SD-WAN and zones
we had a pretty nice zone based basic configuration for new implementation. this got more complicated when the sd-wan interface was introduced. because it acts a little different.
from 6.2.1 it is possible to create firewall policies on the interfaces that are part of the sd-wan interface.
it is also possible to add these interfaces to zone, so again it should be possible to create all firewall policies based on zones. which in my opinion makes way more sense, specially if you share WAN (public) and VPN connectivity (private) on one sd-wan interface.
anyone been working on this? issues or working fine?
it did some basic testing with vpn interfaces and ended up with being unable to run diagnose debug ike ... at some point getting this error
could not connect to virtual server on /tmp/iked_recv_socket
