IP Groups - Exlude rule matches both IN and OUT erroneously
Hi Group,
Started playing with NFA at my new job and I have a question regarding IP Groups.
I wrote a perl script that pulls a list of "local" addresses from my ISPs public BGP route server. These local addresses are then assigned to two IP Groups, National and International. Since National and International traffic is metered differently by our ISP, having such a logical grouping is important to us.
The national group is working 100%, and I get the relevant values on both IN and OUT. The problem is with the International rule, which looks essentially the same as national except all networks are EXCLUDED from the match.
The issue is that both IN and OUT traffic on the International rule (the excluded netblocks) are always equivalent, always.
To test this further, I even created a new IP group that excludes only one IP, even for this group IN and OUT are exactly (wrongly) equivalent.
Does anyone have any idea what I'm doing wrong?
New to ADSelfService Plus?