I didn’t realise intrazone firewalling wasn’t possible in Vyatta/VyOS but wanted it working today.
It appears to work fine if a few lines are commented out of the following files:
— prevents you from commit’ing a zone to zone rule with the same zone name
— comment out the section that adds an implicit RETURN for intra-zone traffic
After these changes, a zoneX_to_zoneX chain appears to work fine.
Is this desirable by others?