Hi Osmar,
I hope you are well.
You can achieve what you have described by creating an ACL policy and set the policy to block all IP's with the configuration 0.0.0.0/0, then in the exception list you can add the IP's you want to exclude from the ACL.
This will block all IP's but allow the IP's listed in your exception to access the site:
------------------------------
Ciaran McAnespy
Technical User
Tel Aviv CA
------------------------------