Manual Chapter :
Managing Zones
Applies To:
Show VersionsBIG-IQ Centralized Management
- 8.3.0, 8.2.0, 8.1.0, 8.0.0
Managing Zones
About AFM Zones
AFM Zones allow you to specify lists of VLANs that can be referenced in a firewall rule for source or destination packet matching. Using BIG-IQ, you may create, edit, delete, and deploy Zones to managed BIG-IP devices and centrally manage your Zone objects.
Configure an AFM zone
Before you create a Zone, you must first create one or more network VLANs. Existing VLANs will populate in a list on this page.
You can create an AFM Zone to perform source and destination packet matching based on one or more VLANs. Use this workflow to assign one or more VLANs to a Zone object. To do so, select the check box next to the VLAN or VLANs you are interested in and use the arrows to move them from Available to Selected.
- To begin, go to.
- To create a new Zone, selectCreate, or select an existing Zone object to make modifications.You will be directed to a page to configure a Zone object.
- Enter a uniqueNamefor this Zone object.
- Enter aDescription.
- Enter aPartition.The default isCommon. You can also enter a custom path to a partition you have created. Only users with access to a partition can view the objects that the partition contains. If the object resides in theCommonpartition, all users can access it.
- Use the arrows to move one or more VLANs from theAvailablelist to theSelectedlist to add VLANs to this Zone.
- ClickSave & Close.
The new or modified Zone will display in the list of Zone objects.
Managing AFM zones
From BIG-IQ, you can create, view, and deploy Zones. Members of one Zone can overlap with members of another Zone.
- To begin, go to.
- To create a new Zone, clickCreate.
- To delete a Zone, select the check box for the Zone and clickDelete.
- To deploy a Zone to a managed BIG-IP device or group of devices, select the check box for all of Zones you wish to push to the target devices and selectDeploy. For more information about deployments, visitSecurity Deployment Best Practices.
- To edit an existing Zone, click the name of the Zone you would like to modify.
- To see the properties of a Zone displayed in the lower pane, click anywhere in the row except the name. In theRelated Itemsarea, you can clickShowto see items related to the Zone.