If the VLAN interfaces are set in different L3 security zones from the
Ethernet interfaces with which they're paired, Security policy rules must be
configured for the solution to work. The figure below shows example rules when
multiple VLAN interfaces have been configured to support multiple Ethernet
interfaces.
Policy rule 1: This policy rule allows relayed unicast DHCP messages from the
zones assigned to interfaces ethernet1/1 - ethernet1/3 to the DHCP zone. In
addition, enable log forwarding and choose the log-forwarding profile you
previously created to send EALs for this traffic to the logging service.
If you name the log forwarding profile "default" (all lowercase), the
firewall will automatically apply it to new Security policy rules when
they're created—or when they're
imported from Device Security.
Doing this will save you time and effort when importing Security policy
rule recommendations from
Device Security. Because imported rule
recommendations don't include a log forwarding profile, you have to add
one manually to each rule after you import it. However, by naming the
profile "default", you can avoid this step. (Note that the "default" log
forwarding profile will be applied when adding new Security policy rules,
but it won't be retroactively applied to existing rules.)
Policy rule 2: This rule allows ping (ICMP echo requests) from the VLAN
interfaces in the DHCP zone to networks configured on ethernet1/1 -
ethernet1/3.
Policy rule 3: This rule allows ping from the IP addresses assigned to
ethernet1/1 - ethernet1/3 to VLAN interfaces configured in the DHCP zone.