@jambulo wrote: Are the subnets equal to each other? Not sure what you mean. I meant if these subnets are all the same and the only reason you have more than one is mabe because one /24 isn't big enough, so you created a second. But as you wrote you want to group the servers based on their functions. Depending on the number of subnets and the hardware you are using, I would create one zone per vlan/subnet. As you group the servers by their functions this would fit perfectly into the zonenames so you have a better overview in the ruleset. If you have more than 40 subnets and you are using a PA-3020, then you have to go the way with one zone where you drop intrazone traffic, but in case you have a PA-5220 or even bigger then the number of zones will probably not be a limit in any way.
... View more