Idea ID 2762019
Based on our understanding of Compliance status for configuration rules in MF NA, there are only two status options for rules within a policy, Compliant - Yes or No.
Based on rule definition and criteria's selected there is a possibility of 3rd status like "Not Applicable" where rule condition is not matching and we can't decide on the compliance based on available information and logic applied. However in current scenario all those not applicable scenarios are also reported as "compliant".
Our request is to make this new status available so as to have an accurate compliance reporing.
Just to give more information let us see the below example:
We have a policy where we are checking software version on the routers.
Our requirement is as follows:
Rule 1 - if router model is X then Software on that device should be "12.2.x".
Rule 2 - if router model is Y then Software on that device should be "13.2.x".
Rule 3 - if router model is Z then Software on that device should be "14.2.x".
so we will create 3 different rules with Boolean expression as "if A then B", where A is having model details and B is having version details.
In the inventory where policy is applied there are combination of routers with different models and all rules within a policy are validated against each router. Currently it will report as Compliant for Rule 1 and Rule 2 even if the router doesn't belong to that model. The router belong to model mentioned in Rule 3 which will give me correct result based on software running on that device. Ideally for a device it is expected to give compliant/non-compliant status and other rules status should be "Not Applicable". Thus giving correct information on software compliance level for the device.
Is it something already available or some enhancement in the tool need to happen to introduce this new status? Appreciate if you can look into this scenario on priority and take decision.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.