intra-zone default

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

intra-zone default

L6 Presenter

Hi,

Do we have an option to disable default intrazone-allow policy which is hidden.

thanks

1 accepted solution

Accepted Solutions

Hello,

There is no option available to disable the default behaviour but only way is to setup a 'any' 'any' block rule at the bottom to block same zone traffic.

The different zone traffic is not allowed by default. The zones are meant for same area traffic which needs to be allowed.

You may contact SE and request for a 'feature request' to have a configurable option instead of setting up a 'deny all' policy towards bottom.

Hope this helps.

Please mark the answer as 'Correct answer or helpful' if appropriate.

View solution in original post

5 REPLIES 5

L6 Presenter

Not any as far as i know !!

L7 Applicator

You can add an explicit "deny any any" rule at the bottom of your security policy which will override the implicit permit intra-zone policy.  That doesn't disable that default policy, but no traffic will ever hit that implicit rule because the explicit deny any rule will get hit first. 

L5 Sessionator

Hi Bulent,

By default same zone traffic is allowed and different zone traffic is denied.

If you want to block the same zone traffic you and create a security rule and define it and that will block the traffic between the same zone.

Example

Capture.JPG

Hope this helps.

Thank you

Numan

Thanks for all.I know how to block with a rule but I wonder if there is any cli command for changing default behaviour.For different vendors there is a choice to do this.I see that there is no choice for us.Thanks.

Hello,

There is no option available to disable the default behaviour but only way is to setup a 'any' 'any' block rule at the bottom to block same zone traffic.

The different zone traffic is not allowed by default. The zones are meant for same area traffic which needs to be allowed.

You may contact SE and request for a 'feature request' to have a configurable option instead of setting up a 'deny all' policy towards bottom.

Hope this helps.

Please mark the answer as 'Correct answer or helpful' if appropriate.

  • 1 accepted solution
  • 5216 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!