Firewall layer 3 inbound interface rules

Mr-cook
Here to help

Firewall layer 3 inbound interface rules

Hi ,

 

Does any on know if is it possible to specify Inbound interface or outbound interface in a layer 3 rule ?

 

This looks very basic and important to a firewall to define in access rules and I found it weird that we could not do it on meraki MX.

 

regards,

3 Replies 3
Nash
Kind of a big deal

It's not interface dependent with access-groups like on, say, an ASA.

 

You get a separate firewall for cellular failover, for data usage control.

 

Then you have a general L3 firewall. As per the screenshot below, inbound traffic will be restricted according to the other rules on the Firewall page:

 

2019-12-04 09_53_48-Firewall Configuration - Meraki Dashboard.png

 

If you've got 1:1 NAT or 1:Many, you can restrict allowed remote IPs directly on those statements if you really need. (I'm personally skeptical on the value of IP blocks, since spoofing is a thing.)

KRobert
Head in the Cloud

As far as outbound interface preferences, you can create a flow preference in the SD-WAN & Traffic Shaping section.

 

KRobert_0-1575478799159.png

This only works outbound, not inbound. 

CMNO, CCNA R+S
PhilipDAth
Kind of a big deal
Kind of a big deal

>Does any on know if is it possible to specify Inbound interface or outbound interface in a layer 3 rule ?

 

What happens is no traffic is allowed inbound by default until you create a NAT rule to allow it.  When you create a NAT rule there is a section where you can limit where that NAT can be accessed from.

1.PNG

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels