I mimic above rules on local litespeed box, looks working -- if the 1.2.3.4T is allow list, even deny list is ALL, still can access from 1.2.3.4T
so if you remove ALL from "Denied List", there should be no "403 Forbidden" ?
and can you test on a simple static page, like /readme.html ?
also be...