Hi James,
Thanks for your answer. We have a different domain for each of our clients, so each event has an associated domain, which means none of them has "Default Domain".
When creating a network I have to assign it either the "Default Domain" or one of the client domains. But the private network ranges are the same for each client, of course, but if I want to use the network "private_ips" in rules and searches, the network seems to need having the same domain that the log source, that is, if a specific log source has domain A, I need to compare the local network of its events towards a network on the same domain, then, to use the "private_ips" network on each of the customers, I need to create a "private_ips" network on each domain, at least I do not see any alternative at this moment.
Sorry if it is not clear enough, I am afraid my English is quite limited.
Best Regards,
Jorge
------------------------------
Jorge García
------------------------------
Original Message:
Sent: Thu February 27, 2020 06:27 AM
From: James Hill
Subject: Cross-Domain reference sets
A little more info around your use of Default Domain would allow a better anwer from myself.
We have a senario where we have a shared service between domain's such as a resilient internet connection which feeds each domains specific firewall. For our senario we migrated this IP range to a "service" type domain - any offence's raised against this domain is then acted as a customer itself.
Any IP's (such as athe ones allocated to the domain specific firewall is assigned to the customers network hirarchy itself.
------------------------------
JH
------------------------------