Meraki MX L7 features behind Firewall

Solved
Blink
New here

Meraki MX L7 features behind Firewall

MX85 MX 18.211.2

 

We are soon changing internet service provider and the new ISP will have a standard L3-L7 firewall policy on all outbound internet access.

 

Could be a non issue, but will MX L7 features work ok behind a firewall. URL filtering, AMP, IPS...

 

It's also a VPN hub but apparently this will work (via cloud brokering) on high UDP ports which are allowed through standard ISP policy.

 

I do understand that we will obviously only see what the external FW allows through but would any functionality on the MX actually break due to any L7 packet manipulation on the outside ISP FW? I have casually asked about whitelisting this device completely but might be a pain to do for all devices in the future.

1 Accepted Solution
KarstenI
Kind of a big deal
Kind of a big deal

The "?" in the top right corner of the dashboard has a section "Firewall Info". Just make sure that the ISP isn't blocking any of this communication and at least the Meraki Part will be fine.

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.

View solution in original post

6 Replies 6
KarstenI
Kind of a big deal
Kind of a big deal

The "?" in the top right corner of the dashboard has a section "Firewall Info". Just make sure that the ISP isn't blocking any of this communication and at least the Meraki Part will be fine.

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
Blink
New here

Thanks very much I'll get this verified

Blink
New here

Might sound like a stupid question but would these IPs in the Firewall Info section be susceptible to URL category blocking? ..for example they could be load balanced by URL and DNS mechanisms and resolved to either of these IPs. Or they maybe programmed in as IPs directly in the Meraki software which I would then assume would not be susceptible to URL category blocking.

KarstenI
Kind of a big deal
Kind of a big deal

Theoretically, they can be subject to any filtering. But I wouldn't expect any ISP to do that.

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
Blink
New here

Well there is this on their outbound policy but we'd be unlucky to be categorised as Malware.

Blocks by URL from Malware Categories - silent
Brash
Kind of a big deal
Kind of a big deal

Yeah I wouldn't expect it to be categorized as malware.

They would likely pull from the same sources that other security vendors/firewalls pull from anyhow.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels