Citrix SD-WAN

Zones

You can configure zones in the network and define policies to control how traffic enters and leaves zones. By default, the following zones are created:

  • Internet_Zone
    • Applies to traffic to or from an Internet service using a Trusted interface.
  • Untrusted_Internet_Zone

    • Applies to traffic to or from an Internet service using an Untrusted interface.
  • Default_LAN_Zone

    • Applies to traffic to or from an object with a configurable zone, where the zone has not been set.

You can create your own zones and assign them to the following types of objects:

  • Virtual Network Interfaces (VNI)

  • Intranet Services

  • GRE Tunnels

  • LAN IPsec Tunnels

The destination zone of a packet is determined based on the destination route match. When a SD-WAN appliance looks up the destination subnet in the route table, the packet will match a route, which has a zone assigned to it.

  • Source zone

    • Non-Virtual Path: Determined through the Virtual Network Interface packet was received on.

    • Virtual Path: Determined through source zone field in packet flow header.

    • Virtual network interface - the packet was received on at source site.

  • Destination zone

    • Determined through destination route lookup of packet.

Routes shared with remote sites in the SD-WAN maintain information about the destination zone, including routes learned through dynamic routing protocol (BGP, OSPF). Using this mechanism, zones gain global significance in SD-WAN network and allow end-to-end filtering within the network. The use of zones provides a network administrator an efficient way to segment network traffic based on customer, business unit, or department.

The capability of SD-WAN firewall allows the user to filter traffic between services within a single zone, or to create policies that can be applied between services in different zones, as shown in figure below. In the example below, we have Zone_A and Zone_B, each of which has a LAN Virtual network interface.

localized image

Zones