Opening Ports

RahulPrasadh
Getting noticed

Opening Ports

I need to open few ports in Meraki for using Sonos, I have created outbound firewall rule with only ports source and destination any. And still, I'm unable to access it. Is there any other way we can allow access.

 

https://support.sonos.com/en-us/article/configure-your-firewall-to-work-with-sonos

7 Replies 7
BlakeRichardson
Kind of a big deal
Kind of a big deal

By default all outgoing traffic is allowed. Can you provide a screenshot of your configuration so we can have a look? 

RahulPrasadh
Getting noticed

RahulPrasadh_0-1730755878317.png

Accessing Sonos through a phone app.

BlakeRichardson
Kind of a big deal
Kind of a big deal

As I thought the default rule is allowing all traffic so creating extra rules will not have any effect. I suspect this is a Windows firewall issue and not a Meraki issue. 

MartinLL
Building a reputation

Sounds like traffic is still being blocked then. You can look at the live firewall logs on the MX. See if that gives you a clue into whats going on.

 

https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/Firewall_Logging 

MLL
RaphaelL
Kind of a big deal
Kind of a big deal

And still, I'm unable to access it

 

How are you trying to access it ? Via Port forwarding / NAT ? Or via it's private LAN IP ?

Brash
Kind of a big deal
Kind of a big deal

It seems to me like the issue is with your source ports.

The ports listed in the linked website are outbound destination ports. The source ports will be ephemeral ports (typically 32768–60999). The easiest thing to do though is just set the source port to Any.

Brash
Kind of a big deal
Kind of a big deal

Re-reading the rules in your image, @BlakeRichardson has a point - the last rule is an allow any-any so the rules above it shouldn't matter. Check downstream - any other network devices, windows firewalls etc.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels