Published 20 days ago
Published 20 days ago
Peter Larin
Updated 20 days ago
0
I couldn't find it in official docs, but found elsewhere, so am seeking official confirmation. Imagine a scenario: I white list a subnet but want to blacklist one IP from it. So just putting that IP on a blacklist won't work? - So I'd need to include all the IPs of my subnet less the blacklisted IP explicitly in a while list?
Sylvie
Updated 20 days ago
whitelist rules have a higher priority than blacklist rules. You can find the processing order in our official docs:
https://docs.waf.chaitin.com/reference/articles/http-request-processing
In your case, if you whitelist a subnet and then blacklist one IP inside that subnet, the blacklist rule won't take effect because the whitelist has higher priority.
The recommended way is:
Allow rule: Source IP belongs to your subnet
AND
Source IP does not equal the IP you want to block
Deny rule: Source IP equals the IP you want to block
This will allow the subnet while blocking the specific IP.
Peter Larin
Updated 20 days ago
0
Thank you for explaining!
Sylvie
Updated 20 days ago
☺️