TMS zl Management and Configuration Guide ST.1.1.100226
4-37
Firewall
Firewall Access Policies
Adding an Overlapping, Higher-Position Policy
If you add a policy that overlaps an existing policy, and the new policy is a
higher priority, then traffic in the overlapping address set that was allowed by
the original policy will be dropped and reevaluated.
In Figure 4-18, the endpoint in the Internal zone has an established FTP
session with the FTP server in the DMZ. This connection was permitted by
Internal-to-DMZ policy 2.
Figure 4-18. Example Firewall Access Policy Process