cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
366
Views
2
Helpful
3
Replies

FTD Question

N3om
Level 3
Level 3

Hi

Is it ok to have two interfaces in different security zones in the same vrf, So traffic comes in on a sub-interface in security zone(visitors) then egresses through a RB VPN  VTI in security zone(guest-inet) is this ok or should i be doing it a different way??

 

Thanks

1 Accepted Solution

Accepted Solutions

@N3om no, I would recommend using different zones for each interface.

View solution in original post

3 Replies 3

@N3om yes, two interfaces in two different zones should be fine, even in the same vrf. I assume this vrf is for visitors/guest traffic and segmented from your normal corporate traffic, so that would be secure.

@Rob Ingram Yes its guest and is segregated, Is it best practice to have source and destination interfaces in the same security zone then.??

Thanks

@N3om no, I would recommend using different zones for each interface.

Review Cisco Networking for a $25 gift card