Bind Zones to Devices
Table of Contents
Expand all | Collapse all
-
-
- Add a Branch
- Add a Data Center
- Add a Branch Gateway
- Configure Circuits
- Configure Internet Circuit Underlay Link Aggregation
- Configure Private WAN Underlay Link Quality Aggregation
- Configure Circuit Categories
- Configure Device Initiated Connections for Circuits
- Add Public IP LAN Address to Enterprise Prefixes
- Manage Data Center Clusters
- Configure a Site Prefix
- Configure a DHCP Server
- Configure NTP for Prisma SD-WAN
- Configure the ION Device at a Branch Site
- Configure the ION Device at a Data Center
- Switch a Site to Control Mode
- Allow IP Addresses in Firewall Configuration
-
- Configure a Controller Port
- Configure Internet Ports
- Configure WAN/LAN Ports
- Configure a Loopback Interface
- Configure a PoE Port
- Configure and Monitor LLDP Activity and Status
- Configure a PPPoE Interface
- Configure a Layer 3 LAN Interface
- Configure Application Reachability Probes
- Configure a Secondary IP Address
- Configure a Static ARP
- Configure a DHCP Relay
- Configure IP Directed Broadcast
- VPN Keep-Alives
-
- Configure Prisma SD-WAN IPFIX
- Configure IPFIX Profiles and Templates
- Configure and Attach a Collector Context to a Device Interface in IPFIX
- Configure and Attach a Filter Context to a Device Interface in IPFIX
- Configure Global and Local IPFIX Prefixes
- Flow Information Elements
- Options Information Elements
- Configure the DNS Service on the Prisma SD-WAN Interface
- Configure SNMP
-
-
- Prisma SD-WAN Branch Routing
- Prisma SD-WAN Data Center Routing
-
- Configure Multicast
- Create a WAN Multicast Configuration Profile
- Assign WAN Multicast Configuration Profiles to Branch Sites
- Configure a Multicast Source at a Branch Site
- Configure Global Multicast Parameters
- Configure a Multicast Static Rendezvous Point (RP)
- Learn Rendezvous Points (RPs) Dynamically
- View LAN Statistics for Multicast
- View WAN Statistics for Multicast
- View IGMP Membership
- View the Multicast Route Table
- View Multicast Flow Statistics
- View Routing Statistics
- Prisma SD-WAN Incident Policies
-
- Prisma SD-WAN Branch HA Key Concepts
- Configure Branch HA
- Configure HA Groups
- Add ION Devices to HA Groups
- View Device Configuration of HA Groups
- Edit HA Groups and Group Membership
-
- Configure Branch HA with Gen-1 Platforms (2000, 3000, 7000, and 9000)
- Configure Branch HA with Gen-2 Platforms (3200, 5200, and 9200)
- Configure Branch HA with Gen-2 Embedded Switch Platforms (1200-S or 3200-L2)
- Configure Branch HA for Devices with Software Cellular Bypass (1200-S-C-5G)
- Configure Branch HA for Platforms without Bypass Pairs
- Configure Branch HA in a Hybrid Topology with Gen-1 (3000) and Gen-2 (3200) Platforms
- Prisma SD-WAN Incidents and Alerts
Bind Zones to Devices
Prisma SD-WAN zbfw allows you to bind zones to devices.
Where Can I Use This? | What Do I Need? |
---|---|
|
|
Bind zones to logical Layer 3 interfaces on
a device and specify separate bindings for standard VPNs. Zones bound
to the interfaces:
WAN interface types with attached WAN circuit
labels:
- Layer 3 stand-alone interfaces
- Layer 3 sub-interfaces
- Layer 3 PPPoE interfaces
- Layer 3 bypass pair, where the WAN member interface is available for zone binding
- Layer 2 bypass pair, where the WAN member interface is single for zone binding
- Loopback bypass pairs
Layer 3 Interfaces
and Bypass pairs without a WAN circuit label:
- Stand-alone Layer 3, where Used_for is LAN
- Layer 3 bypass pair, where Used_for is LAN, and the LAN member interface is available for zone binding
- Sub-interface Layer 3, where Used_for is LAN
- Stand-alone, non-parent interface, where Used_for is NONE
- Standard tunnel interface
- Loopback bypass pairs
Zones cannot be bound
to the following types of interfaces:
- Controller interfaces
- LAN member interfaces of Layer 2 bypass pairs
- Parent interfaces of sub-interfaces and PPPoE interfaces
If
a site has both site-level bindings and device-level bindings, the
two settings’ resulting configuration is united. In the event of
a conflict between site-level bindings and device-level bindings,
device-level bindings take precedence.
- Click Map.Perform one of the following to search or select a site to display its configuration details.
- Type a site name or address in the search field.Click the right-facing arrow to display a list of existing sites.Select Options > Security Zone Binding and then once on the appropriate tab, click Bind Zone.Bind zones to devices from the Devices tab (zone bindings on devices override zone bindings on the site).Choose the zone name from the list of zones and Select.Choose the zone network bindings for the zone and Save.All VPNs are bound to a single zone. Verify that the networks you select for zone bindings are attached to an interface. A zone is bound to multiple networks, including LANs, WANs, or VPNs. However, each network is attached to one zone.Bind the zone to networks for a site when editing a policy set by selecting the security policy set. All VPNs are bound to a single zone and indicated as a single VPN in the Name column on the Zone Network Bindings for Zone screen. Once you have bound the zones to a site and an interface, create Security Policy Sets and Security Policy Rules for your traffic.