- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
MX Templates for with VPN firewall rules
Hi All, I’m planning a deployment of multiple MXs where I need to apply a common set of firewall rules to the auto-vpn. Can this be achieved via templates?
Solved! Go to solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi , yes I'm 99% sure.
These firewall rules will apply to all MX networks in the organization that participate in site-to-site VPN (both AutoVPN and Non-Meraki).
Also if you scroll a bit higher on the S2S page you will see :
I'm assuming OP wants to modify VPN Site-to-Site rules
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Definitely yes. See this link.
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi ,
No Yes but since VPN firewall rules are org-wide. https://documentation.meraki.com/MX/Site-to-site_VPN/Site-to-site_VPN_Firewall_Rule_Behavior
See example below
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Are you sure about this? It's a template example?
And the documentation you sent does not explicitly say what you are stating.
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi , yes I'm 99% sure.
These firewall rules will apply to all MX networks in the organization that participate in site-to-site VPN (both AutoVPN and Non-Meraki).
Also if you scroll a bit higher on the S2S page you will see :
I'm assuming OP wants to modify VPN Site-to-Site rules
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, but that doesn't mean I can't apply it via template, right? that's actually the way we do it today and it works very well.
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes probably , but the goal from templates is to have unified configurations between all child networks binded to that template.
Template A and B can't have different Site-to-Site VPN rules is what I tried to explain (which wasn't very clear I have to admit haha )
Sorry bout the confusion.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No no no, everything is fine, it's just to try to make everything clearer. 😊
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@RaphaelL is correct, VPN S2S rules are not set in a template. Yes, you can see and edit the S2S rules when in a template network, but that's still simply an org wide section visible in any network or template.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, I know, there was just a little confusion, which we have now resolved. 😉
Please, if this post was useful, leave your kudos and mark it as solved.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ok this escalated 🤣.
So Site-to-Site VPN firewall rules are org wide? What if I want to implement the opposite where I want one site to have additional rules, is that possible?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Create a rule(s) that only have source or destinations of the specific site you want additional rules applied to. The ruleset still lives in the org wide section.
Example, if you wanted to deny traffic from Spoke 1 to Spoke 2, but allow Spoke 1 to Spokes 3 and beyond just create a rule that denies Spoke 1 to Spoke 2. Traffic to anything besides Spoke 2 would still be permitted.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Gotcha, so it’s just one big table of rules that’s org wide.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for all the input so far BTW guys most helpful.
