Just to build on @BlakeRichardson answer. Content filtering only runs between WAN and LAN interfaces. Threat protection runs between WAN and LAN interfaces, and also between VLAN interfaces. https://documentation.meraki.com/MX/Content_Filtering_and_Threat_Protection/Threat_Protection "Intrusion detection feeds all packets flowing between the LAN and Internet interfaces and in-between VLANs through the SNORT® intrusion detection engine and logs the generated alerts to the Security Report."
... View more