ipSecurity - how to add range of ip addresses

We have a requirement to whitelist the range of IP addresses from WAF) below:

More detail:


And I'm using .net ipSecurity section. But haven't found any example of how to add the above ip addresess without having to add ALL ip addresses.


<ipSecurity allowUnlisted="false">
        <!-- this line blocks everybody, except those listed below -->

        <add ipAddress="xx.xx.xx.xx" allowed="true"/>

I'm newbie on subnet mask.

Is there an elegant way to implement this?

Nil Pun Avatar asked Nov 25 '15 00:11

Nil Pun

1 Answers

In, 21 is the CIDR format of the subnet mask. You can use a conversion table to convert the CIDR format to an IP address.

Then set your IPSecurity to deny all except the specified IP addresses. I.e.:

  <ipSecurity allowUnlisted="false">
    <add allowed="true" ipAddress=""   subnetMask=""/>
    [add additional ip addresses here]

Hoppe Avatar answered Oct 02 '22 06:10

