02-10-2021 05:58 AM
Hi,
I have noted recently that ISE allows to create two overlapped NAD objects in terms of IP. Does anyone have an idea how the matching process looks like then? In our company /24 object had preference causing issues. I am wondering if this is anywhere documented.
See example below:
Solved! Go to Solution.
02-10-2021 09:23 AM
02-10-2021 09:23 AM
02-21-2021 01:46 AM
OK. I think concept is as follow.
Lets assume there are 4 NAD objects as follow:
TEST.IP1 = 80.80.80.0/24 (Type IP address)
TEST.IP2 = 80.80.80.30/32 (Type IP address)
TEST.IP3 = 80.80.80.16/32 (Type IP address)
TEST.IP4 = 80.80.80.8-9/32 (Type IP range)
Matching order will be:
1. TEST.IP2 and TEST.IP3 becuase the longest match
2. TEST.IP1 becuase IP address type has higher preference over IP range object
3. TEST.IP4 becuase IP range object has lower preference than IP address object
It may be miisleading becuase defining range 80.80.80.8-9/32 administrator expect that it will matched over entire subnet 80.80.80.0/24 but becuase IP range object has lower preference than IP address type its exactly oposite.
02-21-2021 08:04 PM
I'm curious if you tested that and confirmed the behavior of longest match?
02-21-2021 11:29 PM
Hi,
Actually our problem started when we had "IP range" object containing two IPs "80.80.80.8-9/32". It had been never matched despite the there were only one overlapped "80.80.80.0/24" IP address object. Then i asked this question why longer matches didint happen between "IP range" and "IP address". ISE documentation explains that type "IP address" has always higher preference over "IP range". Thats why my test provides results exacly as follow:
As i said it may be sometimes missleading
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: