Meraki MX misclassifying traffic

Solved
Sarv
Getting noticed

Meraki MX misclassifying traffic

 

We have an MX at a customer site that identifying DNS traffic as Pandora and is blocking based on the Layer7 Video/Music/Pandora Deny Rule. Anyone else see this issue? I had reported this to Meraki Support at least 6 months ago and again today with no resolution. Here is a snipet from the event log (192.168.1.50 is the internal DNS server for the customer)

 


Source IP: 172.16.1.13, Source Port: 29590, Destination IP: 192.168.1.50 « hide

Destination Port 53

Protocol UDP

Block Type DNS

NBAR ID 1451

Classification Pandora Internet Radio

Layer 7 firewall rule Deny

 

 

1 Accepted Solution
Brash
Kind of a big deal
Kind of a big deal

This may actually be a correct classification.

DNS lookups that match a given NBAR rule will get blocked.

"NOTE: DNS traffic (TCP/UDP Port 53) may also get blocked by Layer 7 rules if it contains a query for a domain the rule in question covers.

For example, you may see a block on UDP port 53 classified as "abc.com" if the "All News" rule is configured on Dashboard, and a user device sends a DNS query for said domain."

Mapping Layer 7 Firewall Rules to NBAR IDs - Cisco Meraki

View solution in original post

3 Replies 3
Sarv
Getting noticed

I received another response from Meraki support on this. Same thing as before. Anyone from Meraki look at issues in this forum?

 

Response from Meraki: they are aware of this on-going issue and have attached my case/ticket to the parent case.

 

As I stated I opened a case for this at least 6 months ago with the same type of response.

 

I can only say that I am disappointed that Cisco/Meraki does not take these type of issues seriously or they would have had a fix by now.

Brash
Kind of a big deal
Kind of a big deal

This may actually be a correct classification.

DNS lookups that match a given NBAR rule will get blocked.

"NOTE: DNS traffic (TCP/UDP Port 53) may also get blocked by Layer 7 rules if it contains a query for a domain the rule in question covers.

For example, you may see a block on UDP port 53 classified as "abc.com" if the "All News" rule is configured on Dashboard, and a user device sends a DNS query for said domain."

Mapping Layer 7 Firewall Rules to NBAR IDs - Cisco Meraki

Sarv
Getting noticed

Thanks Brash. That makes sense.

Get notified when there are additional replies to this discussion.