Internet gateway traffic that flows between zones and that doesn't match the rules you defined
matches the predefined interzone-default rule at the bottom of the rulebase and is
denied. (The predefined intrazone-default allow rule matches traffic within the same
zone by default; only traffic between different zones is denied by default.) To gain
visibility into the traffic that doesn't match the allow and block rules you
created, enable logging on the interzone-default rule: