negate destination IP's

Showing results for 
Show  only  | Search instead for 
Did you mean: 

negate destination IP's

L4 Transporter


@reaper @BPry

Is you create an allow rule and then select to negate the destination IP's does that mean those IP's are blocked?


L6 Presenter

Nope, it means all IPs except those will match that field in rule.


Thats what I thought, they can be picked up by another rule and still be allowed

correct, it simply means "match everything except these"

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

@reaper @santonic


Just for curiousity what would be a good use case of using negate instead of just not adding those IP ranges to the rule


When there are specific IPs within a given range that you would want to exclude. For example; If I created a policy that says that everything within my 'GUEST' zone is denied from accessing anything within my 'SERVER' zone I would likely want to negate my switches so they could actually access NTP servers and DHCP services. 


Then those IP's that you negate from that rule can still match on another rule and be allowed. I can see where it might save you time if you have alot of IP's to block and only a few that you don't want blocked on that rule

  • 6 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!