Creating Layer 2 Security Zones
A Layer 2 security zone is a zone that hosts Layer 2 interfaces.
Before You Begin |
|---|
For background information, read Understanding Layer 2 Security Zones. |
This example configures the security zone l2–zone1 to include the previously configured Layer 2 logical interface ge-3/0/0.0 and security zone l2-zone2 to include the Layer 2 logical interface ge-3/0/1.0. In addition, l2-zone2 is configured to allow all supported application services (such as SSH, Telnet, SNMP, and other services) as host-inbound traffic.
You can use either J-Web or the CLI configuration editor to configure Layer 2 security zones.
This topic covers:
J-Web Configuration
To create a Layer 2 security zone:
- Select Configure>CLI Tools>Point and Click CLI.
- Next to Security, click Configure or Edit.
- Next to Zones, click Configure.
- Next to Security zone, click Add new entry.
- In the Name box, type l2–zone1, and then click OK to return to the Security Zones page.
To create a Layer 2 security zone and allow host-bound traffic:
- Next to Security zone, click Add new entry.
- In the Name box, type l2–zone2.
- Next to Host inbound traffic, click Configure.
- To allow the security zone to use all supported application services, next to System services, click Add new entry.
- From the Service name list, select All, and then click OK.
- Click OK to return to the Security Zones page.
To configure an interface and assign it to the created security zone:
- On the Security Zones page, next to the newly created security zone l2–zone1, click Edit.
- Next to Interfaces, click Add new entry.
- In the Interface unit box, type ge-3/0/0.0, and then click OK to return to the Security Zones page.
- Next to the newly created security zone l2–zone2, click Edit.
- Next to Interfaces, click Add new entry.
- In the Interface unit box, type ge-3/0/1.0, and then click OK to return to the Security Zones page.
- Click OK to return to the Zones page.
- Click OK to return to the Security page.
CLI Configuration
To create a Layer 2 security zone and assign interfaces to the zone:
To configure a Layer 2 security zone to allow host-inbound traffic:
Hide Navigation Pane
Show Navigation Pane
Download
SHA1