Challenge IPv6 addresses that start with 2600::?

Hi - is there a way to write a WAF rule that apply’s managed challenge or block to any IPv6 address that starts 2600? I know that would be impacting a huge amount of addresses, but I can’t seem to write it in a way that works.

I tried setting IP Source Address is in 2600:: and it doesn’t do anything. Any help is appreciated.

That helped - thank you Sandro.

