Hi Community,
Hopefully this will be a quick answer. New to the community so thanks in advance.
My customer is requesting we block such things as logmein and other remote control, but accept others that they like such as Team Viewer.
Now I am expecting it is done this way
Layer 7 - Deny Remote Mgmt and Sharing
Layer 3 - Permit associated Team Viewer info such as proxy IP/ports etc.
I need to have the above confirmed - there may be a better way to do this and also - and more importantly - is there a list of applications and which category they relate to?
Cheers
Thanks a lot for the quick response. I can see that this may be an interesting one. I suspect that the URL will not be that simple either. I'll wireshark Team Viewer and Logmein for a start and see where I go. If I find a list I'll share, if not I'll start compiling one, I'm not going out anyway!! 😉
L7 rules only allow you to deny - not permit.
It denies what appears in the drop-down box.
If you want to block a specific site then I'd block it by URL.
https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/MX_Firewall_Settings#FQDN_Support