禁用IP或IP段:

deny 1.2.3.4;
deny 91.212.45.0/24;
deny 91.212.65.0/24;

禁止所有外网IP,仅允许内网IP:

location / {
# block one workstation
deny 192.168.1.1;
# allow anyone in 192.168.1.0/24
allow 192.168.1.0/24;
# drop rest of the world
deny all;
}

Related Posts: Nginx访问控制-allow deny :