ip_acl
IP-based access control filter.
On this page
IP-based access control filter.
Configuration Notes
When allow is configured, only matching clients are permitted. When deny is configured, matching clients are rejected. Both cannot be set together; [from_config] rejects configurations with both lists.
Denied requests receive a 403 Forbidden response.
Configuration
| Field | Type | Required | Description |
|---|---|---|---|
allow | string[] | no | IPs/CIDRs to allow. If non-empty, only these are permitted. |
deny | string[] | no | IPs/CIDRs to deny. |
Example
filter: ip_acl
allow:
- "10.0.0.0/8"
- "192.168.0.0/16"