- 78 -
Deny Policy Sample
Case 1: Deny specific Source IP Address – Host
Purpose:
Verify positive and negative matches to a specific host IP address with a 32 bit mask, no matter the rule defined as
permit or deny. Check for Class A,B, and C address.
1. To set a Host as the target at this case.
2. Once the deny policy be applied, all IP packets from the target Host IP Address will be dropped.
3. No matter IP packets form the target be transmitted to Internet or Intranet within the same IP segment, they will
be dropped.
Case Design:
Action DENY
Match IP
Source IP Address
Host IP
192.168.1.1 / 255.255.255.255
Destination IP Address ANY
Device Connection and Configuration:
Stream
Target
ID Source Address Destination Address
Protocol
Host
1 192.168.1.1 Any Any
ACL Policy Configuration: