Overlapping objects in access control policy
Overlapping objects in access control policy are network objects that
-
contain IP addresses or port numbers that are either the same or a complete subset (fully overlapping)
-
contain some subset of repeated IP addresses but not all (partially overlapping), and
-
are listed in the Overlapping Objects tab for analysis and remediation.
Overlapping object types and remediation
The system identifies two types of overlapping objects:
-
Fully overlapping objects: Objects where the IP addresses or port numbers are either the same or a complete subset. For example, if a rule contains an object for 192.168.1.1 and another for 192.168.1.0/24, the 192.168.1.1 object is fully overlapped by the other object and is not needed in the rule.
-
Partially overlapping objects: Objects where some subset of IP addresses are repeated, but not all addresses overlap.
For fully overlapped objects, you can remediate all fully overlapped observations in the category, selected observations, or selected rules. Click Remove All Fully Overlapped Objects from Rules to remove fully overlapped objects only from the staged items.
For partial overlaps, you need to evaluate each occurrence, determine if any changes can be made, and implement those changes directly by editing the objects.
Fully overlapping objects analysis
This example shows the analysis interface for fully overlapping objects:
Partially overlapping objects analysis
This example shows the analysis interface for partially overlapping objects: