FW Supported features

Solved
route_map
Building a reputation

FW Supported features

just checking to see if Meraki MX's support the following features

 

Support traffice filtering by IP host add/range and deep packet inspection at wire speed?

Manageable via SNMPv3, supports snmp trap messages

Support 802.1q

The firewall shall support syslog protocol for reporting events?

Continue to log events while under attack (DOS, DDOS, etc)

THe FW should support DNS functionality for local host that resolves uo to a public DNS

 

1 Accepted Solution
CptnCrnch
Kind of a big deal
Kind of a big deal

Regarding your questions:

 

> Support traffice filtering by IP host add/range and deep packet inspection at wire speed?

DPI is not possible at Wire Speed. But that's the case for every other firewall out there. Please find throughput figures here: https://meraki.cisco.com/products/appliances/#models

 

> Manageable via SNMPv3, supports snmp trap messages

Management is done completely cloud-based (via Dashboard), you could also leverage the API for that. SNMPv3 could be used for monitoring puposes though: https://documentation.meraki.com/zGeneral_Administration/Monitoring_and_Reporting/SNMP_Overview_and_...

 

> Support 802.1q

Yes, but you'll have to activate VLANs first: https://documentation.meraki.com/MX/Networks_and_Routing/Configuring_VLANs_on_the_MX_Security_Applia...

 

> The firewall shall support syslog protocol for reporting events?

Yes, not only Syslog:

https://documentation.meraki.com/zGeneral_Administration/Monitoring_and_Reporting/Meraki_Device_Repo...

https://documentation.meraki.com/zGeneral_Administration/Monitoring_and_Reporting/Syslog_Server_Over...

 

> Continue to log events while under attack (DOS, DDOS, etc)

As long as the box is up and running it will produce logs. Perhaps Meraki could elaborate further on that.

 

> THe FW should support DNS functionality for local host that resolves uo to a public DNS

What exactly do you mean? MX itself won't be able to do that but could leverage Cisco Umbrella to add DNS layer enforcement.

View solution in original post

1 Reply 1
CptnCrnch
Kind of a big deal
Kind of a big deal

Regarding your questions:

 

> Support traffice filtering by IP host add/range and deep packet inspection at wire speed?

DPI is not possible at Wire Speed. But that's the case for every other firewall out there. Please find throughput figures here: https://meraki.cisco.com/products/appliances/#models

 

> Manageable via SNMPv3, supports snmp trap messages

Management is done completely cloud-based (via Dashboard), you could also leverage the API for that. SNMPv3 could be used for monitoring puposes though: https://documentation.meraki.com/zGeneral_Administration/Monitoring_and_Reporting/SNMP_Overview_and_...

 

> Support 802.1q

Yes, but you'll have to activate VLANs first: https://documentation.meraki.com/MX/Networks_and_Routing/Configuring_VLANs_on_the_MX_Security_Applia...

 

> The firewall shall support syslog protocol for reporting events?

Yes, not only Syslog:

https://documentation.meraki.com/zGeneral_Administration/Monitoring_and_Reporting/Meraki_Device_Repo...

https://documentation.meraki.com/zGeneral_Administration/Monitoring_and_Reporting/Syslog_Server_Over...

 

> Continue to log events while under attack (DOS, DDOS, etc)

As long as the box is up and running it will produce logs. Perhaps Meraki could elaborate further on that.

 

> THe FW should support DNS functionality for local host that resolves uo to a public DNS

What exactly do you mean? MX itself won't be able to do that but could leverage Cisco Umbrella to add DNS layer enforcement.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels