Implementing Cisco Network Security (IINS v3.0) (#9)

How does a zone-based firewall implementation handle traffic between interfaces in the same zone?

Traffic between two interfaces in the same zone is allowed by default.
Traffic between interfaces in the same zone is blocked unless you configure the same-security permit command.
Traffic between interfaces in the same zone is always blocked.
Traffic between interfaces in the same zone is blocked unless you apply a service policy to the zone pair.