SonicOS/X 7 About SonicOS and SonicOSX

About the Shadow Feature

The POLICY | Rules and Policies > Shadow page shows which rules are being shadowed by other rules and which rules are shadowing other rules. Select the Policy Type at the top to view shadowing for each type of policy.

Shadow page for Security Policy

Each rule in the RULE NAME column might have a rule in the SHADOWED BY column and the SHADOWING column. The rule in the SHADOWING column might not be hit because the rule in the RULE NAME column will match the traffic first. The rules under SHADOWED BY will be hit before the rules in the RULE NAME column, possibly preventing the RULE NAME column rule from being hit.

Rules can be partially shadowed. In this case they will be hit if they match traffic characteristics that the other rule is not matching on.

For example, say A+B is being matched in rule #2 which is shadowed by rule #1, where rule #1 matches A. If traffic matches A, rule #1 will hit. If traffic matches B, rule #2 will hit.

Another example involves two subnets. Rule #1 blocks traffic matching the 10.0.0/24 subnet. Rule #2 allows traffic matching the 10.0/16 subnet.

Rule #1 shadows Rule #2. This is a partial shadow.

You can click on any rule to view details:

Shadow details for Security Policy

Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

  • Hidden
  • Hidden

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.
  • Hidden
  • Hidden