Good plan. If I have an MX available my preference is to use the MX for rules and not the AP. Your first example is correct. You have to keep in mind that Meraki has a "permit everything" rule at the end you can't change. So your approach should be allow as specifically as you can, and then block broadly everything else. Your second example would likely work, but from an administrative point of view it's harder to read and understand, and more prone to errors if modifications are needed. Especially if it's not you in the future making changes.
... View more