System defined alert reporting a warning that one default rule is being masked by another default rule in Aria Operations for Networks.
search cancel

System defined alert reporting a warning that one default rule is being masked by another default rule in Aria Operations for Networks.

book

Article ID: 381699

calendar_today

Updated On:

Products

VMware Aria Operations for Networks

Issue/Introduction

System Defined alert reporting a waring that one default rule is being masked by another default rule.

A firewall rule is masked by one of more preceding rules. This condition may indicate a configuration error, such as redundant rule.

Refer to Screenshots as below:

Environment

VMware vRealize Network Insight 6.9
Aria Operations for Networks 6.10.0
Aria Operations for Networks 6.11.0
Aria Operations for Networks 6.12.0
Aria Operations for Networks 6.12.1
Aria Operations for Networks 6.13.0
Aria Operations for Networks 6.14.0

Cause

Computation of the Alert in VMware Aria Operations for Networks should be as below:
ETHERNET > EMERGENCY > INFRASTRUCTURE > ENVIRONMENT > APPLICATION

But in VMware Aria Operations for Networks  were evaluating it as :
EMERGENCY > INFRASTRUCTURE > ENVIRONMENT > APPLICATION > ETHERNET 

Resolution

This is a known issue and will be fixed in upcoming release.

As a workaround we can either ignore or Deactivate an Alert.


 

Additional Information

The order of precedence in which the rules should be evaluated is mentioned in below documentation under section Distributed Firewall policy