MX67W - does 1:1 NAT forwarding superceed layer 7 country blocking?

alceryes1
Here to help

MX67W - does 1:1 NAT forwarding superceed layer 7 country blocking?

Subject.

If yes, is there any way to set up a 1:1 NAT (external facing RDWeb protected by MFA) that checks the layer 7 block list first?

6 Replies 6
Brash
Kind of a big deal
Kind of a big deal

No, from my understanding L7 rules are not applied to uninitiated inbound flows. They only apply on outbound flows and the return traffic.

 

"The Layer 7 Firewall can be used to block traffic based on the destination country of outbound traffic and the source of return traffic"

https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/MX_Firewall_Settings#Geo-IP_Based_F...

PhilipDAth
Kind of a big deal
Kind of a big deal

Negative.  Layer 7 rules do block inbound traffic as well, such as when using NAT to allow the Internet to access an internal server.

alceryes1
Here to help

Is this something new? Did layer 7 country blacklist (to and from) not check/block 1:1 NATs at some point in the past?

Brash
Kind of a big deal
Kind of a big deal

I don't believe it ever applied to inbound NAT traffic.

I do know however that at some point the wording in the documentation has been updated to more clearly reflect this.

 

Solved: MX GEO IP filtering on Port Forward rules - The Meraki Community

alceryes1
Here to help

Unfortunately, the link you posted shows two contradictory statements about blocking traffic to a 1:1 NAT.

If it's definitely true that it does NOT block inbound to a 1:1 NAT, then they really need to change the wording when enabling it. It just uses 'To/From' there's no disclaimer. Also, that thread is also 5 years old.

 

I may open up a ticket to get clarification. Will post the response here if I do.

Brash
Kind of a big deal
Kind of a big deal

The key takeaway is what was posted in the solution.

In response to a case opened with support, the user received the following:

 

"Port forwarding, 1:1 NAT and 1:M NAT traffic are not inspected by layer 7 rules. So, any external traffic coming from one of the blocked countries will still be seen in your network; traffic will not go out to those countries though."

 

We can also see that the wording in the documentation was updated to reflect that it will only inspect return traffic from external, not externally sourced traffic hitting DNAT.

 

Original:

"The Layer 7 Firewall can also be used to block traffic based on the source country of inbound traffic or the destination country of outbound traffic. "

 

Now:

"The Layer 7 Firewall can be used to block traffic based on the destination country of outbound traffic and the source of return traffic"

 

This to me aligns and is quite clear, however if you require further clarification, as you mentioned you can open a support case to confirm.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels