Hmm, I was also leaning towards Option C, but I'm not sure about the 'Any' source and destination addresses. Shouldn't we be more specific with the zones?
I think Option C looks promising. The policy allows traffic from the Trusted zone to the SFTP server in the DMZ zone, and it's using App-ID to identify the SFTP application.
Tiera
8 months agoRolande
8 months agoDorian
8 months agoErin
8 months agoKati
8 months agoCyndy
8 months agoClay
8 months agoCarri
8 months agoAvery
8 months ago