Summary:
Section titled “Summary:”Purpose of this article is to walk you through adding countries to the Geo-IP based Layer7 Firewall Rules in the Meraki Portal. The policy is set up to “Deny traffic NOT to/from the following countries: USA,CAN,UK. Countries not listed will be blocked.
To add countries to the allow list:
- Log into the Meraki Portal
- Go to Adstra>>>Datacenter
- Go to Security & SDWAN>>>Firewall>>>Layer7 Rules
- Add the country you wish to allow traffic to in the policy listed “Deny countries traffic not to/from:”
- Click Save. Wait at least 2 minutes after saving the configuration before having the client test it.
Assumptions, Risks, or Dependencies:
Section titled “Assumptions, Risks, or Dependencies:”Assumptions:
Section titled “Assumptions:”Assumes you have access to the Meraki Admin Portal. Assumes you have an approved request to add/remove countries to the access list. Assumes you have an understanding of firewall and switching concepts, including Meraki MX Appliances.
Section titled “Assumes you have access to the Meraki Admin Portal. Assumes you have an approved request to add/remove countries to the access list. Assumes you have an understanding of firewall and switching concepts, including Meraki MX Appliances.”Risks:
Section titled “Risks:”There are risks of causing unintended network interruptions if the policy is applied incorrectly. Conversely, you may open up network access to countries not approved if the policy is applied incorrectly.
Dependencies:
Section titled “Dependencies:”Dependent on admin access to the Meraki Admin Portal. Dependent on change control with vITM and Client approval to execute changes. Dependent on the Meraki Datacenter firewall, hostname: ALC-LWDC-MX-1
External References:
Section titled “External References:”- EXTERNAL only – i.e., industry best practices, CIS18, this is not for cIT internal references
https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/MX_Firewall_Settings 2. Add link to website, if applicable
Section titled “https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/MX_Firewall_Settings 2. Add link to website, if applicable”Note: Please add KB relationships to appropriate CI on the right.