Software Secure Access
Activity Manage

Cisco Secure Access Help Manage the Access Policy Using Wildcard Masks on Access Rules Guidelines

Last updated: Aug 07, 2025

Guidelines

  • You can add a 32-bit IPv4 address with a wildcard mask on an Access rule, for example: 192.168.0.1/0.0.255.0.
  • Secure Access accepts valid wildcard masks only.
  • If the bit value on the position in the wildcard mask is zero (0), then the bit value on the position in the IP address must match.
  • If the bit value on the position in the wildcard mask is one (1), then the bit value on the position in the IP address is ignored.
  • Secure Access does not support a comma-separated list of wildcard masks in composite sources or destinations.
  • Secure Access does not support composite sources or destinations that include a subnet mask with an IPv4 address.