- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Port Forwarding and Firewall Rules
Hi all:
Does any one know if Port forwarding rules are affected by Firewall rules?
Say I configure a port forwarding rule (on an MX with its WAN interface directly on the internet) to forward TCP 22 (SSH) to a server on a private subnet connected to the MX. Then say I don't want someone from 1.2.3.4 to SSH in so I create a firewall rule that looks like this:
Would someone from 1.2.3.4 still be able to SSH in? I tried something like this, but with RDP and I could still RDP in even though I had a firewall rule preventing any source IP and sourcing from the RDP port to my public IP and it still worked. It's as if the firewall rule isn't considered because of the port forward rule.
Solved! Go to solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Meraki Support can enable a beta feature named "custom layer 3 inbound firewall rules" where you have more flexibility in controlling the inbound way similar to what is available now for outbound rules. Perhaps this feature is of benefit for you.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The firewall rules are not for inbound traffic. They only control traffic from VLANs to the internet and between VLANs. That is the reason your tests did not block RDP.
https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/MX_Firewall_Settings
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Adding to @KarstenI 's reply.
The firewall rule you've got in the screenshot is for SSH connections initiated inside your network with a destination of 1.2.3.4. It does not apply to SSH connections inbound from 1.2.3.4.
If you have inbound connections from specific IP's that you want to port forward, you can apply them in the port forwarding rule under "Allowed Remote IP's"
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
At the port forwarding setting you can specify what remote ip is allowed.
You can also use a group policy assigned to vlan or client
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for the quick replies all! That's too bad that I can't block that from the firewall page. That seems like the most logical place to me. I tried applying a group policy to the client and that worked as expected. Another reason I wish the "firewall rule" way worked is because those can be logged. I don't see an option to log hits on Group Policies.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Meraki Support can enable a beta feature named "custom layer 3 inbound firewall rules" where you have more flexibility in controlling the inbound way similar to what is available now for outbound rules. Perhaps this feature is of benefit for you.
