Cisco Security Cloud Control: Secure Firewall Device Management

PDF

Cisco Security Cloud Control: Secure Firewall Device Management

Security zone object

Want to summarize with AI?

Log in

An overview of security zone object, including interface names, security levels, IP addressing, VLANs, and enablement options.


A security zone is a grouping of interfaces. Zones divide the network into segments to help you manage and classify traffic. You can define multiple zones, but a given interface can be in one zone only.

The Firepower system creates the following zones during initial configuration and they are displayed in Security Cloud Control's object page. You can edit zones to add or remove interfaces, or you can delete the zones if you no longer use them.

  • inside_zone: Includes the inside interface. This zone is intended to represent internal networks.

  • outside_zone: Includes the outside interface. This zone is intended to represent networks external to your control, such as the internet.

Typically, you would group interfaces by the role they play in your network. For example, you would place the interface that connects to the internet in the outside_zone security zone, and all of the interfaces for your internal networks in the inside_zone security zone. Then, you could apply access control rules to traffic coming from the outside zone and going to the inside zone.

Before creating zones, consider the access rules and other policies you want to apply to your networks. For example, you do not need to put all internal interfaces into the same zone. If you have 4 internal networks, and you want to treat one differently than the other three, you can create two zones rather than one. If you have an interface that should allow outside access to a public web server, you might want to use a separate zone for the interface.


Create a security zone object

To create a security zone object, follow these instructions:

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the left pane, click Objects.

3.

Click > FTD > Security Zone to create the object.

4.

Enter an object name and, optionally, a description.

5.

Select a mode:

  • Routed : Routed interfaces are the normal interfaces used for through traffic that can apply security policies.

  • Passive: Passive interfaces operate as packet sniffers and do not affect the traffic flow through the device.

6.

Select the interfaces to put in the security zone.

7.

Click Add.


Edit a security zone object

After onboarding an FDM-managed device, you will find there are already at least two security zones, one is the inside_zone and the other is the outside_zone. These zones can be edited or deleted. To edit any security zone object, follow these instructions:

Procedure

1.

From the Security Cloud Control Home page, click Firewall.

2.

In the left pane, click Objects.

3.

Find the object you want to edit:

  • If you know the name of the object, you can search for it in the Objects page:

    • Filter the list by security zone.

    • Enter the name of the object in the search field.

    • Select the object.

  • If you know the object is associated with a device, you can search for it starting on the Security Devices page.

    • In the left pane, click Security Devices.

    • Click the Devices tab.

    • Click the apporpriate tab.

    • Use the device filter and search bar to locate your device.

    • Select the device.

    • In the Management pane at the right, click Objects.

    • Use the object filter and search bar to locate the object you are looking for.

Note

If the security zone object you created is not associated with a rule in a policy for your device, it is considered "unassociated" and you will not see it among the search results for a device.

4.

Select the object.

5.

Click the Edit icon in the Actions pane at the right.

6.

After editing any of the attributes of the object. Click Save.

7.

After clicking Save you receive a message explaining how these changes will affect other devices. Click Confirm to save the changes or Cancel.


Create or edit a Firepower security zone object

A security zone is a grouping of interfaces. Zones divide the network into segments to help you manage and classify traffic. You can define multiple zones, but a given interface can be in one zone only.

A security zone object is not associated with a device unless it is used in a rule for that device.