This message was deleted.
# citrix-netscaler
s
This message was deleted.
k
I would replace that expression just with "true"
because the aim is to have a "drop all" -rule?
and above that you probably would have the rules that allow traffic
or even create a "reverse rule" using data/patternset & expressions, where the rule drops everything and the expression is sth like !whitelist-ip
c
I don't really want to change things for this customer as the task paid work was only to convert the existing authorization polices to advanced using the existing expressions which they have no issues with
The classic expression "REQ.IP.destIP == 0.0.0.0 -netmask 0.0.0.0" worked for them but the equivalent in advanced doesn't
j
Agree with @Kari Ruissalo (WyW) on this. nspepi will not help you on this, some stuff needs to be changed manually.
c
i have created all new authorization polices using advanced expressions and was planning on unbinding the existing classic authorization polices from the AAA groups and binding the new Advanced authorization policies but they wont unbind ? No errors it just doesnt unbind them ? they are bound to the AAA Vserver