Two issues: Client VPN - almost zero firewall rules around this. Excluding the hack job of using group policy and assigning to the VPN client device (which isn't reliable) Site to Site VPN w/ 3rd party firewalls - no ability to block inbound traffic. Meraki's position is that it all needs to be blocked "closest the the source". That's all good and well, but what if you don't have control over the source. We have multiple cases of setting up S2S VPN's w/ 3rd party firewalls and outside vendors. I don't like it, I don't want to do it, but didn't have a choice. That really terrible part is that we have to expose our entire network to the 3rd party and can't control the ingress on the VPN. We NEED firewall rules on inbound VPN traffic - both S2S AND Client VPN - but especially S2S. Every other firewall I've worked with has this capability. PLEASE!!
... View more