Matching an IP address or address range in rules


This article applies to:

  • Trustwave SEG

Question:

  • How do I match an IP address or range of addresses in certain rules?
  • IP address "groups" in rules

Reply:

SEG 8.0 IP Groups

In SEG 8.0 and above, you can apply User Matching with IP Groups in all rules. This option supports the "to or from", "to and from" and exceptions, as available with User Groups.

Earlier versions method

To exclude messages coming from certain IP addresses or ranges from a rule, use the rule condition "Where sender's IP address matches address".

  • This condition is available in Connection and Content Analysis rules.
  • To apply an IP matching condition to a group of rules (such as anti-spam rules), create a rule "above" (evaluated before) the set of rules you want to affect, and use the "Pass the message to rule" action to skip to a later rule or policy group. For example:
     
    When a message arrives
    Where the message is addressed to or from any user
    Where sender's IP address matches 10.1.0.0/24
    Pass the message on to the next policy group

Notes:

The condition can include multiple addresses and ranges.

You can also use this condition to apply a set of rules for a specified IP address or range

For more information on this feature see Help and the User Guide for your version of SEG or MailMarshal SMTP.


Last Modified 5/1/2020.
https://support.trustwave.com/kb/KnowledgebaseArticle20643.aspx