Software Secure Access
Activity Manage

Rule does not match traffic as expected

Some things to try:

  • Check the private resource configuration.
  • Make sure that the internal address for the private resource does not duplicate or overlap with any other private resource or IP address or CIDR block typed directly into the destination in an access rule. For example, if Private Resource A is defined with a CIDR block as the internal address, and Private Resource B is defined with an IP address that is included in the same CIDR block.
  • Check the sources and destinations configured in the rule to be sure they include the problematic source and destination.
  • Endpoint requirements as specified in posture profiles are matching criteria, not security criteria. Try specifying posture profile(s) that have no requirements and see if the traffic matches.
  • Check other rules in the rule order; traffic may be hitting a different rule than the one you expect.
  • If you have deployed the client on iOS devices, see unique matching information in the "Guidelines and Limitations" section of the Set up the Zero Trust Access App for iOS Devices topic.
  • If you have configured a Private Resource, then modified the automatically created entry on the Traffic Steering page (for example, to exclude subdomains from zero-trust access), then modified addresses on the Private Resource configuration page, the resource addresses are not updated for traffic steering purposes. You must manually update the address(es) on the Traffic Steering page.