Established sessions on a MX95

Fbell
Just browsing

Established sessions on a MX95

Hi,

 

We have have an MX95 with few services behind.

 

To publish these services we create a NAT 1:1 and allow inbound rules.

Then on the top of that we also have an outbound rule that allow any protocols from any ip to any.

 

My issue is : The published services works fine as incoming traffic is match by inbound rules, but when we try access outside resources from the server that hold the services, it does not work unless we had an inbound rule that allow incoming from any ip and from any port.

 

so it seems that firewall does not care of established sessions from the inside or return traffic.

I thought that MX95 as stateful firewall handle these kind of thing by default.

 

What could be the issue ?

 

Thanks by advance for any help.

 

FB.

8 Replies 8
alemabrahao
Kind of a big deal
Kind of a big deal

You need to have a default block rule before the Allow Any Any rule.

 

alemabrahao_0-1709648337191.png

 

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Fbell
Just browsing

Hmm my MX95 interface is quite different from your : 

 

Fbell_0-1709649988210.png

I can only allow, so it suggest that deny is implicit.

alemabrahao
Kind of a big deal
Kind of a big deal

You are talking about NAT, for NAT there is no way to see the Hit count.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Fbell
Just browsing

The screen I sent is related to publish service and regarding what's on top of my Meraki config page there is no other way to add inbound rules  : 

Fbell_0-1709654257857.png

 

My forwarding rules : 

Fbell_1-1709654428361.png

 

 

 

alemabrahao
Kind of a big deal
Kind of a big deal

If you want to enable inbound rules, you must ask Meraki support.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
alemabrahao
Kind of a big deal
Kind of a big deal

Solved: Meraki MX Inbound Firewall Rules - The Meraki Community

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
ww
Kind of a big deal
Kind of a big deal

Your problem is?

The lan to wan traffic is not working/blocked for this lan server, when the server initiate the session?

Fbell
Just browsing

Hi,

 

My problem is that return traffic is not allowed for server behind my publish services unless I put an inbound rule which allow any to any.

 

 

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels