Skip to main content

 

 

Cisco Defense Orchestrator

Manage Meraki Access Control Policy

Use this procedure to edit a Meraki access control policy using CDO:

  1. Open the Devices & Services page.
  2. Select the Meraki MX device template whose access control policy you want to edit. 
  3. In the Management pane at the right, select policy_shield_icon.png Policy.
  4. Do any of the following:
  • To create a new rule, click the blue plus button cli_create_plus.png.
  • To edit an existing rule, select the rule and click the edit button pencil.png in the Actions pane. (Simple edits may also be performed inline without entering edit mode.)
  • To delete a rule you no longer need, select the rule and click the remove button trash.png in the Actions pane.
  • To move a rule within the policy, select the rule in the access control table and click the up or down arrow at the end of the rule row to move the rule.

When editing or adding a rule, continue with the remaining steps in this procedure.

  1. In the Order field, select the position for the rule within the policy. Network traffic is evaluated against the list of rules in numerical order, 1 to "last."

Rules are applied on a first-match basis, so you must ensure that rules with highly specific traffic matching criteria appear above policies that have more general criteria that would otherwise apply to the matching traffic. 

The default is to add the rule to the end of the list. If you want to change a rule's location later, edit this option.

  1. Enter the rule name. You can use alphanumeric characters, spaces, and these special characters: + . _ -

Note: The Name of the access control rule is used as the name of the rule in CDO while the Remark field is treated as the name of the rule in the Meraki dashboard. The two fields are not dependent on each other. 

  1. Select the action to apply if the network traffic is matched by the rule: 

  • Block—Drop the traffic unconditionally. The traffic is not inspected.
  • Allow—Allow the traffic subject to the intrusion and other inspection settings in the policy.

Note: You can only set or modify the rule action. You cannot change the default policy action from CDO.  

  1. Define the traffic matching criteria by using any combination of attributes in the following tabs:
  • Source-Click the Source tab and add or remove networks (which includes networks and continents) or ports from which the network traffic originated. The default value is "Any." 
  • Destination—Click the Destination tab and add or remove networks (which includes networks and continents), or ports on which the traffic arrives. The default value is "Any."

Note: The source and destination networks must be within one of the configured VLAN subnets or, if a VLAN subnet is not manually configured, the default VPN subnet. Deploying a rule that includes an invalid source or destination network will fail. 

  1. Click Save.
  2. When you are ready, return to the Devices & Services page, select the device whose policy who changed, and click Preview and deploy... to deploy the changes to the device.

 

Related Articles:

  • Was this article helpful?