@jthunderbird wrote: Wow, so you cannot setup content filtering at a central location even with the advanced security license? I have to build a template to apply to all spoke nodes... This seems silly and counter to a server/client relationship. Frustration understood. I'm assuming there are two good reasons for this though: Processing overhead can be distributed vs condensed on a single appliance Its best practice (in general terms) to stop any unwanted traffic as close to the source as possible, at least from a security perspective (think ACLs etc.).
... View more