02-19-2026 04:15 AM
Hi
Is it ok to have two interfaces in different security zones in the same vrf, So traffic comes in on a sub-interface in security zone(visitors) then egresses through a RB VPN VTI in security zone(guest-inet) is this ok or should i be doing it a different way??
Thanks
Solved! Go to Solution.
02-19-2026 05:37 AM
@N3om no, I would recommend using different zones for each interface.
02-19-2026 04:23 AM
@N3om yes, two interfaces in two different zones should be fine, even in the same vrf. I assume this vrf is for visitors/guest traffic and segmented from your normal corporate traffic, so that would be secure.
02-19-2026 05:34 AM
@Rob Ingram Yes its guest and is segregated, Is it best practice to have source and destination interfaces in the same security zone then.??
Thanks
02-19-2026 05:37 AM
@N3om no, I would recommend using different zones for each interface.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide