Firewall rule is not updated when object group is updated
searchcancel
Firewall rule is not updated when object group is updated
book
Article ID: 385794
calendar_today
Updated On: 01-13-2025
Products
VMware VeloCloud SD-WAN
Issue/Introduction
It is possible that traffic which is expected to match the firewall rule after changing the object group is not to match the rule.
This issue is caused by the following step:
The firewall rule is configured by using an object group as shown below. In this case, the 'TestRule' firewall rule is configured to allow the source IP addresses by using the 'Test' object group. All traffic that does not match the 'TestRule' will be dropped.
Generate a flow from a source address X.X.X.X that does not match the 'TestRule'.
Update the object group and add the new source address X.X.X.X to the 'Allow' rule.
The flow created by step2 will continue to be dropped regardless of the fact that X.X.X.X must match the "TestRule".
Environment
Velocloud SDWAN, VMware SDWAN, Firewall Rule, Object group
Cause
This issue is caused by known software issue #147800.
Edge does not re-apply all the rules to the existing flow when only the object group is updated.