Whitelisting a Client from the Firewall using a Group Policy

Solved
Patumusiime
Here to help

Whitelisting a Client from the Firewall using a Group Policy

Does anyone know how I can exclude a client(s) from the firewall? I have created a group policy that is excluded from the firewall and then added clients using their MAC addresses and assigned them to the whitelisted group policy, however the firewall still blocks those clients. Group_policy.pngClients.pngPatrick.png

1 Accepted Solution
alemabrahao
Kind of a big deal
Kind of a big deal

Have you tried the default Allow List?

 

alemabrahao_0-1697629543387.png

 

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

View solution in original post

6 Replies 6
ww
Kind of a big deal
Kind of a big deal

Did you follow this steps, for example did the client reconnect the network?

https://documentation.meraki.com/General_Administration/Tools_and_Troubleshooting/Troubleshooting_Gr...

Patumusiime
Here to help

Yes I did. The clients have disconnected and re-connected to the network several times.

Brash
Kind of a big deal
Kind of a big deal

This config is correct.

That client should be whitelisted from all firewall rules. 

Patumusiime
Here to help

Well, for some reason it doesn't seem to working as it should.

ww
Kind of a big deal
Kind of a big deal

You dont have gp attacher to a vlan?

What is your l3 fw rule at the moment?

How do you verify its not working when the gp is attached

alemabrahao
Kind of a big deal
Kind of a big deal

Have you tried the default Allow List?

 

alemabrahao_0-1697629543387.png

 

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels