- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Content Filtering and Threat Protection through Meraki Client VPN (L2TP/IPsec)
Hi everyone,
I'm using a Meraki MX68 with several users connected via the Meraki VPN client (L2TP/IPsec) in full tunnel mode. I'm trying to determine whether the security features like content filtering and threat protection are applied to traffic from these VPN clients. I couldn't find a clear answer in the documentation, so I'm hoping someone here might have experience or insight on this.
Also, i would think if i apply group policies to these users, the features mentioned above could apply to them, but i'm not sure.
Thanks in advance for your help!
Solved! Go to solution.
- Labels:
-
Client VPN
-
Firewall
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey @gabriel-ribba
Content Filtering and Threat protection features will apply to Anyconnect/Client VPN Users.
The Threat protection page mentions the following:
In both IDS and IPS modes the following is inspected:
all traffic between LAN and the Internet
all traffic between VLANs
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey @gabriel-ribba
Content Filtering and Threat protection features will apply to Anyconnect/Client VPN Users.
The Threat protection page mentions the following:
In both IDS and IPS modes the following is inspected:
all traffic between LAN and the Internet
all traffic between VLANs
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I am not confident that content filtering is applied to client VPN users. I would test this specific case.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @PhilipDAth , I tested and it works. But only if you have full tunnel. Split tunnel, naturally doesn't get traffic instection.
I think it is the same logic as Site-to-Site VPN in full tunnel.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for testing this.
