Quantcast
Channel: All ScreenOS Firewalls (NOT SRX) posts
Viewing all articles
Browse latest Browse all 2577

Re: Tunnel Interface in Trust Zone - Security Poblem?

$
0
0

The security difference will be in how your policies are setup and which zone the local traffic going into the tunnel is coming from.

 

You normal tunnels have the remote traffic in the untrust zone and I assume then your local traffic is in the trust zone.  So access to and from the tunnel traffic is controled by:

inbound: untrust to trust policies

outbound: trust to untrust policies

 

for this tunnel both the remote and local zone is trust so both directions are controled by your

trust to trust policies

 

So to see the difference you would look at the differeneces between those policies.

 

You can then either change the zone of the tunnel interface so they are the same.

Or you can add more policies to trust to trust to make the traffic on this tunnel match the security setup of your untrust to trust and trust to untrust vpn policies.

 


Viewing all articles
Browse latest Browse all 2577

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>