Is it possible to Allow some source IP (i.e. from Thailand) for some destination IP (some web server) for some rule? i.e. from the detection log, they would like to Allow the IP address from Thailand / internal IP address to bypass the ‘Cross Site Scripting’ rule. (PS: As I tested, it seems the Black / White List IP will effect to all of security rules. Am I correct?)