Can you send me a screengrab of the rule in the User Interface? I forget what is what in the code but I think it can be done with one rule, but I'd have to look at your current rule to explain what it means.
The rules are read line by line... if it hits a "restrict if" rule that fails it stops there and immediately fails. If it hits an "allow if" rule that passes, it stops and allows access without going on to the next line. So it can be a bit confusing to figure out sometimes which to use.