Unable to block traffic between VLANS

BlakeRichardson
Kind of a big deal
Kind of a big deal

Unable to block traffic between VLANS

I am trying to block traffic between two VLANS on an MX8CW and nothing I have tried works and I feel like it's probably something simple. I have tried blocking using CIDR and VLAN ( screenshots below), neither of the rules are showing any hits and I can ping devices from either direction. 

 

I have another rule not shown that blocks a device from accessing the internet and that works fine so I am out of ideas. If anyone has any suggestions that would be appreciated.

 

Screenshot 2024-11-22 at 11.04.59 PM.png

 

Screenshot 2024-11-22 at 11.13.20 PM.png

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
5 Replies 5
Brash
Kind of a big deal
Kind of a big deal

Hmmm the only things that come to mind are the usual:

1. Either reboot the MX or wait at least 15 mins after creating the rule before testing

2. Ensure you're not testing using IP addresses on the MX as they will always respond to ping across VLANs

AmitPanchal
Here to help

Are the L3 VLAN interfaces configured on the firewall. If No then these rules are of no use. Also try by creating a vice-versa rule like from testing to default and from default to testing and then check.

Frank-NL
Getting noticed

If you are sure the traffic is being routed by the MX, you can confirm that with a packet capture

Frank-NL
Getting noticed

*If you want to be really sure

Frank-NL
Getting noticed

The rule configuration is good in both screenshots

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels