We utilize a dynamic rule to tag hosts that reside within external subnets.
This rule is based on "IP Address In Range(s)".
Over the past few months, we have noticed that several hosts that reside within internal subnets are being tagged as external.
After some research, the cause of this issue appears to be hosts that have Cloud Agent installed and also have an egress route through one of our external ranges. This seems to indicate that AssetView is applying tags based on both the host IP Address and the "Connected From" IP Address detected by the Cloud Agent.
This causes major issues with any of our reporting or dashboards that utilize our external tagging.
For now, we have modified our tag-based queries to include NOT tags.name:`Cloud Agent`, but this is not ideal.
Should we reconsider how we construct our tags, or is it possible to have AssetView ignore the "Connected From"
results in Cloud Agent?