https://documentation.meraki.com/MX-Z/Firewall_and_Traffic_Shaping/Firewall_Settings Note: In NAT mode, all inbound connections are denied except for ICMP traffic to the appliance, by default. If you want to allow additional inbound traffic, you will need to create a new port forwarding rule or NAT policy and explicitly allow connections based on protocols, ports, or remote IP addresses (see below). Outbound connections are allowed by default. Customers may need to add a default deny rule for compliance and increased security.
... View more