25 Barracuda NG Network Access Client - Administrator’s Guide2.4 Access Control Service TrustzoneEach Access Control Service belongs to a so-called trustzone. To enable a company to enforce theirsecurity policies across multiple Barracuda NG Firewalls the Barracuda NG Control Center providesAccess Control Service Trustzones as global objects. This advanced feature allows all Access ControlServices within the same trust zone to share the same set of security policies. In addition they sharea signing key, so that a mutual trust relationship can be established.On stand-alone Barracuda NG Firewalls, configuration of the trustzone is located in the configurationnode Virtual Servers > > Assigned Services > (Access ControlService) > Access Control Service Trustzones.The Barracuda NG Control Center provides Access Control Service Trustzones either within theGlobal Settings directory or specifically as Range Settings or Cluster Settings. As usual these objectspermit access only to administrators with appropriate administrative scope and appropriatepermission.Access Control Objects provide an hierarchical override mechanism. Objects on cluster level sharing the same nameas global or range objects override the global definition(s). This mechanism works like the one using global firewallobjects for the Barracuda NG Firewall.Fig. 2–7 Access Control Service Trustzone - Configuration tree