---
title: "Inter-VLAN traffic control"
canonical: "https://docs.aryaka.com/space/KNOW/1271562287/Inter-VLAN%20traffic%20control"
format: markdown
---
Inter-VLAN traffic control is an optional feature you can enable for your sites to restrict traffic between the VLANs of a zone. This document provides an overview of inter-VLAN traffic control and describes how to enable this feature in MyAryaka. Inter-VLAN traffic control overview Every site has  inter-zone  traffic control enabled by default. This feature, which cannot be disabled, allows the  Interzone Firewall security engine  to inspect traffic between the VPN or DMZ zones of a site and determine whether to permit or deny the zone-crossing traffic according to configured security rules. However, this does not include inspection of traffic between different VLANs within a zone. Inter-VLAN  traffic control can be enabled for sites with an ANAP. When inter-VLAN traffic control is enabled for a site, the traffic between the VLANs of a zone at the site is inspected by the security engines and the traffic is permitted or denied according to your security rules. If this feature is disabled for a site, the security engines do  not  inspect the traffic between the VLANs within a zone at that site. Inter-VLAN traffic control cannot be enabled for sites without an ANAP. These sites only support one VPN zone, which does not support multiple VLANs. For sites with inter-VLAN traffic control enabled, you can configure  perimeter policies  and  security rules  to control the inspection of traffic between the VLANs of a zone at the site. When configuring Next Generation Firewall security rules for inter-VLAN traffic, you can use the source and destination IP address as match criteria in the rule. Default configuration Inter-VLAN traffic control is disabled by default. This means that any traffic sent between VLANs within a zone is allowed. Note that, due to the default Interzone Firewall rule, traffic sent between VLANs in different zones is denied. If you want to allow this traffic, you can create an  Interzone Firewall rule  to do so.  If Inter-VLAN traffic control is enabled for a site, the following defaults apply: If there is a rule match in the ANAP’s routing table, the traffic is  blackholed  (that is, the traffic is denied and no message is sent to the sender).  If there is no rule match in the ANAP’s routing table, the traffic is inspected by the Next Generation Firewall security engine—if there are no rule matches, traffic is permitted and skips further inspection.  Best practices Consider the following best practices when configuring inter-VLAN traffic control: Use Next Generation Firewall rules to control inter-VLAN traffic within a zone.  When you enable inter-VLAN traffic control for a site, traffic within a zone is permitted by default. For sites with NGFW-SWG,  configure a Next Generation Firewall rule  to block inter-VLAN traffic based on your organization’s needs.  Use Interzone Firewall rules to control inter-VLAN traffic between zones.  When you enable inter-VLAN traffic control for a site, cross-zone traffic is blocked by default.  Configure an Interzone Firewall rule  to allow cross-zone inter-VLAN traffic based on your organization’s needs. Test new rules . Test inter-VLAN rules you want to add to your configuration in a safe environment before applying them to your network. Monitor inter-VLAN traffic.  Regularly audit your logs to ensure your inter-VLAN rules are operating as expected. If you discover that you need to block a certain type of traffic or create a rule exception due to a false positive, you can modify the rule or create additional rules as needed. Configuration You can enable inter-VLAN traffic control for an individual site in MyAryaka. See the following topics for instructions on how to configure this features: To enable Inter-VLAN traffic control for a site, see step 8 of the  Configure routing for sites with an ANAP  procedure described in the  Configure routing  topic. To configure rules to block inter-VLAN traffic within a zone, see the  Configure site-level security features  topic to configure a Next Generation Firewall rule. To configure rules to allow inter-VLAN traffic between different zones, see the  Create Internet policies  topic to configure an Interzone Firewall rule.  Related topics Configure routing Configure site-level security features