MX SDWAN FIrewall Layer 3 Outbound Rules

RobChandler
Conversationalist

MX SDWAN FIrewall Layer 3 Outbound Rules

RobChandler_0-1750348424841.png

 

Hi - Sorry if been discussed before. Is there any way I use an IP range instead of individually putting ip's in.

I know I can create a group which is messy but would rather just be able to block out like above so 10.226.3.10-10.226.3.35. 

I know you can use CIDR but not for this range 

Am I missing something here???

Thanks Rob 

7 Replies 7
Mloraditch
Kind of a big deal

Unfortunately, you are not missing anything. This is what groups are for.

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
RobChandler
Conversationalist

So I would have to create a policy object for each IP address in that range, assign them to a group and then and then add the group to the rule??? 2001 wants its firewall rule base back 🙂 

AlexL1
Meraki Employee
Meraki Employee

Hi RobChandler,

Welcome to Meraki Community 🙂

 

Yes, you are correct.

 

Option 1 - You can change your Subnet range and add ACLs on the switch to forbit the traffic from the left 4-5 IP addresses to everywhere:

 

Network Address:10.226.3.0/27
Usable Host IP Range:10.226.3.1 - 10.226.3.30
Broadcast Address:10.226.3.31
Total Number of Hosts:32
Number of Usable Hosts:30
Subnet Mask:255.255.255.224
 

 

OR

 

Option 2 - You should be able to use individual /32 IP address in either the Src or Dest fields:

10.226.3.10/32

10.226.3.11/32

10.226.3.12/32

10.226.3.13/32

10.226.3.14/32

10.226.3.15/32

10.226.3.16/32

10.226.3.17/32

10.226.3.18/32

10.226.3.19/32

10.226.3.20/32

10.226.3.21/32

10.226.3.22/32

10.226.3.23/32

10.226.3.24/32

10.226.3.25/32

10.226.3.26/32

10.226.3.27/32

10.226.3.28/32

10.226.3.29/32

10.226.3.30/32

10.226.3.31/32

10.226.3.32/32

10.226.3.33/32

10.226.3.34/32

10.226.3.35/32

 

Option 3 - Create policy object group - kind of like a double work, in comparison with Option 2

 

AlexL1_1-1750359106688.png

 

AlexL1_2-1750359250230.png

 

AlexL1_3-1750359270008.png

 

 

https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/Network_Objects_Highlights

 

https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/Network_Objects_Configuration_Guide

 

If you have any questions, please don't hesitate to contact us.

 

If you found this post helpful, please give it kudos.
If my answer solved your problem, click "accept as solution" so that others can benefit from it 🙂

If you found this post helpful, please give it kudos.
If my answer solved your problem, click "accept as solution" so that others can benefit from it.
RobChandler
Conversationalist

Hi Alex

 

Thanks for confirming - is there any scope for this to be changed? Using a range would so much more beneficial and is a standard feature on basically every other firewall product there is!

 

Thanks Rob  

JonoM
Meraki Employee
Meraki Employee

We would strongly recommend making a feature request on the Meraki Dashboard as this is our primary method of tracking the requests for future dashboard changes.

If you found this post helpful, please give it kudos. If my answer solved your problem, click "accept as solution" so that others can benefit from it.
RobChandler
Conversationalist

Hi Jono - I have, I just hope more users do the same 

 

Thanks Rob 

alemabrahao
Kind of a big deal

You can use a group of objects.

 

https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/Network_Objects_Configuration_Guide

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco ID. If you don't yet have a Cisco ID, you can sign up.
Labels