Group policy inspection

Solved
ShlomiTufin
Just browsing

Group policy inspection

Hi,

Let's assume that I have vlan1 with GP_1 and vlan2 with GP_2.

On MX appliance, which group policy would be inspected in case of vlan1's host to vlan2's host packet ? GP_1 ? GP_2 ? or maybe both ? 

 

1 Accepted Solution
Brash
Kind of a big deal
Kind of a big deal

When a group policy is applied to a vlan, it is assigned to all clients within that vlan.

So in a packet from host 1 to host 2 (in two different vlans and with group policies applied to those vlans), host 1's group policy is taken into consideration. Then the reverse for the reply packet.

View solution in original post

2 Replies 2
Brash
Kind of a big deal
Kind of a big deal

When a group policy is applied to a vlan, it is assigned to all clients within that vlan.

So in a packet from host 1 to host 2 (in two different vlans and with group policies applied to those vlans), host 1's group policy is taken into consideration. Then the reverse for the reply packet.

alemabrahao
Kind of a big deal
Kind of a big deal

When a group policy is applied to a VLAN, that policy becomes the new "network default" for any other group policies applied to clients in that VLAN. Since this policy is the new "network default," the client devices will still show a "normal" policy applied under Network-wide > Monitor > Clients.

For example, a group policy named "Guest Network" with more restrictive layer 3 firewall rules than the network-wide configuration is applied to the guest VLAN, and a second group policy "Low Bandwidth" has a custom bandwidth limit, but is set to Use network firewall & shaping rules. If the Low Bandwidth group policy is applied to a client on the guest VLAN, the client will use the layer 3 firewall rules configured on the Guest Network group policy, not the network-wide layer 3 firewall rules configured on the Security & SD-WAN > Configure > Firewall page.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels