Warning: Unreachable rule while installing VPM policy after upgrade to 7.3.6.x
search cancel

Warning: Unreachable rule while installing VPM policy after upgrade to 7.3.6.x

book

Article ID: 250942

calendar_today

Updated On:

Products

ProxySG Software - SGOS

Issue/Introduction

Warning are shown due to Policy Compile Behavior Changes in 7.x , Same VMP policy would not show any warnings in 6.7.x version. 

https://techdocs.broadcom.com/us/en/symantec-security-software/web-and-network-security/proxysg/7-2/c-determine-upgrade-downgrade-path/c-behavior-changes/behavior_73.html 

 

Environment

SGOS Release : 7.3.x

 

Cause

Known issue when VPM policy rule(s) contain IP addresses in a category definition. 

 

Resolution

The issue due to "IP addresses in a category" is fixed in version SGOS 7.3.7.1. 

However if a policy layer contains rules with identical conditions, installing policy will still results in the message for the subsequent rule(s): "Warning: Unreachable rule, conditions will be matched by a preceding rule".

We need to make sure that rule conditions are unique, so that policy coverage does not record duplicate statistics.