Configuration details
The key to the Deny All implementation is thematch_all attribute. When set to true, this attribute ensures the rule bypasses specific signal matching (such as IP or geolocation) and instead applies the action to all requests targeting the specified scope.
Example configuration
The following configuration demonstrates thematch_all attribute: