Early Access: Organization Wide Group Policies

RWelch
Kind of a big deal
Kind of a big deal

Early Access: Organization Wide Group Policies

Organization Wide Group Policies.png

Security-NEW.png

 

Not sure when it became early access in the dashboard but I just noticed it.  Recall reading something about it earlier.

 

Organization Wide Group Policies

Enables organization wide group policy firewall rules for MX.

 

Update: found it - Meraki MX Group Policy Has Been Supersized to Organization-Wide! 

 

And as a bonusOrganization-wide Group Policy with video (noice)!

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
11 Replies 11
RaphaelL
Kind of a big deal
Kind of a big deal

I enabled it earlier this week and I'm not too impressed. 

 

At the moment it's org-wide group policies firewall. The configuration is a bit confusing and not too user friendly.

 

But I'm sure it will improve overtime ! 

PhilipDAth
Kind of a big deal
Kind of a big deal

This does sound like an interesting feature.

 

At the moment I have scripts to copy group policies from one network to another.  Having one central place would help.

GIdenJoe
Kind of a big deal
Kind of a big deal

To be clear, this DOES or DOES NOT require any Secure Connect or Secure Access connectivity.
Is this a merger of the L3/4 firewall rules or does this also include group policy settings like content filter.  And when you enable that do you still get the group policy overrides locally?

GIdenJoe
Kind of a big deal
Kind of a big deal

So I checked it out a bit but I don't have an MX supporting 19.x so I can't really test it but I noticed following:

This only pertains to the MX firewall rule settings including L7 NBAR based rules alas excluding countries...
So I believe (correct me if I'm wrong) all the content filtering is still done the regular way using local per network settings and local group policies.

RaphaelL
Kind of a big deal
Kind of a big deal

Correct ! 

RWelch
Kind of a big deal
Kind of a big deal

Screenshot 2025-08-13 at 13.27.50.png

After enabling (opt-in) Organization Wide Group Policies, the header at the top of the browser indicates Cisco Plus Secure Connect.  

I've yet to see in the document where it elaborates - likely because it's an early beta (trial).

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
Ryan_Miles
Meraki Employee All-Star Meraki Employee All-Star
Meraki Employee All-Star

Yes the browser tab name needs fixing

Ryan_Miles
Meraki Employee All-Star Meraki Employee All-Star
Meraki Employee All-Star

It's a GP that today can apply to MX VLAN interfaces. Broader use cases are in the future.

GIdenJoe
Kind of a big deal
Kind of a big deal

Hey @Ryan_Miles does the document mention what happens to local firewall rules when you enable the feature.  My network at  home has a non supported MX so I couldn't really use the feature save for some settings.

However when you enable it on an org which of course has existing firewall rules.  How are these processed?  Before the org wides, after?  Since port forwarding is not really a thing in the group wide I suggest both sets will remain active..

RaphaelL
Kind of a big deal
Kind of a big deal

I would assume that is it exactly the same way if you apply a GP to a VLAN because this is what this feature is currently supporting.

 

When I go to Adressing & Vlans , I see the GP applied : 

 

RaphaelL_0-1755176330688.png

 

GIdenJoe
Kind of a big deal
Kind of a big deal

Oh okay nice.  So when a vlan is scoped it will behave like a group policy that overrides the local firewall but leave other vlans untouched.

Get notified when there are additional replies to this discussion.