The deny element defines a denied IP address or range of IP addresses, and contains an ip attribute, composed of an ip value and a mask value, separated by a slash (/).
The Gateway ANDs each incoming IP address with the deny mask. Then it ANDs the ip value in the deny element with the mask. If the results of the two ANDs match, the Gateway denies the incoming IP address to access the database
The deny element can appear only as a child of an ipfilter element. You can use as man deny elements as needed in the XML IP restriction document. When multiple deny elements appear in a document, only one match is needed to deny the incoming IP address.