ACL Policies: lack of AND logic when assigning groups #1111

Open
opened 2025-11-20 05:24:16 -05:00 by saavagebueno · 3 comments
Owner

Originally created by @reana-ovo on GitHub (Jul 30, 2024).

Currently when i add multiple groups it means devices only need to match one of the group. I can't create a policy where devices need to match both groups. It is a weird behavior because you can simply add multiple policies when you need to use an OR logic in those group selections and achieving AND logic is much more difficult.
Port ranges seems not supported yet, i saw related issues.
pic

Originally created by @reana-ovo on GitHub (Jul 30, 2024). Currently when i add multiple groups it means devices only need to match one of the group. I can't create a policy where devices need to match both groups. It is a weird behavior because you can simply add multiple policies when you need to use an OR logic in those group selections and achieving AND logic is much more difficult. Port ranges seems not supported yet, i saw related issues. ![pic](https://github.com/user-attachments/assets/251e8dc7-500c-4129-9838-414eed5596dd)
saavagebueno added the feature-request label 2025-11-20 05:24:16 -05:00
Author
Owner

@GhaziTriki commented on GitHub (Jul 30, 2024):

Indeed port range would be useful especially for UDP.

@GhaziTriki commented on GitHub (Jul 30, 2024): Indeed port range would be useful especially for UDP.
Author
Owner

@alexcupertme commented on GitHub (Aug 1, 2024):

Why not create one more group and add devices that fits condition?

@alexcupertme commented on GitHub (Aug 1, 2024): Why not create one more group and add devices that fits condition?
Author
Owner

@nazarewk commented on GitHub (Apr 23, 2025):

about port ranges: https://github.com/netbirdio/netbird/issues/1995#issuecomment-2824144423

@nazarewk commented on GitHub (Apr 23, 2025): about port ranges: https://github.com/netbirdio/netbird/issues/1995#issuecomment-2824144423
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: SVI/netbird#1111