Yeah, but what is "this operation" ?
Say, you have this:
[block these bad addresses]
[10 policies to allow various traffic, perhaps mostly based on the destination address]
OP aims to do something similar to a routing policy syntax without having to duplicate policies for the exceptions. In other words, NOT this:
[10 policies to allow various traffic from the exceptions to the bad address list]
[block these bad addresses]
[10 policies to allow various traffic, perhaps mostly based on the destination address]
which would then require to duplicate any changes to the 10 policies going forward.
------------------------------
Nikolay Semov
------------------------------
Original Message:
Sent: 08-19-2025 10:36
From: Anonymous
Subject: How to user blacklist and whitelist in security policies
This message was posted by a user wishing to remain anonymous
if you're using security zones, is this an SRX? If so, that would be straightforward, at the TOP of the zone, the first policy should did this operation.