Zones
Group network interfaces into zones to simplify flow rules and service ACLs.
Zones are reusable interface groups. Use them for trust boundaries such as internal, external, management, or VPN networks so flow rules and service ACLs do not need to list every interface individually.
New Flow zone items can be added.
Flow zone
A named group of interfaces for flow rules and access control lists.
Properties
Label
The label used to describe this zone.
Choose a label that describes the role of the interfaces in the zone, such as Trusted LAN, WAN, VPN, or Management.
- Data type: string
- Configuration
- Required
CLI: (cli)> config network flow zone <key> label
Interfaces
Interfaces that belong to this zone.
Any rule or ACL that references this zone applies to all enabled interfaces in this list.
- Data type: reference list
- Configuration
CLI: (cli)> config network flow zone <key> interface
