Kaspersky SD-WAN

Managing firewall zones

You can view the table of common firewall zones or the table of firewall zones on the CPE device:

  • To display the table of common firewall zones, go to the SD-WAN → Firewall zones menu section.
  • To display the table of firewall zones on a CPE device, go to the SD-WAN → CPE menu section, click the CPE device, and select the Firewall settings → Zones tab.

The following firewall zones are created by default:

  • wan (WAN firewall zone) is the firewall zone for network interfaces that are connected to the WAN, for example, to the internet or the service provider network. Masquerading is enabled in the settings of the firewall WAN zone to replace the source IP address of outbound traffic packets from the firewall zone with the IP address assigned to the egress network interface.
  • lan (LAN firewall zone) is the firewall zone for network interfaces that are connected to the LAN.
  • mgmt (management firewall zone) is the firewall zone for the network interface that is used for passive monitoring of the CPE device by the Zabbix monitoring system, as well as for the SSH connection of the orchestrator to the CPE device.

You cannot delete the default firewall zones or create firewall zones with the same names.

When you upgrade Kaspersky SD-WAN from version 2.1 to 2.2, the following changes are made in the settings of all CPE templates:

  • sdwan<0–4> network interfaces are automatically added to the WAN zone of the firewall.
  • lan, br-lan, and overlay network interfaces are automatically added to the LAN zone of the firewall.

Information about common firewall zones is displayed in the following columns of the table:

The actions that you can perform with the table are described in the Managing solution component tables instructions.

Information about firewall zones on the CPE device is displayed in the following columns of the table:

  • Name is the name of the firewall zone.
  • Settings contains the actions that the firewall applies to traffic packets.
  • Interfaces/Networks are network interfaces and subnets that have been added to the firewall zone.

In this section

Creating a firewall zone

Editing the name of the firewall common zone

Cloning a firewall common zone

Viewing the usage of a firewall common zone

Editing a firewall zone on a CPE device

Deleting a firewall zone