Hello everyone,
I have a small question and I hope you can help me understand the issue.
In an environment with an MX250 Firewall and L3 on an MS250 switch,
I host a virtual machine in a 'DMZ' hosting a website that needs to be accessible from the internal network.
This 'DMZ' VLAN is created at the L3 switch level, and I've created an ACL to block internal traffic to it.
However, I need to provide access to this website to my internal users, some of whom are on a Meraki NAT WIFI network.
When I activate my ACL, my website is no longer accessible internally.
When I ping the name of my website, the public IP address of my firewall responds correctly.
And when I perform a trace route to the address, I still go through my internal network '10.3.1.1 = IP of my Firewall.'
Any idea how to make it accessible while still blocking the DMZ?
Thank you