1.2 Ensure intra-zone traffic is not always allowed

Information

This is to make sure that only specific, authorized traffic is allowed between networks in the same zone.

This adds an extra layer of protection between different networks.

Solution

In this example, we'll turn off intra-zone traffic in the zone DMZ.In CLI:

FGT1 # config system zone
FGT1 (zone) # edit DMZ
FGT1 (DMZ) # set intrazone deny
FGT1 (DMZ) # end
FGT1 #

In the GUI, click on Network -> Interfaces, select the zone and click on "Edit" and turn on "Block intra-zone traffic"

See Also

https://workbench.cisecurity.org/benchmarks/15284