Is that doable with Meraki Firewall?

RobustMeraki
Getting noticed

Is that doable with Meraki Firewall?

Posting here again if Secure Connect was not the correct section for this post.

 

One of our customers is fixed to the following solutions offered from Sophos and would be interested to know if we can cover them using a Meraki Firewall and if needed pairing it with Meraki's Secure Connect/Cisco Security/ Duo etc. The following are the features doable using Sophos. I would wish this is possible with Meraki, if not would wish alternative solutions which could cover these features below.

 

Sophos can do this. Can Meraki do it as well??

 

a)  Using network masking to create DNAT rules

b) presence of a transparent proxy

c) Sophos RED has a (permanent) connection to external service providers and it restricts access to SQL database stored in the main office and may only give access to trusted people.

 

The following points are additionally required by the customer and expected from Meraki

 

d) Can Meraki function fully as a web application firewall?
e) Can Meraki provide Live firewall protocol for problem analysis?

@Daniel-BC 

1 Reply 1
PhilipDAth
Kind of a big deal
Kind of a big deal

>Using network masking to create DNAT rules

 

No.

 

>presence of a transparent proxy

 

Umbrella SIG can do this (and can be done via SecureConnect as well).

 

>Sophos RED has a (permanent) connection to external service providers and it restricts access to SQL database stored in the main office and may only give access to trusted people.

 

Is that a NAT with an ACL?  If so, yes.

 

>Can Meraki function fully as a web application firewall?

 

No.

 

> Can Meraki provide Live firewall protocol for problem analysis?

 

Yes, but it is not good at it.

https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/Firewall_Logging

 

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels