<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Upstream firewall rules in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/upstream-firewall-rules/m-p/5526844#M310495</link>
    <description>&lt;P&gt;&lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/1890"&gt;@jdb1&lt;/A&gt; &lt;BR /&gt;Okay, I think I'm following. So I am interpreting the rule wrong the document says inbound ..&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://documentation.meraki.com/General_Administration/Other_Topics/Upstream_Firewall_Rules_for_Cloud_Connectivity" target="_blank" rel="noopener nofollow noreferrer"&gt;https://documentation.meraki.com/General_Administration/Other_Topics/Upstream_Firewall_Rules_for_Cloud_Connectivity&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;so not inbound from the outside zone but inbound from the network the AP MGMT is on, destined for those 172 addresses. &lt;BR /&gt;&lt;BR /&gt;So the addressing under destination IP (172.19.0.25/32 and 172.25.0.25/32) are just examples then? I would put Source ip  = Meraki MR Management IP&lt;BR /&gt;Destination = RADUIS server&lt;BR /&gt;&lt;BR /&gt;Thanks for your help in advice. &lt;/P&gt;</description>
    <pubDate>Wed, 13 Jan 2021 16:14:52 GMT</pubDate>
    <dc:creator>ToryDavenport58911</dc:creator>
    <dc:date>2021-01-13T16:14:52Z</dc:date>
    <item>
      <title>Upstream firewall rules</title>
      <link>https://community.cisco.com/t5/wireless/upstream-firewall-rules/m-p/5526842#M310493</link>
      <description>&lt;P&gt;Would someone be able to explain to me what this rule is doing?&lt;BR /&gt;&lt;BR /&gt;Control traffic?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ToryDav_0-1610551621015.png" style="width: 800px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/269793iDC0044FE9D4077F2/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The customer has internal RADIUS so my understanding is that the firewall should allow RADIUS east/west though zones but this is inbound, and to seemingly private IP addressing. &lt;BR /&gt;&lt;BR /&gt;Tory&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 15:28:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/upstream-firewall-rules/m-p/5526842#M310493</guid>
      <dc:creator>ToryDavenport58911</dc:creator>
      <dc:date>2021-01-13T15:28:13Z</dc:date>
    </item>
    <item>
      <title>Re: Upstream firewall rules</title>
      <link>https://community.cisco.com/t5/wireless/upstream-firewall-rules/m-p/5526843#M310494</link>
      <description>&lt;P&gt;Thats the radius ip and port you configured.  Its should be able to communicate  to the meraki mr manamgement IP.  So in case you have any fw  between mr and radius server that fw should allow that flow&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 15:40:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/upstream-firewall-rules/m-p/5526843#M310494</guid>
      <dc:creator>ww^</dc:creator>
      <dc:date>2021-01-13T15:40:53Z</dc:date>
    </item>
    <item>
      <title>Re: Upstream firewall rules</title>
      <link>https://community.cisco.com/t5/wireless/upstream-firewall-rules/m-p/5526844#M310495</link>
      <description>&lt;P&gt;&lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/1890"&gt;@jdb1&lt;/A&gt; &lt;BR /&gt;Okay, I think I'm following. So I am interpreting the rule wrong the document says inbound ..&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://documentation.meraki.com/General_Administration/Other_Topics/Upstream_Firewall_Rules_for_Cloud_Connectivity" target="_blank" rel="noopener nofollow noreferrer"&gt;https://documentation.meraki.com/General_Administration/Other_Topics/Upstream_Firewall_Rules_for_Cloud_Connectivity&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;so not inbound from the outside zone but inbound from the network the AP MGMT is on, destined for those 172 addresses. &lt;BR /&gt;&lt;BR /&gt;So the addressing under destination IP (172.19.0.25/32 and 172.25.0.25/32) are just examples then? I would put Source ip  = Meraki MR Management IP&lt;BR /&gt;Destination = RADUIS server&lt;BR /&gt;&lt;BR /&gt;Thanks for your help in advice. &lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 16:14:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/upstream-firewall-rules/m-p/5526844#M310495</guid>
      <dc:creator>ToryDavenport58911</dc:creator>
      <dc:date>2021-01-13T16:14:52Z</dc:date>
    </item>
    <item>
      <title>Re: Upstream firewall rules</title>
      <link>https://community.cisco.com/t5/wireless/upstream-firewall-rules/m-p/5526845#M310496</link>
      <description>&lt;P&gt;That page is just a example. &lt;/P&gt;&lt;P&gt;The fw rules depends on if you configured the radius and on what meraki dc you are hosted etc.. If you dont have a radius server that rule is not present under help&amp;gt; fw info on your dashboard.&lt;/P&gt;&lt;P&gt;Yes source is &amp;lt;you networks ip&amp;gt; (management ip from switch,ap,mx)  dst  =radius ip&lt;/P&gt;&lt;P&gt;Not sure why i says  inbound (that would asume the radius server always initiates the session, im not sure about this), i would allow it both ways&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 16:30:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/upstream-firewall-rules/m-p/5526845#M310496</guid>
      <dc:creator>ww^</dc:creator>
      <dc:date>2021-01-13T16:30:44Z</dc:date>
    </item>
    <item>
      <title>Re: Upstream firewall rules</title>
      <link>https://community.cisco.com/t5/wireless/upstream-firewall-rules/m-p/5526846#M310497</link>
      <description>&lt;P&gt;On my "Help&amp;gt;Firewall Info" page, the field "Destination" is populated with my real RADIUS-server. I think it is taken from the dashboard-config.&lt;/P&gt;&lt;P&gt;For the firewall-rules:&lt;/P&gt;&lt;P&gt;Traffic to 1812/1813 is always from the NAD to the RADIUS-server, traffic initiated by the RADIUS-server is typically a CoA which runs on port 1700.&lt;/P&gt;&lt;P&gt;There is also one situation where this traffic is really "inbound": When the Meraki RADIUS-proxy is used. But I would not use it as long as there is no DTLS support.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 18:31:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/upstream-firewall-rules/m-p/5526846#M310497</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2021-01-13T18:31:03Z</dc:date>
    </item>
  </channel>
</rss>

