When creating or modifying IP Restriction rules in the Symantec Identity Security Platform (IDSP) admin console, users may observe the following:
- Multiple rules assigned the same priority value appear to be logically "bound" together.
- Modifying the priority or settings of one rule automatically updates other rules sharing that same priority.
- Changes cannot be isolated to a single rule without affecting the group.
Product: Symantec Identity Security Platform - IDSP (formerly VIP Authentication Hub)
Version: 4.0.01157 and later
A defect in the admin console's policy evaluation and management interface causes rules with identical priority values to be treated as a single entity during a browser session. This behavior occurs most frequently when creating multiple new rules simultaneously before a save operation is performed.
This issue is scheduled to be addressed in a future release of the Symantec Identity Security Platform.
Workaround
To prevent rules from binding together and to avoid accidental policy changes, follow these best practices:
1. Use Unique Priorities:Always assign a unique numeric priority to each rule during the creation phase. Avoid using placeholder values that overlap with existing rules.
2. Save Individually: Instead of creating multiple rules in one batch, save each rule individually after assigning its priority. This forces the console to commit the rule with its specific ID and priority, preventing it from binding to others.
3. Correction Steps: If rules are already bound, delete the affected rules and recreate them one by one, ensuring unique priorities are assigned and saved at each step.