---
title: "FAQ: How do I segment a site?"
canonical: "https://docs.aryaka.com/space/KNOW/1271693648/FAQ%3A%20How%20do%20I%20segment%20a%20site%3F"
format: markdown
---
This topic includes questions users often ask about segmenting their site into VLANs and into zones. 

### Can the LAN interface of the ANAP support multiple VLANs?

Yes, the ANAP’s LAN interface (LAN: copper; FLAN: fiber) can support multiple VLANs. These VLANs can belong to different VPN and DMZ zones.

### Can VPN and DMZ zones be hosted on different physical interfaces of the ANAP?

Currently, the ANAP only has one active LAN-facing interface. This is either the LAN interface, which uses copper or the FLAN interface, which uses fiber. This interface can have the following multiple zones configured on it:

- Corporate Zone—A VPN zone, which includes VLANs 0, 1, and 2
- Lab Zone—A VPN zone, which includes VLANs 12 and 13
- Guest Zone—A DMZ zone, which includes VLANs 20 and 22

### How many zones can a site have?

A site with an ANAP can have a maximum of 32 zones. A site without an ANAP can have only have a single VPN zone. 

### How many VLANs can a zone have?

A site with an ANAP can have zones that can be configured with up to 4000 VLANs. A site without an ANAP does not use VLANs to identify a zone. All traffic arriving at the POP from a site’s tunnel belongs to a single VPN zone.

### Can traffic between VLANs be blocked?

Traffic between VLANs that belong to the same zone can be blocked if [inter-VLAN traffic control](https://aryakadocs.atlassian.net/wiki/spaces/KNOW/pages/1271562287) is enabled for the site. See [Configure routing](https://aryakadocs.atlassian.net/wiki/spaces/KNOW/pages/1511461) for details on enabling this feature for a site with an ANAP. Traffic between VLANs that belong to different zones is blocked by the default [Interzone Firewall rule](https://aryakadocs.atlassian.net/wiki/spaces/KNOW/pages/1275232263/FWaaS#Interzone-firewall).

### Is traffic between zones at a site permitted or denied by Aryaka?

Traffic between a site’s local zones is denied by the Interzone Firewall table’s default rule. Specific traffic between zones may be permitted by a user-defined Interzone Firewall rule. For more information, see the Interzone Firewall section of the Aryaka [Basic Firewall](https://aryakadocs.atlassian.net/wiki/spaces/KNOW/pages/1275232263) topic.

### Can a site’s zone access the same zone of another site?

It depends on the type of zone:

- A client at a DMZ zone cannot access a server in the same DMZ zone at a remote site.
- A client at a VPN zone can access a server with the same VPN zone at a remote site unless the following conditions are true:
  - The destination’s route is not known to the local site.
  - There is a WAN Routing rule at the local site that blackholes the traffic. For more information, see the WAN routing section of the Aryaka [Basic Firewall](https://aryakadocs.atlassian.net/wiki/spaces/KNOW/pages/1275232263) topic.

Note that a client at a VPN zone cannot access a server at a different VPN zone at a remote site as the route for the destination zone at the remote site is not known in the local site’s zone routing table.

### How does segmenting a site into zones affect the bandwidth sent to the Aryaka POP?

Segmenting a site into zones and VLANs does not affect the bandwidth guaranteed by Aryaka’s Core Services. The WAN ISP bandwidth is allocated to various WAN-side networks including VPN Path Aryaka, VPN Path Internet, Direct Internet, and so on. This allocation is unaffected by which zones send traffic over these networks.