Hi
I will explain how i solved the firewall policy issue (related to second issue).
I mentioned that i have two issues:
1)For the first issue, i have not solved it yet but u guys mentioned use firewall filter. I have not tried it yet. Can anyone show it to me an example (CLI configuration)
FIrst issue
----------------------------------------------------------------------------
The following is my setup environment for the first issue:
1) Security zone Z5 which contains two interfaces: fe-0/0/2 and fe-0/0/3
2) a firewall policy p which deny traffic sent from zone Z5 to Z5
The issue is that the policy does not deny the traffic sent from zone Z5 to zone Z5.
-----------------------------------------------------------------------------
2) For the second issue, i have solved it
second issue:
----------------------------------------------------------------------------
The following is my setup environment for the second issue:
1) PC A (ip address: 169.254.0.201 subnet mask: 255.255.0.0) is connected to Zone A
2) PC B (ip address: 169.254.0.5 subnet mask: 255.255.0.0) is connected to Zone B
3) an UDP program is sending UDP packet to IP address 169.254.0.5 from PC A (169.254.0.201 ) to PC B (169.254.0.5)
But policy All_zoneA_zoneB is not working such that it does not allow traffic to be sent from Zone A to Zone B.
So i changed to new setup environment
New setup
1) PC A (ip address: 169.254.0.21 subnet mask: 255.255.255.0) is connected to Zone A
2) PC B (ip address: 169.254.1.5 subnet mask: 255.255.255.0) is connected to Zone B
3) an UDP program is sending UDP packet to IP address 169.254.1.5 from PC A (169.254.0.21 ) to PC B (169.254.1.5)
4) Vlan 1 for Zone A : 169.254.0.22/24
5) vlan 2 for Zone B : 169.254.1.6/24
But it is still not working.
----------------------------------------------------------------------------
Solution for second issue
1) Any ip address starting with 169.254.x.x at Zone A will not sent traffic to zone B even the subnet mask is 255.255.255.0 (refer to https://en.wikipedia.org/wiki/Link-local_address) athough the link i posted here mentioned only IP address with 169.254.x.x/16 will not cause the router to route the traffic from Zone A to Zone B. I tried with different IP address (172.16.0.x/24 for Zone A and 172.16.100.x/24) for Zone B) and the firewall policy is working
2) Zone A and Zone B must be in different subnet (172.16.0.x/24 for Zone A and 172.16.100.x/24) for Zone B)