backend ssh-all mode tcp acl allowed_destination var(sess.dstIP) -m ip 192.168.0.201 acl allowed_destination var(sess.dstIP) -m ip 192.168.0.202 acl allowed_server_names var(sess.dstName) -i -- ssh-server3.example.local tcp-request content set-dst var(sess.dstIP) tcp-request content accept if allowed_server_names tcp-request content accept if allowed_destinations tcp-request content reject server ssh 0.0.0.0:22