---
title: "Configure zones"
canonical: "https://docs.aryaka.com/space/KNOW/1543463/Configure%20zones"
format: markdown
---
The Settings > Zones page allows you to segment a site into security domains on which rules can be applied to permit or deny traffic based on 5-tuple match criteria. There are two types of zones that can be configured at a site: Segments (also known as a VPN zones) DMZ Zones (can only be configured for sites with an ANAP) Segments are network-level segregation of your LAN. You can use segments to manage traffic by business function (for example, your engineering department) across multiple sites (typically organized geographically by city, region, country, and so on). They are segregated routing/security domains. Traffic from a segment at a site can access all the networks at the site. A DMZ zone is a special type of zone which has limited access. By definition, it has a lower trust level than a VPN zone and can only access the internet using a cloud security connector or a Direct Internet network. A host in a DMZ zone cannot access a host in any other zone. A DMZ zone is typically used for guest wireless network access and con only by configured for sites with an ANAP.  A zone must be created at the customer level and then associated with a site for it to have a local presence at the site. While a VPN zone can be instantiated at several sites to make up a single network segment, the DMZ zone, when instantiated at a site, is isolated from the same DMZ zone at another site. To view and edit existing zones Log in to MyAryaka. The Home page appears. Click  Security  >  Settings  in left navigation pane. The Settings page appears.  Click  Manage  in the Zones tile. The Zones page appears and displays a tile for each existing segment (VPN zone) and each DMZ zone including the two default zones: Default Zone (Segment) Guest Network (DMZ Zone) Click the tile of the zone whose details you want to view or edit. The selected zone's details page appears in read-only mode. Click the  Edit  icon. The page appears in edit mode. Edit the fields as necessary. (Optional) Click  Add New  to add a policy as described in  Create customer-level WAN Routing and Basic Firewall policies . Click  Submit . You are prompted to activate your configuration updates now or later. See  Activate configuration update s for details. To add a new zone Log in to MyAryaka. The Home page appears Click  Security  >  Settings  in left navigation pane. The Settings page appears.  Click  Manage  in the Zones tile.  The Zones page appears and displays a tile for each existing segment (VPN zone) and each DMZ zone including the two default zones: Default Zone (Segment) Guest Network (DMZ Zone) Click the  Add  icon. The Add Zones page appears.  Enter a name and, optionally, a description for the zone in the corresponding fields in the Basic Information section. Select  Segment  or  DMZ Zone  in the Type field. Add policies as described in  Create customer-level WAN Routing and Basic Firewall policies . Click  Submit . You are prompted to activate your configuration updates now or later. See  Activate configuration update s for details. Note:  While the change request is being processed by Aryaka, the status for the segment is Provisioning, and the segment  cannot  be edited. After the segment has been configured by Aryaka, it can be assigned to one or more sites as described in  Configure routing . Related topics Create customer-level WAN Routing and Basic Firewall policies Create site-level WAN Routing and Basic Firewall policies Manage match rules Create internet policies Related videos Add a zone