Author Topic: How to Block Specific Subnets or IP Addresses From Accessing a Particular URL  (Read 3055 times)

Offline jmelika

  • Administrator
  • Hero Member
  • *****
  • Posts: 339
  • Karma: 7
Summary

This article describes how to block specific subnets or IP addresses from accessing a particular URL on your servers (for example, /status/).

Procedure

Issue the following commands:

   1. add expression secure_url “url == /status/”
   2. add expression not_subnet2 “SOURCEIP != 65.186.55.0 -netmask 255.255.255.0”
   3. add expression not_subnet1 “SOURCEIP != 65.202.35.0 -netmask 255.255.255.0”
   4. add filter policy url_filter -rule "(secure_url && (not_subnet1 || not_subnet2 )) " -reqAction RESET
   5. bind filter global url_filter -priority 0 -state ENABLED