MX Firewall not allowing traffic in even with policy. A different MX works just fine with same rule

Slothinator007
Just browsing

MX Firewall not allowing traffic in even with policy. A different MX works just fine with same rule

I have a client with multiple sites.  At one site they have a security system panel and we have a rule that allows the security company to come in and manage it and that site works fine.  At another site we have the same setup but they can't get in.  The rule is roughly the same except for the endpoint IP being different of course.  I can see traffic on a packet capture for the internet port.  Nothing LAN.  What can I be missing.

Rule is   Internet2 -> Port 2001 -> 10.10.12.252 -> 2001

 

What else could I be missing?  

Thanks in advance

5 Replies 5
Brash
Kind of a big deal
Kind of a big deal

If you're seeing the packets reach the WAN port, sounds like the ISP side is fine.

Does the MX have a route to the 10.12.12.252 network?

Slothinator007
Just browsing

Yes. The route is directly connected.  10.10.12.0/24 

10.10.12.0/24 NightWatch Local VLAN  Always Available

CptnCrnch
Kind of a big deal
Kind of a big deal

How do NAT rules look like on both sides?

Slothinator007
Just browsing

Nat is working out no problem.  I have not setup any other nat in.

PhilipDAth
Kind of a big deal
Kind of a big deal

Can the MX ping 10.10.12.252?

 

Nothing on the LAN side suggests to me the MX is failing to communicate with it (such as ARP is failing).

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels