My understanding is that the L7 Geo only blocks outbound initiated sessions, so whilst it will block inbound attempts to your NAT rules from those countries, it is only doing it because the response from the server gets dropped. Solved: MX GEO IP filtering on Port Forward rules - The Meraki Community EDIT: The documentation also states: "The Layer 7 Firewall can be used to block traffic based on the destination country of outbound traffic and the source of return traffic." MX Firewall Settings - Cisco Meraki Documentation
... View more