You may want to consider putting "ALL:ALL" in your hosts.deny. If you read the man page for hosts.allow and hosts.deny, it say that if there is no match in either file then access is granted. For example, if you explicitly allow domain_a and explicitly deny domain_b, then domain_c is granted access. Using "ALL:ALL" is the catchall for what you do not explicitly allow.
|