Skip to main content
Version: 2.2.1-preview

AD-SUB-03 - Catch-all subnets count should be retrievable

Overviewโ€‹

Catch-all subnets (overly broad IP ranges) can cause:

  • Authentication inefficiency: Clients may authenticate to distant DCs
  • WAN congestion: Unnecessary cross-site authentication traffic
  • Security concerns: Difficult to track and audit client locations
  • Operational confusion: Site boundaries don't reflect actual topology

Common catch-all subnets include 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16.

Security Recommendationโ€‹

  • Replace catch-all subnets with specific, appropriately-sized subnets
  • Use /24 or smaller subnets for most locations
  • Document exceptions where catch-all subnets are intentionally used
  • Review subnet definitions during network planning

How the Test Worksโ€‹

This test identifies subnets with overly broad CIDR notation that could encompass multiple physical locations.

  • Test-MtAdSubnetNonInternalCount - Identifies public IP subnets
  • Test-MtAdSubnetTotalCount - Counts total subnets
  • Test-MtAdSiteWithoutSubnetCount - Identifies sites without subnets

Test Metadataโ€‹

FieldValue
Test IDAD-SUB-03
SeverityInfo
SuiteActive Directory
CategoryAD.Site
PowerShell testTest-MtAdSubnetCatchAllCount
TagsAD, AD-SUB-03, AD.Site

Sourceโ€‹

  • Pester test: tests/ad/site/Test-MtAdSubnetCatchAllCount.Tests.ps1
  • PowerShell source: powershell/public/ad/site/Test-MtAdSubnetCatchAllCount.ps1