Sip permit-deny-mask clarification

i want to secure user/peer in sip.conf using permit-deny-mask. instead of creating deny-permit for every user/peer, can i just apply it to the carrier entry? example below.

[quote][cc101]
username=cc101
secret=test
accountcode=cc101
callerid=“station 101” <0000000000>
mailbox=101
context=default
type=friend
host=dynamic

[Carrier01]
disallow=all
allow=g729
type=friend
host=sip.carrier01.com
username=carrier
fromuser=carrier
secret=blah
deny=0.0.0.0/0.0.0.0
permit=192.168.3.0/255.255.255.0
[/quote]

only addresses using this block (192.168.3.0/255.255.255.0) can make a call.

anyone?