So .. I was thinking......
If I create a Group policy with "custom network firewall and shaping rules" what happens ?
I know that if I apply this manually, directly to a VLAN interface on an MX, it will override the ACLs in the global MX firewall setting.
But if I apply this GP to a client, on a switch or AP, using Filter-ID in the dot1x radius response, does it still override the MX global firewall settings ?
(My thought process was that applying the GP will only affect the device its connected to (switch / AP), so having a fx. deny local LAN IP ACL and permit any any in the GP, the global firewall (up the stack) will still take effect on the GP permit any any traffic.)
I just wonder, and cant quite seem to find any documentation.