cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
65
Views
0
Helpful
1
Replies

Security Zone Best practice

5010
Frequent Visitor
Frequent Visitor

Is it best practice to create one security zone per interface, or should interfaces with some common traits in terms of the services behind them be grouped into the same zone?

For example, if I have 10 interfaces, would you typically create 10 zones or group some of them together?

1 Reply 1

@5010 its a matter of what best fits your environment. If you have a simple deployment then typically, one interface per zone works fine. In a larger more complex environment, I would recommend grouping interfaces with similar roles into a single zone, this helps reduce complexity in security policy design.

Remember, an interface can only be a member of one zone.

Review Cisco Networking for a $25 gift card