backend ssh-all mode tcp acl allowed_destination var(sess.dst) -m ip 192.168.0.201 acl allowed_destination var(sess.dst) -m ip 192.168.0.202 acl allowed_destination var(sess.dst) -m ip 10.0.12.0/24 tcp-request content set-dst var(sess.dst) tcp-request content accept if allowed_destination tcp-request content reject server ssh 0.0.0.0:22