TMS zl Management and Configuration Guide ST.1.2.100916

1-18
Overview
Deployment Options for Routing Mode—Threat Protection
Figure 1-5. Plan for Zones
9. Select at least one zone from which you will manage the TMS zl Module.
Add a VLAN to this zone and assign the module an IP address on the
VLAN’s subnet. Enable management access for this zone.
In Figure 1-5, the management station is on VLAN40 (subnet 10.1.40.0/24),
which you have planned to place in Zone1. On the TMS zl Module, you
would associate VLAN40 with Zone1 and assign the module the IP address
10.1.40.99 on this TMS VLAN. You would then enable management access
for Zone1.
When you associate a VLAN with a zone, the module’s data port (port 1)
is automatically tagged for that TMS VLAN. When you enable manage-
ment access for a zone, the module automatically creates the correct
firewall access policies to support SSH, HTTPS, and SNMP access to the
module (that is, to the Self zone) from that zone. (Other access policies
are created as well. See “Management-Access Zones” on page 2-10 in
Chapter 2: “Initial Setup in Routing Mode.”)
For more detailed instructions on this step, see “Boot the TMS zl Module
to the Product OS” in Chapter 2: “Initial Setup in Routing Mode.”