Overlapping objects in access control policy

Overlapping objects in access control policy are network objects that

  • contain IP addresses or port numbers that are either the same or a complete subset (fully overlapping)

  • contain some subset of repeated IP addresses but not all (partially overlapping), and

  • are listed in the Overlapping Objects tab for analysis and remediation.

Overlapping object types and remediation

The system identifies two types of overlapping objects:

  • Fully overlapping objects: Objects where the IP addresses or port numbers are either the same or a complete subset. For example, if a rule contains an object for 192.168.1.1 and another for 192.168.1.0/24, the 192.168.1.1 object is fully overlapped by the other object and is not needed in the rule.

  • Partially overlapping objects: Objects where some subset of IP addresses are repeated, but not all addresses overlap.

For fully overlapped objects, you can remediate all fully overlapped observations in the category, selected observations, or selected rules. Click Remove All Fully Overlapped Objects from Rules to remove fully overlapped objects only from the staged items.

For partial overlaps, you need to evaluate each occurrence, determine if any changes can be made, and implement those changes directly by editing the objects.

Fully overlapping objects analysis

This example shows the analysis interface for fully overlapping objects:

Fully overlapping objects interface
The analysis interface for managing fully overlapping objects in access control policy, illustrating options for remediation and removal of observations.

Partially overlapping objects analysis

This example shows the analysis interface for partially overlapping objects:

Partially overlapping objects interface
The analysis interface for partially overlapping objects in an access control policy, illustrating how different objects interact within the policy framework.