I've tried looking at the documentation but I couldn't find anything regarding this.
The question is regarding how MX devices process firewall rules. There are two sections which can apply rules, under "Site-to-site VPN" and then under "Firewall".
I'm wondering about order of operations in how the traffic is subjected to the two different types of firewall rules.
As an example take the following, a host residing behind a spoke in meraki auto-vpn wants to access https on a host located on the hub network. As far as I gather the vpn firewall rules will be subject for the host traffic when entering the vpn tunnel on the spoke. When traffic arrives at the hub MX will the "regular" firewall rules on the hub MX also be ran against the traffic?
Or take another example, we have a host on the hub MX which wants to talk to another host behind a non-meraki VPN peer. Will the "regular" firewall rules be ran against the traffic first and following that the vpn firewall rules?