. . . . .
P O L I C Y C O N F I G U R A T I O N
About Security Policies
Version 3R2
Security Appliance User Guide
9-3
set policy from trust to untrust Host_A Server_B http
permit
save
If Server B initiates an HTTP connection, the appliance drops the packet,
since no configured policy allows any HTTP requests from the untrust
zone to the trust zone.
Figure 9-2: Interzone Policy
C O N F I G U R I N G I N T R A Z O N E P O L I C I E S
Intrazone policies control traffic to and from all hosts within the same
zone. By default, all hosts configured in the same zone can
communicate. Therefore, a policy allowing communication between hosts
within a zone is unnecessary. In
Figure 9-3
, intrazone blocking is enabled
to restrict hosts from communicating with each other. Intrazone blocking
denies all traffic between two or more subnets configured to be in the
same zone.
Use the
set zone
command with the
block
option to block intrazone
communication:
set zone {name_str} block