Skip to main content
rhap4boy
New Member
July 30, 2020
Question

Not possible to specify individual interface after adding interface to a zone?

  • July 30, 2020
  • 1 reply
  • 2122 views

Is it correct that after you add an interface to a zone, you will not be able to add the interface individually as source or destination interface to a firewall policy?  You can only add the zone.  Is there a workaround?

    1 reply

    lobstercreed
    New Member
    July 30, 2020

    That is the whole point of zones, so no, there's not a workaround. 

     

    You can still effectively control traffic between interfaces in a zone if you have the zone set not to allow intrazone traffic and then you create a policy with both the source and destination interfaces set as the zone.  Then you control traffic by specifying source/destination addresses correctly.