Hi, Sorry for the delayed response. @Igor I tried putting the deny statement after the real_ip_header True-Client-IP line and didn't do the job. Any other suggestions? Sameer Posted at Nginx Forum: http://forum.nginx.org/read.php?2,13912,15177#msg-15177