You can bind security zones at the
site-level or
at the
device-level.
You can associate a security zone with a specific interface or a
subnet or with multiple interfaces and networks at a site, including
LANs, WANs, or VPNs. However, each interface or network attaches
to only one zone. If you do not bind a security zone to an interface
or subnet, it blocks all the traffic.