Although I run a Shorewall firewall I normally do not block addresses in Shorewall. I do it in my iptables configuration on my web server (I do not run Shorewall and the web server on the same box). If I were to do it on Shorewall I would probably do it like this: