Internal Zone to External Zone policy not applying
Hi,
I've had an issue with a 200F v7.2.8
We have an issue where policies for VLANs attached to a port that is part of a Zone labelled DMZ are not applied when using the Zone in the firewall policy.
for example
Port 2 has multiple separate VLANs that are various DMZ networks.
Port 2 is assigned to the DMZ Zone
One such DMZ VLAN is a quarantine DMZ (for testing suspicious USBs etc)
Port 24 is our main internet connection assigned to the WAN zone
If I create a rule From DMZ Zone to WAN Zone with source set to the IP Range used on the quarantine DMZ destination all, service all
I see no traffic hit that rule and logs show traffic from the IP of the device being blocked.
Even if I use a DMZ Zone interface source all to WAN destination all I still get not policy hits.
If I modify the rule so that the incoming interface is the Quarantine VLAN instead of the DMZ zone then the policy works.
I've worked around this by using the VLANs for the rules but I would like to consolidate our rules to start tidying this up by using zones.
