Prohibit access from "Custom" to "Trusted" network

I have created a guest network as VLAN.
The IP range is
No matter if the "Security Zone" is set to "Custom" or "Optional" - in both cases I can access the internal "Trusted" network.
Where can I change this behaviour?

  • By default - these accesses can't happen without some policy allowing it.
    Check your policies - especially ones which have To: Any and To: Any-trusted

