Safari Books Online is a digital library providing on-demand subscription access to thousands of learning resources.
This section briefly examines the use of the ZFW approach in a topology that employs the Transparent mode. The policy building blocks and structure are completely analogous to those used so far, with the particularity that the ZFW-enabled interfaces reside on the same L3 subnet.
Example 10-23 assembles the commands for Transparent mode operation in the network represented in Figure 10-11. In this arrangement, Routers R1 and R2 are connected to subnet 10.10.10.0/24 but located on different security zones. A ZFW policy called OUTBOUND1 controls connection setup from zone INSIDE to zone OUTSIDE.