- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Firewall log always shows Layer 7 default rule allowed the traffic
Hello there,
yesterday we created about 80 new FW rules after migrating all services to our MX-Cluster.
Today I want to see if everything is working and if traffic is getting allowed by the correct rules.
In the firewall log I can see almost every entry is allowed by layer 7 default rule. We don't use any layer 7 rules, only layer 3.
See screenshot from log. Traffic from 10.10.241.130 should be allowed by rule #1.
Is this normal behaviour or am I missing something?
Regards
Philipp
- Labels:
-
Firewall
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
When processing firewall rules, L3 rules are checked, and if not blocked then L7 rules are checked. L7 rules are the last rules to be checked.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I think you should be seeing both entries as per : https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/Firewall_Logging
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi there,
you guys are right. But most of the time only the L7 entry is shown. Sometimes I can see the associated L3 rule.
Its just getting weirder. Because the L3 rule is always shown as #0. I have no #0 rule allowing anything. Before the default allow rule is a deny any rule.
Here is a screenshot of the log with L7 and L3 entries:
Here a screenshot of my fw rules:
Please enlighten me regarding this matter.
Regards Philipp
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would probably open a ticket if I were you. This seems like a bug ( probably a known issue )
A bit out of the topic , but why do you have a catch all allow and a catch all deny ? Seems counter intuitive
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
When doing a migration with over 80 fw rules its always good to have a catch all rule to see if traffic is not matched above. Its an allow rule because we dont want to get errors on the user end. If the firewall log is working like any other firewall I could easliy see what traffic matches that rule and make the corrections.
But it seems im stuck here. I will open a ticket.
Thanks anyway 🙂
