Content ACL
Navigation: Security Profiles
Match request headers, hostnames, URI values, or GEOIP and apply allow, drop, or block actions.

Add / Edit forms
Click + Add New to open the creation dialog, or Edit on an existing row to modify a record.
List view

Add form — all tabs
The add dialog contains 2 tabs. Example values in the filled screenshots are for documentation only — do not save them on a production appliance.
General
| Field | Required | Description | Example | Why this data is needed |
|---|---|---|---|---|
| Profile Name | Yes | Unique name for proxy rule attachment. | API_ACL |
Required — proxy rules select this profile by name. |
| Default Action | Yes | Allow or deny when no ACL rule matches. | Deny |
Required — secure default is Deny (whitelist approach). |
| Status | Yes | Enable or disable this profile. | Enabled |
Must be Enabled for ACL rules to take effect. |
Empty:

Filled with example data (for illustration — shows why each field needs a value):

ACL Rules
| Field | Required | Description | Example | Why this data is needed |
|---|---|---|---|---|
| URI Pattern | Yes | Path or regex to match (e.g. /api/*). | /api/v1/* |
Required — defines which URLs this ACL entry controls. |
| HTTP Method | No | GET, POST, PUT, DELETE, or any. | GET |
Optional — restrict rule to specific HTTP methods. |
| Action | Yes | Allow or deny matched requests. | Allow |
Required — determines whether matching traffic passes. |
Empty:

Filled with example data (for illustration — shows why each field needs a value):

Edit form — all tabs
The edit dialog contains 2 tabs. Fields are the same as Add — values show the currently saved record:
General
| Field | Required | Description | Example | Why this data is needed |
|---|---|---|---|---|
| Profile Name | Yes | Unique name for proxy rule attachment. | API_ACL |
Required — proxy rules select this profile by name. |
| Default Action | Yes | Allow or deny when no ACL rule matches. | Deny |
Required — secure default is Deny (whitelist approach). |
| Status | Yes | Enable or disable this profile. | Enabled |
Must be Enabled for ACL rules to take effect. |

ACL Rules
| Field | Required | Description | Example | Why this data is needed |
|---|---|---|---|---|
| URI Pattern | Yes | Path or regex to match (e.g. /api/*). | /api/v1/* |
Required — defines which URLs this ACL entry controls. |
| HTTP Method | No | GET, POST, PUT, DELETE, or any. | GET |
Optional — restrict rule to specific HTTP methods. |
| Action | Yes | Allow or deny matched requests. | Allow |
Required — determines whether matching traffic passes. |

Page sections
- Content ACL Profiles
Available actions
- ▦ Overview
- ⚙ System Settings ›
- General
- Updates
- ◉ User Management
- ⌁ Network Settings ›
- Interfaces
- Static Routs
- Static DNS
- □ Aliases & Objects ›
- Address
- Ports
- ◇ Rules & Policies ›
- Proxy Certificate
- Proxy Rules
- ◆ Security Profiles ›
- Web Security
- Geoip Security
- DDoS Guard
- Content ACL
- Content Rewrite
- Email Intelligence
- Time Profiles
- Content Route
- ◆ Event & Monitor ›
- • Logs & Events ›
- Sign Out
- Refresh Data
- Main
- Add Record
- Edit
- Clone
- Delete
Table columns
- RECORD
- ID
- PROFILE NAME
- DEFAULT ACTION
- STATUS