How to Block external IP's on MX100

SOLVED
gparach
Here to help

How to Block external IP's on MX100

I need to enter IP filtering on the MX100 to keep certain IP's from trying to login to our mail server accounts causing them to lockout constantly. I do not have the option to only allow designated static IP's access to the mail IMap server. I also get monthly excel updates of Malware IP's and Domains that need to get blocked from/to our firewall. What method(s) will allow this?

1 ACCEPTED SOLUTION
Tat0rt0t
Getting noticed

Perhaps the layer 7 section under Firewall you can deny a specified IP range?

View solution in original post

12 REPLIES 12
MijanurRahman
Getting noticed

This method wont work for users that don't have static IP addresses. I don't want an ALLOW list, I want a DIS-ALLOW list.


@gparach wrote:

This method wont work for users that don't have static IP addresses. I don't want an ALLOW list, I want a DIS-ALLOW list.


Why don't you make a reservation for these users. This way they will have a static IP.

Found this helpful? Give me some Kudos! (click on the little up-arrow below)

Because they are Public IP cell phone users.

PhilipDAth
Kind of a big deal
Kind of a big deal

Have you got an advanced security licence?  If so, go:

Security Appliance/Threat Protection/

AMP Mode=Enabled

Intrusion detection and prevention mode=Prevention

Ruleset=Security

 

Secuity Appliance/Content Filtering

Add: Bot Nets, Illegal, Malware Sites, Proxy Avoidance and Anonymlisers

 

Do the above till will gain you substantial protection - using dynamic lists rather than something manually configured.

I have the advanced functionality and am using it, but, I get advanced lists of known bad entities that I want to make sure are getting blocked.
PhilipDAth
Kind of a big deal
Kind of a big deal

To only allow specific IPs to get to your IMAP service go:

Security Appliance/Firewall/Forwarding rules

 

 

Locate your IMAP forwarding rule.  Scroll across to the "Allowed remote IPs" columns.  Change "Any" to just the list of allowed remote IPs.  All others will be blocked.

Tat0rt0t
Getting noticed

Perhaps the layer 7 section under Firewall you can deny a specified IP range?

PhilipDAth
Kind of a big deal
Kind of a big deal

The layer 7 firewall blocks outbound requests, not inbound requests due to NATed ports.

I have been using this method but was not completely convinced it was working. I tried another test and it seems to work from what I can tell. The only problem is it is an inconvenient way to enter many entries.
Tat0rt0t
Getting noticed

@gparach So your post got me thinking and I spoke with out exchange admin as well about it. It does seem that we have no way to block specific IP's on a NAT statement. You can blacklist IP's however via exchange according to out exchange admin, but he did warn, if it is a attacker, They will just attack from another IP. His recommendation to solve this issue was the change the users account username for authentication. 

This isn't exchange email and changing the user account is temporary at best (until they discover it) and a huge inconvenience to re-distribute the users change out to all contacts. My upcoming email version has Two Factor Authentication that should alleviate this issue, however, there should still be something built into the Meraki firewall to add IP block lists to reject someone trying to probe you or break in.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels