Group Policies not being applied

oldroo
Getting noticed

Group Policies not being applied

HI all,

 

i understand certain policies override other policies. I have specified no other policies on the AP or switches. The only policy applied is on the vlan's themselves, where i applied the group policy.

 

I have my MX terminating all vlans, and all vlan's are routing fine. I applied a group policy to each of the vlan's, which blocks all traffic to the other vlan's.

 

The problem is, i can still ping and telnet to ports on the other vlan's.

 

Why is the group policy not being applied ?

14 Replies 14
PhilipDAth
Kind of a big deal
Kind of a big deal

Most likely an error in your group policy.

 

Could you post a screenshot of the rules and highlight the rule denying the traffic?

vlan 1 10.0.0.0 /24 Policy Name: Group A

vlan 2 10.0.1.0 /24 Policy Name: Group B

vlan 3 10.0.2.0 /24 Policy Name: Group C

 

Group A policy has: (all the others are similar as mentioned above)

 

under custom network firewall & shaping policy rules enabled.

 

# Policy   Protocol       Dest                Port

1 deny       ANY        10.0.1.0/24        ANY

2 deny       ANY        10.0.2.0/24        ANY

3 Allow      Any           Any                  Any

 

PhilipDAth
Kind of a big deal
Kind of a big deal

I think I would use a safer rule, and have a single "deny" rule blocking access to 10.0.0.0/8 (aka, block access to anything beginning with 10).

 

If the group policy has only just been applied to the VLAN its possible existing cached flows might still exist, and they will use the cached rules until they expire.  Usually waiting 10 minutes is long enough, but rebooting the MX guarantees there is no cached rules.

its been applied for at least a day.

 

I have also tried, rebooting, and forcing the devices whether cabled or using wifi to reconnect and renew IP addresses.

Also running the latest software.

PhilipDAth
Kind of a big deal
Kind of a big deal

Have any of the hosts got a group policy applied (like whitelisting) which might be overriding your VLAN group policy?

when i look at the clients at policies

 

Bandwidth limit
unlimited
Layer 3 firewall
No firewall rules
Layer 7 firewall
No Layer 7 rules
Traffic shaping
No shaping rules
Splash
None
oldroo
Getting noticed

to verify this. i selected all clients, then selected policy -> normal and applied to all clients.

 

Did a ping, still could reach other subnets.

 

Further to this behaviour.

 

If a wireless client connects via the AP, the Group policy seems to work.

If a wired client is connected via the MS switch between the MR and MX in the same vlan it can ping and connectivity is as if the policy did not exist.

PhilipDAth
Kind of a big deal
Kind of a big deal

>If a wired client is connected via the MS switch between the MR and MX in the same vlan it can ping 

 

An MX group policy applied to a VLAN acts on traffic entering the MX going to another interface.  It does not act on traffic between two hosts in the same VLAN (indeed it can not - as the traffic never gets seen by the MX).

That may have come out wrong.

 

I meant if a wired client and a wireless client in the same vlan try to ping host on other vlan, different results.

 

 

 

 

 

 

PhilipDAth
Kind of a big deal
Kind of a big deal

Are you sure you have the group policy applied to the VLAN interfaces in the MX?

yep 100% sure.

oldroo
Getting noticed

update have a TAC case open, and they have confirmed, configuration is good.

Packet captures uploaded.

 

 

oldroo
Getting noticed

Update:

 

1 Bug

Added Layer 3 Firewall rules not showing hits on specified rules. The only hits seen are on the default rule of any any.

 

1 Bug

objects cant be added to groups, error saying unknown object

 

1 expected behaviour (albeit not good):

The MX series allows connectivity from hosts on all vlan's to configured default gateways for all vlan's regardless of firewall rules / policies.

Requested their be override for this as security issue. This includes ping and http requests (from my testing)

PhilipDAth
Kind of a big deal
Kind of a big deal

You can disable access to the local status page under "Network Wide > General".

 

Firewall objects are in beta and this is a known limitation.  As it gets closer to production release these kinds of things will get added.

 

 

I've never had much luck with the hit counters.  They seem to work sometimes.  I don't rely on using them.  I use packet captures.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.