACCOUNT SET NETWORK_POLICY=foo_policy;
CREATE OR REPLACE NETWORK POLICY bar_policy
ALLOWED_IP_LIST = (‘3.3.3.0/24’)
BLOCKED_IP_LIST = (‘3.3.3.10’)
COMMENT = ‘user level policy’;
ALTER USER user1 SET NETWORK_POLICY=BAR_POLICY;
Afterwards, user1 attempts to log in to Snowflake from IP address 3.3.3.10.
Will the login be successful?
Although 3.3.3.10 is in the ALLOWED_IP_LIST, it is also explicitly listed in the BLOCKED_IP_LIST of the user-level policy (bar_policy). Blocked IPs always take precedence over allowed IPs in Snowflake network policies, so the login attempt will fail.