Default Zones (DMZ,VPN) disappear during settings import/Failover
03/26/2020 9 13544
This article explains the issue caused by HA failovers or settings import in TZ devices. If there are custom zones existing in the settings, one of the default zones, mainly DMZ or VPN are missing when there is a HA failover or the settings are imported into the firewall.
This issue has been observed in TZ 400, 500, 600 and NSA 2600 firewalls only.
The issue is caused due to a pointer not being initialized as expected, causing the bits representing the DMZ and VPN zone to be flushed by Custom Zones in the settings file.