Fun Fact - layer 3 firewall rule blocks will show up in syslog as "l7_firewall".....blocked

CraigCummings
Getting noticed

Fun Fact - layer 3 firewall rule blocks will show up in syslog as "l7_firewall".....blocked

Fun Fact - layer 3 firewall rule blocks will show up in syslog as "l7_firewall".....blocked.  

 

Example:

l7_firewall src=192.168.40.5 dst=208.67.220.220 protocol=tcp sport=36211 dport=7 decision=blocked

 

This was not being blocked by a layer 7 rule (I know because I removed them all).  It was being blocked by a layer 3 rule.  I also confirmed this by adding an Allow rule in Layer 3. 

 

Isn't that fun? 

 

Thanks for making it so easy Meraki. 

0 Replies 0
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels