Block IP address for inbound \ outbound traffic

Solved
Mad_Dog_82
Here to help

Block IP address for inbound \ outbound traffic

Hi All,

 

I have MX68CW-WW.

Could you please advise how to block IP address for inbound \ outbound traffic.

 

Thanks. 

1 Accepted Solution
DarrenOC
Kind of a big deal
Kind of a big deal

Hi @Mad_Dog_82 , the firewall is stateful (edited @CptnCrnch 😉) so all inbound traffic is blocked by default.  For outbound traffic you need to add a Layer 3 firewall rule.

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.

View solution in original post

5 Replies 5
DarrenOC
Kind of a big deal
Kind of a big deal

Hi @Mad_Dog_82 , the firewall is stateful (edited @CptnCrnch 😉) so all inbound traffic is blocked by default.  For outbound traffic you need to add a Layer 3 firewall rule.

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
DarrenOC
Kind of a big deal
Kind of a big deal

Take a look here for config guidance:

 

https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/MX_Firewall_Settings#:~:text=The%20....

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
CptnCrnch
Kind of a big deal

Sorry @DarrenOC, but it's stateful in that case. 😉

DarrenOC
Kind of a big deal
Kind of a big deal

Thanks for keeping me inline @CptnCrnch 

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
jimmyt234
A model citizen

If you happened to have inbound NAT/PAT rules configured with any source allowed then I would use the Layer 7 firewall to block Remote IP Range, this should block those IP's coming in on your NAT rules.

Get notified when there are additional replies to this discussion.