06-04-2026 11:22 PM
I have about 3000 Ip's that need to be blocked/rejected connectins when an incoming email are reeived from them.
I know, I had to do this in HAT - - but adding 3000 IP's in HAT is a real manual and tedious process.
is there a way to achieve this with groups - ie., dictrionaries or address lists
in CES, I see there is an option "IP Addresses only" when creating Address lists - if I had to add something like @[146.200.16.233]
- but if I create it where do I use that address list for blocking incoming connections..
If I dont have that option to reference IP list - then why does cisco CES give that option..
06-04-2026 11:59 PM
You can export the hat, add the ips, import the hat.
06-17-2026 01:06 AM
well, we have alrady added manually.
But the orignall question is "if there is no place that I can use the address list created as IP address only" - what is the significacen of it. -
where I need to use this IP address only address list - in the configuration or settings or condtions etc..
If I dont have that option to reference IP list - then why does cisco CES give that option..
06-17-2026 11:37 AM
Address lists are used in specific spots..
SDR exceptions
Forged email detection exceptions
Mailflow policy exceptions
Domain reputation checks against External Threat feeds.
If you go here:
And search the whole book for Address list, it will give you all of the spots they are used.
It does feel like a leftover bit of config that could have been replaced with more generic Dictionaries, but the gui does limit what's allowed... so maybe that's why they kept it.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide