Should vpn access rules be part of the layer 3 outbound area, or layer 3 inbound area?

Solved
Announcer
Getting noticed

Should vpn access rules be part of the layer 3 outbound area, or layer 3 inbound area?

I have one vpn setup in the MX, along with some other vlans.  Where would I put access/firewall rules concerning the vpn subnet?  In the inbound section or outbound?  For example I want vpn subnet to have access to a file share on vlan2?   What about non-vpn inter vlan access; would I put these in inbound or outbound section?

 

thanks.

1 Accepted Solution
Brash
Kind of a big deal
Kind of a big deal

To add to @KarstenI 's post, if you're talking about client VPN (rather than site-to-site vpn), you use outbound rules.

 

https://documentation.meraki.com/MX/Client_VPN/Restricting_Client_VPN_access_using_Layer_3_firewall_...

View solution in original post

3 Replies 3
KarstenI
Kind of a big deal
Kind of a big deal

If the traffic comes from or goes to the VPN, the rules need to be configured on the organization-wide VPN-rules. VPN traffic is not filtered by L3 Firewall rules. For inter VLAN-traffic, they have to be in the outbound section of the L3 rules. Inbound is for traffic from the WAN.

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
Brash
Kind of a big deal
Kind of a big deal

To add to @KarstenI 's post, if you're talking about client VPN (rather than site-to-site vpn), you use outbound rules.

 

https://documentation.meraki.com/MX/Client_VPN/Restricting_Client_VPN_access_using_Layer_3_firewall_...

Announcer
Getting noticed

Yes, it's client vpn.  Thanks for verifying.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels