Can I create an IP addresses group for Layer 3 Firewall rule?

Solved
Mad_Dog_82
Here to help

Can I create an IP addresses group for Layer 3 Firewall rule?

Hi All,

 

Referring to this article https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/MX_Firewall_Settings#:~:text=The%20...

It says for Layer 3 Firewall outbound rule, multiple comma separated IP addresses can be added as destination. 

What if I need to add say 20 addresses and the number of addresses will grow month by month?

Can I create an IP addresses group and refer to that group in the Destination field?

Mad_Dog_82_0-1726464970612.png

Thanks in advance.

1 Accepted Solution
Brash
Kind of a big deal
Kind of a big deal

You can certainly do multiple comma separated IP addresses in the L3 firewall rules.

However for your scenario where there are 20+ addresses, you may want to look at using policy objects to group them.
Network Objects Configuration Guide - Cisco Meraki Documentation

View solution in original post

4 Replies 4
Brash
Kind of a big deal
Kind of a big deal

You can certainly do multiple comma separated IP addresses in the L3 firewall rules.

However for your scenario where there are 20+ addresses, you may want to look at using policy objects to group them.
Network Objects Configuration Guide - Cisco Meraki Documentation

Mad_Dog_82
Here to help

Hi @Brash 

 

Thanks for your reply.

Just wondering if the highlighted rule already blocks all outbound traffic?

Otherwise I don't understand what it is for.

 

Mad_Dog_82_0-1726468247349.png

Thanks.

Brash
Kind of a big deal
Kind of a big deal

I'm not actually sure. I don't think I've ever seen a rule before that's all blank. I would have assumed the dashboard wouldn't let you save it.

Typically a block all outbound traffic rule would have "Any" for all of the source and destination IP's and Ports.

PhilipDAth
Kind of a big deal
Kind of a big deal

That rule is malformed.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels