Skip to content

Security Zone

Configure Security Zone.

  • Each Security Zone must have either vpns or interfaces configured, but not both.
  • VPN names must reference existing LAN VPNs defined in service_profiles.lan_vpns.
Diagram

policy_object_profile (sdwan.feature_profiles)

Section titled “policy_object_profile (sdwan.feature_profiles)”
NameTypeConstraintMandatoryDefault Value
security_zonesList[security_zones]No

security_zones (sdwan.feature_profiles.policy_object_profile)

Section titled “security_zones (sdwan.feature_profiles.policy_object_profile)”
NameTypeConstraintMandatoryDefault Value
nameStringRegex: ^[^&<>! "]{1,32}$Yes
vpnsListString[Regex: ^[^&<>! "]{1,128}$]No
interfacesListString[Regex: (ATM|ATM-ACR|AppGigabitEthernet|AppNav-Compress|AppNav-UnCompress|Async|BD-VIF|BDI|CEM|CEM-ACR|Cellular|Dialer|Embedded-Service-Engine|Ethernet|Ethernet-Internal|FastEthernet|FiftyGigabitEthernet|FiveGigabitEthernet|FortyGigabitEthernet|FourHundredGigE|GMPLS|GigabitEthernet|Group-Async|HundredGigE|L2LISP|LISP|Loopback|MFR|Multilink|Port-channel|SM|Serial|Service-Engine|TenGigabitEthernet|Tunnel|TwentyFiveGigE|TwentyFiveGigabitEthernet|TwoGigabitEthernet|TwoHundredGigE|Vif|Virtual-PPP|Virtual-Template|VirtualPortGroup|Vlan|Wlan-GigabitEthernet|nat64|nat66|ntp|nve|ospfv3|overlay|pseudowire|ucse|vasileft|vasiright|vmi)(\w+)((\/\d+)*(\.\d+)?)?]No

Example-1: This example demonstrates how to configure a Security Zone with VPNs.

sdwan:
feature_profiles:
policy_object_profile:
security_zones:
- name: security_zone1
vpns:
- service_lan_vpn1
- service_lan_vpn2

Example-2: This example demonstrates how to configure a Security Zone with Interfaces.

sdwan:
feature_profiles:
policy_object_profile:
security_zones:
- name: security_zone2
interfaces:
- GigabitEthernet1
- GigabitEthernet2