URL filtering for non http/https traffic

Solved
Dunky
Head in the Cloud

URL filtering for non http/https traffic

I'm hoping posting here is going to get me a quicker answer than me trying to find sites to test and configure this.

I am working on putting together a plan to migrate a new site to Meraki infrastructure and have a requirement to permit traffic outbound from a specific vlan to to say *.abc.com on tcp ports 8080-8180.

 

Can I add a L3 rule with the dst as *.abc.com ?

 

I know about using a group policy and adding "Allow list URL patterns" but I believe that would only apply to http/https traffic?   Or am I mistaken and that is indeed the way to do it by adding say abc.com:8080-8810 ??

 

Any help/guidance would be greatly appreciate as I'm under a quite restrictive timeline on this one.

 

 

1 Accepted Solution
KarstenI
Kind of a big deal
Kind of a big deal

URL filters only work when there is a URL to look at in any form. For your task, the FQDN-rules is the feature of choice:

https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/MX_Firewall_Settings#FQDN_Support

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.

View solution in original post

2 Replies 2
KarstenI
Kind of a big deal
Kind of a big deal

URL filters only work when there is a URL to look at in any form. For your task, the FQDN-rules is the feature of choice:

https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/MX_Firewall_Settings#FQDN_Support

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
Dunky
Head in the Cloud

Many thanks.

I will have a 'play' with this on my test network over the Xmas hols, no doubt I will be bored and looking for something to occupy myself! 🙂

 

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels