Hmm, I was also leaning towards Option C, but I'm not sure about the 'Any' source and destination addresses. Shouldn't we be more specific with the zones?
I think Option C looks promising. The policy allows traffic from the Trusted zone to the SFTP server in the DMZ zone, and it's using App-ID to identify the SFTP application.
Tiera
11 months agoRolande
10 months agoDorian
10 months agoErin
10 months agoKati
10 months agoCyndy
10 months agoClay
11 months agoCarri
11 months agoAvery
11 months ago