1.2 Ensure intra-zone traffic is not always allowed

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

This is to make sure that only specific, authorized traffic is allowed between networks in the same zone.

This adds an extra layer of protection between different networks.

Solution

In this example, we'll turn off intra-zone traffic in the zone DMZ.In CLI:

FGT1 # config system zone
FGT1 (zone) # edit DMZ
FGT1 (DMZ) # set intrazone deny
FGT1 (DMZ) # end
FGT1 #

In the GUI, click on Network -> Interfaces, select the zone and click on "Edit" and turn on "Block intra-zone traffic"

See Also

https://workbench.cisecurity.org/benchmarks/15284