29.1 Zones Overview
Set up zones to configure network security and network policies in the USG. A zone is a group of
interfaces and/or VPN tunnels. The USG uses zones instead of interfaces in many security and
policy settings, such as Secure Policies rules, UTM Profile, and remote management.
Zones cannot overlap. Each Ethernet interface, VLAN interface, bridge interface, PPPoE/PPTP
interface and VPN tunnel can be assigned to at most one zone. Virtual interfaces are automatically
assigned to the same zone as the interface on which they run.
Figure 304 Example: Zones
Use the Zone screens (see
29.1.1 What You Need to Know
Zones effectively divide traffic into three types--intra-zone traffic, inter-zone traffic, and extra-zone
traffic.
Intra-zone Traffic
• Intra-zone traffic is traffic between interfaces or VPN tunnels in the same zone. For example, in
Figure 304 on page
C
Section 29.7.2 on page
453, traffic between VLAN 2 and the Ethernet is intra-zone traffic.
USG20(W)-VPN Series User's Guide
453
HAPTER
498) to manage the USG's zones.
2 9
Object