Description
This article discusses the intent definition on a CSO admin page. It defines what the object "Internet" means while creating a FW Policy
Symptoms
Requirement of the user is to allow traffic coming from IPVPN all the way from Phubs into a Spoke. Then exit out to the internet via a ZIBO breakout profile towards Zscaler tunnel.
Solution
In a CSO UI, ALL Sites for a tenant are usually configured with a FW Policy rule, which defines All Sites --> Destination (Object:- Internet). This intent would allow traffic from LAN segment towards untrust, hence would create a LAN Zone to Untrust Zone traffic.
However, traffic from (IPVPN ---> Phub --- ipsec/gre --- Spoke ) would land onto trust zone and the "Internet" object intent would not allow this traffic.
To allow this traffic, as user must define a specific Zone based FW Policy, defining source Zone as "Trust", and destination zone as "Untrust".
Add the source address book with the allowed source prefixes and the destination address book with the allowed destination addresses.
Lastly, select the action as allow and save, then deploy the intent.
Modification History
.
Related Information
Reference case :- 2022-0508-469398
Understanding the meaning of 'Internet' when defining an Intent in CSO and the traffic it allows