Communication Between Vsys Flashcards
What is the name of a special type of zone that is associated with vsys and allows it to communicate with other vsys on a firewall without the need of the traffic leaving the firewall?
external
What is external zone assoiciated with?
a specific virtual system that it can reach - the zone is external to the virtual system
How many external zones can a vsys have?
only one, regardless of how many security zones the virtual system has within it
Unlike security zones, an external zone is not associated with an interface, but with what object?
a virtual system
Do external zones have interfaces or IP addresses associated with them?
no, therefore some zone protection profiles are not supported on external zones
What is necessary to allow communication between vsys?
security policies
How many sessions are used for communication between two virtual systems?
two
A host from vsys1 needs to access a server on vsys2.
How are the two sessions established?
- host in the trust1 zone initiates traffic to the firewall, and the firewall creates the first session: source zone trust1 to destination zone untrust1; traffic is routed to vsys2, either internally or externally
- firewall creates a second session: source zone untrust2 to destination zone trust2