I'm not meaning to hijack athan1234's thread, but I stumbled across this thread while researching my own related issue.
Is this to say that it is the expected behavior that the MX's Ping Live tool will basically ignore any firewall rules?
I have explicit deny rules configured similarly to athan1234, and I can confirm that real clients in one VLAN are successfully blocked from reaching clients in any other VLAN. However, the MX's Ping Live tool can ping any client in any VLAN regardless of which "Source IP Address" I select.
For example, although there is an explicit deny firewall rule configured in both directions between VLAN 3 and VLAN 4, the MX Ping Live tool with a "Source IP Address" of VLAN 3 can ping any device in VLAN 4. But again, no real clients in VLANs 3 or 4 can ping each other, so I can see that the firewall rules are working for real clients.
I actually started this research because I discovered that any device in any VLAN could reach the management IP address of any other VLAN. For example, any device in VLAN 3 can ping/reach the MX's management IP address for VLAN 4. I found this article seemingly saying that this is expected behavior for AP's, but I am still searching for documentation indicating the expected behavior for MX's. https://documentation.meraki.com/MR/Firewall_and_Traffic_Shaping/All_VLANs_can_ping_the_Cisco_Meraki...