AD-SUB-06 - Non-RFC1918 (public IP) subnets count should be retrievable
Overviewβ
Using public IP addresses internally can cause:
- Routing conflicts: If public IPs are also used on the internet
- Security risks: Internal resources may be exposed
- Compliance issues: Violation of IP address allocation standards
- Connectivity problems: NAT and firewall complications
RFC1918 private ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) should be used for internal networks.
Security Recommendationβ
- Use RFC1918 private IP ranges for internal networks
- If public IPs are required internally, ensure proper isolation
- Document any exceptions with business justification
- Review subnet assignments for compliance
How the Test Worksβ
This test identifies subnets that use public IP address ranges outside of RFC1918 private ranges.
Related Testsβ
Test-MtAdSubnetNonInternalDetails- Lists public IP subnetsTest-MtAdSubnetTotalCount- Counts total subnetsTest-MtAdSubnetCatchAllCount- Identifies overly broad subnets
Test Metadataβ
| Field | Value |
|---|---|
| Test ID | AD-SUB-06 |
| Severity | Info |
| Suite | Active Directory |
| Category | AD.Site |
| PowerShell test | Test-MtAdSubnetNonInternalCount |
| Tags | AD, AD-SUB-06, AD.Site |
Sourceβ
- Pester test:
tests/ad/site/Test-MtAdSubnetNonInternalCount.Tests.ps1 - PowerShell source:
powershell/public/ad/site/Test-MtAdSubnetNonInternalCount.ps1

