Zone Configurations for Root and Vsys Overview
At the root-level, you can configure a zone as shareable, enabling that zone to be used by all vsys. To share a zone, the zone must be in a shared virtual router; however, a shared virtual router can contain both shared and unshared zones.
![]() |
At the vsys level, zones are automatically created or inherited as described in Table 1.
Table 1: Zone Configuration for Root and Vsys
Each vsys also supports user-defined security zones; you can bind these zones to any shared virtual routers defined at the root level or to the virtual router dedicated to that vsys.
![]() |
Note: In ScreenOS 6.2, a new shared zone called shared-DMZ allows inter-vsys communications. NAT is also available for traffic from vsys-to-vsys based on the shared-DMZ zone to solve overlapping address issues. For details on configuring the shared DMZ zone, see the Managing Inter-Vsys Traffic with Shared DMZ Zones. |


