Block IP address for inbound \ outbound traffic

Solved
Mad_Dog_82
Conversationalist

Block IP address for inbound \ outbound traffic

Hi All,

 

I have MX68CW-WW.

Could you please advise how to block IP address for inbound \ outbound traffic.

 

Thanks. 

1 Accepted Solution
DarrenOC
Kind of a big deal
Kind of a big deal

Hi @Mad_Dog_82 , the firewall is stateful (edited @CptnCrnch 😉) so all inbound traffic is blocked by default.  For outbound traffic you need to add a Layer 3 firewall rule.

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.

View solution in original post

5 Replies 5
DarrenOC
Kind of a big deal
Kind of a big deal

Hi @Mad_Dog_82 , the firewall is stateful (edited @CptnCrnch 😉) so all inbound traffic is blocked by default.  For outbound traffic you need to add a Layer 3 firewall rule.

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
DarrenOC
Kind of a big deal
Kind of a big deal

Take a look here for config guidance:

 

https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/MX_Firewall_Settings#:~:text=The%20....

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
CptnCrnch
Kind of a big deal
Kind of a big deal

Sorry @DarrenOC, but it's stateful in that case. 😉

DarrenOC
Kind of a big deal
Kind of a big deal

Thanks for keeping me inline @CptnCrnch 

Darren OConnor | doconnor@resalire.co.uk
https://www.linkedin.com/in/darrenoconnor/

I'm not an employee of Cisco/Meraki. My posts are based on Meraki best practice and what has worked for me in the field.
jimmyt234
Building a reputation

If you happened to have inbound NAT/PAT rules configured with any source allowed then I would use the Layer 7 firewall to block Remote IP Range, this should block those IP's coming in on your NAT rules.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels