Specifying the default action for packets between interfaces in the same security zone
By default, packets exchanged between interfaces in the same security zone are dropped if no zone pair is configured from a security zone to the security zone itself. You can use this feature to change the processing policy for the packets.
To specify the default action for packets exchanged between interfaces in the same security zone:
Step | Command | Remarks |
---|---|---|
1. Enter system view. | system-view | N/A |
2. Specify the default action for packets exchanged between interfaces in the same security zone. |
| By default, the default action is deny for packets exchanged between interfaces in the same security zone. |