Zone elements allow you to group network interfaces of Firewall, IPS, and Layer 2 Firewall engines.

You can use Zones to specify the receiving or sending interfaces in policies. The Zone element represents all interfaces that belong to the Zone. All rules that include a Zone element also apply to any new interfaces that you associate with the same Zone.

There are several predefined System Zones available:
  • DMZ: interfaces connected to DMZ networks.
  • External: interfaces connected to the Internet or other external networks.
  • Guest: interfaces connected to guest networks.
  • Internal: interfaces connected to internal networks.
  • Node-internal: Firewall, IPS, and Layer 2 Firewall nodes themselves. This Zone is automatically assigned to interfaces through which traffic to or from the engine node travels. It cannot be assigned to other interfaces, but it can be used in policies.

