The Meraki Community
Register or Sign in
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • About PAI-Aaron
PAI-Aaron

PAI-Aaron

New here

Member since May 12, 2020

‎05-12-2020
Kudos given to
User Count
ww
Kind of a big deal ww
1
View All

Community Record

1
Post
0
Kudos
0
Solutions
Latest Contributions by PAI-Aaron
  • Topics PAI-Aaron has Participated In
  • Latest Contributions by PAI-Aaron

L3 Firewall Rules and "On-VPN" network interaction.

by PAI-Aaron in Security / SD-WAN
‎05-12-2020 09:08 AM
‎05-12-2020 09:08 AM
I have an MX84 configured with 3 VLANs each of which are assigned a /24 subnet from the 172.16.0.0/12 block. The networks are designated inside, DMZ, and guest.   I'm trying to understand the firewall / security interaction when I mark the DMZ network as "On-VPN". In particular I have firewall rules:   1: allow tcp (DMZ host) any (VPN-Connected host) any ... 8: deny Any (DMZ subnet) Any Any Any   The goal is to deny everything from the DMZ network by default (rule 8 above) what's killing me is that my default deny rule doesn't seem to apply to networks that are part of our VPN connected mesh.   I can't ping the inside network from (DMZ host), I can't ping the guest network from (DMZ host), but I can ping any IP address on a subnet connected to the MX84 via the Meraki cloud.   So is there an implied "permit" rule hidden somewhere that is overriding my L3 rules on the MX84 because the destination is part of our VPN mesh? If so how can I prevent (DMZ host) from accessing everything connected to our VPN mesh? We have about 40 subnets advertised this way and I only want to permit my DMZ network to access specific hosts on specific endpoints.   ... View more
Kudos given to
User Count
ww
Kind of a big deal ww
1
View All
Powered by Khoros
custom.footer.
  • Community Guidelines
  • Cisco Privacy
  • Khoros Privacy
  • Cookies
  • Terms of Use
© 2023 Meraki