Bind Zones to Devices
Table of Contents
Expand all | Collapse all
-
-
- Add a Branch
- Add a Data Center
- Add a Branch Gateway
- Configure Circuits
- Configure Internet Circuit Underlay Link Aggregation
- Configure Private WAN Underlay Link Quality Aggregation
- Configure Circuit Categories
- Configure Device Initiated Connections for Circuits
- Add Public IP LAN Address to Enterprise Prefixes
- Manage Data Center Clusters
- Configure a Site Prefix
- Configure a DHCP Server
- Configure NTP for Prisma SD-WAN
- Configure the ION Device at a Branch Site
- Configure the ION Device at a Data Center
- Switch a Site to Control Mode
- Allow IP Addresses in Firewall Configuration
-
- Configure a Controller Port
- Configure Internet Ports
- Configure WAN/LAN Ports
- Configure a Loopback Interface
- Configure a PoE Port
- Configure and Monitor LLDP Activity and Status
- Configure a PPPoE Interface
- Configure a Layer 3 LAN Interface
- Configure Application Reachability Probes
- Configure a Secondary IP Address
- Configure a Static ARP
- Configure a DHCP Relay
- Configure IP Directed Broadcast
- VPN Keep-Alives
-
- Configure Prisma SD-WAN IPFIX
- Configure IPFIX Profiles and Templates
- Configure and Attach a Collector Context to a Device Interface in IPFIX
- Configure and Attach a Filter Context to a Device Interface in IPFIX
- Configure Global and Local IPFIX Prefixes
- Flow Information Elements
- Options Information Elements
- Configure the DNS Service on the Prisma SD-WAN Interface
- Configure SNMP
-
-
- Prisma SD-WAN Branch Routing
- Prisma SD-WAN Data Center Routing
-
- Configure Multicast
- Create a WAN Multicast Configuration Profile
- Assign WAN Multicast Configuration Profiles to Branch Sites
- Configure a Multicast Source at a Branch Site
- Configure Global Multicast Parameters
- Configure a Multicast Static Rendezvous Point (RP)
- Learn Rendezvous Points (RPs) Dynamically
- View LAN Statistics for Multicast
- View WAN Statistics for Multicast
- View IGMP Membership
- View the Multicast Route Table
- View Multicast Flow Statistics
- View Routing Statistics
- Prisma SD-WAN Incident Policies
-
- Prisma SD-WAN Branch HA Key Concepts
- Configure Branch HA
- Configure HA Groups
- Add ION Devices to HA Groups
- View Device Configuration of HA Groups
- Edit HA Groups and Group Membership
-
- Configure Branch HA with Gen-1 Platforms (2000, 3000, 7000, and 9000)
- Configure Branch HA with Gen-2 Platforms (3200, 5200, and 9200)
- Configure Branch HA with Gen-2 Embedded Switch Platforms (1200-S or 3200-L2)
- Configure Branch HA for Devices with Software Cellular Bypass (1200-S-C-5G)
- Configure Branch HA for Platforms without Bypass Pairs
- Prisma SD-WAN Incidents and Alerts
Bind Zones to Devices
Prisma SD-WAN zbfw allows you to bind zones to devices.
Where Can I Use This? | What Do I Need? |
---|---|
|
|
Bind zones to logical Layer 3 interfaces on
a device and specify separate bindings for standard VPNs. Zones bound
to the interfaces:
WAN interface types with attached WAN circuit
labels:
- Layer 3 stand-alone interfaces
- Layer 3 sub-interfaces
- Layer 3 PPPoE interfaces
- Layer 3 bypass pair, where the WAN member interface is available for zone binding
- Layer 2 bypass pair, where the WAN member interface is single for zone binding
- Loopback bypass pairs
Layer 3 Interfaces
and Bypass pairs without a WAN circuit label:
- Stand-alone Layer 3, where Used_for is LAN
- Layer 3 bypass pair, where Used_for is LAN, and the LAN member interface is available for zone binding
- Sub-interface Layer 3, where Used_for is LAN
- Stand-alone, non-parent interface, where Used_for is NONE
- Standard tunnel interface
- Loopback bypass pairs
Zones cannot be bound
to the following types of interfaces:
- Controller interfaces
- LAN member interfaces of Layer 2 bypass pairs
- Parent interfaces of sub-interfaces and PPPoE interfaces
If
a site has both site-level bindings and device-level bindings, the
two settings’ resulting configuration is united. In the event of
a conflict between site-level bindings and device-level bindings,
device-level bindings take precedence.
- Click Map.Perform one of the following to search or select a site to display its configuration details.
- Type a site name or address in the search field.
- Click the right-facing arrow to display a list of existing sites.
- Select Options > Security Zone
Binding and then once on the appropriate
tab, click Bind Zone.Bind zones to devices from the Devices tab (zone bindings on devices override zone bindings on the site).
- Choose the zone name from the list of zones and Select.
- Choose the zone network bindings for the zone and Save.All VPNs are bound to a single zone. Verify that the networks you select for zone bindings are attached to an interface. A zone is bound to multiple networks, including LANs, WANs, or VPNs. However, each network is attached to one zone.Bind the zone to networks for a site when editing a policy set by selecting the security policy set. All VPNs are bound to a single zone and indicated as a single VPN in the Name column on the Zone Network Bindings for Zone screen. Once you have bound the zones to a site and an interface, create Security Policy Sets and Security Policy Rules for your traffic.