Skip to main content
bascheew
Visitor III
September 30, 2019
Question

Feature Request: Nested Zones

  • September 30, 2019
  • 8 replies
  • 7208 views

I'm not sure where to request features, so let me know if there is a better way to send this.

 

We would love the ability to nest zones inside other zones!  This would lower the number of policies required - especially in multi-tenant situations.  In the example below this would allow for incredible flexibility.

 

Zone - Client 1 Networks
   - Client 1, Network 1
   - Client 1, Network 2

Zone - Client 2 Networks
   - Client 2, Network 1
   - Client 2, Network 2

Zone - Guests
   - Guest, Network 1
   - Guest, Network 2

Zone - Clients
   - Client 1 Networks
   - Client 2 Networks

Zone - Untrusted
   - Clients
   - Guests

    8 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    September 30, 2019

    If a multi-tenant situation, I would recommend separating tenants by vdoms. Then they don't share routing-tables and policies.

    bascheew
    bascheewAuthor
    Visitor III
    September 30, 2019

    I agree with you, and in most cases we do use VDOMs. Thanks!

     

    That doesn't mean that nested zones couldn't still be useful, that was just the first example that came to mind.  Here's an alternate use, but substitute any use case for nesting zones:

     

     

    Zone DMZ
       -DMZ Network 1
       -DMZ Network 2

    Zone Servers
       -Servers Network 1
       -Servers Network 2

    Zone High Security
       -DMZ
       -Servers

    Toshi_Esumi
    SuperUser
    SuperUser
    September 30, 2019

    Zone doesn't aggregate networks but interfaces. Do you have multiple groups of DMZ interfaces?

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!