Forum Discussion
dennypayne
Apr 03, 2009Employee
Since it's temporary, you could just use packet filters rather than writing a rule.
Or, something like:
when CLIENT_ACCEPTED {
if { not (IP::addr[IP::client_addr] equals "x.x.x.x") } {
add add'l IP's with an || operator if needed
discard
}
}
or if you create a Data Group (class) with your list of IP's:
when CLIENT_ACCEPTED {
if { not ( [matchclass $::data_group_name contains IP::addr[IP::client_addr]]) } {
discard
}
}
Denny