port forwarding rule priority

Solved
FabrizioF
Here to help

port forwarding rule priority

Hi, port forwarding rule has priority on outbound deny rule?

If I have created a Outbound rules that block/deny from a specific local ip to Any, the port forwarding rule continue to works?

 

thanks in advance

Fabrizio 

1 Accepted Solution
FabrizioF
Here to help

Hi, technical support confirms that everything is normal

 

Port forwarding rules do have priority over outbound Layer 3 firewall rules. This behavior is due to how traffic flows are processed in the Meraki MX:

  1. Inbound Port Forwarding Rules: These rules apply to traffic coming from the internet into your network. When you create a port forwarding rule, the MX forwards the specified traffic to the designated internal IP address and port.

  2. Outbound Layer 3 Firewall Rules: These rules apply to traffic initiated from your internal network going to the internet. They do not control the traffic already forwarded by the inbound rule.

When a port forwarding rule is created, the Meraki MX explicitly allows the incoming traffic to pass through to the specified internal host. The outbound Layer 3 rule that denies the internal host's traffic to all destinations does not impact the incoming traffic allowed by the port forwarding rule.

 

thanks for the all replies

 

 

View solution in original post

8 Replies 8
RWelch
A model citizen

Have you restarted the flow?  It might take a bit to kick in.

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
FabrizioF
Here to help

sorry, do you mean restarting the MX?

RWelch
A model citizen

No, recycle the port for the IP address (device) you are wanting to deny outbound ANY.

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
FabrizioF
Here to help

I have already rebooted the PC (destination of Port Forwarding)

RWelch
A model citizen

Any chance you can share the port forwarding rule and/or the deny outbound rule to better understand?

If you found this post helpful, please give it Kudos. If my answer solves your problem please click Accept as Solution so others can benefit from it.
alemabrahao
Kind of a big deal
Kind of a big deal

As far I know outbound firewall rules take precedence over port forwarding rules. This means that if you have an outbound rule that blocks traffic from a specific local IP to any destination, this rule will override any port forwarding rules you have set up.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
ww
Kind of a big deal
Kind of a big deal
FabrizioF
Here to help

Hi, technical support confirms that everything is normal

 

Port forwarding rules do have priority over outbound Layer 3 firewall rules. This behavior is due to how traffic flows are processed in the Meraki MX:

  1. Inbound Port Forwarding Rules: These rules apply to traffic coming from the internet into your network. When you create a port forwarding rule, the MX forwards the specified traffic to the designated internal IP address and port.

  2. Outbound Layer 3 Firewall Rules: These rules apply to traffic initiated from your internal network going to the internet. They do not control the traffic already forwarded by the inbound rule.

When a port forwarding rule is created, the Meraki MX explicitly allows the incoming traffic to pass through to the specified internal host. The outbound Layer 3 rule that denies the internal host's traffic to all destinations does not impact the incoming traffic allowed by the port forwarding rule.

 

thanks for the all replies

 

 

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels