Port forward on port 80 with restrictions.

Solved
BillMcC
Here to help

Port forward on port 80 with restrictions.

Hey guys, I have an issue with a customers port forward. typical setup webserver port 80 with a list of allowed remote IP's. For some reason it is allowing all internet traffic on the forward. I looked for incorrect address entries but I do not see any. Any crazy or obvious thing that would cause the allow list to be ignored? 

 

Thanks,

 

1 Accepted Solution
alemabrahao
Kind of a big deal
Kind of a big deal

Yes, you are probably allowing all traffic to the MX status page, this could influence it, because if I'm not mistaken it responds to both port 80 and 443.

 

alemabrahao_0-1713462831835.png

It's a bit bizarre, but I've seen similar problems before.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

View solution in original post

3 Replies 3
alemabrahao
Kind of a big deal
Kind of a big deal

Yes, you are probably allowing all traffic to the MX status page, this could influence it, because if I'm not mistaken it responds to both port 80 and 443.

 

alemabrahao_0-1713462831835.png

It's a bit bizarre, but I've seen similar problems before.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

I thought of this but said “Surely Not” 🙂 Let me test this right quick. 

Thanks!

That was it. Of all the crazy. Maybe they should update this on the KB page to include what you shared. 

Forwarding TCP 443/80

If a port forward for ports 443 or 80 is configured, you may be unable to reach the local status page via the MX's WAN IP address.

Thanks again! 

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels