Creating a zone pair

A zone pair has a source security zone and a destination security zone. The device examines received first data packets and uses zone pairs to identify data flows.

You can use the zone-pair security source any destination any command to define the any-to-any zone pair. This zone pair matches all packets from one security zone to another security zone.

After you apply security policies to zone pairs, the device processes data flows based on security policies.

If you apply an object policy and a packet filtering policy to a zone pair, the object policy takes precedence.

To create a zone pair:

Step

Command

Remarks

1. Enter system view.

system-view

N/A

2. Create a zone pair and enter zone pair view.

zone-pair security source { source-zone-name | any } destination { destination-zone-name | any }

By default, no zone pair exists