Allow a destination range to exclude smaller ranges within that rule, without turning those exclusions into global deny rules.
| Example |
Expected behaviour |
Allow 192.0.2.0/24, except 192.0.2.128/25 |
That rule allows the first half of the range, but does not match the excluded half. |
Another rule explicitly allows 192.0.2.200/32 |
That address can still be allowed; the earlier exclusion must not globally block it. |
| An address is excluded from a deny rule |
Other rules and the egress default decide its outcome; exclusion does not automatically allow it. |
| An exclusion lies outside its parent CIDR |
Reject with a clear validation error. |
Explicit deny rules must still take precedence over allow rules. Verify overlapping rules so that an exclusion affects only the rule containing it.
MXC schema requirement: to[].cidr and to[].except, for example:
{
"to": [{
"cidr": "192.0.2.0/24",
"except": ["192.0.2.128/25"]
}]
}
Allow a destination range to exclude smaller ranges within that rule, without turning those exclusions into global deny rules.
192.0.2.0/24, except192.0.2.128/25192.0.2.200/32Explicit deny rules must still take precedence over allow rules. Verify overlapping rules so that an exclusion affects only the rule containing it.
MXC schema requirement:
to[].cidrandto[].except, for example:{ "to": [{ "cidr": "192.0.2.0/24", "except": ["192.0.2.128/25"] }] }