This message was deleted.
# citrix-netscaler
s
This message was deleted.
c
The client.IP.SRC.EQ expression would only allow access from a single IP (The IP defined)
πŸ‘ 1
j
Thanks, John.. I now have a working test vip/svc to play with πŸ™‚ I dont see any actions configured with the policies.. I'll have a play this AM and feedback, cheers sir
j
I would remove the default load-balancer binding on the content-switch. Then as John already mentioned, use the CLIENT.IP.SRC.EQ expression to select the load-balancer in a content-switching policy. Use a responder with the inverse expression !CLIENT.IP.SRC to display a message or reset/drop the connection for unauthorized IP addresses.
Shameless plug, you can also use CoreLogic to help with these demands, but that’s a rather big config-change right now.
k
if the issue is that the default lb passes the traffic though, you could always implement a responder policy in the target lb vserver
where action is drop and then the expression is sth like
Copy code
!client.ip.src.eq(123.123.123.123)
so that would block requests that don't originate from the IP... if you need to have a list of single IPs, you could leverage a dataset or a patternset if you need subnets (this requires a bit trickier responder policy), for this one; see this blog https://www.jeroentielen.nl/citrix-adc-netscaler-client-ip-or-subnet-black-and-whitelist/
πŸ‘ 1
j
Thanks, folks... all very helpful.. it turned out to ne an issue with the policy having a copy of the string/URL contents with no IPs defined whic was being matched by anyone trying to go to them.... I'll have a read at the links πŸ™‚
πŸ‘ 1