Hmm, I was also leaning towards Option C, but I'm not sure about the 'Any' source and destination addresses. Shouldn't we be more specific with the zones?
I think Option C looks promising. The policy allows traffic from the Trusted zone to the SFTP server in the DMZ zone, and it's using App-ID to identify the SFTP application.
Tiera
1 years agoRolande
12 months agoDorian
12 months agoErin
12 months agoKati
12 months agoCyndy
12 months agoClay
1 years agoCarri
1 years agoAvery
1 years ago