Hello
 
I'm starting to play around with using NMAP to run various host discovery and port scans against clients on our network.  I have a client VPN subnet and I am scanning against other subnets that are connected by site to site vpn.  I have a site to site outbound firewall rule that allows any/any from the client vpn subnet to the target subnets.
 
My expectation is that I should get answers from hosts that are up and set to reply to the discovery scan and that I should  get no reply from IP addresses that are not in use.  However I continually get results that show all hosts are up on a subnet.  Even when I know that there is no host associated with a particular address.  
 
Is this expected behavior from Meraki firewalls?  Do they just reply to all requests even if there is no client there?  Is this behavior documented somewhere so that I can review and try to understand what's going on?  
 
Thanks!