Core issue
The following " Error: CIDS 5.0 Validation Error: 'service NetworkAccess' Config Item: 'ip-address netmask' Reason:/ip-address/ -- The IP network address, x.x.x.x/24, specifies an IP address that is partially masked by the net mask " error message appears when the never-shun command is used with the wrong subnet mask.
Resolution
As a workaround, make sure that the never-shun-hosts ip-address command is configured with a 32-bit subnet mask. Refer to the Configuring Addresses Never to Block section of Configuring the Sensor Using the CLI for usage guidelines on this command
Refer to the Upgrading to 5.0 section of the Release Notes for Cisco Intrusion Prevention System 5.0 for additional help.
.