Security zones

Security zones segment your network to help you manage, classify, and decrypt traffic flow by grouping interfaces across multiple devices. Security zones control or decrypt traffic based on its source and destination zone.

Zone configuration requirements

When configuring security zones, consider these requirements:

  • If you add both source and destination zones to a zone condition, matching traffic must originate from an interface in one of the source zones and leave through an interface in one of the destination zones.

  • All zones used in a zone condition must be of the same type (all inline, passive, switched, or routed).

  • You cannot use a zone with passive interfaces as a destination zone because devices deployed passively do not transmit traffic.

  • Minimize the number of matching criteria whenever possible, especially for security zones, network objects, and port objects. If you specify multiple criteria, the system must match every combination of the criteria contents.

Tip

Constraining rules by zone is one of the best ways to improve system performance. If a rule does not apply to traffic through any of device's interfaces, the rule does not affect that device's performance.