The Meraki Community
Register or Sign in
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • About DarrenH
DarrenH

DarrenH

New here

Member since Jan 4, 2023

‎01-04-2023
Kudos given to
User Count
PhilipDAth
Kind of a big deal PhilipDAth
1
View All

Community Record

4
Posts
0
Kudos
0
Solutions
Latest Contributions by DarrenH
  • Topics DarrenH has Participated In
  • Latest Contributions by DarrenH

Re: FQDN Policy object does not seem to be working

by DarrenH in Security / SD-WAN
‎01-04-2023 12:07 PM
‎01-04-2023 12:07 PM
Thanks, this is making sense with my intermittent issues. I did some digging and the vlan that the server is on has a static route configured for the DNS server on a different subnet and that other subnet is using the L3 switch to reply going around the Meraki. Unfortunately to fix this there will probably be down time while I cut over the vlan from the L3 switch to the firewall. I was hoping I could build the vlan with a different gateway, trunk the vlan to the meraki, cut over the gateway on the DNS servers from the core, remove the static route. but it wont let me build the new vlan because it overlaps with the static route (as expected) I will just wait for after hours and make the changes probably. ... View more

Re: FQDN Policy object does not seem to be working

by DarrenH in Security / SD-WAN
‎01-04-2023 10:21 AM
‎01-04-2023 10:21 AM
same result, it is live so I had to roll it back but I am testing now using allow rules and logging to the syslog server first rule is the group 2nd is just the fqdn  3rd is the IP strange thing is that it logs just 2 times for the allow rule on the first one and then nothing, although I see more traffic when I look at the flow so the DNS is resolving. ... View more

Re: FQDN Policy object does not seem to be working

by DarrenH in Security / SD-WAN
‎01-04-2023 09:33 AM
‎01-04-2023 09:33 AM
it works if I remove the deny L3 rule for the server, so its more like the meraki is having issues with the DNS name ... View more

FQDN Policy object does not seem to be working

by DarrenH in Security / SD-WAN
‎01-04-2023 09:23 AM
‎01-04-2023 09:23 AM
So I have a policy object group that contains 2 domains (*.vendor.com,*.vendor.net) this group is linked to an allow L3 firewall rule.   I have a server that requires access to prod1.vendor.net attached to the allow, rule but the rule does not seem to be taking effect as in my syslog server I see deny hits and it is the IP address of prod1.vendor.net, what is the process that Meraki uses to resolve DNS names to the wildcard rules, other rules work just fine that use wild cards but this one does not. I have re created the rule and still have issues. ... View more
Kudos given to
User Count
PhilipDAth
Kind of a big deal PhilipDAth
1
View All
Powered by Khoros
custom.footer.
  • Community Guidelines
  • Cisco Privacy
  • Khoros Privacy
  • Privacy Settings
  • Terms of Use
© 2023 Meraki