Managing Multiple Sites' Firewalls with Templates - No Override

Solved
Andrew_Laeddis
Conversationalist

Managing Multiple Sites' Firewalls with Templates - No Override

Hi,

 

I'm trying to create an appliance template with firewall rules that can be applied to a number of new sites being onboarded into SD WAN.

 

I would like to manage the template centrally, and be able to push new rules to all sites. I would also like site-specific firewall rules to be applied to sites individually.

 

This doesn't seem possible, and it looks like I'll have to do this by cloning a "template" network, and then managing each site individually. Is this correct?

 

Thanks, 

1 Accepted Solution
alemabrahao
Kind of a big deal
Kind of a big deal

If you want to apply individually on each site yes. But maybe (I'm not sure) you can use group policies to achieve It. I will confirm it.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

View solution in original post

3 Replies 3
alemabrahao
Kind of a big deal
Kind of a big deal

If you want to apply individually on each site yes. But maybe (I'm not sure) you can use group policies to achieve It. I will confirm it.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

I just confirmed It, and you cannot apply group policy individually on each site, justo on the template.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Andrew_Laeddis
Conversationalist

Thanks, I didn't know templates were this limited. Hopefully it's possible to add specific L3 rules at each site in future, while using templates. For any updates to the "template configuration", looks like we're in the position where each firewall is going to have to be manually updated with the same rule, because many sites need specific rules.

Get notified when there are additional replies to this discussion.