Hmm, I was also leaning towards Option C, but I'm not sure about the 'Any' source and destination addresses. Shouldn't we be more specific with the zones?
I think Option C looks promising. The policy allows traffic from the Trusted zone to the SFTP server in the DMZ zone, and it's using App-ID to identify the SFTP application.
Tiera
7 months agoRolande
6 months agoDorian
6 months agoErin
6 months agoKati
6 months agoCyndy
6 months agoClay
7 months agoCarri
7 months agoAvery
7 months ago