<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Network Appliance L3 Firewall Rules in Network Platform API</title>
    <link>https://community.cisco.com/t5/network-platform-api/network-appliance-l3-firewall-rules/m-p/5431517#M5127</link>
    <description>&lt;P&gt;The default outbound rule is allow any-any.&lt;/P&gt;&lt;P&gt;Any additional rules you add are &lt;EM&gt;higher&lt;/EM&gt; priority than the default rule.&lt;/P&gt;&lt;P&gt;Traffic is tested against each rule, top-down in priority order.&lt;/P&gt;&lt;P&gt;If traffic does not match any of the deny/allow rules that you added, it will eventually match the default rule and be allowed.&lt;/P&gt;&lt;P&gt;This explains rule processing in more detail: &lt;A href="https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Layer_3_and_7_Firewall_Processing_Order" target="_blank" rel="noopener nofollow noreferrer"&gt;https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Layer_3_and_7_Firewall_Processing_Order&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 09 Mar 2023 08:21:09 GMT</pubDate>
    <dc:creator>sungod</dc:creator>
    <dc:date>2023-03-09T08:21:09Z</dc:date>
    <item>
      <title>Network Appliance L3 Firewall Rules</title>
      <link>https://community.cisco.com/t5/network-platform-api/network-appliance-l3-firewall-rules/m-p/5431516#M5126</link>
      <description>&lt;P&gt;Suppose you have an mx64 with outbound L3 firewall rules in place that are denying traffic to all three private subnet ranges, but then allowing to any other destination.  Will the host be able to reach internet, or traffic will be denied unless you specifically allow traffic to the gateway IP address for the host subnet on the MX?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 05:04:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-platform-api/network-appliance-l3-firewall-rules/m-p/5431516#M5126</guid>
      <dc:creator>as_</dc:creator>
      <dc:date>2023-03-09T05:04:04Z</dc:date>
    </item>
    <item>
      <title>Re: Network Appliance L3 Firewall Rules</title>
      <link>https://community.cisco.com/t5/network-platform-api/network-appliance-l3-firewall-rules/m-p/5431517#M5127</link>
      <description>&lt;P&gt;The default outbound rule is allow any-any.&lt;/P&gt;&lt;P&gt;Any additional rules you add are &lt;EM&gt;higher&lt;/EM&gt; priority than the default rule.&lt;/P&gt;&lt;P&gt;Traffic is tested against each rule, top-down in priority order.&lt;/P&gt;&lt;P&gt;If traffic does not match any of the deny/allow rules that you added, it will eventually match the default rule and be allowed.&lt;/P&gt;&lt;P&gt;This explains rule processing in more detail: &lt;A href="https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Layer_3_and_7_Firewall_Processing_Order" target="_blank" rel="noopener nofollow noreferrer"&gt;https://documentation.meraki.com/General_Administration/Cross-Platform_Content/Layer_3_and_7_Firewall_Processing_Order&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 08:21:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-platform-api/network-appliance-l3-firewall-rules/m-p/5431517#M5127</guid>
      <dc:creator>sungod</dc:creator>
      <dc:date>2023-03-09T08:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: Network Appliance L3 Firewall Rules</title>
      <link>https://community.cisco.com/t5/network-platform-api/network-appliance-l3-firewall-rules/m-p/5431518#M5128</link>
      <description>&lt;P&gt;Thank you for the link.  I am just wondering if a host is able to talk to it's gateway IP address on the MX, if you deny all private IP addressing.  &lt;BR /&gt;So for example, lets say you have a hosts on 192.168.0.0/24, with mx 192.168.0.1 and host is 192.168.0.5.  &lt;BR /&gt;And you first firewall rule say 192.168.0.5 is denied to 192.168.0.0/24.  Will the host still be able to reach the gateway?  Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 15:48:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-platform-api/network-appliance-l3-firewall-rules/m-p/5431518#M5128</guid>
      <dc:creator>as_</dc:creator>
      <dc:date>2023-03-09T15:48:52Z</dc:date>
    </item>
    <item>
      <title>Re: Network Appliance L3 Firewall Rules</title>
      <link>https://community.cisco.com/t5/network-platform-api/network-appliance-l3-firewall-rules/m-p/5431519#M5129</link>
      <description>&lt;P&gt;It won't block intra-vlan traffic ( L2 ). Simply L3 trafic.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 16:07:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-platform-api/network-appliance-l3-firewall-rules/m-p/5431519#M5129</guid>
      <dc:creator>Raphael_L</dc:creator>
      <dc:date>2023-03-09T16:07:13Z</dc:date>
    </item>
    <item>
      <title>Re: Network Appliance L3 Firewall Rules</title>
      <link>https://community.cisco.com/t5/network-platform-api/network-appliance-l3-firewall-rules/m-p/5431520#M5130</link>
      <description>&lt;P&gt;You don't need to allow traffic to your MX IP for clients to be able to connect to the internet.  The MX will evaluate SRC and DST IP's by the rules that are configured.  So if a deny to private addresses is present but an allow any behind it then your devices will reach the internet just fine.  This is in fact the way you can have internet only VLANs.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 21:25:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-platform-api/network-appliance-l3-firewall-rules/m-p/5431520#M5130</guid>
      <dc:creator>joey.debra</dc:creator>
      <dc:date>2023-03-09T21:25:42Z</dc:date>
    </item>
    <item>
      <title>Re: Network Appliance L3 Firewall Rules</title>
      <link>https://community.cisco.com/t5/network-platform-api/network-appliance-l3-firewall-rules/m-p/5431521#M5131</link>
      <description>&lt;P&gt;So for example, if you have a host 192.168.0.5 that needs to talk to the gateway 192.168.0.1/24, and your first outbound l3 firewall rule is that 192.168.0.5 is denied to 192.168.0.0/24, traffic will still go through because it's intra-vlan traffic, right?  &lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 22:42:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-platform-api/network-appliance-l3-firewall-rules/m-p/5431521#M5131</guid>
      <dc:creator>as_</dc:creator>
      <dc:date>2023-03-09T22:42:04Z</dc:date>
    </item>
  </channel>
</rss>

