Firewall SD-WAN Traffic on MX65 or MX68?

Solved
j_e_m_67
Here to help

Firewall SD-WAN Traffic on MX65 or MX68?

I tried using the Firewall but doesn't match any SD WAN traffic, not seeing any hits. I could do this on Velocloud so not sure how this works on Meraki. I couldn't find documentation on anything related to firewalling SD WAN traffic. Thanks for any help!

 

I will elaborate, I have SD WAN configured and is working fine. I would like to block certain traffic from being allowed over SD WAN from one of the spoke sites to the Hub. 

1 Accepted Solution
Brash
Kind of a big deal
Kind of a big deal

L3 firewall rules don't apply so Auto-VPN traffic. You instead need to configure site-to-site VPN firewall rules (which are org wide)

https://documentation.meraki.com/MX/Site-to-site_VPN/Site-to-site_VPN_Firewall_Rule_Behavior

View solution in original post

4 Replies 4
alemabrahao
Kind of a big deal
Kind of a big deal

The SD-WAN will work on any MX model.

 

https://documentation.meraki.com/Architectures_and_Best_Practices/Cisco_Meraki_Best_Practice_Design/...

 

https://meraki.cisco.com/product-collateral/mx-family-datasheet/?file

 

https://documentation.meraki.com/General_Administration/Licensing/Meraki_MX_Security_and_SD-WAN_Lice...

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.

Take a look at this article.

 

https://meraki.cisco.com/blog/2018/07/sd-wan/

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Brash
Kind of a big deal
Kind of a big deal

L3 firewall rules don't apply so Auto-VPN traffic. You instead need to configure site-to-site VPN firewall rules (which are org wide)

https://documentation.meraki.com/MX/Site-to-site_VPN/Site-to-site_VPN_Firewall_Rule_Behavior

j_e_m_67
Here to help

Thanks Brash, that is what I was needing!

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels