Hmm, I was also leaning towards Option C, but I'm not sure about the 'Any' source and destination addresses. Shouldn't we be more specific with the zones?
I think Option C looks promising. The policy allows traffic from the Trusted zone to the SFTP server in the DMZ zone, and it's using App-ID to identify the SFTP application.
Tiera
9 months agoRolande
9 months agoDorian
9 months agoErin
9 months agoKati
9 months agoCyndy
9 months agoClay
9 months agoCarri
9 months agoAvery
9 months ago