Showing results for 
Show  only  | Search instead for 
Did you mean: 


L1 Bithead

Is it possible to use DG layering to solve DaaS Zone issue??

1. Can we create a DG-DaaS whose parent will be ‘DG-AWS_DQA’.
2. Assign Seattle DQT firewall to DG-AWS_DQA
3. Assign Ashburn n future Chicago to DG-DaaS (since it has DG-AWS_DQA as parent, it will have both DaaS and DQT rules attached)

Not sure if this will work or I’m missing basic configuration that needs to be taken care of.
any ideas?


Cyber Elite
Cyber Elite


Would you be able to provide us with a more detailed explaination and/or a drawing? From what it sounds like is you will have multiple PAN's in AWS, just not sure how they will connect and/or what traffic they will need to pass.



So had the solution for this basically it's the wrong message they sent us they were trying to setup DaaS and they want to know if they have device group named DG-DaaS under the device group DG-AWS_DQA which already exists.

Hi @kpotru


Yes, it will work. All existing rules in DG-AWS_DQA will also be applied to the firewall(s) in DG-DaaS. Just make sure that you have the same zones on all firewalls configured in these device-groups or the commit will fail.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!