. . . . .
S E C U R I T Y Z O N E S A N D I N T E R F A C E S
Security Zones
Version 3R2
Security Appliance User Guide
3-3
•
DMZ
—The DMZ zone is commonly used to segment publicly accessible
servers from the local area network (LAN) and WAN.
•
Global
—The global zone is used to apply policies independent of
zones.
Figure 3-3
displays the security appliance with two security zones: trust
and untrust. The trust zone is configured for the LAN and the untrust
zone is configured for the WAN. Security policies can now enforce access
control between the two zones.
Figure 3-3: Security Zone (Trust and Untrust)
In addition to the four default zones, additional custom zones (refer to
Figure 3-4
) can be created to further divide the internal network into
more granular segments.
Figure 3-4: Custom Security Zones