Hello I'm preparing to move my server that is mail/dns/www into DMZ zone. I did some tests and it seems to be working - but as good as I can test... Do I should use application (dns,smtp,pop3,imap,ftp,web-browsing) or use a services on ports 53,25,110,21,80,465,993,995)? What are you using and why? My NAT rule: My security policy: I have of course U-turn policy to allow acces to this server from my local zones. What about profiles? I did one group for servers: Is it make sens to scan trafficwith this all profiles? Could someone share their policies - please? I didn't see such topic in this forum and it could be very useful for every new PA user. With regards SLawek
... View more