Creating VLAN interfaces
(20 December 2010, ScreenOS 6.2)
This is stupid-simple, but I always forget exactly how to do it. There's always the temptation to set up the security zone and interface as a VLAN type, but that's wrong.
So:
Create your new security zone as a layer-3 security zone.
Go to the interfaces page.
Select New SubInterface.
On this screen you can now set:
- the physical interface (or bgroup) to use
- the VID
- the security zone (which you created above)
- IP and management information for the interface (usually I don't have a management IP, and enable only ICMP management)
Tag up the switchport which is connected to the physical interface in use, set your policies, and you should be good to go.